World Bank Under Cybersiege In "Unprecedented Crisis"
JagsLive sends in a Fox News report on large-scale and possibly ongoing security breaches at the World Bank. "The World Bank Group's computer network — one of the largest repositories of sensitive data about the economies of every nation — has been raided repeatedly by outsiders for more than a year, FOX News has learned. It is still not known how much information was stolen. But sources inside the bank confirm that servers in the institution's highly-restricted treasury unit were deeply penetrated with spy software last April. Invaders also had full access to the rest of the bank's network for nearly a month in June and July. In total, at least six major intrusions — two of them using the same group of IP addresses originating from China — have been detected at the World Bank since the summer of 2007, with the most recent breach occurring just last month. In a frantic midnight e-mail to colleagues, the bank's senior technology manager referred to the situation as an 'unprecedented crisis.' In fact, it may be the worst security breach ever at a global financial institution. And it has left bank officials scrambling to try to understand the nature of the year-long cyber-assault, while also trying to keep the news from leaking to the public." Update: 10/11 01:15 GMT by T : Massive spyware infestations might be good cause to reevaluate the TCO of non-Windows systems on the desktop.
These days financial institutions consider IT (and other) security as something that costs them money, without giving them any benefit.
Will this wake them up?
I hear the question "Can we afford"? when talking about security in IT shops. The question that I am coming back with is "Can we afford not to"?
Just how many more banks machines are compromised? How about Federal and Local Government's machines and networks.
If you had enough financial data somebody could cause an economic collapse - I wonder what it would look like.
while also trying to keep the news from leaking to the public
Oops
--
Oh Well, Bad Karma and all . . .
Beer is proof that God loves us and wants us to be happy.
previously, i thought the markets were melting down due to gay marriage
perhaps this is the obvious run up to 2012 and the end of the mayan calendar
paranoid schizophrenics, want to help me out here?
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
Well of course I can't be certain but this appears to be ntohing more than a breach of their email system (encrypt your damn email people).
From the leaked memo "MD and CIO has directed that all external Webmail accounts be disabled immediately for all staff who have not changed their passwords yet"
I'd really like to read about this from a source other than Fox news.
First thing I would do is launch my attack from a compromised host in country X while being in country Y
I don't know the meaning of the word 'don't' - J
Does anyone have a link to a story on this from a reputable news source?
Damn, they got owned completely, 3 different times. Someone in their security department needs to get a clue. Somehow their offsite data store got accessed, then an IT consultant worker key logged them, and finally they got in again through a third party and escalated to admin rights.
3 different attack vectors, all completely successful. That is just kinda pathetic...
Jim Rogers, Adventure Capitalist and Fox News business commentator, has said the same thing. What I'm trying to say is that the parent is not some leftist nut.
I hear you have an opening for a security expert...
As the possible first post, I want to make sure no one thinks this is in anyway related to the markets crashing, as it stands if china did originate the attack, they are losing as much as the USA right now, and are still losing dealing with their own problems(with the food illnesses).
I was one to believe that Chinese were doing a lot of hacking on purpose to advance in cyber tactics, however this move if were caused by them, ended costing them more then it returned.
It may more have been a Russian hacker rerouting through china using tor or something.
It is Satan's rectum, poised over the third-world.
Best slashdot line in ages.
Trolling is a art,
Face it, no matter how secure a system is, if it is usable by humans it can be breached. Easily.
There is anywhere from a 100 to 1000 hackers/crackers/slimeballs out there that are ready and willing to take on each and every system. Ones that claim to be "secure" are just a bigger target. There is no such thing as a completely "secure" system that is usable and accessible by ordinary humans. True security would require controlled physical access, multiple authenticating factors, and so on. None of this is going to happen for an accessible system usable by "ordinary humans".
About all that is realistic is to minimize the damages. Face the fact that if you are a target you are going to lose. Try not to lose too much.
Prosecution of the break-in? Forget it. It's the Internet. It is International. If it looks like it is coming from China, it could be real or it could be a proxy. There are no effective International laws that will assist in any sort of prosecution. There is no supra-national police force that will break down the door of the cracker and haul them away. Nothing is going to happen. Unless the guy is a complete idiot that brags about it.
I expect the slashdotting will have an effect :)
sensitive data about the economies of every nation
What's so sensitive about the economy of a nation that it must be kept secret, thereby not even allowing the nation itself (the people) to know about it?
Swedish plasma phys. PhD student; MSc EE; knows maths, programming, electronics; finance interest; seeks opportunities
Please, please, please mod parent comment down. The last thing we need is for the phrase "It is Satan's rectum, poised over ..." to become a new Slashdot meme.
I mean can you imagine:
- an item about Linux and posts like "It is Satan's rectum, poised over capitalism";
- an item about fascism and posts like "It is Satan's rectum, poised over our freedoms";
- an item about the Cheney/Bush government and posts like "It is Satan's rectum, poised over privacy and the U.S. Constitution"
- an item about a new Windows version and posts like "It is Satan's rectum, poised over the computer world";
Yech! Please stop it before it starts!
Is there some scarred super-villain out there somewhere petting a hairless cat laughing like a maniac as the world falls into economic ruin?
No, is he a good-looking WASP, attended St. Paul's School and Yale (or maybe Lawrenceville and Princeton), and he made a shit-load of money while his bank was going to Hell in a hand-basket.
And he is petting a pure bred golden retriever.
He is not laughing, but chuckling, because you get to pay the tab.
Schroedinger's Brexit: The UK is both in and out of the EU at the same time!
It is interesting, though, that it has been about a year since the current run on the stock markets and world finances began. (The current credit crunch, if you look at the graphs, is simply a continuation of a trend that began probably about April last year.)
Now, to use the oft-quoted "correlation does not prove causation", it would be totally absurd to say that the coincidence of dates proves the current problem is related to the cyber-attacks. Lots of things probably happened in April of last year. To pick one out, just for the sake of picking something, would be stupid. However, if I were in charge of IT security at the World Bank, I would be wanting to know if sensitive or classified information was continually exposed over that period that would permit someone to destabilize things.
It's almost certain that unencrypted sensitive information would be present on e-mail servers, which is stupid and naive, and members of the World Bank who don't make use of secure methods of communication for sensitive material should be made to walk the plank regardless of whether any harm was done. The IT managers who allowed unencrypted data to be present and who did not properly install suitable intrusion countermeasures should follow shortly thereafter. In the (extremely dubious and unlikely, but arguably possible) circumstance that the crisis is related to the infiltration, then the game changes from a mere fix-things-up and discipline-the-bastards scenario to a more severe lockdown-the-damn-network-now-defcon-1 type of situation.
The former simply means you need to apply suitable patches and/or servers, and maybe hire a pirate ship to escort the former employees to shark-infested waters. Since this is the most likely situation by far, that's all they need to do. But concealing it hasn't helped them apply the measures they needed, or the attacks could not have continued the moment it tripped the first intrusion detector. In this case, the secrecy has caused severe harm to the World Bank, but probably nobody else. Like I said, this is the most likely.
The worst-case is that we're seeing a positive feedback loop. Sensitive/classified information on volatile situations that could cause those situations to get considerably worse being posted, then lifted and used to do exactly that, causing people to post even more such information, and so on. Positive feedback loops are not simply a technological problem but an entire attitude problem and social engineering problem. That requires more than IT security, because IT security can't debug or firewall the brain. Yet. Such a loop might easily require a complete organizational shutdown, because no amount of patching will help. It needs a major attitude shift - not just on the part of internal employees but also on the part of all countries involved - and that takes time. If it's the mind that's the vulnerability -AND- it is causing massive devastation, the World Bank would have to shut down all operations completely. Otherwise, you can't guarantee killing the loop. The chances this would need to happen are extremely slim, but as I said, it is technically possible, and you can't afford to be piecemeal when it comes to such scenarios.
If it's so unlikely, why mention it at all? Because the timing -is- interesting (a crisis is uncommon, so two parallel financial crises should raise eyebrows), along with the fact they even see it is as a crisis is exceptionally interesting, the fact that their response has been one of paralysis (suggesting a non-trivial people problem, rather than an idiotic individual or an unpatched machine), and the fact that everyone else's management of their perceived problem isn't managing it in the least, is suggestive that (a) the wrong problems are being fixed, and (b) that there is a lot of pressure to avoid fixing - or even seeing - the right problems. Suggestive isn't proof, of course, which is why I'm more interested in whether they're even looking to see if this is a possibility.
It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
Secrecy is the hallmark of your government. There are good reasons for this. Bush-Cheney would be dangling by piano wire at this moment if the American public could freely see into what they've done and how they did it. (Actually there's more than enough of what we know they've done.)
It's one reason why a Democrat isn't permitted to be elected; Obama-Biden have threatened to prosecute criminal acts under Bush-Cheney. You can bet that puts the fear of god into them. Too many powerful people have too much to lose.
you had me at #!
I've always thought the next world war would be fought with I.T. tools, acquiring data, corrupting data, putting economies into turmoil. Is this what is happening? China and others(recall cybertraffic around the olympics when Georgia-Russia got into it), are they secretly waging war or deceptively setting up the next war? And what, if any response is the U.S. countering with? Is this something hidden from citizens or is it just not happening?
What if the hokey-pokey is what it's all about?
You know, corporate accounting is sure as hell gonna notice $305,326.13....
The world bank makes HUGE loans to entire nations and imposes draconian reform rules and regulations, requires real assets as collateral, usually the target nation's most valuable raw resources, and charges interest. If that ain't a bank of sorts, what is?
Well keep in mind in the 1997 Asian Financial Crisis the IMF recommended the Asian Governments to do about the opposite of what the USA is doing now.
http://en.wikipedia.org/wiki/Asian_financial_crisis
"The IMF's support was conditional on a series of drastic economic reforms influenced by neoliberal economic principles called a "structural adjustment package" (SAP). The SAPs called on crisis-struck nations to cut back on government spending to reduce deficits, allow insolvent banks and financial institutions to fail, and aggressively raise interest rates."
Raise interest rates, allow insolvent banks and institutions to fail (even if they are "too big to let fail"). And allow them to be bought up by foreigners. How'd the USA like it if AIG got bought up by China/Japan (they do have enough money, it's just that they know it'll annoy their number 1 customer ).
Go compare what the USA is doing now to the IMF's recommendations in 1997.
So, forgive me if I see the IMF as evil. The World Bank? Probably the other arm ;).
They're both just tools for the US to increase its power over the rest of the world.
The US government has a long history of conjuring up fictitious demons in order to justify bringing in more police state measures.
I bet we're about to hear of a clampdown on the Internet, "to safeguard freedom and the effective operation of world markets".
Of course, the reason our government does that is because it is a government By, Of and For The People. That means our leaders are (to a limited degree) accountable to us, and have to sell us on any such nonsense they wish to implement. That they're able to do that is speaks more to the caliber of the American citizen than anything else. We should be a harder sell than we are, that's for sure. As it is, just mention children or terrorists and we'll bend right over.
Put it this way: the reason that national governments of countries such as China, or Russia, or North Korea don't have to run a con on their citizens is because those people are nothing more than subjects, serfs in fact. They have no say in what their governments do, so their governments do whatever the hell they want.
The higher the technology, the sharper that two-edged sword.
>>I've always thought the next world war would be fought with I.T. tools, acquiring data, corrupting data, putting economies into turmoil.
I hope you're right. I'd rather have my flights redirected and my credit cards canceled then be gut-shot by a 17-year-old conscript.
After all, I'm a 2 hour drive from Canada as it is... I can just see the Tim Horton's signs going up as they politely herd us into 're-education' camps to watch hour after hour of the Red Green show.
Yes, I've thought about this a lot.
-b
No offense, but I've stopped responding to AC's.
UPDATE: After FOX News published its story, a World Bank spokesman issued the following statement: "The Fox News story is wrong and is riddled with falsehoods and errors. The story cites misinformation from unattributed sources and leaked emails that are taken out of context.
"Taken out of context" by definition means "it happened and we can't deny it, but we're not crazy to confirm it".
I don't know why would Skype be installed, but you should read the memo a bit more thoroughly before making "bogus" claims.
Nowhere does the it say that a Lotus Notes Admin account has been compromised. It says that the Notes Server sent a notification triggered by an attempt to access the mail inbox for a (compromised) sysadm account of some guy who was on vacation.
And nowhere does it say that Microsoft was doing the forensics, it says that "Microsoft forencsics is being worked on by Charles team". Since the server they mention is a Domain controller, it would make sense that they're running some M$ software on it, wouldn't it?
I'm not saying the memo is for real, but you need to work a bit harder than that to discredit it