Daily Nation Newspaper

HOW HACKERS USED BETTING SITE TO ACCESS AIRTEL MONEY IN UGANDA

-

KAMPALA - Black hats hackers used the website of a gaming platform in Uganda to plunder money from the systems of Airtel Mobile Commerce Uganda Limited (AMCUL), making away with about $2 million.

While the licensed betting firm’s website prides itself on making “use of standard encryption to protect the data of its users,” cybercrimi­nals used it as a gateway to Airtel Money’s digital systems.

After tweaking AMCUL’s software to approve transancti­ons, the hackers drained its central systems of just under $2.1 million in a meticulous­ly planned operation.

The hack affected a number of banks and microfinan­ce deposit-taking institutio­ns operating in Uganda. The Monitor understand­s that one of the microfinan­ce deposit-taking institutio­ns filed an official complaint with Cyber and Counter Electronic Measure Desk at Criminal Investigat­ions Directorat­e (CID) headquarte­rs in Kibuli, Kampala.

Black box attack

Initial investigat­ions indicate that the hackers accessed Airtel Money systems via one of its clients - the betting firm, whose name has been withheld. Punters who use the gaming platform to load virtual bet slips stake bets only after crediting their accounts with mobile money on Airtel or MTN.

CID detectives told Monitor that when the black hats accessed AMCUL’s systems they launched what is known in the hacking underworld as a black box attack. Multiple accounts of banks and microfinan­ce institutio­ns bore the brunt of the ‘jackpottin­g’ with money mules acting on behalf of the black hats receiving mobile money from the hack.

Monitor learnt that 1,840 registered and preregiste­red SIM cards were readied for big withdrawal­s. Sources say that the hackers had completed transactio­ns on 1,800 of the SIM cards before the daring raid was stopped in its tracks.

In a statement, Airtel Uganda said the “incident did not impact any Airtel Money or bank balances.” It added that “our platform is secure and built to world-class specificat­ions to give our Airtel Money customers an instant, safe and secure experience.”

Attempts to talk to the top brass of the betting firm were unsuccessf­ul. The daring raid on AMCUL’s digital systems took place on October 28.

– MONITOR, Uganda.

Newspapers in English

Newspapers from Zambia