News: 1705604650

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

JPMorgan exec claims bank repels 45 billion cyberattack attempts per day

(2024/01/18)


The largest bank in the United States repels 45 billion – yes, with a B – cyberattack attempts per day, one of its leaders claimed at the World Economic Forum in Davos.

Mary Callahan Erdoes, JPMorgan Chase's CEO in charge of asset and wealth management, revealed the figure during a [1]discussion of the future of banking at Davos yesterday, adding that the number is twice what the institution faced a year prior.

JPMorgan Chase, the largest US bank by market cap, claims to have 62,000 technologists working to protect corporate assets - a figure Erdoes claims tops the engineer count at Google or Amazon.

[2]

"Why? Because we have to," Erdoes said.

[3]

[4]

OK, here's where we bring this back down to Earth: 45 billion is a lot. That's an average of 521,000 per second per day. But we all know that is going to be mostly port scans, automated checks for known vulnerable services, and similar chaff. It's not going to be 45 billion fully formed attacks per day; it's more of an indication of the amount of traffic being thrown at JPMC's network boundaries.

We imagine the bank's biggest worry, or one of them, isn't the volume of poking it's getting, it's that the wave after wave of connections may be masking more sophisticated and tangible attempts to break into its networks. It's a tactic crooks use: distract IT admins with loads of suspicious-looking traffic while sneaking in round the back via some quiet vulnerable service or a spear-phishing email. A big challenge will be determining out of all the scans and prodding the actual legit intrusion attempts.

[5]

And don't forget to go tell the WEF all about your dropped packet count at the firewall.

That all said, it's not a surprise that JPMorgan Chase, with its high profile in one of the [6]sectors most targeted by cyber-crooks, faces so many probings and prodding: There's a lot of money to be siphoned from the financial giant, which reported $3.9 trillion in assets as of [7]Q4 [PDF] last year.

A [8]report from the Bank of England further solidifies the perceived risk of cyberattacks in the banking world, with such incidents topping the list of what bank executives see as their top threats and greatest challenges.

[9]JPMorgan latest to pile into quantum upstart with $5B valuation

[10]Something nasty injected login-stealing JavaScript into 50K online banking sessions

[11]Now collapsed SVB's parent files for bankruptcy as Biden calls for stiffer penalties

[12]Capital One: Convicted techie got in via 'misconfigured' AWS buckets

Even epic levels of investment in people and tech haven't been enough for institutions like JPMorgan, however.

JPMC was [13]ordered to face a lawsuit in January 2023 filed by a subsidiary of eyewear megafirm EssilorLuxottica, who alleged the bank was negligent in ignoring signs of fraud. That negligence, the complaint states, allowed cyber crooks to make off with $272 million in funds from Essilor's manufacturing arm over the course of 243 fraudulent transactions.

[14]

"Fraudsters [are getting] smarter, savvier, quicker, more devious and more mischievous," Erdoes said at Davos yesterday.

"They go into the law firm that's sending you an email, take over the email, and they send the bank a note saying 'please send the money here,'" she added, almost as if addressing the Essilor matter. "That is happening everywhere in the world on a daily basis … staying one step ahead of it is the job of each and every one of us."

Beyond lapses of judgement that allow fraud to proliferate, JPMorgan Chase has also made internal technical mistakes that have cost it millions - an admittedly small number for a firm that had a net income of $9.3 billion in the fourth quarter of last year. The SEC in June [15]fined the company $4 million for deleting millions of emails, meaning the bank was unable to hand over communications the SEC subpoenaed in a dozen regulatory investigations.

Accidentally, of course. ®

Get our [16]Tech Resources



[1] https://www.weforum.org/events/world-economic-forum-annual-meeting-2024/sessions/are-banks-ready-for-the-future/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zamtnisy6rWQvqHIi9oZnAAAAZA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zamtnisy6rWQvqHIi9oZnAAAAZA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zamtnisy6rWQvqHIi9oZnAAAAZA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zamtnisy6rWQvqHIi9oZnAAAAZA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2022/10/03/moodys_cyber_risk_ratings/

[7] https://www.jpmorganchase.com/content/dam/jpmc/jpmorgan-chase-and-co/investor-relations/documents/quarterly-earnings/2023/4th-quarter/30e66a2f-5f41-4616-b831-fee985b61b8a.pdf

[8] https://www.bankofengland.co.uk/systemic-risk-survey/2023/2023-h2

[9] https://www.theregister.com/2024/01/16/jpmorgan_quantum_banking/

[10] https://www.theregister.com/2023/12/20/credentialstealing_malware_infects_50k_banking/

[11] https://www.theregister.com/2023/03/17/svb_financial_chapter11/

[12] https://www.theregister.com/2022/06/20/captial_one_wire_fraud/

[13] https://www.theregister.com/2023/01/06/jp_morgan_lawsuit_essilor/

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zamtnisy6rWQvqHIi9oZnAAAAZA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://www.theregister.com/2023/06/26/jp_morgan_fined_for_deleting/

[16] https://whitepapers.theregister.com/



Tom Chiverton 1

They presumably count a connection attempt or port scan in that number. Which is why is so lubricous

Yet Another Anonymous coward

No, they count each separate byte in each portscan packet as an attack

Maventi

WEF in a nutshell. Hyperbole to justify hubris.

Innumeracy

Anonymous Coward

I suspect that the executive is misreading a report. It makes for a good headline though.

Yorick Hunt

Such is the quality of those appointed to executive positions.

Messrs Dunning and Krüger would be proud.

Bloated headcount

Anonymous Coward

The 62k Cybersecurity technologists is also a very inflated number. That's the tally of drones on the bank's cyber's line of business, and counts everything from your RBAC auditor to your scrum master and your bean counter. A very small fraction of those is dedicated to engineer protection against external threats.

I heard this from a friend of a friend, who's uncle may or may not be employed by this firm...

I've said some stupid things and some wrong things, but not that. No one
involved in computers would ever say that a certain amount of memory is enough
for all time ... I keep bumping into that silly quotation attributed to me that
says 640 K of memory is enough. There's never a citation; the quotation just
floats like a rumor, repeated again and again.

-- Gates (19 January 1996), "Career Opportunities in Computing-and More".
Bloomberg Business News

Do you realize the pain the industry went through while the IBM PC was limited
to 640 K? The machine was going to be 512 K at one point, and we kept pushing
it up. I never said that statement - I said the opposite of that.

-- "Gates talks". U.S. News & World Report. August 20, 2001. Retrieved on
October 8, 2014.

I have to say that in 1981, making those decisions, I felt like I was providing
enough freedom for 10 years. That is, a move from 64k to 640k felt like
something that would last a great deal of time. Well, it didn´t - it took about
only 6 years before people started to see that as a real problem.

-- speech to the Computer Science Club at the University of Waterloo, 1989

-- https://en.wikiquote.org/wiki/Bill_Gates#Misattributed