BankInfoSecurity.com - Information Security News, Regulations, & Education

Bank Information Security Articles

'Crime Server' Found with Thousands of Bank Customer Records

Credit
Eligible
As a BankInfoSecurity.com annual member, this content can be used toward your membership credits and transcript tracking. Click For More Info
FBI Investigating Breach Affecting 40 Global Institutions
May 7, 2008 - Linda McGlasson, Managing Editor

This article was originally created for BankInfoSecurity.com, and contains information that should interest our GovInfoSecurity.com readers.
Share

Comment on this article

More than 5,000 customer records from 40 international financial institutions were discovered last month on a computer server in Malaysia.

Dubbed a "crime server" by Finjan, the information security vendor that discovered it, this machine held more than 1.4 gigabytes of business and personal data stolen from Trojan-infected computers. The compromised data (all less than one month old), consists of 5,388 unique log files, comes from around the world and contains information from individuals and businesses alike.

The types of compromised data found on the crime server includes user names, passwords, account numbers, social security numbers and credit card numbers. Finjan's chief technical officer Yuval Ben-Itzhak estimates that more than 60 percent of the information on the server was bank customer data. Other information includes compromised patient data, business-related email communications, as well as captured Outlook accounts containing emails.

The crime server was detected using "command and control" tools to operate crimeware that was executed on the end users infected computers. The same server was used as a "drop site" for the personal information harvested from the infected computers. The stolen data was then left unprotected on the server without any access restrictions or encryption, meaning that the data was available to criminals. Ben-Itzhak notes the fact that sensitive business and personal data in more than 5,000 cases were compromised in a timeframe of less than one month indicates that "The current numbers quoted in the industry reflect only the tip of the cybercrime iceberg."

Click to Get Updates on the Latest Information Security News

The server has been taken down, says Ben-Itzhak.

Finjan says it has since discovered two more "crime servers" holding similar information, and both have been turned over to law enforcement for investigation.

So far, the San Jose, CA-based security vendor has contacted 40 major international financial institutions located in the US, Europe and India that had customers' data compromised. Finjan would not reveal the names of any of the institutions impacted. The Federal Bureau of Investigation and other law enforcement agencies in Germany, France, India, UK, Spain, Canada, Italy, Netherlands and Turkey were notified of the information found on the server. The U.S. investigation is in the hands of the FBI. Paul Bresson, spokesperson at the FBI's national press office in Washington, DC. would not comment on the crime server or what it contained. "As a policy we don't discuss information or acknowledge that information was received when investigations are initiated or while an investigation is ongoing," Bresson says.

"The scope and ramifications of this particular incident are staggering," says Viveca Ware, director of Payments and Technology Policy at the Independent Community Bankers of America (ICBA). "It is very unusual to have such a diversity of information available on one server in one location."

"It looks like a one-stop shopping location for criminals to get information," Ware says.

Scope and Scale
Doug Johnson, Vice President and Senior Advisor, Risk Management Policy at the American Bankers Association, notes that compared to last year's arrest of criminals in South Florida caught with 250,000 credit card numbers (Six were arrested after committing $75 million in credit and debit card fraud), orders of magnitude come into play. "The bottom line is data breaches are a fact of life these days and we take every threat seriously," Johnson says.

Johnson says breaches of information such as found on this crime server are investigated appropriately by law enforcement The financial services industry has strong mechanisms to get the word out very quickly, such as the Financial Services Information Sharing and Analysis Center, and will vet this threat to determine as to the need for a wider dissemination of the information, he adds. "The process works when it comes to informing affected companies."

As a hands-on security assessor of US financial institutions, Ken Stasiak, CISSP, CISA, CISM, GSEC, and President of Secure State, an information security assessment company in Cleveland, OH., sees this crime server as something that is evolving from the attack vector used for the past four years, a "bot network" or "zombies" that are used to collect information.


1 | 2




Question
Question
?What's your reaction to news of the 'crime servers' with thousands of customer records?
Here's your chance to be a part of the dialogue and engage with your peers! Just enter your comment to the right, click submit to send it to our Editor. All entries are posted anonymously.
Please login if you would like to post a comment on this question.

"This certainly is not surprising since technology has come up with a way to receive information as it goes through air waves! What is next? Hiding the information from those whose records were compromised is not going to help anyone. If the criminals have discovered the technology to capture this information-why isn't it available to those of us whose systems might be compromised by it?
"Why are the thives so much farther ahead of our financial institutions at getting this information then the banks are at protecting it?

You are always playing catch up rather than being defensive about our information. I believe that it is going to take some class action law suits to wake you people up.

A word to the thieves: get in on the movement to sue these places that are losing this information to you. Help the lawyers and cash in on that part, too.
"My first question is did the data come from a financial institution or individual's personal computers? My sense is that it came from personal computers, but that won't stop the media from saying that the financial institutions' systems may have been compromised. How far from the front doors of a brick and mortar branch does a bank's responsibility go? I have always struggled with the fact that we have no control over how an individual secures their home computer, but seem to have the responsibility to keep that data safe. I can see a future where a version of NAP is used to ensure that any system getting data from a financial institution, even a customer's, meets a minimum level of patching and anti-virus/malware, and doesn't have any known malicious code running on it. Customers may not like it, but they need to take some responsibility for security, or this problem will never get solved effectively.
"We will eventually revert back to the age of no internet usage. As long as there are people out there like this, it threatens those things that were designed to make life easier.
"I'm not surprised at all. The main question is - how many others are out there?