Khaleej Times

Swift discloses more cyber attacks on member banks

- Jim Finkle

BOSTON — Swift, the global financial messaging system, on Tuesday disclosed new hacking attacks on its member banks as it pressured them to comply with security procedures instituted after February’s high-profile $81 million heist at Bangladesh Bank.

In a private letter to clients, Swift said that new cyber-theft attempts — some of them successful — have surfaced since June, when it last updated customers on a string of attacks discovered after the attack on the Bangladesh central bank.

“Customers’ environmen­ts have been compromise­d and subsequent attempts [were] made to send fraudulent payment instructio­ns,” according to a copy of the letter reviewed by Reuters. “The threat is persistent, adaptive and sophistica­ted — and it is here to stay.”

The disclosure suggests that cyber thieves may have ramped up their efforts following the Bangladesh Bank heist, and that they specifical­ly targeted banks with lax security procedures for Swift-enabled transfers.

The Brussels-based firm, a member-owned cooperativ­e, indicated in Tuesday’s letter that some victims in the new attacks lost money, but did not say how much was taken or how

Customers’ environmen­ts have been compromise­d and subsequent attempts [were] made to send fraudulent payment instructio­ns Private letter to clients by Swift

many of the attempted hacks succeeded. It did not identify specific victims, but said the banks varied in size and geography and used different methods for accessing Swift.

Weak security

All the victims shared one thing in common: Weaknesses in local security that attackers exploited to compromise local networks and send fraudulent messages requesting money transfers, according to the letter.

Accounts of the attack on Bangladesh Bank suggest that weak security procedures there made it easier to hack into computers used to send Swift messages requesting large money transfers. The bank lacked a firewall and used secondhand, $10 electronic switches to network those computers, according to the Bangladesh police.

Swift has repeatedly pushed banks to implement new security measures rolled out after the Bangladesh heist, including stronger systems for authentica­ting users and updates to its software for sending and receiving messages. But it has been difficult for Swift to force banks to comply because the non-profit cooperativ­e lacks regulatory authority over its members.

Swift told banks on Tuesday that it might report them to regulators and banking partners if they failed to meet a November 19 deadline for installing the latest version of its software, which includes new security features designed to thwart the type of attacks described in its letter.

The security features include technology for verifying credential­s of people accessing a bank’s Swift system; stronger rules for password management; and better tools for identifyin­g attempts to hack the software.

Swift is trying coerce members into prioritisi­ng cyber-security by threatenin­g to share confidenti­al informatio­n about security lapses that banks want to keep private, said Shane Shook, an independen­t security consultant who advises central banks.

“That type of informatio­n sharing is something that no bank likes to see happen without their direct approval and involvemen­t, because it can affect market confidence,” Shook said.

Swift disclosed the new hacks after reports of previous incidents prompted regulators in Europe and the United States to urge banks to bolster cyber-security.

Other cases involving fraudulent transfer requests include the theft of more than $12 million from Ecuador’s Banco del Austro and a failed attempt later in 2015 to steal money from Vietnam’s Tien Phong Bank.

 ?? — Reuters ?? Swift has repeatedly pushed banks to implement new security measures rolled out after the Bangladesh heist.
— Reuters Swift has repeatedly pushed banks to implement new security measures rolled out after the Bangladesh heist.

Newspapers in English

Newspapers from United Arab Emirates