Hackers Steal $6.7M In Bank Cyber Heist
Orome1 writes "A perfectly planned and coordinated bank robbery was executed during the first three days of the new year in Johannesburg, and left the targeted South African Postbank — part of the nation's Post Office service — with a loss of some $6.7 million. The cyber gang behind the heist was obviously very well informed about the post office's IT systems, and began preparing the ground for the heist a few months before, by opening accounts in post offices across the country and compromising an employee computer in the Rustenburg Post Office."
It's not whether you can get into a bank, or even out of it, it's how long you can keep the money.
It will teach them to not have so many holidays I hope!
And you expect credibility while posting as an AC and off-topic, why?
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
Not sure if serious. he posted evidence, you just don't like it. Refute the claims.. oh wait you won't even post your name. great job.
CS majors know the time/space tradeoff, but they never get taught the 3rd, crucial, tradeoff of the set: comprehension!
"Hey, can I check my Facebook real quick?"
He only expects further trolling, which has been granted.
When the foot seeks the place of the head, the line is crossed. Know your place. Keep your place. Be a shoe.
I was part of a small team that described a pretty similar attack scenario to a customer almost 10 years back. It is no surprise at all that this worked and it would work in a lot of other places as well. The only really tricky part is coordinating the mules (and keeping them quiet) as you do not know how much money is available at each specific ATM. But you can guess by observing usage patterns (counting customers) and how often they are re-stocked.
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
Time to just nuke 'em all and be rid of the devil dogs once and for all !!
42m Rand is not 6.7m USD, it is more like 5.2m.
Wall Street CEO's have been stealing much larger amounts from their own banks for years.
How could an investigation rule out a possible inside job? These hackers are pretty good at covering their tracks.
One of the many clever ways they employed in one heist, was to run malicious code that incapacitated random parts of the system once it detected that it was itself under some kind of detection or surveillance. Clever indeed.
Are we really supposed to believe that? Specially when you seem to have waited right there till the news item to come out to post this accusation? /. is your job description.
Seriously? A first post with the exact time stamp as the news item, it undoubtedly seems that:
- you don't have anything else to do;
- hanging around on
(posting as AC to avoid harassment)
I think all of you need to settle it after 3 like school children are supposed to. I'm tired of all you idiots.
Does any of it really matter? Those mod points are, in the end, worthless. Work your e-peen elsewhere that makes it look like you matter, like a aol chatroom.
Go away, DCTech. Eat your down mods like the office drone that you are.
Those who can, do. Those who can't, sue.
I'm much more surprised by the fact that they managed to take about 1% of the entire assets of the wanna-be bank. That's pretty disturbing - because that means that nothing was working right. Not their security, not their required privileges, not their fraud detection, nothing. Note to self: don't do business in SA.
Those who can, do. Those who can't, sue.
I love conspiracies. I can't wait until the twist where Bonch and GreatBunzinni turn out to be the same person
Politicians have been stealing much larger amounts for years.
No brain, no pain.
he clearly showed that Bonch and Overly Critical Guy had posts which were themes on the same base material. Certainly, a professional advertiser would use such a permutation. That's evidence enough for the court of slashdot... the burden of proof is yours, AC.
CS majors know the time/space tradeoff, but they never get taught the 3rd, crucial, tradeoff of the set: comprehension!
When will idiots understand that windows is the best friends of terrorist and criminals? So many claim that it is cheap to run, but they NEVER take into account things like this. WHy? Because the costs are externalized. Insurance companies need to get a clue and start jacking up their prices for companies that run insecure systems like Windows.
I prefer the "u" in honour as it seems to be missing these days.
I could understand the mass media using the word "hackers" here but /. should know better. These guys are just bank robbers and we dont differentiate between bank robbers who use handguns vs those with knives vs those who claim to have a bomb strapped to them.
"stopping completely when the offices were opened again on January 3" ...and returning to their jobs at the post
This isn't the first "cyber heist" in South Africa, just the first one to make the news.
Seriously, though, criminals realised long ago that you can steal more electronically than you can carry in a 'traditional' heist. Just look at the Russian's and their level of organised e-crime!
Dan. -- So what if it's spelt wrong, nobody's perfect
My very wealthy American uncle, who was the American consulate attache to Guyana, recently passed away. While we are very sad for his passing, he has left a great fortune in the Bank of Amerika that, unfortunately, cannot be transferred back to Guyana without completing the probate process. Since my wealthy American Uncle (Sam was his name) was too big to fail (er I mean die), I stand to inherit a great deal of wealth. I will gladly share with you this windfall at the Bank of Guyana if you will help me complete the probate. If you will kindly Paypal 52m Rand to help defray the cost of the probate, I will in turn send you 52billion US dollars. Please respond in confidence to my email address: Angelo.Mozilo@Countrywide.com.
"The investigation will hopefully reveal whether the backdoor into the compromised computer was installed by the employee unwittingly or whether the employee was recruited by the gang to allow them access." I would not want to be that employee!
So fucking retarded. They both made points obvious to anyone holding that view. That fact that they hold the same view at an abstract level is not evidence that they are the same person or a shill. Unless most accounts on here are shills for Linus. Yeah, that works.
If you ignore ACs because they are anonymous - you're an idiot.
Didn't you hear? Everyone else on the internet is just one big fat guy.
Bio questions? Ask me to start a Q&A journal. Computer analogies available for most topics!
im guessing that the main reason it seems like an 'unusual south africa thing' is because US banks never, ever talk about this kind of thing.
partly out of embarassment, partly because the entire system is based on 'security through obscurity'.
----
of course, oblig. comment about how thousands of US banks failed in 2008/9/10 due to the CDO fraud system - which directly involved and benefited the ratings agencies. but its almost like nobody cares about that. they care about 5 million stolen from ATMs, but not about 2 trillion stolen from the taxpayers.
This sounds like more of a case of social engineering rather than hacking.
I am pretty sure their Systems Analysts and Programmers will cop most of the shit that is coming for what I predict is some stupid emplyees fault. "Yes, what can I do for you Jo?"
I could be wrong, but that's my take.
The whole book is this heist.
Literally.
Just check out the summary.
The thing that makes this book series special is that they don't say, "I ran nmap and knew from the output they were running a webserver."
They say "I ran nmap with 'sudo nmap -P0 -T3 -p 80 127.0.0.1 -oA localscan'
And got:
Starting Nmap 5.21 ( http://nmap.org/ ) at 2012-01-17 20:55 PST Nmap scan report for localhost (127.0.0.1) Host is up (0.000083s latency). PORT STATE SERVICE 80/tcp open http Nmap done: 1 IP address (1 host up) scanned in 0.07 seconds And could see from the line "80/tcp open http"
http://www.amazon.com/Stealing-Network-How-Own-Continent/dp/1931836051
"Chinese Amazons, power armor, laser swords.... things just meant to be." - Shampoo, A Very Scary Bet
... they managed to [loose] about 1% of the entire assets of the wanna-be bank.... Note to self: don't do business in SA.
The correct conclusion is that incompetent governments should not be involved in banking.
The correct conclusion is that incompetent governments should not be involved in banking.
But incompetent corporations should?
Asked if there were concerns about the risk the security breach posed to government departments using the Trust Centre hosted by the post office...
If that's what I think it is, look forward to another wave of MITM-facilitating rogue certificates, this time from South Africa...
, Pule said: "The centre has high security parameters to protect all the services delivered through it."
oh, after that much buzz-word laden alphabet soup, I feel so much better. Hopefully their flux capacitors are fully charged or else there high security parameters might unload.
I'm much more surprised by the fact that they managed to take about 1% of the entire assets of the wanna-be bank.
At least, that means that their ATMs were well-stocked for the long New Years' break. Around here they'd have run out of money on the second day...
At least the criminals are not blowing up ATM's (while people are there) or money vans (on busy highway), and not rushing into a local supermarket armed with AK-47's - as is the case often across johannesburg, where I live :-)
http://www.youtube.com/watch?v=XIizDImrzHI Video of ATM bombings which is also epidemic in South Africa.
Are they sure it wasn't just a penny rounding scheme gone terribly awry?
Monstar L
Since Money is just an abstract representation of value that only works as well as the agreed use by those using it, so to ease trade (vs. barter) and in this case its wasn't even paper or coin, they can type the numbers back into the system, like it was never gone. And this would be far from the first or last time the banksters do this.
This idea that to much of this abstract tool in circulation leads to inflation is bull shit, just and excuse of the banksters to play their game of manipulating the economies. Take enough money out of circulation and things crash (as would a car lacking oil) and here is where the banksters then buy properties and other real value up at pennies on the dollar. Then they put money back into circulation and build public confidence to the point of high consumer spending..... Rinse and repeat.
And now you know the game being played by the few at the top of the banksters criminal organization.
Is this the one where George sets up a house to be tilted, no wait, that was the second? .....
Oh yeah, ok, they rent a whole bunch of small mini coopers and.....nope...
Ok, I got it....she has to go under all the infrareds and slowly stealth her way through to the
Ok, nevermind, I think I am overloaded as it is...movin on....nothin I want to see here.
This "shill" crap that has been flying around lately has to stop.
such as Galestar, NicknameOne, and flurp
Oh, please. It is obvious that this crapflood is from bonch (== Overly Critical Guy) who has a problem with Galestar, NicknameOne, flurp, and GreatBunzinni.
bonch: The "shill" accusations flying around on Slashdot lately are getting out of control.
Overly Critical Guy: This isn't bonch... Aren't you Galestar/NicknameOne/flurp who replies to all his posts?
Overly Critical Guy: Hi, GreatBunzinni. How do I know it's you? ... This is not bonch.... Signed, NOT bonch
"This isn't bonch"? Ha ha. BUSTED!
bonch: Seamless experiences win out in the long term. We saw this when gaming moved from PCs to consoles in the 2000s, and it's happening now in the transition to the post-PC era.
Overly Critical Guy: Seamless experiences always win out over time. We saw it when gaming shifted from PCs to consoles, and now the industry is shifting from desktops to mobile devices.
Overly Critical Guy Android phones used to look like this
bonch: Android used to look like this
Overly Critical Guy: The keyboard looks exactly like Apple's flat keyboard, and the trackpad is the Magic Trackpad that Apple started offering a year or so ago
bonch: The keyboard looks just like Apple's flat keyboard introduced a few years ago, the trackpad is a clone of the Apple Trackpad.
bonch: A Slashdot employee recently told me that my comments generate more moderations than any he's ever seen. (yes, that is what happens when you mod your own troll posts up from multiple accounts.)
It didn't:
http://inaudit.com/audit/it-audit/online-theft-that-sucked-13m-from-financial-firm-in-florida-unmasked-9888/
This was in Florida last year.
They're both Apple fanboys, apart from that they have nothing in common. Bonch is one of the bloggers on MacJournal.
"When information is power, privacy is freedom" - Jah-Wren Ryel
But incompetent corporations should?
I think you meant: But incompetent corporations are?
Also, not sure about off-shore but in the states the government is not involved in the banks which are private entities for the most part, no idea about SA, but it doesn't seem so? lol