Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Bank-Hacking Malware Threatens Global Financial Institutions
News & Analysis

Bank-Hacking Malware Threatens Global Financial Institutions

ISB Editorial StaffBy ISB Editorial StaffApril 27, 2016Updated:May 8, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Over ten thousand banks and financial institutions are being urged to remain vigilant after the secure Swift (Society for Worldwide Interbank Financial Telecommunication) system – used to send messages between global firms – was reportedly compromised by the sophisticated hacking scheme that targeted the Bangladesh central bank in March 2016.

IT security experts from ESET, Proofpoint and Lieberman Software provide commentary.

Mark James, Security Specialist at ESET:

“Any successful malware attack is a very real threat to happen again no matter where it is. Malware is typically a “keep trying” business model and with so many financial organisations using all manner of both good and bad security measures, it only takes one weak link in this industry to provide a wealthy return. Even taking something that has worked before and adapting it for another market or country is often a low cost opportunity to reuse a working model.”

With so many vectors making up the whole security bubble for these organisations, it’s extremely difficult to ensure all the systems are safe and watertight. On top of that, financial services are a very rewarding target if successfully breached. With malware getting more and more complex these days the only way to stay safe is to keep ahead of the bad guys. Data monitoring and segregation has to be in place to not only be on the lookout for anything suspicious as it happens but also to limit access to systems in the case of a compromise. Keeping your operating systems, software and (hardware) firmware updated needs to be a high priority alongside ensuring your staff are incorporated into your security regime.

With so many individual points of failure it only takes one to be successful for malware to gain control. If the very basics of security are not being adhered to, like firewalls and user or staff education, then you are basically handing your companies innermost secrets over for all. For security to be effective it has to be moulded into your individual means, a global or broad program is ok as a basic start but you can’t allow it to be your only means of defence, you need to take that as a starting point and expand or manipulate it to fit your needs.”

Kevin Epstein, VP, Threat Operations Centre at Proofpoint:

“From Stuxnet to Zeus and earlier, there’s a longstanding trend of re-use of malware tactics and code. Given the level of investment and sophistication of the attack, it seems extremely likely that similarly themed campaigns will be attempted – re-emphasizing the need for frontline targeted attack protection and threat response systems.

Multi-layer defenses using modern techniques are crucial.  Attackers are constantly innovating, seeking weaknesses; defenders should invest in innovative defenses accordingly. It’s at least as important to deploy new defenses against inbound targeted attack vectors such as email, mobile, and social networks as it is to reinforce deep interior systems code; in other words, best practice is to conclusively secure external doors and windows as well as worrying about better interior desk drawer locks.

While the malware in question appears to represent an unusually large and specific investment on the part of the attackers, the premise is similar to that used by mainstream malware actors; infiltrate and intercept, a strategy comparable to that used with Dridex and other banking Trojans. A multi-layered defense would ensure that many such attacks could be – and have been – blocked at the point of infiltration, using targeted attack protection and threat response systems applied to email, social media, mobile devices and other inbound threat vectors.”

Jonathan Sander, VP of Product Strategy at Lieberman Software:

“The specific attack on the Swift bank messaging system that was compromised in Bangladesh is not likely to appear in US or UK banks, but the damages from attacks on that system very well could. Like so many other systems today, the global banking system is interconnected in so many ways that the chain truly is broken through one weak link. The losses in Bangladesh were $81m (£56m, €71m), but you have to imagine that will have ripples in other banks doing business there and elsewhere because of how things work in a global economy. The cybersecurity of those you do business with is no longer a curiosity, it’s a critical risk you must understand and address.

The best thing banks can do to protect themselves from the sort of damage that is likely here is to review and understand how they set the bar for doing business with partners. The executives in any business are very good at seeing the revenue potential of new business partners and tend to see putting in provisions for starting those partnerships as bad ideas that decrease how nimble they are. But if the new partner is using $10 routers and no firewalls to run critical IT systems that you will now be directly dependent upon, wouldn’t you want to know that before signing any contracts? Basic cybersecurity practices will soon become as common sense to business partnerships as basic insurance coverage is today.

BAE casually mentions in their reporting of the Bangladesh central bank incident that the attackers original intent was to steal credentials. Security experts have come to assume that attackers go after credentials first as their gateway to getting all the good stuff an organization may have to steal, but everyday practitioners still seem stuck on firewalls and other security basics. Of course, these folks apparently had little to no firewall to speak of, but that only doubly highlights that with no wall to keep a bad guy out the first thing they’re after when they get in are the credentials.”

ISB Editorial Staff
  • ISB Editorial Staff
    Navigating the Cyber Threat Landscape: Key Insights from Trellix ARC’s Q1 2023 Report
  • ISB Editorial Staff
    Experts’ Responses: Cyber Security Predictions 2022
  • ISB Editorial Staff
    ISB Virtual Conference: Key Cyber Security Challenges and Solutions in 2021
  • ISB Editorial Staff
    Cyber Security Predictions 2021: Experts’ Responses

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}