- How to make new stuff from your piles of obsolete tech
- Why your computer sucks
- 10 recession-proof IT skills
- Juniper execs share network vision
- 9-year-old plots his fifth Microsoft certification
Cyberthieves are hacking into small- and medium-sized organizations every week and stealing millions of dollars in an ongoing scam that has moved about US$100 million out of U.S. bank accounts, the U.S. Federal Bureau of Investigation warned Tuesday.
It's now one of the top problems being addressed by the National Cyber Forensics and Training Alliance (NCFTA), which works with the FBI and industry to share information about cyber attacks, according to NCFTA Executive Director Ron Plesco. "Every year there seems to be a trend and this has been the trend this year," he said.
There has been a "significant increase" in what's known as ACH (automated clearinghouse) fraud over the past few months, much of it targeting small businesses, municipal governments and schools, the FBI said in an alert posted to its Web site.
The criminals can move thousands or even millions of dollars out of their victims' accounts very quickly, using online banking to add new payees to the organization's bank account and then moving the money overnight. Usually the first step is an e-mail to the company's bookkeeper or financial officer that can include malicious attachments designed to look like Microsoft software patches, or simply links to malicious Web sites. The idea is to get the criminal's keylogging software onto a computer with online banking access and then steal login credentials.
Once they have access to the bank account, the hackers set up ACH transfers to money mules -- typically innocent victims who think they're doing payroll processing for international companies -- who then transfer the money overseas via services such as Western Union and Moneygram.
In one case, the criminals even launched a distributed denial-of-service attack against an ACH processor to prevent the bank from recalling transfers before the money mules could move them overseas.
Once the money is out of the country, it is gone for good.
Criminals prefer smaller organizations such as school boards because they tend to work with smaller regional banks that may not have the fraud detection controls in place to stop these fake ACH transfers. These organizations often publish contact information for financial personnel, or even organizational charts posted to their Web sites, making them easy pickings for fraudsters.
According to a report by the FBI's Internet Crime Complaint Center (IC3), banks and financial service providers are often part of the problem. Based on FBI interviews, the IC3 concluded that "in several cases banks did not have proper firewalls installed, nor anti-virus software on their servers or their desktop computers. The lack of defense-in-depth at the smaller institution/service provider level has created a threat to the ACH system."
The FBI is opening new cases every week on average, the IC3 said. "As of October 2009, there has been approximately $100 million in attempted losses."
The NCFTA is tracking between $1 million and $1.5 million in losses each week to this type of fraud, according to Ron Plesco, the NCFTA's executive director. "That's just from the folks we deal with. We're thinking it's larger than that," he added.
Partner Content
www.bmc.com
Gartner 2009 Magic Quadrant for Job Scheduling
Gartner has positioned BMC CONTROL-M in the Leaders Quadrant of their "2009 Magic Quadrant for Job Scheduling." The report assesses the ability to execute and completeness of vision of key vendors in the marketplace. Read a full copy today, courtesy of BMC Software.
Download whitepaper
Dell's SMART Approach to Workload Automation
Read a compelling case study by EMA, Inc. to learn how Dell uses BMC CONTROL-M to cut cost and increase productivity with workload automation.
Download whitepaper
Workload Automation Cost Savings 2 Minute Video
A major computer manufacturer uses BMC CONTROL-M and just four people to schedule and run over 85,000 jobs every month. By switching to BMC CONTROL-M, they more than quadrupled the workload without adding a single staff member. See how in this 2-minute video overview.
Go to video
Comments (7)
Please finish the articleBy Anonymous on November 4, 2009, 7:56 amGreat read but you help no one unless you give examples of what e-mails to look for to insure they are being blocked. IT Director
Reply | Read entire comment
Non-secure OSBy Anonymous on November 4, 2009, 8:51 amI wonder if moving to a more secure OS, such a Linux might solve the problem.
Reply | Read entire comment
Linux has its own security woes - This scam happened to us Dec 2By Anonymous on November 4, 2009, 8:59 amIf not configured right, Linux is no more secure than Windows - I perform security for both, and there are idiots on both sides. This EXACT scam happened to us last...
Reply | Read entire comment
sadBy Anonymous on November 4, 2009, 9:00 amLinux would help but one also has to be more vigilant and not open fake emails. The antivirus and firewall issues should be addressed as well. Why aren't they using...
Reply | Read entire comment
Check images vs. ACHBy AB on November 4, 2009, 9:42 amThis probably stems from the Check 21 law combining with the way ACH works. A bank that participates in the ACH (and I think all of them do) must fulfill a funding...
Reply | Read entire comment
Fake emails had NOTHING to do with our situation - nor WebBy Anon on November 4, 2009, 9:45 amOur case was where some Federal bank Clearinghouse employee or other higher-level person apparently turned to "the dark side" and, instead of trashing old cleared...
Reply | Read entire comment
View all comments