Powered By InformationWeek Business Technology Network
 
Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

FDIC Warns Banks Of 'Money Mule' Bank Customers

Financial institutions should be on the lookout for money mules depositing funds stolen via electronic file transfers, says the Federal Deposit Insurance Corp.

Oct 30, 2009 | 03:58 PM

By Kelly Jackson Higgins
DarkReading

The FDIC issued a warning yesterday to banks about the rise in so-called "money mules" being deployed to move money stolen via online banking.

Money mules -- banking customers recruited by fraudsters to take in and transmit stolen funds -- often are hired under the guise of phony "work-at-home" schemes. As unemployment rates have climbed, so have the number of money-mule recruitment and job-related spams that prey on people losing their jobs. Money mules are often lured by promises of hundreds or thousands of dollars an hour to perform jobs such as rebate processing, for instance. The duped money mule usually ends up wiring funds to Eastern Europe, security researchers say.

Several types of transaction events can indicate possible money-mule activity, according to the FDIC. If an account suddenly adds large EFT deposits, or if deposit customers suddenly start sending and receiving funds electronically that are related to business or employment found on the Internet, then this could indicate money mule activity.

Other examples of money-mule operations include a new account that's highly active with large dollar amounts or numbers of EFTs; when an account receives a funds transfer and then shortly thereafter sends wire transfers or cash withdrawals at 8 to 10 percent less than the original transfer; and if a foreign exchange student with a J-1 Visa and a phony passport opens a student account with a lot of EFT deposits and transfers.

"The Federal Deposit Insurance Corporation (FDIC) is warning financial institutions of an increase in schemes to recruit individuals to receive and transmit unauthorized electronic funds transfers (EFTs) from deposit accounts to individuals overseas," according to the FDIC special alert sent to financial institutions. "These funds transfer agents, often referred to as 'money mules,' are typically solicited on the Internet by criminals who have gained unauthorized access to the online deposit account of a business or consumer. In a typical scenario, the criminal will originate unauthorized EFTs from a victim's account to a money mule's deposit account. The money mule is then instructed to quickly withdraw the funds and wire them overseas after deducting a 'commission' (commonly eight to ten percent)."

The FDIC said in its alert that money-mule activity is basically electronic money laundering, and said that stronger identification of customers and high-risk account monitoring practices can help detect such suspicious activity.

Meanwhile, some bad guys are getting cagier about hiding their real money-mule connections. RSA researchers recently discovered a cybergang setting up decoy mule accounts to hide their real mules. Shutting down money mule channels basically stops the money from moving, so fraudsters are motivated to protect this conduit.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.


Subscribe to RSS



Insider Threat Reports

report Inside Out: Protecting Your Partnerships -- and Your Data
Today's businesses depend on e-commerce among partners, but allowing third parties to access internal networks may endanger your data. How can IT security pros ensure that contractors, supplies and others get the access they need -- without becoming threats? This report offers some answers.

report Rotten Apples: How To Detect And Stop Malicious Insiders In Your Organization
Most data leaks are unintentional - but in every enterprise, there are a few hard cases that defy this truism and threaten the very heart of your data.What can you do to stop these rotten apples from using their intimate knowledge of your organization - and its data access methods - to wreak havoc? This report offers a detailed look at how malicious insiders might attack your data, how they’re motivated, and what you can do to stop them.

report Understanding The Insider Threat
Think you know your trusted users? Think again. The availability of new Internet technologies and the pressures of a spiraling economy are changing the nature of the data breach, and your employees may have their fingers on the trigger. This report offers a look at the full spectrum of insider threats, and the risks associated with each.

report Well-Meaning Employees -- And How To Stop Them
The most dangerous threat to your data isn't hackers or criminal insiders: it's the well-meaning employee, whose missteps may lead to the unintentional leak of your most sensitive corporate data. Learn how employees accidentally expose sensitive information, and how you can keep those good intentions from paving the road to your company's ruin.