How a hacker's typo helped stop a billion dollar bank heist
reuters.com
reuters.com
The subject of the email was "Please see attached documens" in which a PDF was attached that upon opening would hijack your email account and send the same. Over the first day, I had about 100 emails from coworkers in my inbox. After our "IT Security" team sent out an email claiming they stopped the threat, the following day more emails came from coworkers that was a slight variant but had more typos.
I still wonder what sort of breach occurred and whether our internal teams performed a true investigation... obviously a foreign intrusion and they managed to at least gain control of quite a few internal machines.
I still get a laugh out of using the same subject in an occasional email to coworkers...
I think I'm stuck at how code is able to execute when opening a document inside a PDF viewer or something of the sort. Thanks for sharing your story!
The typical defenses against these attacks include:
* Exploit mitigation tools, such as EMET
* Writing applications to be more memory-safe
* Various other tactics, many of them disingenuous.
I am sure that the Bangladesh Central Bank could have requested daily or transaction limits for their accounts. But they most likely did not have that in place. Being a government bank they might make $20M transactions on a daily basis. They probably also could have 2-factor authentication, but that won't help you if its an inside job.
The most telling part of the story is that you can transfer $80M into Manila casinos (a city I didn't even know had casinos before today) and get that in chips without any trouble. I can't even imagine the volume of money flowing in Vegas or Macau casinos.
Reminds me of http://www.theguardian.com/business/2015/oct/20/deutsche-ban...