Published by Gbaf News
Posted on March 25, 2015

Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.
Published by Gbaf News
Posted on March 25, 2015

By Ofer Or
The banking industry is no stranger to cyber-attacks. The latest attack uncovered by Kaspersky Labssaw cybercriminals use known malware, Carbanak, to exploit the vulnerabilities found in banks too large to keep all their systems patched.
However , this attack marks a departure from more common attacks directed at banks in so far as the criminals were not after the usual treasure trove of personally identifiable information (PII) belonging to bank customers, but instead targeted the banks’ own systems: internal money processing services and automated teller machines(ATMs).It’s the first instance we’ve seen of a cyber-espionage technique used in nation-state attacks being turned on the private sector for financial gain. And since it was successful – to the tune of $1 billion—we can bet it won’t be the last.
Big Phish: Reeling in the victims
Kaspersky Labs revealed that the initial infections of bank machines by Carbanak malware, possibly linked to Russian or Ukraine cyber groups, were achieved through spear phishing emails that appeared to be legitimate banking communications. Recipients of this email believed the messages were legitimate notices from within the company or from trusted sources such as the Russian Federal Bank, and clicked on email attachments as instructed. Phishing essentially opened the gateway for hackers to exploit known vulnerabilities in commonly used Microsoft Office applications that remained unpatched by large banks due to their cumbersome infrastructures. Once the malware was embedded, the hackers were able to take control of the infected machines and move laterally throughout the banks’ IT network in order to launch the next phase of the attack.
It’s hard to believe that in 2015, we are still seeing spear phishing attacks. But phishing scams aren’t going away anytime soon. In the UK alone, online banking losses attributed to phishing scams cost £30 million, according to a report by banking organisation Financial Fraud Action. In the US, the month of December 2014 saw 46,747 identified phishing attacks, according to the RSA Anti-Fraud Command Center.
The very the nature of a financial organisation’s IT infrastructure makes it easy to launch a phishing campaign. Most banks have a large number of employees spread out across multiple locations, and numerous business applications requiring constant upgrades. But bank IT teams remain focused on protecting customer data and tracking fraudulent behaviour rather than their internal systems due to financial regulations and a number of recent credit card breaches that have put customers’ PII at risk.
A moving target

Ofer Or
Historically,cyber attacks have been aimed at the bank’s customers. The common goal: stealing PII such as bank account and credit card numbers, social security numbers, dates of birth and other data that can be used in global identity theft schemes. The target for cyber attacksis shifting from banking customer to the bank itself. As we’ve seen with this Carbanak attack, the payoff of this kind of cyber heist is enormous – far more than cyber criminals could make on credit card or identity theft.
Locking down the vault
Is this far-reaching cyber attack the beginning of a disturbing new trend? What can banking organisations do to mitigate risk and prevent even more devastating theft like this? Here are a few steps.
Managing network security for today’s financial organisations has become a complex, resource-intensive operation involving hundreds of firewalls, router, switches, applications, regulations and more. Despite all of this complexity, senior management requires an accurate, realistic picture of the organisation’s security posture at all times, and take measures to improve gaps as quickly and efficiently as possible. We’re facing a new era of bank robbers, armed with intimate knowledge of banking systems’ inner workings. The Carbanak attack demonstrates that the industry requires a better approach that is less about prevention of zero-day incidents, and more about mitigation of breaches that may already be happening under the radar.
About the author
Ofer Or is vice president of products for Tufin. Tufin automates and accelerates network configuration changes while maintaining security and compliance for the world’s leading financial institutions. For more information, visit http://www.tufin.com.