Information Security Blog

Cybermiscreants Continue to Blast Banks as “Operation Ababil” Enters New Phase


14 Flares

14 Flares


×

These Financial IT Security links are part of a weekly series, Ethical Hacker Roundup, featuring recent information security and cyber security related articles that we’ve read over and thought worth sharing.

These articles were emailed to us, shared on Twitter @pivotpointsec and our Google+ page, and read in RSS subscriptions this week.

Anonymous Leaks Bank of America Data in “Spy Revenge Hack”

Black hat hackers associated with the so-called Anonymous Intelligence Agency just leaked over 14GB of e-mails and other data that they claim was stolen in a systems breach against Bank of America IT contractor TEKsystems. The hackers allege that the bank is “running an online intelligence gathering operation against hactivists.”

The stolen data contains random salary data as well as memos from the contractor to the bank’s security staff, reporting on chat room and social network reconnaissance. It is said to have been filched from a “misconfigured server” in Israel that was “basically open for grabs” such that no security exploits were needed. Bank of America asserts that the data came from a third-party, and that its own systems were not compromised.

Large companies may increasingly be monitoring hacker forums and other social networks for signs that they might come under attack. Financial institutions, in particular, are also increasingly aware of the need to manage third-party risk in line with the growing need to share data with partners for business-critical reasons.

Has “Operation Ababil” Resumed?

Shortly after announcing that they would suspend their DDoS attacks against US banks after the removal of the main copy of a controversial film from YouTube, the hacking group calling itself the al-Qassam cyber fighters (widely believed to be Iranian state-backed) is now claiming responsibility for attacking a number of banks again this week, including CapitalOne, Fifth Third Bank, PNC Bank and Citizens Bank.

The hackers’ alleged motive continues to be the removal of various videos from YouTube. In their latest ultimatum on Pastebin they warn, “…if the insulting films are not removed in the following days the Operation Ababil will be started again next week, March 5, 2013.”

NBC’s Website Hacked to Serve Up Banking Malware

Broadcaster NBC suffered a website hack last week that resulted in its site serving up malware designed to steal bank account details for a period of several hours. Frequently visited sites like these are prime targets for cybercriminals because they provide an opportunity to infect large numbers of systems quickly.

According to security companies, Nbc.com and several related sites were hacked to serve up an iframe, which loads content into a website from another domain. The iframe loaded an exploit kit called Redkit, which checks whether victims are running unpatched software from Oracle and Adobe.

If so, a drive-by download can infect your computer just from viewing the website. The malware steals account credentials for banks that include Bank of America, Chase, Wells Fargo and others.

More financial IT security news from recent days:

  • A recent report shows that mobile phishing schemes are increasingly targeting online banking users. In the past year, 75% of mobile phishing URLs were rogue versions of popular banking or financial sites. Among the most targeted institutions are PayPal, Wells Fargo and Bank of America. Mobile users are thought to be more vulnerable because smartphone form factors make it harder to view anti-phishing security elements. Security certification processes are key for all financial services organizations.
  • A DDoS attack mounted on Christmas Eve against a regional California bank was meant to distract security staff from an online account takeover against one of its clients. Hackers made off with over $900,000. Computers at the victimized firm’s offices were blocked from accessing the bank during the sophisticated attack.
  • Open disclosure and discussion of tactics used in recent major security breaches by various media giants, Facebook, Twitter, Apple – and now Microsoft – is already paying off, as other organizations proactively shore up their defenses. “There is now a grass-roots, band-of-brothers kind of approach with the good guys,” said one analyst. Perhaps the tide is shifting from reluctance about disclosure to greater openness in the hope of helping others.

Financial IT Security

Arguably, beyond the government itself, no industry has a greater impact on the health of our economy than financial services. And nothing has a greater impact on a financial entity than to lose the confidence and trust of its customers. Your Financial IT Security concerns can and should be addressed by an independent and objective Information Assurance firm. Pivot Point Security can help your Financial Organization to know you’re secure and prove you’re compliant. See how we can help.

0


Is ISO 27001 Right for (Y)our Organization?

iso-27001-webinar

Thinking about ISO 27001 Certification? View our free On-Demand ISO 27001 Webinar

  • How to deal with increasing threats
  • How to manage multiple regulatory requirements
  • How to handle client requests for attestation
  • To validate that significant changes did not have unanticipated results

Free Whitepaper: Five Best Practices for SIEM

siem-whitepaper

The promise of SIEM is the consolidation of all relevant Security Event Logs from disparate sources into a single unified and normalized data store.

Best Practices for Firing A Network Security Administrator

Firing A Network Security AdministratorWant to know how to fire a Network Admin? Need to know what precautions to take? Firing any employee can be a stressful event. Firing one who has significant knowledge of and privileged access to your Information Technology/Security infrastructure is even more stressful, as the risks are so notable.

Download: Information Security Attestation Guide

Information Security GuideA Best-Practices Guide to Information Security Attestation

Download our proven Information Security Guide to simplify the process of protecting your data, proving you’re secure and growing your business.

Free Whitepaper: Stop Wasting Money on Penetration Testing

penetration-testing-whitepaper

Penetration Testing is most frequently performed to:

  • Substantiate the net effectiveness of a mature control environment
  • Prove to a third party that an environment is secure/trustworthy
  • Quickly assess the security of a less mature control environment (in a sense a technical risk assessment)
  • To validate that significant changes did not have unanticipated results

Free Download: A Best Practices Guide to Database Security

database security roadmap

Because data is only as secure as the systems & processes it relies on – a holistic approach to data security is essential. This roadmap is not meant to be exhaustive but rather to stimulate the necessary thought process to put you on the path to good data security.

Free Download: ISO 27001 Implementation Roadmap

ISO 27001 RoadmapHave no fear – our “roadmap” will guide you, step by step, through the entire ISO 27001 process.

Getting to ISO 27001 certification is a process made up of things you already know – and things you may already be doing!

About the Author:

Marketing at Pivot Point Security

Add a Comment

14 Flares Twitter 4 Facebook 2 Google+ 1 LinkedIn 5 Reddit 0 StumbleUpon 0 Email -- Email to a friend 14 Flares ×