Author Topic: Blog: DDoS Attack on Bank Hid $900,000 Cyberheist  (Read 83 times)

Offline menotu

  • PCLinuxOS Tester
  • Super Villain
  • *******
  • Posts: 15515
  • ┌∩┐(◕_◕)┌∩┐
Blog: DDoS Attack on Bank Hid $900,000 Cyberheist
« on: February 19, 2013, 08:03:30 AM »
Brian Krebs 19 February 2013 (krebsonsecurity)

A Christmas Eve cyberattack against the Web site of a regional California financial institution helped to distract bank officials from an online account takeover against one of its clients, netting thieves more than $900,000.

At approximately midday on December 24, 2012, organized cyber crooks began moving money out of corporate accounts belonging to Ascent Builders, a construction firm based in Sacramento, Calif. In short order, the company’s financial institution – San Francisco-based Bank of the West — came under a large distributed denial of service (DDoS) attack, a digital assault which disables a targeted site using a flood of junk traffic from compromised PCs.

KrebsOnSecurity contacted Ascent Builders on the morning of Dec. 26 to inform them of the theft, after interviewing one of the money mules used in the scam.

Money mules are individuals who are willingly or unwittingly recruited to help the fraudsters launder stolen money and transfer the funds abroad. The mule in this case had been hired through a work-at-home job offer after posting her resume to a job search site, and said she suspected that she’d been conned into helping fraudsters.Ascent was unaware of the robbery at the time, but its bank would soon verify that a series of unauthorized transactions had been initiated on the 24th and then again on the 26th.

The money mule I spoke with was just one of 62 such individuals in the United States recruited to haul the loot stolen from Ascent. Most of the mules in this case were sent transfers of between $4,000 and $9,000, but several of them had bank accounts tied to businesses, to which the crooks wired huge transfers from Ascent’s account; five of the fraudulent transfers were for amounts ranging from $80,000 to $100,000.

http://krebsonsecurity.com/2013/02/ddos-attack-on-bank-hid-900000-cyberheist/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29
PCLinuxOS 32bit KDE 4.10.4; kernel-3.4.11-pclos1.bfs & 64bit 3.4.38bfs; NVidia GeForce 8400GS 1GB 310.19 driver

Sony Vaio SVE1513A4ESI Laptop, Intel Core i5, 2.6GHz, 6GB RAM, 750GB, 15.6" Intel HD Graphics 4000

Offline Tony

  • Hero Member
  • *****
  • Posts: 1771
  • naturam expelles furca, tamen usque recurret
Re: Blog: DDoS Attack on Bank Hid $900,000 Cyberheist
« Reply #1 on: February 19, 2013, 11:13:06 AM »
It's incidents such as this which make me wonder why the Internet is deemed a suitable vehicle for creating infrastructure in monetary and business institutions, Government, and the like. Such attacks have been happening for at least a decade, and are so easily orchestrated, criminals would be amiss to not exploit the vulnerabilties.
PCLOS *MiniMe 2013 - KDE 4.10.1 + *LDXE Full  Computing is Fun with Linux, mostly ;) *Software Updates

Offline kjpetrie

  • PCLinuxOS Tester
  • Hero Member
  • *******
  • Posts: 4037
Re: Blog: DDoS Attack on Bank Hid $900,000 Cyberheist
« Reply #2 on: February 19, 2013, 02:03:56 PM »
Perhaps because the authorities consider it less disruptive than an armed robbery where people get hurt. There was no danger of anyone getting beaten or shot.

However you handle money, someone will try to break in and steal it. The Internet method leaves a trail which can be followed in most cases. They'll probably get caught and some of the money will be recovered because the mules got suspicious.
-----------
KJP
-----------------------------------------------------------
PClos64 RC1 on Intel D945GCLF2 motherboard (Atom 330), 2GB DDR2 RAM, Maxtor STM325031, HL-DT-ST DVDRAM GSA-H42N, Amilo LSL 3220T monitor. Also Acer 5810TG (with custom kernel) and Asus eeePC 2G surf

Offline Tony

  • Hero Member
  • *****
  • Posts: 1771
  • naturam expelles furca, tamen usque recurret
Re: Blog: DDoS Attack on Bank Hid $900,000 Cyberheist
« Reply #3 on: February 20, 2013, 05:53:03 AM »
That's the first logical answer to my criticism of doing important stuff online ever. Well done kjpetrie  :D

Not sure I agree, but some logical assertions.
PCLOS *MiniMe 2013 - KDE 4.10.1 + *LDXE Full  Computing is Fun with Linux, mostly ;) *Software Updates