Up to a dozen banks are reportedly investigating potential SWIFT breaches

The incidents are part of a larger trend of cybercriminals targeting financial institutions directly instead of customers

More banks have reportedly launched investigations into potential security breaches on their networks after hackers stole US$81 million from the Bangladesh central bank earlier this year through rogue SWIFT transfers.

Security firm FireEye, which was hired to investigate the Bangladesh bank attack, was also called in to look for possible compromises at up to 12 additional banks, Bloomberg reported Thursday, citing an unnamed source familiar with the investigations.

Most of the banks are from Southeast Asia but include banks in the Philippines and New Zealand, Bloomberg reported.

The Bangladesh bank heist was pulled off with the help of custom malware that was designed to interfere with the software used by banks to perform transactions on the SWIFT global financial network. Similar malware was later found on the systems of a bank in Vietnam.

The Brussels-based Society for Worldwide Interbank Financial Telecommunication (SWIFT), a cooperative society owned by thousands of financial institutions, recently warned customers it is aware of "a number of fraudulent payment cases where affected customers suffered a breach in their local payment infrastructure."

SWIFT’s own network, services, and software were not compromised, the cooperative said. But SWIFT launched an initiative to share cyberthreat information with customers and help them protect their own environments from intrusions and malware.

These latest attacks that sought to abuse the SWIFT infrastructure are part of a larger trend observed over the past two years in which cybercriminals have targeted financial institutions directly instead of going after their customers.

FireEye declined to comment on the new investigations mentioned in the Bloomberg report, but the company has recently published research about targeted attacks against banks in the Middle East.

Those attacks consisted of rogue emails with macro-enabled XLS attachments that downloaded a modified penetration testing tool called Mimikatz, which can be used to steal sensitive credentials from Windows systems.

Last year, security researchers from Kaspersky Labs identified three separate cybercriminal groups that used malware programs to infect bank systems and steal money. One of them used a malware program called Carbanak to steal millions of dollars from hundreds of financial institutions in at least 30 countries.

Security firm Trend Micro recently analyzed the malware used in an attempted cyber theft attempt at Tien Phong Commercial Joint Stock Bank in Vietnam. The malicious program was designed to interact with the SWIFT messaging system and had the SWIFT codes of eight banks hardcoded inside.

The Trend Micro researchers did not name the targeted banks but said six of them are located in the Asia Pacific region and the other two are from the U.S. and Europe.

"We believe that it’s no coincidence that most of their targets are based in Asia," the Trend Micro researchers said in a blog post. "These cyber crooks are perhaps familiar with the banking landscape and challenges of cybersecurity in the region. Despite major improvements in security, certain banks in Asia still lag behind those in U.S. and Europe."

Join the CSO newsletter!

Error: Please check your email address.

More about BloombergFireEyeKasperskyTrend Micro

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Lucian Constantin

Latest Videos

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

  • 150x50

    IDG Live Webinar:The right collaboration strategy will help your business take flight

    Speakers - Mike Harris, Engineering Services Manager, Jetstar - Christopher Johnson, IT Director APAC, 20th Century Fox - Brent Maxwell, Director of Information Systems, THE ICONIC - IDG MC/Moderator Anthony Caruana

    Play Video

More videos

Blog Posts

Market Place