LockBit claims to exfiltrate 33TB of data from US Federal Reserve
securityaffairs.com
securityaffairs.com
Banks don't systematically hand over account-level data to the FDIC, much less for insurance.
If it's technical analysis data ("In October 1957, Idaho produced X tons of potatoes..."), then it's less interesting.
Department of Homeland Security, I imagine. Probably the IRS too. Probably not the Fed, they can't really do anything with the data other than report it to someone else.
FedACH processes roughly half of all ACH transfers, which include effectively all payroll direct deposit transactions in the US.
Yes. FedNow and FedWire are real-time rails.
FedACH is net settled, but I believe the Fed would see the full contents of each ACH message.
This is the definition of a Net settlement scheme (multiple transactions are combined at end of a period, resulting in only the net changes being transferred), not a Gross settlement scheme.
That's how wire transfers work in the US, for example, and that's one reason why they're more expensive than ACH: Without netting, transfers actually reduce reserves, and by extension liquidity, from the sending bank in real time.
FedACH in particular is a retail payment service, and the operator would have visibility into individual transactions, I believe.
The Fed charges between 4 and 19¢ for a wire [1]. For the delta to be explained by the cost of warehousing reserves, we'd need to assume Zimbabwean costs of capital for the big banks.
RTGS is fundamentally more expensive than net settling. But wires are expensive because we're getting hosed. (If you wire frequently, there are banks that won't charge you for it, e.g. Fidelity.)
[1] https://www.frbservices.org/resources/fees/wires-2024 if you're a small bank, it could be as much as 95¢
If it were, FedNow (which is also real-time, although I'm not sure on whether it's also real-time settled) and non-US equivalents would be equally expensive, yet SEPA instant and FPS are usually free to consumers. They do have an amount cap per day, though.
Weirdly, 100k is not an absolute limit; the scheme allows banks to have bilateral agreements to exceed it, though I’m not sure how common this is.
Some banks offer "rush payments" for that use case in particular, which I believe essentially correspond to either an RTGS payment and a phone call or fax to the receiving bank ("hey, can you check your TARGET2 account real quick for our transfer <reference> and credit your account x for the sum please?"), or just a regular old SEPA credit transfer with somebody making sure that it's not caught in some AML or fraud control queue for several days. It's not a pan-European standardized scheme, in any case.
This is related to fraud risk, which is only ameliorated by net-settlement systems in that they're slower. (An RTGS with a built-in delay would have a similar fraud profile.)
Wires' immutability makes them both ideal for large transactions and more risky for fraud. If I understand correctly, FedNow payments are reversible.
In essence, you have to pick two among fast settlement, immutability and low cost. FedWire is fast and immutable and low cost at volume. FedNow is fast and low cost. ACH is stupid.
There must be some cost of capital associated with needing reserve buffers for outgoing instant payments sent outside of the operating hours of the interbank money market and the Fed discount window.
In the end, both effects (cost of fraud and cost of liquidity) will of course get baked into the cost per dollar to the banks and it might be hard to untangle them.
Correct.
The average FedWire is $5.4mm [1]. The Fed Funds rate is 5.3% [2]. ACH settles in 1 to 3 business days [3]. Actual/360, that's $800 to 2,400 to finance wholesale.
If, on the other hand, you're JPMorgan and can pay 2 bps for deposits [4], that cost drops to $3 to 9. These are the economics that drive bank consolidation.
[1] https://www.frbservices.org/resources/financial-services/wir...
[3] https://www.frbservices.org/resources/resource-centers/same-...
[2] https://fred.stlouisfed.org/series/fedfunds
[4] https://www.chase.com/content/dam/chase-ux/ratesheets/pdfs/r...
There were many (almost all) journalists and intelligence professionals that claimed the Hunter Laptop was not real… except of course it was and entered into evidence in his gun trail and conviction recently.
The only thing that turned out to be true and actually criminal was that Hunter Biden acquired a gun while forbidden from doing so, for which he was recently convicted.
[1] https://en.wikipedia.org/wiki/Hunter_Biden_laptop_controvers...
[2] https://en.wikipedia.org/wiki/Biden%E2%80%93Ukraine_conspira...
50 intelligence officials signed a politically motivated letter to cast doubt on the authenticity of any of this[0] and the majority of media outlets inferred that it not only could be misinformation, but that it was and gaslighted anyone who alleged differently. The officials opinion was wrong from the outset, and appears to have been a screen for a very politically connected family.
0 - https://www.politico.com/f/?id=00000175-4393-d7aa-af77-579f9...
The dump from their Boeing hack was excruciatingly boring.
Trust in the Federal Reserve, and ignorance of its function, can be a strong partisan issue without waiting for a payload.
Humans can spontaneously self organise to a surprising extent. No government was behind Reddit's meme trading, for instance.
Not saying you're wrong. Just that spontaneous bursts of organisation aren't per se evidence of outside influence.
Why restrict the data to journalists when it causes much more harm to the breached org for other criminals to get the data?
Yea. Windows sucks, but that is often off topic.
The rest of the list was off the top of my head. Other than WannaCry and Stux, how many large scale windows malwares can you name without looking them up?
I guess you could call it social engineering, but it seems like the words Microsoft Outlook and Active Directory are way overrepresented in these attack vectors (hopefully not in this particular case.)