Bank at middle of cyber heist lacks even firewall : The Tribune India

Join Whatsapp Channel

Bank at middle of cyber heist lacks even firewall

DHAKA: Bangladesh’s central bank was vulnerable to hackers because it did not have a firewall and used second-hand switches that cost $10 to network computers connected to the SWIFT global payment network, an investigator into one of the world’s biggest cyber heists said.



Dhaka, April 22

Bangladesh’s central bank was vulnerable to hackers because it did not have a firewall and used second-hand switches that cost $10 to network computers connected to the SWIFT global payment network, an investigator into one of the world’s biggest cyber heists said.

The shortcomings made it easier for hackers to break into the Bangladesh Bank system earlier this year and attempt to siphon off nearly $1 billion using the bank’s SWIFT credentials, said Mohammad Shah Alam, head of the Forensic Training Institute of the Bangladesh police’s criminal investigation department.

“It could be difficult to hack if there was a firewall,” Alam said in an interview. The lack of sophisticated switches, which can cost several hundred dollars or more, also means it is difficult for investigators to figure out what the hackers did and where they might have been based, he said.

Experts in bank security said the findings described by Alam were disturbing.

“You are talking about an organisation that has access to billions of dollars and they are not taking even the most basic security precautions,” said Jeff Wichman, a consultant with cyber firm Optiv.

Tom Kellermann, a former member of the World Bank security team, said the security shortcomings described by Alam were “egregious”, and that he believed there were “a handful” of central banks in developing countries that were equally insecure.

Kellermann, now chief executive of investment firm Strategic Cyber Ventures LLC, said some banks failed to adequately protect their networks because they focused security budgets on physically defending their facilities.

Cyber criminals broke into Bangladesh Bank's system and in early February tried to make fraudulent transfers totalling $951 million from its account at the Federal Reserve Bank of New York. Most of the payments were blocked, but $81 million was routed to accounts in the Philippines and diverted to casinos there. Most of those funds remain missing.— Reuters

Top News

Non-bailable warrants can’t be issued in a routine manner, says Supreme Court

Non-bailable warrants can’t be issued in a routine manner, says Supreme Court

A Bench led by Justice Sanjiv Khanna says ‘the liberty of an...

Lok Sabha election: BJP drops MP Brij Bhushan Singh from UP’s Kaiserganj, fields his son

Lok Sabha election: BJP drops MP Brij Bhushan Singh from UP’s Kaiserganj, fields his son

Brij Bhushan is accused of sexual harassment by women wrestl...

L-G Saxena gives nod to sack 223 Delhi Commission for Women employees hired ‘without due procedure’

L-G Saxena okays sacking of 223 Delhi Commission for Women employees hired ‘without due procedure’

Former DCW chief and AAP Rajya Sabha MP Swati Maliwal slams ...

Lookout notice issued against Prajwal Revanna in sex scandal case

Lookout notice issued against Prajwal Revanna in sex scandal case

On Prajwal seeking 7 more days to appear before the SIT as h...


Cities

View All