How Hackers Stole $100M from the New York Fed
zerohedge.com
zerohedge.com
At the time, 10 years ago, we didn't even have ability to parse or OCR the images. I was really disappointed in how low tech this was, and how easy it would have been to make it better.
Perhaps I only saw a piece of it, and it did have more going on. But I always thought "what's preventing someone from faxing in a false trade?" We would execute any trade that got faxed in if the letter head and account numbers looked normal.
But this was for front office and back office. Access to all keys. Small team, 10 people.
That's important.
Knew how much we had in the petty cash bank account. Usually around USD 40MM. Liquidity usage, etc. Also had access to the cheque book (via key locked cabinet), where via sealed internal mail, cash payment requests (cheque) were sent to the banking department.
Speaking to a friend in the banking department, he remarked that whitelists of authorised payment receivers where being introduced. Being introduced? "Sure, if a payment request comes in, and it is authorised correctly (signature, in case of cheques), we send it ASAP." "Do you telephone the signer to verify? No." "Any transaction limits?" "No." This was 2005.
Could have walked away with USD 40MM - then fled rapidly to another country. But didn't. Well, did go to another country.
2 factor authentication is essential, and whitelists too - a central bank doesn't change their account number. The FED seems to have had neither.
http://www.scmp.com/news/asia/south-asia/article/1922556/ban...
VICE: "The Fed had the responsibility to keep the money safe," Shamim Ahamad, press minister at the Bangladesh Embassy in Washington, told VICE News. "We are suspecting that Chinese hackers have done it."
https://news.vice.com/article/bangladeshs-central-bank-accus...
"""
Security experts said that to pull off the attack, cyber criminals had to first gather information about Bangladesh Bank's procedures for ordering transfers, so that the fraudulent requests would not raise red flags.
In addition to stealing credentials for processing transfers, the hackers likely spied on Bangladesh Bank staff to get a deep understanding of the central bank's operations, according to experts in banking fraud.
Kayvan Alikhani, a senior director with security firm RSA, said that in addition to user names and passwords for accessing SWIFT, the hackers likely needed to obtain cryptographic keys that authenticated the senders.
"""
So maybe insiders were involved?
http://www.reuters.com/article/us-usa-fed-bangladesh-idUSKCN...
If SWIFT security is really as bad as this incident seems to suggest, I'm shocked that more fraudulent transfers don't occur.
It sort of sounds (from the public information) like the Bangladeshi bank's credentials were compromised and used to make fraudulent transfer requests to the NY Fed.
That's not really a problem with SWIFT. Arguably the NY Fed should have flagged the requests as suspicious, but that's probably a best-effort kinda thing.
http://business.inquirer.net/207742/100-m-laundering-via-ph-...
> a total of $100 million that was brought into the country’s banking system, sold to a black market foreign exchange broker, transferred to at least three large local casinos, sold back to the money broker and moved out to overseas accounts.
Here's how I think that this heist went and I am just speculating here based solely on the info in the report:
- They first wired the money to multiple accounts of a secondary financial institution (Remittance or FX business) which is characterized by heavy and frequent transactions so as not to raise suspicions.
- They collected the money with the help of the facilitator in that organization.
- They exchanged the dollars into pesos and likely in counterfeit bills at very lucrative rates just to account for the risks hoping for more rewards from the operation.
- They took the money and deposited them in the casinos for ships settling debts and laundering the money in the process.
- They traded the chips for authentic cash from the casinos and then went back to their FX broker to exchange it back in USD.
- Finally, they reached out to their man at the FX/remittance business to have the funds wired overseas to the final recipients and probably masked with other legitimate transactions for better security for them.
Having money in an account is useless as long as it can be traced to the fraudulent transfer. So you move the money through a casino or any other large scale cash flow, such as counterfeiting (buy fake money for cents in the fake dollar and then sell it at a loss somewhere else)
Treasury ops at banks live in fear of clients getting ripped off like this. The liability is probably not the Fed's, but the reputation hit from large value transfer fraud is enough that loss of client business is a very real possibility.
Consider also that the Fed is also facing competition in the intra-government "hold my cash" business from the Chinese, and this could be the first reputational domino in a real geopolitical shift in how funds are held and managed internationally.
There's more at play here than Bangladesh getting ripped off.
"In other words, the Fed was funding gamblers, only these were located in Philippine casinos, not in the financial district. Ironically, that's precisely what the Fed does, only it normally operates with gamblers operating out of Manhattan's financial district."
http://www.bloomberg.com/news/features/2015-02-05/germany-s-...
EDIT: Although maybe you're right, if the "gamblers" deposited funds to the casino via wire, direct from the fed, and then exchanged them for chips. So the casinos should presumably have some record of who came to claim that wire in chips.
Do you have evidence for this? I find it rather plausible that casinos have anti-fraud measures built into their chips to allow tracking of where each chip came from.
EDIT: A quick google shows this is indeed the case for some casinos at least: http://singularityhub.com/2011/02/12/1-5m-robbery-of-bellagi...
Typical player tracking is done through comp cards, where they account for your buy-ins at the table, and buy out at the cashier.
and how would casino be laundering money then? :)
they do need plausible lack of total control and accounting of all chips' movements.
Casinos have cameras at the cage, and beyond that cash transactions in a casino have the same reportability as cash transactions everywhere. If it's in the US that means IRS paperwork at $10k. I have no idea what the limits are in the Philippines, but I'll bet they have video of the people who collected the money.
Chips can be flagged or invalidated by serial number.
[1] http://singularityhub.com/2011/02/12/1-5m-robbery-of-bellagi... [2] http://www.cnbc.com/2014/04/16/cheaters-may-speed-need-for-p... [3] http://www.gpigaming.com/rfid-technology/rfid-in-casino-chip...
PS: In the US the government requires casino's to track large winnings for the IRS they hand out W9's.
The best way to legally launder money is to use a casino. You bring in your dirty money, exchange it for chips. Then sit on your chips for a week, maybe a month, then go back and cash out your chips for clean money.
Meanwhile, all the cash you moved through the casino is now scattered to some 50-100 different banks as it gets deposited in their daily drops and then transferred as necessary between the banks. In a few weeks, the dirty money is albeit untraceable.
You showed up with lets say $50k at the casino, you departed with the same $50k. If you'll be investigated, you still can't justify the money you walked in with.
CA2, CA3 and CA4 come into the casino a few different times over several months, gamble for while for a net zero gain or loss, and then convert their "winnings" from chips into cash in chunks of $5k or so - flying under the radar.
C1 never needs to come back to the casino where the police might catch him - and he is the only one who is linked to the big heist.
If the casino isn't involved in the scheme, how can a thief take that $100M, using chips or not?
I consider the Daily Show both, as do many others.
Typical ZH logic: when gold goes up, it's the smart investors noticing the corruption of the "markets" and acting accordingly. When gold goes down, it's the HFTs and the Feds slamming it down because if it goes up it destroys the faith in the US Dollar. If it spikes up, it smart money doing a play. If it spikes down, it's blatant manipulation by someone without a "fiduciary duty" (ie: they imply that the seller doesn't care that he loses money because it sells quickly instead of working the order more slowly)
http://www.zerohedge.com/news/2016-03-10/world-economy-wreck...
ZeroHedge is full of conspiracy theories about the banks, Fed, EU, and the Western World in general. On the other hand, whatever Russia or China does, especially militarily, is great and shows good leadership.
Even this article starts by accusing the Fed multiple times of not noticing the fraudulent wire transfers, when in fact towards the end they say that the feds stopped 90% of the fraudulent transfers and notified the Bangladesh central bank of irregularities!
I submit the 'China' category page as a counter-argument: http://www.zerohedge.com/taxonomy/term/139
If you just want one recent story, here: http://www.zerohedge.com/news/2016-03-10/world-economy-wreck...
But if you read the articles, you'll see that ZH has a very favorable opinion of China, especially when it provokes the US, like the current situation in the Spratly islands
However Russia, I never ever saw a bad article about them, or especially about Vlad, which is the current ZH hero.
I wonder if you can burn zerohedge at 451 degrees?
On HN we care about about the quality of the story, not the site. Of course, the two are related; sites are penalized or banned here according to the probability of their stories not being good based on past experience. But it's important to leave room for exceptions.
They hacked the Bangladesh Central Bank, but stole money from the New York Fed. It is even debatable if the NY Fed is even at fault given that the hackers had legitimate credentials to make the transfer (the Bangladeshis are arguing that the NY Fed is still responsible because they should have flagged the Casinos as unusual and stopped it).
You'd think that with accounts as large as these they would have a "whitelist" of valid accounts to transfer funds to, and some long convoluted process to add additional whitelist entries.