Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

6/29/2016
09:00 AM
50%
50%

Hackers Pilfer $10 Million From Ukraine Bank

Reports allege criminals used SWIFT to transfer money, have compromised several Ukraine, Russia banks.

An unidentified bank in the Ukraine was allegedly hacked and $10 million stolen via the SWIFT network, says International Business Times quoting the Information Systems Audit and Control Association (ISACA).  Details of the theft are unclear but the investigators suspect hackers had exploited “publicly available information and tools.”

The country’s ISACA branch, which is part of the probe, said several banks in Ukraine and Russia have been compromised and hundreds of millions of dollars stolen from them. 

Unconfirmed local media reports say the theft was via the SWIFT messaging system akin to the February $81-million Bangladesh Bank cyber heist. However, SWIFT has repeatedly rejected allegations that its system was compromised in the bank thefts and now warned that institutions with weak internal security may be suspended from its network.

For more on this story, click here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
RyanSepe
100%
0%
RyanSepe,
User Rank: Ninja
6/29/2016 | 9:53:04 AM
SWIFT messaging system
Outside of SWIFT, what have firms attributed in the messaging system to be the result of these attacks?
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/29/2016 | 11:21:51 AM
SWIFT
You would think there is tons of confirmation so this money transferring would not be compromised ever. That is obviously not the case. The banks need to keep up with the technology.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/29/2016 | 11:24:34 AM
Re: SWIFT messaging system
SWIFT can continue to reject the responsibility; it does not matter where it happened if it touched their network they are still responsible. They may not have a legal obligation but they are certainly responsible.
Commentary
Ransomware Is Not the Problem
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  6/9/2021
Edge-DRsplash-11-edge-ask-the-experts
How Can I Test the Security of My Home-Office Employees' Routers?
John Bock, Senior Research Scientist,  6/7/2021
News
New Ransomware Group Claiming Connection to REvil Gang Surfaces
Jai Vijayan, Contributing Writer,  6/10/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-0324
PUBLISHED: 2021-06-14
Product: AndroidVersions: Android SoCAndroid ID: A-175402462
CVE-2021-0467
PUBLISHED: 2021-06-14
In Chromecast bootROM, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the bootloader, with physical USB access, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andr...
CVE-2021-21554
PUBLISHED: 2021-06-14
Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and, Dell Precision 7920 Rack Workstation BIOS contain a stack-based buffer overflow vulnerability in systems with Intel Optane DC Persistent Memory installed. A local malicious user with high privileges may potentially exploit t...
CVE-2021-21555
PUBLISHED: 2021-06-14
Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and T640 Server BIOS contain a heap-based buffer overflow vulnerability in systems with NVDIMM-N installed. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of Service, a...
CVE-2021-21556
PUBLISHED: 2021-06-14
Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and T640 Server BIOS contain a stack-based buffer overflow vulnerability in systems with NVDIMM-N installed. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of Service, ...