Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

FBI warns of $100M cyber-threat to small business

November 3, 2009 06:20 PM ET

Active Comments
Fatman says: So much of this is due to USER STUPIDITY. People who just click on any damn link they see, and...
Anonymous says: Paper checks and cash do help a little, but ultimately, there's a vulnerable bank backing your checks and savings accounts....


IDG News Service - Cyberthieves are hacking into small- and medium-sized organizations every week and stealing millions of dollars in an ongoing scam that has moved about $100 million out of U.S. bank accounts, the FBI warned Tuesday.

It's now one of the top problems being addressed by the National Cyber Forensics and Training Alliance (NCFTA), which works with the FBI and industry to share information about cyberattacks, said NCFTA Executive Director Ron Plesco. "Every year there seems to be a trend and this has been the trend this year," he said.

There has been a "significant increase" in what's known as ACH (automated clearinghouse) fraud over the past few months, much of it targeting small businesses, municipal governments and schools, the FBI said in an alert posted to its Web site.

The criminals can move thousands or even millions of dollars out of their victims' accounts very quickly, using online banking to add new payees to the organization's bank account and then moving the money overnight. Usually the first step is an e-mail to the company's bookkeeper or financial officer that can include malicious attachments designed to look like Microsoft software patches, or simply links to malicious Web sites. The idea is to get the criminal's keylogging software onto a computer with online banking access and then steal login credentials.

Once they have access to the bank account, the hackers set up ACH transfers to money mules -- typically innocent victims who think they're doing payroll processing for international companies -- who then transfer the money overseas via services such as Western Union and Moneygram.

In one case, the criminals even launched a distributed denial-of-service attack against an ACH processor to prevent the bank from recalling transfers before the money mules could move them overseas.

Once the money is out of the country, it is gone for good.

Criminals prefer smaller organizations such as school boards because they tend to work with smaller regional banks that may not have the fraud detection controls in place to stop these fake ACH transfers. These organizations often publish contact information for financial personnel, or even organizational charts posted to their Web sites, making them easy pickings for fraudsters.

According to a report by the FBI's Internet Crime Complaint Center (IC3), banks and financial service providers are often part of the problem. Based on FBI interviews, the IC3 concluded that "in several cases banks did not have proper firewalls installed, nor anti-virus software on their servers or their desktop computers. The lack of defense-in-depth at the smaller institution/service provider level has created a threat to the ACH system."


Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Jump to comments

FBI

Additional Resources

Microsoft
Here are some of the key reasons why you would want to run Unified Access Gateway with DirectAccess.
Microsoft
Review how one energy firm tightened protection and simplified IT work using business-ready security solutions.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

What People Are Saying

White Papers & Webcasts

Endpoint Security: When Encryption Isn't Enough
Over 60% of data breaches are caused by careless employees or insider theft.  

3 Tips for Faster File System Auditing
Download this White Paper Now!  

Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...

Interactive Brochure: iPhone in the Enterprise
Download This Resource Today!  

Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.