How I 'stole' $14 million from a bank: A security tester's tale
money.cnn.com
money.cnn.com
Another common issue is find a fire exit with disgarded cigerrete butt's and odds are somebody has taped over the door sensor or disabled it and you can just break into the building that way without an alarm going of. Done the going in as weekend to do a cleaning job which was covert security audit and found we could of just gone up the external staircase and in via a fire exit thanks to smokers and there adictions.
Also was common on trading floors to find unapproved modems so the blessed keeness could catch up from home or at weekends, nowadays how many end up trojaning there own pc's so they can remotly work without official sanction from IT and the security department.
Biggest fault in most systems will be the staff, one way or another, intended or not.
Like I said, more you look into it the more you store under your matress :).
I remember the first time I discovered this is how banks operate when I was a kid. It's really pretty mind-blowing when you think about it. And knowing how full of bugs most software is it really made me question the entire banking system. (My mind has still yet to be put at ease on that...)
But that hasn't been the case for a long time. Today, money is just a few bits in a database here and there. And of course, making yourself a millionare (or billionare) is as easy as inserting a row into a database.
Here is the important part: While the article insinuates this creation of money out of thin air as a victim-less crime, it is not!
Even worse, the bank does not lose a penny from this type of criminal activity. The ones who pay for it? We all do. By creating money out of thin air, you are increasing the money supply, which pushes up inflation due to higher demand for goods, which in turns reduces the value of the currency.
In other words, when you create money out of thin air like this, you are taking a tiny bit from everybody who uses the currency! Theft on an absolutely universal and massive scale!
It's just that, to a huge organisation, a $14 million accountancy error could go unnoticed for a long time. Likewise, a dollar or two missing from my piggy bank will probably not be noticed. Merely a question of scale, but the loss is still there.
Banks can't do that right now anyway. Banks only hold onto cash to meet reserve requirements, which is a fraction of the deposits held for depositors. If everyone tried in a bank to withdraw cash, you'd have a run.
Please explain this.
Almost all significant transactions are electronic now. Nobody withdraws millions of dollars in physical currency.
You're just modifying rows in a database.
All the bank would do is tell the other bank that they have the money now and debit a database row which was fake to begin with?
I'd suggest that the hackers who manage to alter their balance are exceedingly likely to be the kind of people to try and obtain a physical withdrawal of their wealth!
But even in electronic form, there is some settlement going on behind the scenes. Let's say I hack my bank and give myself $100 billion dollars, then try and transfer this to another bank in a country with a suitable lack of extradition treaties. No receiving bank is going to blindly accept a transfer in of $100 billion. Do you think they just take the other bank's word for it, that they are good for the money?
Let's say I frequently lend cash to a wide circle of friends, and they lend cash to me too. Because my memory is bad, I have to keep track of things by writing down the debts on a piece of paper, e.g. "Bob owes me $5, I owe Kathy $10" and so on.
In effect, what these hackers have done is to steal my piece of paper while I'm not looking and scribble "I owe Mr hax0r $10" on the bottom of it.
Now, who have they stolen from? Me, of course! I will blindly pay them out $10 should they ask for it. Has Bob lost money? No. Has Kathy lost money? No. Has money magically been created and cost everyone in the world fractions of a cent? No. I am the person who has lost out.
If they stole huge amounts of money from me such that I couldn't make good on my debts to other people, then others will be indirectly affected too. But I am the person who was robbed.
They basically are just creating new rows in their databases. Just like the names-on-paper example above, someone just types "+$X,000" into the row that represents the money in your account. And then someone types the equivalent of "adastra owes us $X,000" into a row in another database for their balance sheet. It really is money created out of thin air.
But then I suppose all money is actually IOU's created out of thin air... It's just that for some reason people think it's only the federal government that can create new IOU's.
1) Bank A will decrement your [fake] balance; 2) Bank B will increment that account's balance; 3) Bank A will note that they owe 1 million to bank B, and Bank B will not that they deserve 1 million from bank A. They'll settle that balance somehow (that's a bit complex and irrelevant), but the debt now exists. If they don't trust each other that much, then bank B will credit the funds only after bank A has paid them; this often causes a couple days delay in international bank transfers.
Do you now see how they can't "create money" by whatever they do in their databases? To give cash out, banks need cash; to send money somewhere else, they need to give money to that somewhere else or convince that 'somewhere else' to lend them that money.
In essence, altering an account balance is exactly equivalent to faking a document stating "Bank owes me X dollars" so well that the bank (temporarily) believes it - nothing more.
In any case, if you fake a dollar in Bank A systems, then no matter where and how you withdraw or transfer it, it's a dollar that Bank A loses.
Well, no, that's extremely relevant. How is that debt settled?
I'm quite certain they don't send over a truck full of cash.
If it's just a matter of Bank A telling Bank B to adjust their books and Bank B taking their word for it, then Bank A isn't losing anything. They just created that money out of thin air.
Is there any difference if I later settle this by giving you cash, write a check, pay with paypal or give you a gold piece? The debt is real, if I gave a binding certificate "I'll owe $100 to you" then I just lost $100.
Bank A isn't simply "telling Bank B to adjust their books", Bank A is telling "please adjust your books to give $X to Y, and for that I'll pay you that amount via method Z", where Z typically is either a clearing house (someone who aggregates the payments and settles the net differences of all the bazillion payments) or a mutual correspondent account. Until they settle, they have a valid, legally binding debt to Bank B.
Trucks full of cash may be involved in settlement, but usually are not since they are very inconvenient and expensive - but if Bank A holds their reserves at a central bank and thus has the right to request it to ship 123 truckloads of cash; then it may transfer part of these reserves to Bank B, so that Bank B will get one of them and Bank A will only be able to request 122 truckloads of cash. Of course, the truckloads of cash are used only as much as needed (say, to fill up ATM's) - but they are real, you can close up your bank, settle all debts, and take all remaining assets out in cash.
I'm not trying to discredit you, it's just kind of an interesting thought.
* - I realize this wont seem 'better' to everyone, but at-least taxing savings has the option of selective application. Printing money hits everyone the same.
Governments have been debasing their currency for millennia, because it's an easier way to raise revenue than actually going out and taxing people for it.
Poorly run governments sometimes try to do this. It generally doesn't work because it results in hyperinflation which wrecks the whole economy.
My understanding of the reserve system, which is entirely limited, is that the Federal Reserve relies on what the bank reports?
If the bank doesn't know it's been hacked, it'll simply report the wrong figures and that will be that?
Cash is is handled separately and banks can slightly fudge those numbers. But, there digital cash on hand better match yesterday's balance plus today's net transactions.
PS: Banks can convert cash back and fort from digital to hard currency, but that's handeled by a third party which also reports those transactions.
The price level/inflation level in macro econ is the intersection of supply and demand. So called demand-pull/cost-push inflation. Sure, you can say that printing money causes inflation ceteris paribus. But in the real world things are not ceteris peribus. You can create money and have deflation if supply/production increases at a greater rate that money creation causes increases in demand. If money creation results in balances held in deposit but not spent, then there is no inflation as a result of the money creation itself. This probably explains why the US economy has been teetering on deflation: most of the money created ends up hoarded in the accounts or rich people who do not spend it.
There are two kinds of money: bank deposits and reserves. Reserves( aka hi powered money/vertical money) are physical currency in circulation or in bank vaults and special deposit accounts at the Fed held by banks that are members of the federal reserve system. Bank deposits ("private money" or vertical money) are created by banks when they create loans. The lending process is regulated by the Fed and government agencies( ex. office of the comptroller of the currency). Yes, the Fed imposes reserve requirements on member banks. But these requirements do not constrain their ability to lend. The reason is b/c banks can make loans and borrow reserves from the federal funds market or the Fed directly in the following accounting period. Reserves are used for interbank deposit settlement. So when a check is written from account holder A in bank A to AH B in bank B, the transaction is settled at the reserve level using reserve accounts at the Fed. It is complex and I could go into capital requirements, which are a true constraint on money creation by banks.
Because of FDIC insurance, bank runs are not a problem in our system. Ultimately the Fed can back stop the FDIC as it kind of did during the crisis of 08.
Since we didn't have any network security professionals on our team, I was especially worried. What we realized though, was that we kept a detailed log of all item/money creations/deletions, where trades were just a creation/deletion pair. Thus, we wrote a script to learn what the most expensive items (and thus most costly, if duplicated) were at any given time, and match creations to deletions with a frequency increasing with item value. Whenever there was a discrepancy, we were alerted.
I suppose banks could do something similar. If they separate the money transfer system from the account creation system, they could add an additional layer of security. I haven't really thought out the details, but it makes sense at first glance. Perhaps they already do something like this?
What he described is an auditing system with some particular policies of interest to a specific use case. Such a system should not have any direct access to the main system, and should ideally live in a fully segregated environment with tightly controlled read-only access to a copy of the data being audited.
The whole idea is that this system would not announce its presence on the network in any way so that the attacker is more likely to miss it. Even if the attacker does know that it's present, he should not know all the checks and validations that such a system uses to detect suspicious behaviour. Hell, you could air-gap the entire thing and just copy over data dumps by using USB sticks.
Granted, even in that situation you could get something like Stuxnet which may compromise the machines. However, if you have the resources to build another Stuxnet, chances are you don't really need to get into a bank network.
i personally would love to do this kind of work, legally breaking into a system to see if it could happen would be very entertaining.
It is more likely that a security consulting firm will be sued if they report no issues and the bank is later compromised.
Or perhaps we only hear of the unsuccessful heists...
If he was serious it would of been many different accounts/transaction and then gets into the arts of money laudering/avoiding the first like auditors/checks.
Yes you do only hear about unseccessful heists, though the times are changing with regards to being more open.
In short he was testing the security of the bank and not the auditing and laudering aspects, which is when you need somebody with some accounting knowledge and banking knowledge.
Makes you wonder about the regulation of money in general.
But if you hacked the Fed itself, yes, you'd be creating new money.
So in a sense the money created IS real. At least, as real as any other money in a bank account.
[1]: http://en.wikipedia.org/wiki/Reserve_requirement#United_Stat...
If the bank had sufficient excess reserves, other banks would honor the new money. And today most banks do have big excess reserves (which is historically unusual).
Under normal conditions, the banks stay pretty close to their reserve requirement, so a hacker suddenly creating a gigantic new loan at a bank is likely to push them over the limit and draw attention, either immediately or when somebody tries to move the money to another institution.
But at present, many banks do have big excess reserves, so getting away with it is more plausible. It essentially becomes a loan the bank didn't really intend to make.
Though any tester who did pentesting on banks would of signed a NDA and if not, somebody really messed up and how are we reading about this within 10 years of it happening!
That leads to either the bank approving of this article or Security Compass having loose lips. I can't imagine a bank signing off on releasing this info, as it paints bank security in a bad light.
I expect that somewhere, someone is contacting their internal IT staff to find the SOW for this pentest, and then contacting their legal dept.
That's just making it too easy.