Cybersecurity firm identifies ‘credible threat’ to 30 U.S. banks


A report from McAfee Labs says hackers could create fake bank transactions, or skim a portion of high-dollar bank transfers. (Jeffrey MacMillan)
December 13, 2012

Hackers may stage a massive fraud attack on 30 U.S. national, investment and regional banks early next year, according to a new cybersecurity report.

The report, scheduled to be released Thursday by McAfee Labs, warns the financial industry to be wary of software that creates fraudulent online banking transactions. Hackers could create fake bank transactions, or skim a portion of high-dollar bank transfers, the report said.

The report links the threat to a program called Project Blitzkrieg, which hackers say has been in development since 2008 and has already stolen $5 million. The attacks have now reached the United States, Mc­Afee reports. There have been 300 to 500 U.S. victims in the past couple of months, and the effort could reach full strength by spring, said Pat Calhoun, a network security expert at McAfee.

The McAfee report backs up an October report from cybersecurity firm RSA that said a Russia-based hacker nicknamed “vorVzakone” was recruiting for the “most substantial organized-banking Trojan operation seen to date.” In an unusual move, vorVzakone publicly discussed his plans on Web forums and in videos, leading some to believe that effort was simply a law enforcement trap.

McAfee found that the threat is not only real, but accelerating.

The software can mimic valid banking transactions and even intercept tracking e-mails consumers use to flag suspicious activity. Calhoun said hackers could target high-dollar transactions, making it more likely that small discrepancies will be overlooked.

“It is a very clever way of doing something. It utilizes the same protocols designed to protect you to harm you,” said Hemanshu Nigam, chief executive of cybersecurity firm SSP Blue.

Hackers have increasingly targeted U.S. banks in recent months. In September, hackers flooded the consumer sites of Bank of America and JPMorgan Chase with traffic, causing them to crash.

Nigam said hackers may use such attacks to understand bank security protocols and designs.

Doug Johnson of the American Bankers Association said financial institutions are aware of these threats and rely on information from the public and private sectors to stay prepared.

Hayley Tsukayama covers consumer technology for The Washington Post.
SECTION: {section=business, subsection=technology}!!!
INITIAL commentConfig: {includereply=true, canvas_permalink_id=washpost.com/8bvh5zpd9k, allow_comments=true, commentmaxlength=2000, includeshare=true, display_comments=true, canvas_permalink_app_instance=m6yzjj840m, display_more=true, moderationrequired=false, includefeaturenotification=true, comments_period=14, defaultsort=reverseChronological, canvas_allcomments_id=washpost.com/km4ey0dajm, includevoteofftopic=false, allow_videos=false, childrenitemsperpage=3, markerdisplay=post_commenter:Post Commenter|staff:Post Writer|top_commenter:Post Forum|top_local:Washingtologist|top_sports:SuperFan|fact_checker:Fact Checker|post_recommended:Post Recommended|world_watcher:World Watcher|cultuer_connoisseur:Culture Connoisseur|weather_watcher:Capital Weather Watcher|post_contributor:Post Contributor, includesorts=true, includeheader=true, defaulttab=all, includeverifiedcommenters=true, includerecommend=true, maxitemstop=3, includereport=true, source=washpost.com, allow_photos=false, maxitems=15, display_ugc_photos=false, includepause=true, canvas_allcomments_app_instance=6634zxcgfd, includepermalink=false}!!!

UGC FROM ARTICLE: {allow_comments=true, allow_photos=false, allow_videos=false, comments_period=14, comments_source=washpost.com, default_sort=, default_tab=, display_comments=true, is_ugc_gallery=false, max_items_to_display=15, max_items_to_display_top=3, moderation_required=false, stream_id=}!!!

FINAL commentConfig: {includereply=true, canvas_permalink_id=washpost.com/8bvh5zpd9k, allow_comments=true, commentmaxlength=2000, includeshare=true, display_comments=true, canvas_permalink_app_instance=m6yzjj840m, display_more=true, moderationrequired=false, includefeaturenotification=true, comments_period=14, defaultsort=reverseChronological, canvas_allcomments_id=washpost.com/km4ey0dajm, includevoteofftopic=false, allow_videos=false, childrenitemsperpage=3, markerdisplay=post_commenter:Post Commenter|staff:Post Writer|top_commenter:Post Forum|top_local:Washingtologist|top_sports:SuperFan|fact_checker:Fact Checker|post_recommended:Post Recommended|world_watcher:World Watcher|cultuer_connoisseur:Culture Connoisseur|weather_watcher:Capital Weather Watcher|post_contributor:Post Contributor, includesorts=true, includeheader=true, defaulttab=all, includeverifiedcommenters=true, includerecommend=true, maxitemstop=3, includereport=true, source=washpost.com, allow_photos=false, maxitems=15, display_ugc_photos=false, includepause=true, canvas_allcomments_app_instance=6634zxcgfd, includepermalink=false}!!
Comments
SECTION: {section=business, subsection=technology}!!!
INITIAL commentConfig: {includereply=true, canvas_permalink_id=washpost.com/8bvh5zpd9k, allow_comments=true, commentmaxlength=2000, includeshare=true, display_comments=true, canvas_permalink_app_instance=m6yzjj840m, display_more=true, moderationrequired=false, includefeaturenotification=true, comments_period=14, defaultsort=reverseChronological, canvas_allcomments_id=washpost.com/km4ey0dajm, includevoteofftopic=false, allow_videos=false, childrenitemsperpage=3, markerdisplay=post_commenter:Post Commenter|staff:Post Writer|top_commenter:Post Forum|top_local:Washingtologist|top_sports:SuperFan|fact_checker:Fact Checker|post_recommended:Post Recommended|world_watcher:World Watcher|cultuer_connoisseur:Culture Connoisseur|weather_watcher:Capital Weather Watcher|post_contributor:Post Contributor, includesorts=true, includeheader=true, defaulttab=all, includeverifiedcommenters=true, includerecommend=true, maxitemstop=3, includereport=true, source=washpost.com, allow_photos=false, maxitems=15, display_ugc_photos=false, includepause=true, canvas_allcomments_app_instance=6634zxcgfd, includepermalink=false}!!!

UGC FROM ARTICLE: {allow_comments=true, allow_photos=false, allow_videos=false, comments_period=14, comments_source=washpost.com, default_sort=, default_tab=, display_comments=true, is_ugc_gallery=false, max_items_to_display=15, max_items_to_display_top=3, moderation_required=false, stream_id=}!!!

FINAL commentConfig: {includereply=true, canvas_permalink_id=washpost.com/8bvh5zpd9k, allow_comments=true, commentmaxlength=2000, includeshare=true, display_comments=true, canvas_permalink_app_instance=m6yzjj840m, display_more=true, moderationrequired=false, includefeaturenotification=true, comments_period=14, defaultsort=reverseChronological, canvas_allcomments_id=washpost.com/km4ey0dajm, includevoteofftopic=false, allow_videos=false, childrenitemsperpage=3, markerdisplay=post_commenter:Post Commenter|staff:Post Writer|top_commenter:Post Forum|top_local:Washingtologist|top_sports:SuperFan|fact_checker:Fact Checker|post_recommended:Post Recommended|world_watcher:World Watcher|cultuer_connoisseur:Culture Connoisseur|weather_watcher:Capital Weather Watcher|post_contributor:Post Contributor, includesorts=true, includeheader=true, defaulttab=all, includeverifiedcommenters=true, includerecommend=true, maxitemstop=3, includereport=true, source=washpost.com, allow_photos=false, maxitems=15, display_ugc_photos=false, includepause=true, canvas_allcomments_app_instance=6634zxcgfd, includepermalink=false}!!
Show Comments