Bluefield Daily Telegraph, Bluefield, WV

National and World

May 10, 2013

Global network of hackers steals $45M from ATMs

NEW YORK (AP) — The sophistication of a global network of thieves who drained cash machines around the globe of an astonishing $45 million in mere hours sent ripples through the security world, not merely for the size of the operation and ease with which it was carried out, but also for the threat that more such thefts may be in store.

Seven people were arrested in the U.S., accused of operating the New York cell of what prosecutors said was a network that carried out thefts at ATMs in 27 countries from Canada to Russia. Law enforcement agencies from more than a dozen nations were involved in the investigation, U.S. prosecutors in New York said Thursday.

“Unfortunately these types of cybercrimes involving ATMs, where you’ve got a flash mob going out across the globe, are becoming more and more common,” said Rose Romero, a former federal prosecutor and regional director for the U.S. Securities and Exchange Commission.

“I expect there will be many more” of these types of crimes, she said.

Brooklyn U.S. Attorney Loretta Lynch, who called the theft “a massive 21st-century bank heist,” announced the case Thursday in New York.

Here’s how it worked:

Hackers got into bank databases, eliminated withdrawal limits on pre-paid debit cards and created access codes. Others loaded that data onto any plastic card with a magnetic stripe — an old hotel key card or an expired credit card worked fine as long as it carried the account data and correct access codes.

A network of operatives then fanned out to rapidly withdraw money in multiple cities, authorities said. The cells would take a cut of the money, then launder it through expensive purchases or ship it wholesale to the global ringleaders. Lynch didn’t say where they were located.

It appears no individuals lost money. The thieves plundered funds held by the banks that back up prepaid credit cards, not individuals or businesses.

Ori Eisen, a cybercrime expert and founder of 41st Parameter, a fraud detection and prevention firm, said the $45 million heist was on the “high-end” of what can be done by cybercriminals who exploit banking systems connected to the Internet.

“Given the scale of the global credit card networks, it is almost impossible to detect every kind of attack,” he said. “This attack is not the last one, and if the modus operandi proves to be successful crooks will exploit it time and again.”

There were two separate attacks in this case, one in December that reaped $5 million worldwide and one in February that snared about $40 million in 10 hours with about 36,000 transactions. The scheme involved attacks on two banks, Rakbank in the United Arab Emirates and the Bank of Muscat in Oman, prosecutors said.

Such ATM fraud schemes are not uncommon, but the $45 million stolen in this one was at least double the amount involved in previously known cases, said Avivah Litan, an analyst who covers security issues for Gartner Inc.

Middle Eastern banks and payment processors are “a bit behind” on security and screening technologies that are supposed to prevent this kind of fraud, but it happens around the world, she said.

“It’s a really easy way to turn digits into cash,” Litan said.

Some of the fault lies with the ubiquitous magnetic strips on the back of the cards. The rest of the world has largely abandoned cards with magnetic strips in favor of ones with built-in chips that are nearly impossible to copy. But because U.S. banks and merchants have stuck to cards with magnetic strips, they are still accepted around the world.

Lynch would not say who masterminded the attacks globally, who the hackers are or where they were located, citing an ongoing investigation.

The New York suspects were U.S. citizens originally from the Dominican Republic who lived in the New York City suburb of Yonkers. They were mostly in their 20s. Lynch said they all knew one another and were recruited together, as were cells in other countries. They were charged with conspiracy and money laundering. If convicted, they each face 10 years in prison.

The accused ringleader in the U.S. cell, Alberto Yusi Lajud-Pena, was reportedly killed in the Dominican Republic late last month, prosecutors said. More investigations continue and other arrests have been made in other countries, but prosecutors did not have details.

An indictment unsealed Thursday accused Lajud-Pena and the other seven New York suspects of withdrawing $2.8 million in cash from hacked accounts in less than a day.

Arrests began in March.

Lajud-Pena was found dead with a suitcase full of about $100,000 in cash, and the investigation into his death is continuing separately. Dominican officials said they arrested a man in the killing who said it was a botched robbery, and two other suspects were on the lam.

The first federal study of ATM fraud was 30 years ago, when the use of computers in the financial community was growing rapidly. At the time, the Bureau of Justice Statistics found nationwide ATM bank loss from fraud ranged from $70 and $100 million a year.

By 2008, that had risen to about $1 billion a year, said Ken Pickering, who works in security intelligence at CORE Security, a white-hat hacking firm that offers security to businesses.

He said he expects news of the latest ring to inspire others.

“Once you see a large attack like this, that they made off with $45 million, that’s going to wake up the cybercrime community,” he said.

“Ripping off cash, you don’t get that back,” he said. “There are suitcases full of cash floating around now, and that’s just gone.”

1
Text Only
National and World
  • Poll: Foreign policy no longer Obama strong point

    August 1, 2014

  • US employers add 209K jobs, rate rises to 6.2 pct.

    August 1, 2014

  • Thousands rally for coal

    The echo of people chanting, “Hey, hey, EPA, don’t take our jobs away” could be heard in downtown Pittsburgh, Pennsylvania, on Thursday.
    The voices came from about 5,000 United Mine Workers of America (UMW) members and their families along with other unions such as the Boilermakers Union and the Brotherhood of Electrical Workers International (IBEW) marching through the streets.

    August 1, 2014

  • West Africa Ebola outbreak tops 700 deaths

    Security forces went house-to-house in Sierra Leone’s capital Thursday looking for Ebola patients and others exposed to the disease as the death toll from the worst recorded outbreak in history surpassed 700 in West Africa.
    U.S. health officials urged Americans not to travel to the three countries hit by the medical crisis:  Guinea, Sierra Leone and Liberia.

    July 31, 2014

  • Sunburn isn't the only sign of summer that can leave you itchy and blistered

    You've got a rash. You quickly rule out the usual suspects: You haven't been gardening or hiking or even picnicking, so it's probably not a plant irritant such as poison ivy or wild parsnip; likewise, it's probably not chiggers or ticks carrying Lyme disease; and you haven't been swimming in a pond, which can harbor the parasite that causes swimmer's itch.

    July 31, 2014

  • The virtues of lying

    Two computational scientists set out recently to simulate the effects of lying in a virtual human population. Their results, published in the Proceedings of the Royal Society B, show that lying is essential for the growth of a cohesive social network.

    July 31, 2014

  • lockport-police.jpg Police department turns to Facebook for guidance on use of 'negro'

    What seems to be a data entry mistake by a small town police department in western New York has turned into a social media firestorm centered around the word "negro" and whether it's acceptable to use in modern society.

    July 31, 2014 3 Photos

  • Screen Shot 2014-07-31 at 2.12.55 PM.png VIDEO: Five-year-old doesn't want her brother to grow up

    Sadie, an adorable 5-year-old from Phoenix, wants her brother to stay young forever, so much so that her emotional reaction to the thought of him getting older has drawn more than 10 million views on YouTube.

    July 31, 2014 1 Photo

  • Comiskey.jpg Sterling not the only bad owner

    As the Donald Sterling era in with the Los Angeles Clippers looks to be winding down, many are calling him the worst owner in sports history. From being cheap with the players to his most recent racist comments, it's hard to argue against.
    Yet, there are a few owners of athletic teams who can give Sterling a run for title of worst in history.

    July 31, 2014 1 Photo

  • Lindley, Tom.jpg Grandstands feel a little empty at NASCAR races

    Two decades after NASCAR started running at Indianapolis Motor Speedway, the crowds have thinned considerably. It's probably no reflection on the sport's massive following, which stretches from coast to coast, but it surely doesn't NASCAR's image help when the cameras pan across all of those empty seats.

    July 31, 2014 1 Photo

Local News
AP Video
Four Rescued From Crashed Plane Clinton Before 9-11: Could Have Killed Bin Laden Couple Channel Grief Into Soldiers' Retreat WWI Aviation Still Alive at Aerodrome in NY Raw: Woman Who Faced Death Over Faith in N.H. Russell Simmons, LL Cool J Visit Youth at Jail Raw: Obama Gets Hug From Special Olympian US, UN Announce Deal on Gaza Cease-Fire Despite Moratorium, Detroit Water Worries Remain Faith Leaders Arrested at DC Deportation Protest Family Dispute Cripples Northeast Grocery Chain CDC Warns Travelers Amid Ebola Outbreak US Stocks Plunge, Wiping Out July's Gains Demoted Worker Shoots CEO, Kills Self Obama Slams Republicans Over Lawsuit Raw: 2 Hurt in NY Trench Collapse House Leaders Trade Blame for Inaction Cantor Warns of Instability, Terror in Farewell Florida Panther Rebound Upsets Ranchers Small Plane Crash in San Diego Parking Lot
Sister Newspapers' News