01:19 PM

Hackers Rob $400,000 From Washington Town

Small Washington State town lost funds from its own Bank of America account, as well as employees' and residents' bank account information.

Hackers have successfully compromised multiple computer systems administered by the town of Burlington, Wash., which has a population of about 8,400.

The thieves' spoils include many town employees' and residents' bank account details, raising the prospect that the information may be used for identify theft purposes. In addition, the thieves were able to successfully make fraudulent wire transfers from a Bank of America account used by the town, although the actual amount of money they stole isn't yet clear.

"Although a total is not yet known, over $400,000 in funds have reportedly been electronically transferred to multiple personal and business accounts across the United States over a two-day period," said Dave Stafford, assistant chief of the Burlington Police Department, in a statement.

"The [town's] finance department notified local authorities immediately after learning of the illegal transfers and the account was frozen," Stafford said. "Computer hacking is suspected and computer forensic examinations are being conducted."

[ Cybercrime now costs a U.S. business $8.9 million per year. See Cybercrime Attacks, Costs Escalating. ]

The ramifications of the related breaches--which occurred on Oct. 9 and 10, and which were spotted by city employees Oct. 11--are widespread, and not yet fully known. But the city has already warned any employees that participate in its payroll deposit program that their personal details were compromised. "Employees are encouraged to contact their banks to flag or close the accounts associated with the electronic payroll deposit and to notify appropriate credit reporting agencies that they may be victims of identity theft," said Stafford.

The town also issued a notice on its website saying that its "Utility Billing Automatic Withdrawal Information (for sewer and storm drain charges) has been compromised," and told anyone enrolled in the automatic payment program that "you should assume that your name, bank, bank account number, and routing number have been compromised."

"We apologize for the inconvenience," read the note.

The U.S. Secret Service Puget Sound Electronic Crimes Task Force is investigating the data breaches, and a neighboring town's police force will help. "As Burlington Police investigators are also potential victims in the case, Mount Vernon Police will be assisting federal investigators," said Stafford.

Unlike consumers, towns such as Burlington aren't covered by laws that hold banks liable for any such fraud, although some lawmakers have introduced legislation that would extend such protections to government entities.

As that suggests, this is far from the first fraudulent wire-transfer attack that's been perpetrated on a small town. Furthermore, the frequency and severity of such attacks has been on the increase. Last month, the FBI, Financial Services Information Sharing and Analysis Center, and the Internet Crime Complaint Center released a joint warning that criminals have been targeting bank account information using "spam and phishing e-mails, keystroke loggers, and remote access trojans (RATs)," as well as variants of the Zeus financial malware. The alert noted that stolen credentials have been used by attackers numerous times to fraudulently transfer between $400,000 and $900,000--at one time--into overseas accounts.

U.S. government officials, in anonymous interviews, have blamed Iran for launching those banking attacks, which they said began over a year ago. But the attack against Burlington, Wash., would seem to differ, since the money was reportedly transferred not overseas, but into U.S. bank accounts.

Regardless, don't expect these types of attacks to cease anytime soon. Security firm RSA recently warned that accounts across 30 different banks were set to be targeted as part of "Operation Blitzkrieg," in which as many as 100 botnet operators planned to join forces to steal money from organizations in the financial services, retail, healthcare, and government sectors. In particular, RSA said that the attackers planned to infect large numbers of PCs with a Trojan application that would allow them to steal banking credentials, which they planned to use to make fraudulent wire transfers.

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Apprentice
10/17/2012 | 6:16:40 PM
re: Hackers Rob $400,000 From Washington Town
The town of Burlington should have purchased a crime policy that covers cybercrime or EFTGuard. Businesses and organizations that bank online are always at risk. They don't understand that Bank's are not liable for such losses as they do not have Regulation E coverage that protects ordinary consumers.
User Rank: Ninja
10/17/2012 | 12:00:29 AM
re: Hackers Rob $400,000 From Washington Town
I have read of many attack where they have caused damage that amounts to a loss of funds ,but have never heard of a hack where they actually got the cold hard cash out of accounts! I would be beyond thrilled to receive that email and furthermore the 'your shit out of luck' essence of the letter. Cmon this is Bank of America who has already been repeatedly attacked, and they still do not have the security measures in place to obviously avoid these attacks. If I was a Bank of America customer, after reading this I would be running to the door and seeking a bank elsewhere that can do there job and protect my money and sensitive information! One time the bank can blame the breech on their lack of security, the second time, it is my responsibility to find a bank that can do the job correctly.

Paul Sprague
InformationWeek Contributor
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: just wondering...Thanx
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.