Attacks/Breaches

11/7/2016
03:45 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Was Theft Of Money From 20,000 Tesco Bank Customers An Inside Job?

UK bank confirms attack, but so far has not used the word 'hack.'

Threat actors appear to have broken new ground with an attack on the UK's Tesco Bank where they managed to steal money from more than 20,000 accounts at nearly the same time in automated fashion.

Details of the weekend attack are still just emerging, but Tesco has confirmed the breach and suspended the ability for current account customers to use their debit card for online transactions.

So far the company has not put any restrictions on the ability for affected customers to use their cards for cash withdrawals, direct debit, and bill payments. Current account customers are also still able to use their debit cards for chip-and-PIN payments.

In the statement announcing the incident, Tesco Bank CEO Benny Higgins reassured customers that any money stolen from their accounts would be reimbursed by end of day Tuesday.

The BBC Monday quoted Higgins as describing the theft as a systematic, sophisticated attack. The bank has already figured out exactly what happened but is unable to disclose details because of the ongoing investigation, Higgins told BBC. So far, the bank has not used the word “hack” in connection with the attack, BBC added.

In total, about 40,000 current accounts experienced suspicious transactions over the weekend and money was illegally withdrawn from about half of them.

Tesco has not revealed how much money the attackers managed to steal from its customers. But it has stressed that only relatively small amounts were stolen from consumer accounts the BBC said.

However, comments posted on Tesco bank’s community forum by irate customers suggest that at least some of them suffered substantial losses. One customer for example complained about a £2,400 loss while another spoke of a £600 dent in his or her account.

The Tesco attack is of course not the first attack on a major bank and it likely may not be the biggest in terms of losses, either. What makes it different is the sheer number of consumer accounts that were looted in what appears to be near-simultaneous fashion.

Typically, online bank heists have either involved individual account takeovers or attacks like those involving the SWIFT network earlier this year. Thousands of US individuals, small businesses, local governments, and school districts, for instance, have cumulatively lost hundreds of millions of dollars in recent years to account takeovers where attackers steal account credentials and use them to initiate illegal wire transfers.

The fact that attackers in the Tesco case somehow had simultaneous access to over 20,000 accounts suggests an inside job, says Greg Salyards, principal sales consultant at Identity Automation.

“I doubt a third-party gained access to and logged on with 20,000 plus client credentials to process transfers externally,” Salyards says. Instead, what likely happened is an IT administrator, bank processor, or contractor with the right credentials to either change client passwords or log on as the client, was somehow involved, Salyards says. But without more information, he notes, this is pure speculation.

“Some type of batch process was probably run internally by someone who has now boarded a flight to a country with no extradition agreement with the UK,” Salyards says.

Mark Wilson, director of product management at STEALTHbits Technologies, says it's highly unlikely the attacks were compromised in a single attack by an external attacker.

It is possible that an attacker managed to infiltrate malware past Tesco’s perimeter security and propagated it across the enterprise. Even so, unless there had been a serious breach of internal policies and processes, it is unlikely an external attacker would have acquired the privileges needed to access so customer accounts.

“If Tesco's data was secured as required by PCI and the various compliance bodies, then the likeliest candidate is a rogue administrator—or administrators,” Wilson says.

Related stories:

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
filthychats
50%
50%
filthychats,
User Rank: Apprentice
11/7/2016 | 8:14:41 PM
That's a lot of money
Even if only a third of the potentially affected accounts had money withdrawn with a mere $50 average, that is still well over half a million dollars lost. Ridiculous. 
It Takes an Average of 3 to 6 Months to Fill a Cybersecurity Job
Kelly Jackson Higgins, Executive Editor at Dark Reading,  3/12/2019
New Mirai Version Targets Business IoT Devices
Dark Reading Staff 3/19/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: LOL  Hope this one wins
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
The State of Cyber Security Incident Response
The State of Cyber Security Incident Response
Organizations are responding to new threats with new processes for detecting and mitigating them. Here's a look at how the discipline of incident response is evolving.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-6149
PUBLISHED: 2019-03-18
An unquoted search path vulnerability was identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0 that could allow a malicious user with local access to execute code with administrative privileges.
CVE-2018-15509
PUBLISHED: 2019-03-18
Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control (issue 2 of 2).
CVE-2018-20806
PUBLISHED: 2019-03-17
Phamm (aka PHP LDAP Virtual Hosting Manager) 0.6.8 allows XSS via the login page (the /public/main.php action parameter).
CVE-2019-5616
PUBLISHED: 2019-03-15
CircuitWerkes Sicon-8, a hardware device used for managing electrical devices, ships with a web-based front-end controller and implements an authentication mechanism in JavaScript that is run in the context of a user's web browser.
CVE-2018-17882
PUBLISHED: 2019-03-15
An Integer overflow vulnerability exists in the batchTransfer function of a smart contract implementation for CryptoBotsBattle (CBTB), an Ethereum token. This vulnerability could be used by an attacker to create an arbitrary amount of tokens for any user.