SWIFT Warns Banks Of Ongoing Cyber Attacks

Banks across the world are being urged to tighten up their lax security procedures after new attacks against the SWIFT (Society for Worldwide Interbank Financial Telecommunication) network were made public.

In a private letter to clients, SWIFT was quoted by Reuters as saying that new cyber-theft attempts (some successful) have surfaced since June.

“Customers’ environments have been compromised, and subsequent attempts (were) made to send fraudulent payment instructions,” according to a copy of the letter reviewed by Reuters. “The threat is persistent, adaptive and sophisticated – and it is here to stay.”

Ongoing Attacks

Royal Bank of ScotlandThe global financial messaging system has reportedly warned its member banks of ongoing hacking attacks in recent months and told partners it expects them to deliver an “operational baseline” of appropriate security measures. SWIFT joined forces with BAE Systems in July to bolster its cyber security expertise.

But it seems at though SWIFT has detected a spike in attacks against the network since the online thieves came close to stealing nearly a billion dollars from the account belonging to the Central Bank of Bangladesh earlier this year.

Those attackers managed to exploit weak local security procedures to pocket at least $81 million (£57m) from its account located at the Federal Reserve Bank of New York. It it reported that the Bank of Bangladesh lacked a firewall and used cheap second-hand switches to connect its SWIFT computers.

Brussels-based SWIFT always insisted the attacks didn’t involve any compromise of the network itself, but rather seem to have been carried out by attackers who obtained valid credentials from financial institutions and used these to impersonate authorised individuals.

That attack was thought to be one of the largest bank robberies in history, and prompted the Bank of England to order British banks to carry out a security review of systems connected to SWIFT.

Learn The Lessons

And SWIFT is concerned that its member banks are not learning the lesson and upping their local security procedures for SWIFT-enabled transfers.

The most recent SWIFT letter to the banks reportedly admitted that some victims had lost money in the latest attacks, but did not reveal how much was taken or how many of the attempted hacks succeeded.

The letter also did not identify specific victims, but said the banks varied in size and geography and used different methods for accessing SWIFT.

But the letter indicated that all the victims shared one thing in common, namely weaknesses in local security that attackers exploited to compromise local networks and send fraudulent messages requesting large money transfers.

SWIFT is reportedly struggling to get its member banks to implement new security measures, including stronger systems for authenticating users and updates to its software for sending and receiving messages. This is because SWIFT is a non-profit co-operative and lacks regulatory powers.

But according to Reuters, it is getting tough and has warned banks it might report them to regulators and banking partners if they failed to meet a 19 November deadline for installing the latest version of its software, which contains new security features.

Quiz: What do you know about cybersecurity in 2016?

Tom Jowitt

Tom Jowitt is a leading British tech freelancer and long standing contributor to Silicon UK. He is also a bit of a Lord of the Rings nut...

Recent Posts

Tesla Recalls 46,000 Cybertrucks Over ‘Crash Risk’ Faulty Trim

All Cybertrucks manufactured between November 2023 and February 2025 recalled over trim that can fall…

2 days ago

Elon Musk Issued Summons By SEC Over Failure To Disclose Twitter Stake

As Musk guts US federal agencies, SEC issues summons over Elon's failure to disclose ownership…

2 days ago

Alphabet Spins Out Taara To Challenge Musk’s Starlink

Moonshot project Taara spun out of Google, uses lasers and not satellites to provide internet…

2 days ago

Pebble Creator Debuts New Watches As ‘Labour Of Love’

Pebble creator launches two new PebbleOS-based smartwatches with 30-day battery life, e-ink screens after OS…

4 days ago

Amazon Loses Appeal To Record EU Privacy Fine

Amazon loses appeal in Luxembourg's administrative court over 746m euro GDPR fine related to use…

4 days ago

Nvidia, xAI Join BlackRock AI Infrastructure Project

Nvidia, xAI to participate in project backed by BlackRock, Microsoft to invest $100bn in AI…

4 days ago