Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The Bank Vault Isn’t Secure: So What Hope Do the Rest of Us Have?
Articles

The Bank Vault Isn’t Secure: So What Hope Do the Rest of Us Have?

ISBuzz TeamBy ISBuzz TeamJune 15, 20165 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The losses being reported for recent bank cyberattacks are frighteningly large– banking cybercrime in 2016 most definitely pays.

Things used to be so simple in the Good Old Days…

Ever since the earliest forms of banking were established there has always been a need to protect the currency of the day. The first treasuries were established within temples to ensure that the loot was not only protected physically, but morally too by the overseeing deity.

Bank strong rooms evolved to incorporate increasing levels of physical security. Safes became vaults, with more steel and concrete being used. Similarly, lock technology increased in sophistication and complexity from simple keys to multiple layers of codes and combinations.

When bank heists began to find success via brute force – drilling, explosives and thermic lances will defeat any lock and even reinforced concrete – alarm systems became increasingly valuable. Sensors to detect unexpected activity could alert bank security before the physical vault defenses were breached. Alarm systems meant that the perpetrators were apprehended before a robbery succeeded, a valuable lesson from history that still holds true today.

In the last 20 years, in the banking sector, as in all other industries, the internet has proven to be a game-changer.

The opportunities for banks to trade faster, more simply and on a global scale has revolutionized the business. Unfortunately, the cybercrime industry has developed even faster and man, have they seized the opportunity to make money from the internet-enabled bank!

The big ones that have caused problems recently are the Carbanak APT which is estimated to have netted $1B worldwide, much of this in cold hard cash from hacked ATMs. There was also the more recent Bangladesh bank heist which shows that attacks often succeed more as a result of opportunism rather than necessarily being due to being uber-sophisticated.

What are the attack methods being used? Are these uniquely crafted for the Banking Sector?

Yes and no! The issue is that there is still the ‘mainstream’ tide of malware which is still an issue and a potential threat, but the major concern are the more targeted attacks. Using a modified or mutated version of existing malware provides a convenient, zero day version – zero day means invisible to anti-virus systems and to an extent, sandbox and IPS systems.

How are these new APT Malware attacks formulated?

Right now there has never been less of a need to create new malware as Brian Krebs reported recently. Existing malware only needs minor modifications to become operational as a zero day threat.

There still needs to be a vector for the malware – a means by which it can be transmitted – typically a vulnerability that is exploited or complicit or gullible personnel (i.e. phishing attacks), which is why vulnerability management and system hardening are key actions to take in order to mitigate the threats.

If a system is infiltrated by a Banking APT, what is the likely trajectory or behavior of the attack?

In a sophisticated attack such as the Carbanak attack, this was the very model of an APT (Advanced, Persistent threat) in that it gradually penetrated further into banking systems over time, stealing credentials in order to gain progressively higher access to more critical systems and provide remote control capabilities and video monitoring of systems usage.  The payoff for the attack was to allow the gang to help themselves to bank reserves and move money to their accounts at will through their access and control of core bank systems. In one especially audacious and creative move, the gang re-programmed ATMs to dispense cash on demand, issuing 5,000 Ruble notes when 100 Ruble notes were requested.

Targeting of ATMs is a scary prospect – how do Banking cyberattacks differ to those active in the Retail sector?

The banking attacks have been successful in directly providing access to funds transferred from bank reserves, whereas Retail attacks have tended to focus on Card Data theft, such as Home Depot, Target etc. Card data is still a highly valuable commodity that allows goods to be acquired fraudulently to be converted to cash. Card Payment Merchants are mandated to comply with the Payment Card Industry Data Security Standard, or PCI DSS, which outlines a series of 12 requirements for the operation of cyber security controls. These include vulnerability management, secure application design and testing, data encryption and breach detection technology, such as file integrity monitoring and event log analysis.

What are the key action points for Information Security teams in the banking sector?

In common with the PCI DSS, layered security best practices are needed to defend effectively against the entire range of insider threats, malware and phishing. Systems must be hardened to reduce the ‘attack surface’ presented by systems, and this must be underpinned by regimented patching with tight change control to better highlight the smoking gun of a breach – unexpected system changes. Internal segmentation of networked systems will help compartmentalize any malware infiltration. And because no system can ever be truly 100% secure, breach detection is critical.

Seems that when it comes to security, as with most other things in life, history tells us everything we need to know.

[su_box title=”About Mark Kedgley” style=”noise” box_color=”#336588″][short_info id=’70961′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}