Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operations

5/9/2016
06:30 PM
50%
50%

Reuters: Police Say SWIFT Techs Made Bangladesh Bank More Vulnerable Before Heist

SWIFT rejects 'baseless allegations' that software company's negligent security procedures had anything to do with $81 million wire transfer heist.

Three months before Bangladesh Bank was victim to an $81 million cyber heist, technicians from financial software platform company SWIFT opened the bank up to new vulnerabilities, Bangladeshi police told Reuters.  

Last month, researchers reported that highly customized malware exploited vulnerabilities in the bank's computing environment, then hid its fraudulent behavior by tricking the SWIFT software; but it did not exploit a SWIFT vulnerability, per se. Now, police and a bank official told Reuters that SWIFT's people, if not its platform, may be partly responsible for making the bank's computing environment more vulnerable.

According to police, SWIFT technicians did not follow adequate security procedures when they connected the platform to a new bank transaction system that enables domestic banks and the central bank to transfer large sums between themselves. Their negligence "caused much more risk for Bangladesh Bank," police said. In February, attackers used this system to send fraudulent messages, requesting nearly $1 billion in wire transfers. Most of them were blocked, but $81 million in transfers were successfully carried out. 

Police told Reuters the SWIFT messaging system was "widely accessible, including remote access with only a simple password," partly because technicians left open a wireless connection they had established just for the project, after the job was finished. They also criticized SWIFT for failing to connect the two systems on a private LAN, failing to disable a USB port, choosing to use an outdated networking switch, and failing to install a firewall between the systems.  

Investigators are trying to ascertain whether these actions were a case of negligence, or whether they intentionally made the bank more vulnerable. 

SWIFT rejected the police statements, telling Reuters in a subsequent story they were "baseless allegations" and that Bangladesh Bank, not SWIFT, "is responsible for the security of its own systems interfacing with the SWIFT network and their related environment."

Police did not provide evidence for their allegations and Reuters has not yet obtained third-party confirmation. 

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Wesk
50%
50%
Wesk,
User Rank: Apprentice
6/21/2016 | 9:59:01 AM
Re: Yup.
Damage control and diversion of blame.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
5/10/2016 | 9:27:31 AM
Yup.
Hey, if they can't find the criminals, then finding someone to sue is the next best thing, right?
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
New 'Nanodegree' Program Provides Hands-On Cybersecurity Training
Nicole Ferraro, Contributing Writer,  8/3/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15058
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
CVE-2020-15059
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
CVE-2020-15060
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.
CVE-2020-15061
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to denial-of-service the device via long input values.
CVE-2020-15062
PUBLISHED: 2020-08-07
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.