How a hacker’s typo helped stop a $1B bank heist

A spelling mistake in an online bank transfer instruction helped prevent a nearly $1 billion heist last month involving the Bangladesh central bank and the New York Fed, banking officials said.

Unknown hackers still managed to get away with about $80 million, one of the largest known bank thefts in history.

The hackers breached Bangladesh Bank’s systems last month and stole its credentials for payment transfers, two senior Bangladesh Bank officials said.

Commuters pass by the front of the Bangladesh central bank building Commuters pass by the front of the Bangladesh central bank building

They then bombarded the Federal Reserve Bank of New York with nearly three dozen requests to move money from the Bangladesh bank’s account there to entities in the Philippines and Sri Lanka, the officials said.

Four requests to transfer a total of about $81 million to the Philippines went through, but a fifth, for $20 million, to a Sri Lankan non-profit organisation got held up because the hackers misspelled the name of the NGO.

The full name of the non-profit could not be learned. But one of the officials said the hackers misspelled “foundation” in the NGO’s name as “fandation”, prompting a routing bank, Deutsche Bank, to seek clarification from the Bangladesh central bank, which stopped the transaction.

Deutsche Bank declined to comment.

At the same time the unusually high number of payment instructions and the transfer requests to private entities — as opposed to other banks — made the Fed suspicious, which also alerted the Bangladeshis, the officials said.

The details of how the hacking came to light and was stopped before it did more damage have not been previously reported. Bangladesh Bank has billions of dollars in a current account with the Fed, which it uses for international settlements.

The transactions that got stopped totaled between $850 million and $870 million, one of the officials said.

Last year, Russian computer security company Kaspersky Lab said a multinational gang of cybercriminals had stolen as much as $1 billion from as many as 100 financial institutions around the world in about two years.

SHOW COMMENTS Please add a username to view or add commentsPublic Username for Commenting

View the original article here

Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s