Wednesday, January 20, 2021
  • Delphix Closes Critical Data Gap in Ransomware Protection for Enterprises
  • Everything we know about the SolarWinds Orion app vulnerability
  • Part 1 – Rancher Kubernetes Engine (RKE) Security Best Practices for Cluster Setup
  • How Utilities Can Mitigate Cyberthreats
  • Improving Your Security Posture with the Pipeline Cybersecurity Initiative

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Bloggers Network
    • Latest Posts
    • Contributors
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming
    • On-Demand
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
  • Library
  • Related Sites
    • MediaOps Inc.
    • DevOps.com
    • Container Journal
    • Digital Anarchist
    • SweetCode.io
  • Media Kit

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Data Security Malware Security Bloggers Network 

Home » Cybersecurity » Data Security » Hackers steal $13.5 million from Indian bank in global attack

Hackers steal $13.5 million from Indian bank in global attack

by Graham Cluley on August 16, 2018

Hackers planted malware on an automated teller machine (ATM) server belonging to an Indian bank as part of a criminal scheme which saw the theft of nearly 944 million rupees (US $13.5 million) in a co-ordinated attack across 28 countries last weekend.

India’s Cosmos Bank, based in the western city of Pune, suffered an attack which saw hackers use malware to steal customer information from the company’s ATM server, and then use that data to clone thousands of Visa and RuPay debit cards.

The debit cards were then used over the course of the weekend in a number of countries including Canada, Hong Kong, and India. In all, 14,859 transactions were made at cash machines – stealing a total of 805 million rupees.

To add insult to injury, the hackers also transferred 139 million rupees to a Hong Kong-based bank account by ordering three unauthorised transactions over the SWIFT inter-bank communication network.

SWIFT (the Society for Worldwide Interbank Financial Telecommunications) is the system that is normally used by banks to send money securely to each other around the world.

However, in recent years cybercriminals have targeted the finance industry’s usage of SWIFT to attempt to steal large amounts of money. Perhaps the most notorious incident occurred in February 2016, when hackers attempted to transfer $951 million from a Bangladesh bank to accounts in the Philippines, successfully making off with a (still impressive) $81 million.

Similar attacks have plagued banks worldwide as they have been targeted with bespoke malware.

Cosmos Bank told the press that the attackers managed to bypass a debit card payment request “switching system” used by its main banking software during the attack:

“During the malware attack, a proxy switch was created and all the fraudulent payment approvals were passed by the proxy switching system.”

The (Read more...)

*** This is a Security Bloggers Network syndicated blog from The State of Security authored by Graham Cluley. Read the original post at: https://www.tripwire.com/state-of-security/security-data-protection/hackers-indian-bank-attack/

August 16, 2018August 16, 2018 Graham Cluley banking, Featured Articles, IT Security and Data Protection, Malware, SWIFT
  • ← New Foreshadow Vulnerabilities Defeat Memory Defenses on Intel CPUs
  • The Seven Security Sessions Not to Miss at VMworld 2018 →

TechStrong TV – Live

Watch latest episodes and shows
Featured Blog

Eric Kedrosky

The Future of Multi-Cloud Security: A Look Ahead at Intelligent Cloud Security Posture Management Solutions

Pam Sornson, JD – Contributed Writer

IAM Best Practices For DevOps

Eric Kedrosky

Identity Risk: Identifying a Misconfigured IAM Trust Policy

Subscribe to our Newsletters

Get breaking news, free eBooks and upcoming events delivered to your inbox.
  • View Security Boulevard Privacy Policy

Most Read on the Boulevard

Revealed: Sophisticated ‘Watering Hole’ Attack – But By Whom?
Managing Identities and Entitlements to Secure the Public Cloud 
Capitol Rioters ID’ed With Help From Dating Apps
Hackers Calling Fair Game on Healthcare Institutions
Is MDR Cybersecurity Training an Oxymoron?
Amanda Gorman: “The Hill We Climb” to be Biden’s Inaugural Poem
How Are Cybercriminals Stealing Business Data?
Security as Code: Why It’s Important and What You Need to Know
People, Process and Technology: Six Best Practices for Cloud Least Privilege
DDoS Response Guide

Upcoming Webinars

Wed 20

Vulnerability Discovery in the Cloud

January 20 @ 3:00 pm - 4:00 pm
Thu 21

Next Generation Vulnerability Assessment Using Datadog and Snyk

January 21 @ 1:00 pm - 2:00 pm
Mon 25

Security Challenges and Opportunities of Remote Work

January 25 @ 1:00 pm - 2:00 pm
Tue 26

Preventing Code Tampering & Verifying Integrity Across Your SDLC

January 26 @ 1:00 pm - 2:00 pm
Thu 28

Protecting Cloud-Native Apps and APIs in Kubernetes Environments

January 28 @ 1:00 pm - 2:00 pm
Feb 03

Too Close to the Sun(burst): A Supply Chain Compromise

February 3 @ 11:00 am - 12:00 pm
Feb 04

Lessons from the FinTech Trenches: Securing APIs at Finastra

February 4 @ 3:00 pm - 4:00 pm
Feb 10

Finding Vulnerabilities in Your Cloud Native Applications Before They Find You!

February 10 @ 11:00 am - 12:00 pm
Feb 11

How to Merge AppSec and DevOps Effectively for the Good of Software

February 11 @ 3:00 pm - 4:00 pm
Feb 17

Finding and Preventing Secrets in Code

February 17 @ 3:00 pm - 4:00 pm

More Webinars

Download Free eBook

Managing the AppSec Toolstack

Recent Security Boulevard Chats

  • Cloud, DevSecOps and Network Security, All Together?
  • Security-as-Code with Tim Jefferson, Barracuda Networks
  • ASRTM with Rohit Sethi, Security Compass
  • Deception: Art or Science, Ofer Israeli, Illusive Networks
  • Tips to Secure IoT and Connected Systems w/ DigiCert

Industry Spotlight

How Utilities Can Mitigate Cyberthreats
Cybersecurity Industry Spotlight Security Boulevard (Original) 

How Utilities Can Mitigate Cyberthreats

January 20, 2021 David Goddard | 7 hours ago 0
Bringing Source Code Security Up to Speed
Application Security Cybersecurity Identity & Access Industry Spotlight Security Boulevard (Original) 

Bringing Source Code Security Up to Speed

January 19, 2021 Dor Atias | Yesterday 0
Hackers Calling Fair Game on Healthcare Institutions
CISO Suite Cybersecurity Data Security Governance, Risk & Compliance Industry Spotlight Security Boulevard (Original) Threat Intelligence 

Hackers Calling Fair Game on Healthcare Institutions

January 18, 2021 Caleb Barlow | 2 days ago 0

Top Stories

Capitol Rioters ID’ed With Help From Dating Apps
Cyberlaw Cybersecurity Featured Incident Response Mobile Security News Security Awareness Security Boulevard (Original) Social Engineering Spotlight Threat Intelligence 

Capitol Rioters ID’ed With Help From Dating Apps

January 18, 2021 Richi Jennings | 1 day ago 0
Revealed: Sophisticated ‘Watering Hole’ Attack – But By Whom?
Analytics & Intelligence Cybersecurity Featured Incident Response Malware Mobile Security News Security Boulevard (Original) Spotlight Threat Intelligence Threats & Breaches Vulnerabilities 

Revealed: Sophisticated ‘Watering Hole’ Attack – But By Whom?

January 15, 2021 Richi Jennings | 4 days ago 0
Hackers Didn’t Only Use SolarWinds to Break In, Says CISA
Analytics & Intelligence Application Security Cloud Security Cyberlaw Cybersecurity Data Security Featured Incident Response Malware Network Security News Security Boulevard (Original) Spotlight Threat Intelligence Threats & Breaches Vulnerabilities 

Hackers Didn’t Only Use SolarWinds to Break In, Says CISA

January 11, 2021 Richi Jennings | Jan 11 0

Security Humor

via     the comic delivery system monikered   Randall Munroe   resident at   XKCD  !

XKCD ‘Pulsar Analogy’

Join the Community

  • Add your blog to Security Bloggers Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: info@securityboulevard.com

Useful Links

  • About
  • Media Kit
  • Sponsors Info
  • Copyright
  • TOS
  • Privacy Policy
  • DMCA Compliance Statement

Other Mediaops Sites

  • Container Journal
  • DevOps.com
  • DevOps Connect
  • DevOps Institute
Copyright © 2021 MediaOps Inc. All rights reserved.
Our website uses cookies. By continuing to browse the website you are agreeing to our use of cookies. For more information on how we use cookies and how you can disable them, please read our Privacy Policy.