Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


03:20 PM
Connect Directly

Cybercrime Group Steals $1.3M from Banks

A look at how the so-called Florentine Banker Group lurked for two months in a sophisticated business email compromise attack on Israeli and UK financial companies.

A cybercriminal group dubbed the Florentine Banker Group launched advanced business email compromise (BEC) attacks on leading Israeli and UK financial firms, stealing $1.3 million dollars in just four separate transactions.

Unlike a basic BEC where an attacker sends one or two emails posing as an executive in the victim organization, the Florentine Banker Group stole email credentials and lurked for two months before diverting important wire transfers worth millions of dollars, a new report by Check Point Research shows.

According to Check Point, only $600,000 was recovered via some emergency intervention immediately after the attack. 

"People need to understand that these attacks happen fast," says Lotem Finkelstein, Check Point's threat intelligence group manager. "In most instances, once the wire transfers are made, they are lost for good; our clients were lucky to even get half of their money back." 

Finkelstein says Check Point had been watching the activities of The Florentine Banker Group for at least six months before his firm started working with the victims last December. The targeted companies are three large UK and Israeli financial sector firms that weekly transfer large sums (in the millions of dollars) to new partners and third-party providers.

The Scam

Here's how the attackers pulled it off: Phishing emails targeting two top officials were sent over several weeks, and they only occasionally added new people to the list of targets until they finally gained access to the victim's email account.

Once the attackers gained control of a victim's email account, they were able to read through their emails to understand the different channels used by the victim to conduct money transfers, the victim's relationships with other third parties such as clients, lawyers, accountants, and banks, and finally, key roles inside the victim company.

Finkelstein says the next step was to isolate the victim from third parties and internal colleagues by creating malicious mailbox rules. In this case, emails with pre-defined words such as "invoice," "returned," or "fail," would be moved to another folder not commonly used by the victim, such as the RSS folder.

"The attackers would only move over a couple of emails into the RSS folder, move them in a way that they wouldn't be noticed by the victim," Finkelstein says.

Richard Henderson, head of global threat intelligence at Lastline, says at this point the attackers had total visibility into the victim's email. So they could wait until the email authorizing a wire transfer was sent, interrupt it, and then send the wire transfer instructions to a bank account held by the fraudsters.

In one case, the attackers noticed a planned transaction with a third party in which the firm suggested using a UK bank account speed up the process. However, the company that was to receive the funds transfer said they didn’t have a UK bank account. The attackers then saw an opportunity: they provided an alternative UK bank account via a phony email and intercepted the payment.

"It's very ingenious how these schemes operate," Henderson says. "Most of us have a couple of hundred emails that we get every day so we wouldn't miss one or two emails if they were diverted to a hidden folder. To the victim, everything looks normal, they don't find out about the stolen money until the bank or the business partner calls 30 days later and asks what happened to the payment."

While ransomware gets a lot of the press, BECs are big business for hackers and deserve a lot more attention, says Peter Firstbrook, a research vice president at Gartner.

Firstbrook adds that the FBI recently reported that there was $1.7 billion stolen in BECs in 2019 alone. That's a massive amount of money compared to the $144 million stolen in bitcoin from ransomware attacks over the past six years. In the most prolific cases, a BEC cost Toyota $37 million and Nikkei $29 million. 

So how can organizations protect themselves?

Check Point's Finkelstein says while organizations must always deploy an email security solution, they can't rely on technology alone. They have to consider the human factor. This includes training the staff on how to spot bad links and fraudulent emails, and setting up processes where the people responsible for large wire transfers add a second verification factor by either calling the person who asked to make the transfer, or calling the receiving party. 

Lastline's Henderson adds that companies need to set aside their top people and educate them on the need for multifactor authentication. He says when CEOs or CFOs make their confirmation calls, they have to have the direct office phone or personal cell phone numbers of the receiving parties and be really sure they are speaking to the right people.

"There's more money in cybercrime than most people realize," says Lastline's Henderson. "You're not looking for a needle in a haystack, you're really looking at atoms in a haystack."

Related Content:

A listing of free products and services compiled for Dark Reading by Omdia analysts to help meet the challenges of COVID-19. 

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's featured story: "5 Ways to Prove Security's Worth in the Age of COVID-19"

Steve Zurier has more than 30 years of journalism and publishing experience, most of the last 24 of which were spent covering networking and security technology. Steve is based in Columbia, Md. View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Ninja
4/30/2020 | 10:31:01 PM
The Most Viable Exploit
The human element is the most vulnerable that it is no wonder phishing campaigns are so heavily used. No need for a crafty exploitation, the keys to the kingdom are you.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 6/4/2020
Abandoned Apps May Pose Security Risk to Mobile Devices
Robert Lemos, Contributing Writer,  5/29/2020
How AI and Automation Can Help Bridge the Cybersecurity Talent Gap
Peter Barker, Chief Product Officer at ForgeRock,  6/1/2020
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: What? IT said I needed virus protection!
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-06-04
In MiniShare before 1.4.2, there is a stack-based buffer overflow via an HTTP PUT request, which allows an attacker to achieve arbitrary code execution, a similar issue to CVE-2018-19861, CVE-2018-19862, and CVE-2019-17601. NOTE: this product is discontinued.
PUBLISHED: 2020-06-04
The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client, which allows remote attackers to cause a denial of service (loss of the ability to establish new connections), as demonstrated by SlowITe.
PUBLISHED: 2020-06-04
Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a NULL pointer dereference in the functions FindServiceControlURLPath and FindServiceEventURLPath in genlib/service_table/service_table.c.
PUBLISHED: 2020-06-04
Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web interface, and included in requests sent by web interface. However, this token is not verified by the application: the token can be removed from all requests and the request ...
PUBLISHED: 2020-06-04
Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console� that is available to users with an administrator role. This console provides an administrator user with the possibility of changing several settings, including the applicat...