Skip the navigation
News

Poughkeepsie, N.Y., slams bank for $378,000 online theft

TD Bank's failure to detect fraudulent money transfers 'unacceptable,' official says

By Jaikumar Vijayan
February 8, 2010 03:52 PM ET

Computerworld - The theft of $378,000 from the town of Poughkeepsie, N.Y., is prompting questions about the responsibility of banks to protect customer accounts from online criminals.

In a statement last week, a Poughkeepsie town official revealed that thieves had broken into the town's TD Bank NA account and transferred $378,000 to accounts in the Ukraine.

The thefts took place over a two-day period in mid-January during which a total of nine attempts were made to steal money. In the end, four of the attempts were successful, resulting in the lost money.

The thefts were discovered by town officials one day after they occurred. So far, TD Bank has managed to recover $95,000, with efforts still under way to try and recover the rest. The theft is being investigated by local police, the FBI and the U.S. Secret Service.

It was not clear how the thieves gained access to the town's bank account, and there was no immediate response from Town Supervisor Patricia Meyers to a Computerworld request for comment. But in other such cases, crooks typically break into commercial and retail bank accounts using stolen log-in credentials belonging to authorized users to transfer large sums of money to banks outside the U.S.

It's a trend that's been gaining steam in recent months. Late last month, Hillary Machinery Inc. in Plano, Texas, said its bank account was depleted by $800,000 after criminals broke into its account and transferred the money to accounts in Romania and Italy.

Last August, NACHA–the Electronic Payments Association warned its 11,000 members about cybercriminals using stolen credentials to take over corporate accounts and initiate unauthorized transfers of funds via electronic payment networks. A similar alert by the Financial Services Information Sharing and Analysis Center identified organized cybercriminals in Eastern Europe as being largely responsible for the thefts. And the FBI's Internet Crime Complaint Center noted that as of October 2009 cybercrooks had attempted to steal approximately $100 million from U.S. banks using stolen log-in credentials.

Such thefts have prompted new scrutiny and criticism about the controls banks have in place for detecting fraudulent transactions.

In a statement, Meyers blasted TD Bank for failing to spot the fraudulent activity. "We find it unacceptable that movement, or attempted movement, of money from a Town account to an account in Eastern Europe did not immediately raise a 'red flag' with the bank, was not questioned by anyone at the bank, but was simply processed," Meyers said.

"We are equally disappointed that in the three weeks since the thefts were detected, no representative from TD Bank has come to Town Hall to speak with us about the situation," she said.

A spokeswoman for TD Bank said the bank may have more information on the break-in after the FBI and the Secret Service complete their investigation. Until then, "it would be premature to speculate on exactly how the fraud occurred," the bank spokeswoman said.

"We also can't elaborate on the matter or the transfers themselves in respect to customer confidentiality. We have been in contact with the Town and are working to set up a meeting to discuss the matter," she said in an e-mailed statement.

Avivah Litan, an analyst at Gartner Inc, said such incidents highlight the continuing failure by banks to implement even rudimentary controls for detecting fraudulent money transfers and other types of fraud. "For banks, it's inexcusable not to have rules for money transfer. It's not rocket science to do a review of a transaction to a foreign account," Litan said.

Given the sharp increase in attacks against U.S. bank accounts from outside the country, financial institutions need to ensure that they have a process in place for vetting money transfer requests -- especially to foreign destinations, she said. "There are so many basic controls they can put in place first before they need to even think about putting up any fancy fraud detection measures," Litan said.

Banking customers also need to do what they can to protect their accounts. But the growing sophistication of online attacks makes it vital for banks also to work to fend off attacks, she said. "Even if customers are using the latest anti-malware tools, the crooks are getting through."

Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at Twitter @jaivijayan or subscribe to Jaikumar's RSS feed Vijayan RSS. His e-mail address is jvijayan@computerworld.com.

Read more about Cybercrime and Hacking in Computerworld's Cybercrime and Hacking Topic Center.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Cybercrime and Hacking White Papers
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
Protecting Point of Sale Systems from Targeted Attack
If you are responsible for protecting retail systems, download this case study to learn how this retailer eliminated the threat of malware on...
From the Frontline - Preventing APT
Is your company's network secure? Are your endpoints and servers secured? Before you answer, read this case study on a US Military Command...
Stop Hackers Before They Attack
Hacktivism, Identify Theft, Financial Gain, Cyber War - regardless of motivation, stopping today's hackers requires a new proactive approach to protecting endpoints. Learn...
The four rules of complete web protection
As an IT manager you've always known the web is a dangerous place. But with infections growing and the demands on your time...
All Cybercrime and Hacking White Papers
Cybercrime and Hacking Webcasts
WikiLeaks: How am I Affected?
The latest WikiLeaks episode has raised questions about how organizations and governments protect their sensitive information. While this incident was isolated, it has...
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
All Cybercrime and Hacking Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs