Bank had no firewall license, intrusion or phishing protection – guess the rest
- Reference: 1649135712
- News link: https://www.theregister.co.uk/2022/04/05/mahesh_bank_no_firewall_attack/
- Source link:
The unfortunate institution is called the Andra Pradesh Mahesh Co-Operative Urban Bank. Its 45 branches and just under $400 million of deposits make it one of India's smaller banks.
It certainly thinks small about security – at least according to Hyderabad City Police, which last week [1]detailed an attack on the Bank that started with over 200 phishing emails being sent across three days in November 2021. At least one of those mails succeeded in fooling staff, resulting in the installation of a Remote Access Trojan (RAT).
[2]
Another technology the bank had chosen not to adopt was virtual LANs, so once the RAT went to work the attackers gained entry to the Bank's systems and were able to roam widely – even in its core banking application.
[3]
[4]
Hyderabad Police's analysis of the attack found that Mahesh Bank had carelessly allowed its population of super-users to reach ten – some with identical passwords. The attackers compromised some of those accounts and gained access to databases containing customer information including account balances.
The attackers also created new bank accounts and moved customers' funds into those accounts. Over $1 million of such stolen funds were shifted to hundreds of other accounts at Mahesh Bank and other financial institutions.
[5]
To complete the heist, the attackers made withdrawals at 938 ATMs across India and made off with the cash.
[6]Pakistan's tax office denies pirated software caused outage – admits it sometimes runs unsupported software
[7]Mailchimp: Crook stole cryptocurrency clients' mailing-list subscriber info
[8]Borat RAT: Multiple threat of ransomware, DDoS and spyware
Hyderabad City Police wrote they were able to spot the attack and freeze another ~$2 million of funds before they could be lifted.
The force's report of the incident is not kind to Mahesh Bank, noting that it had "no proper network infrastructure", took no precautions to isolate head office applications from its branches, lacked many basic security tools, did not train its staff for the eminently foreseeable eventuality of a phishing attack, and did not have a valid license for its firewall at the time of the attacks.
The latter is not uncommon because enterprise software is often priced to western standards, and users in less prosperous nations who find the cost prohibitive roll the dice on unsupported and/or out of date code.
"Investigation so far revealed the hackers, and the main kingpins are located outside India, most likely in UK and Nigeria," Hyderabad City Police has stated. "The amount withdrawn is transferred to Nigeria, most likely through Hawala or crypto currencies."
[9]
Hyderabad Police has detailed the attack in the video below – most of which is not in English, but does feature diagrams in that language. ®
[10]Youtube Video
Get our [11]Tech Resources
[1] https://www.facebook.com/hyderabadpolice/posts/1971771309662264
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YkwTU2wqIG1OtZsyIUDIRgAAAM8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YkwTU2wqIG1OtZsyIUDIRgAAAM8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YkwTU2wqIG1OtZsyIUDIRgAAAM8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YkwTU2wqIG1OtZsyIUDIRgAAAM8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/08/26/pakistan_federal_board_of_revenue_software_licensing_snafus/
[7] https://www.theregister.com/2022/04/05/mailchimp_confirms_breach/
[8] https://www.theregister.com/2022/04/04/borat-rat-ransomware-ddos/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YkwTU2wqIG1OtZsyIUDIRgAAAM8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.youtube.com/watch?v=AlO1y2tX-94&t=55s
[11] https://whitepapers.theregister.com/
Re: What I don't understand...
Because they want to hold their cash in a way that isn't traceable back to the bank.
Re: What I don't understand...
The ATMs were just the last stage of getting hold of the $1M+ that they'd stolen, providing nicely untraceable funds once withdrawn
What could possibly go wrong?
An Indian bank that did not have a valid firewall license, had not employed phishing protection, lacked an intrusion detection system and eschewed use of any intrusion prevention system
A bank without a valid license -- What could possibly go wrong?
Re: What could possibly go wrong?
They get robbed?
IT is a cost center isn't it?
As long as bean counters will see IT as something too expensive whatever it's used for, such nonsense will occur.
Too many times shareholders want more and more year after year, and are willing to put a lot of pressure on 'support' services to increase the profit: those get what they deserve, losses and bad press.
Re: IT is a cost center isn't it?
A thousand times this. My support department has been gutted from 26 people running 24/7/365 to 3. The cracks started showing a long time ago and there are people in management positions who ask why we haven't done X.
Well boss, could it be because you fired everyone and that there are more managers above me than people in my department?
Re: IT is a cost center isn't it?
24/7/365. So 1 day down every 4 years?
Re: IT is a cost center isn't it?
put a lot of pressure on 'support' services to increase the profit
Maybe they should've outsourced it?
Root Causes
Greed: The Board of Directors would not authorize funds for up-to-date software licenses and software support.
Executive Arrogance: "What are the chances we'll get hit? Anyway, I'll get a bonus and/or promotion for cutting costs, and be in a different job by the time it does happen, if ever."
Possible* Bank IT Incompetence: There are open source, free-as-in-beer firewalls available. Why didn't bank IT deploy one if they couldn't get funds to maintain their commercial firewall?
*They may have suggested, and denied this option by their management.
This sort of thing will continue until the people responsible do serious jail time, and office politics ensures anyone found 'officially responsible' will be lower-level types only, and not actual directors.
Re: Root Causes
I remember once a colleague telling me about suggesting something open source to their manager:
"So, how much does it cost?"
"It's free"
"Ok, but who sets it up for us, what consultancy?"
"We can do it ourselves"
"But what if it goes wrong, who do we sue?"
"We don't."
"This sounds like pirate software to me, I'm not approving it. And if you suggest anything like this again, it'll be a written warning."
the Andra Pradesh Mahesh Co-Operative Urban Bank
Is going to quickly learn about networks, intrusion detection systems and that the cost of a proper firewall license means it can continue doing business.
Some people have to learn the hard way.
Re: the Andra Pradesh Mahesh Co-Operative Urban Bank
They're supposed to learn the hard way at audits, not by losing a tonne of money.
So the regional/national regulator seems remiss in their work as well.
Re: the Andra Pradesh Mahesh Co-Operative Urban Bank
It's a shame for the account holder who loose their savings though. Was the bank insured -- would an insurer honour such a fail?
Re: the Andra Pradesh Mahesh Co-Operative Urban Bank
Why the downvotes other than "loose" instead of "lose"? It's the account holders who were the victims. They weren't in a position to know their bank was so lax.
Maybe they should have outsourced their IT...
... to the massive talent pool of IT in India I hear so much about.
Re: Maybe they should have outsourced their IT...
"massive talent pool of IT in India"
It sounds as if the Hyderabad police have more of it than the bank.
Re: Maybe they should have outsourced their IT...
It's almost as if that would cost money, and costing money would impact the executive bonuses and that would be a Bad Thing.
Unfortunate.
"The unfortunate institution"
It's not the bank that's unfortunate, it's their customers. The bank got exactly what it deserved, the customers didn't.
Hello Andra Pradesh Mahesh Co-Operative Urban Bank? My name is Jake and I am calling from Microsoft.
What I don't understand...
If you have Root access to the bank internals & can run unchecked through their digital vaults, why limit yourself to making a few withdrawls at various ATM's?
It's like you've got access to the entire cookie jar, but ignoring the cookies in favour of the crumbs in the bottom.