Russian hacker engineered worldwide crime spree
usatoday.com
usatoday.com
>To draw attention away from the massive transfers, the hackers often created a diversion, such as a "denial of service" attack that would bombard the website with traffic in an attempt to shut it down, the law enforcement official said.
Corporate banking applications have multitudes of layers of approval, authorised signatories, transaction limits, multiple approvers, etc, and increasingly mobile alerts. By creating chaos in an organisation, it does not mean these break down, but everyone is panicking about something they feel is important, and give scant regard to what seems credible and routine. Exploiting a human fallibility.
Disclaimer: I used to do compliance and security training at a very large financial institution. A huge amount focused on social manipulation via stress and pressure being placed in someone at a critical node of the transaction process.
http://www.theaustralian.com.au/business/economics/australia...
How is that even possible?
It's not untraceable, but the cost associated with unraveling a single theft becomes prohibitively expensive.
After such an event the bank will investigate, and if the org violated their conditions and that led to the loss, it's on the org. And I suspect org insurance policies have "we don't make you whole if you're an idiot" provisions.
Or at least that's how it went down here when e.g. a school district was sloppy and lost 6 figures of their bank balance.
My comment was specific to the example given in the article, where to amount was about $195,000. While not a tiny sum of money, the amount of man hours spent to unravel those transactions, to ultimately get to recoverable sum, would be close to if not more than the original amount. And getting to the amount, may not guarantee that you can recover the funds anyway.
I understand it becomes tedious to unravel the transactions, but is it still a tractable problem? Or do these people eventually shift the money into offshore banks that refuse to co-operate with authorities? It seems such a bank would be quickly cut off from the rest of the world if it existed.
How can you possibly trace that? Sift through the casino's financials for deposits and withdrawals of a similar size?
Sometimes the trail goes completely cold.
A confidential informant tipped the
FBI off to the syndicate administrator's
email address...
Humans are the weakest link in any crime machine...And humans are the weakest link in any corporate machine, by having allowed the crime in the first place.
According to the article, "The heist begins with a phishing e-mail designed to entice a computer user to click on a link. The link launches the virus."
So if we accept the article, the hackers weren't finding deep bugs in network software or doing anything highly sophisticated, but relying on stupid employees at companies.
Now we just need to wait for the next bunch of greedy, malevolent sociopaths to create the next round of ransomware... Although I'm sure this has already been done.
There would be news of such and such crime, and while most would be terrified and disgusted, a segment of population (younger delinquents for example) would be very impressed. They also have funny nicknames to add to their "brand". Things like "black bone" or "the green one" etc.
Yet, about the most I have seen an ISP do is block port 25.
In general, it seems that ISPs have a lot of unweilded power in this fight.
Security. Notifying a user that he's been pwned can protect that user's confidential info/identity. It's really a service to the user as much as anything.
The ISP would just need to message it as such. They wouldn't just cut off "clueless users" without explanation. Instead, they'd explain that the user's machine has been compromised and disconnecting them until they can get it cleaned up is for their own good.
Even filtering out SMTP traffic has been really frustrating for me at points in the past.
I really hope ISPs don't start doing this. I want them to be as dumb of a pipe as possible.
Anyway, as devs who need access to this stuff we are in the minority, and I am sure they can find a way to make exceptions for people like us who are "power users".
But, to leave the other 98% of grandmothers, etc. completely vulnerable to botnets by default seems an unreasonable approach.
What seems clear is that they will eventually have to do something.
offtopic: The most funny age-related thing are African soccer players. You see the turning from 19 to 33 overnight all the time :-P