Security vendors are pushing for a more comprehensive revamp of the SWIFT international inter-bank financial transaction messaging system beyond a update prompted by an $81 million hack against Bangladesh's central bank, reports the Registrar.
The loss of $81 m (part of an attempted $950 m heist) in February’s Bangladesh cyber-heist-- reckoned to be the biggest ever bank theft-- has subsequently been linked to the bank’s use of second-hand $10 switches on its network and a lack of firewalls.
As well as network infrastructure weaknesses, the hackers behind the heist used custom malware specifically created to target SWIFT.
The code even adjusted the SWIFT system’s printed reports to hide fraudulent transfers from the Bangladesh central bank account at the New York Federal Reserve Bank.
The malware linked to the attack was identified by security researchers at BAE Systems.
Hackers lifted the Bangladesh central bank key’s before forging messages on SWIFT. Having obtained valid operator credentials, hackers gained authority to create, approve and submit messages while posing as compromised organisations. The hackers then-- posing as the Bangladesh central bank-- instructed the transfer of funds to accounts under their control through a series of messages using the compromised credentials.
The whole incident is better understood as the Bangladesh central bank getting hacked rather than SWIFT itself getting hacked.
SWIFT, a co-operative owned by 3,000 financial institutions worldwide, has confirmed the role of malware in the attack without naming the affected organisation.
SWIFT is aware of a malware that aims to reduce financial institutions’ abilities to evidence fraudulent transactions on their local systems.
Contrary to reports that suggest otherwise, this malware has no impact on SWIFT’s network or core messaging services.
The malware is designed to hide the traces of fraudulent payments from customers’ local database applications and can only be installed on users’ local systems by attackers that have successfully identified and exploited weaknesses in their local security.
Worryingly the Bangladeshi incident is not a one-off. Other thefts of “operator credentials” have happened before, SWIFT’s statement confirms, without going into numbers.
SWIFT said it had “informed our customers that there are other instances in which customers’ internal vulnerabilities have been exploited in order to stress the importance and urgency of customers’ securing their systems” without going into details. In response to the Bangladeshi incident is has pushed a mandatory security update.