Case study
Case study - Bank of Bangladesh - Security Information and Event Management
5 slides · 4 min read · Domain 7
Bank of Bangladesh: Security Information and Event Management
Overview
An organization will typically have a multitude of detection systems runningfirewalls, IDS and IPS systems, Windows-based, UNIX-basedthese detection systems will be located both within network segments and on critical host systems.
But the sheer number and diversity of these systems present a major problem for the individuals tasked with monitoring and identifying malicious activity. On top of this, organizations like Kasperski reported in 2020 the detection, an average of 360,000 new malicious files daily, the explosion of loT devices, and that attacks are becoming ever more sophisticated. | It is little wonder that an IBM 2020 report states that the average time taken to detect a data breach was 280 days.
Let us now use this excerpt from the Bank of Bangladesh case study as an example. In January 2006, attackers managed to successfully install malware on the bank's systems which gathered information about the bank's transaction procedures, this provided the attacker with an in-depth insight into their banking practices. The attackers probably used this malware to delete the file required by the system used for the transaction reports; it likely even "cleaned up" after itself, deleting vital evidence.
Case Study: Bank of Bangladesh
In 2006, the Bank of Bangladesh was the victim of a cyber-attack that resulted in the loss of $81 million. In this case, the attack was leveled against the bank itself rather than the more traditional form of attack, which is normally focused on individuals, be they employees or account holders.
Money is transferred globally using the Society for Worldwide Interbank Financial Telecommunications (SWIFT) network, which consists of a closed, trusted computer network that is managed and maintained by a consortium of banks and overseen by the National Bank of Belgium. The network's committee has members representing major banks worldwide including the U.S. Federal Reserve, the Bank of England, the European Central Bank and the Bank of Japan. It is used to facilitate the global movement of money. This attack targeted this SWIFT system.
While this does seem like a lot of money to lose in one attack, it could have been much worse; the Bank of Bangladesh successfully stopped further transfers totaling $850 million.
How was the attack detected? In short, a print device error. Like most, if not all banks, any out-of-hours money transfers are automatically printed off for the bank staff to examine the following business day. On Friday, February 5, a bank employee (a director found the print device to be out of paper. When refilled, a manual print was initiated but the device generated an error message. The system connected to the print device and was found to have a missing system file. When the missing file was restored, the fraudulent transactions were printed.
In January 2006, attackers managed to successfully install malware on the bank's systems, which gathered information about the bank's transaction procedures. This provided the attackers hackers with an indepth insight into their banking practices. The attackers hackers probably used this malware to delete the file required by the
On February 4, 2006, attackers used stolen SWIFT credentials to initiate fraudulent bank transfers to move money from the Bangladesh Bank funds via the Federal Reserve Bank of New York. In total, more than 36 money transfers were initiated. The transfer request instructed the Federal Reserve to move money to numerous banks throughout Asia.
An account opened in 2005 at the Rizal Commercial Banking Corporation in the Philippines had sat dormant for a year containing just $500. In February 2006, via four transfer requests, the $81 million was moved into this dormant account. A fifth transfer moved an additional $20 million into an account held at the Pan Asia Bank.
system used for the transaction reports; it likely even "cleaned up" after itself deleting vital evidence.
So why didn't anyone catch these transactions? Well, someone actually did: the Federal Reserve Bank sent queries concerning the transfers, but the Bangladesh Bank didn't respond. When the Bangladesh Bank contacted SWIFT and the Federal Reserve to cancel the transfers, it was too late. It was already the weekend in New York, so by the time the fraud was identified, $81 million had been moved from the Rizal Bank to multiple accounts. While the $20 million to the Pan Asia Bank was successfully stopped, all but $68,000 of the $81 million had been withdrawn.
