Showing posts with label banking incidents. Show all posts
Showing posts with label banking incidents. Show all posts

Tuesday, July 21, 2015

A New Proactive Responsibility For Bankers in the Face of Cross Border Frauds

Let's face it - no one,, (whether an individual, a government or an organization)  is immune to or safe from a breach, an attack, a scam, a rootkit or a virus / APT or whatever you may call it. 
A crack is a crack is a crack is a crack (calling it a hack is sacrilege) 
And this is a global problem which is growing (exponentially) by the day, by the hour, minute, second and even nanosecond. Everyone has to face the threat, directly or indirectly, and no one ever knows when he/she will fall victim to an attack or an incident, and it really does not matter whether you are hyper intelligent or live inside Fort Knox. 
We do not have to go too far into history to see institutions like OPM, SONY, White House; global security organizations like RSA, The Hacking Team, HB Gary, NSA etc - the list is really big and includes banks etc.
In this global cybersecurity threat and crime maelstrom the Law Enforcement Agencies (LEA), Intelligence and Defense Agencies are first and foremost affected. They have a responsibility to investigate cybercrimes perpetrated across international borders, using sophisticated attack techniques or compromising insiders into malicious acts, voluntarily or involuntarily. Invariably while following cross-border leads, the LEA meets with insurmountable challenges and lengthy procedures (or red-tape even non-cooperation). And, if the request is to an unfriendly nation, the case might as well be closed and filed away!
Example challenges faced by LEA are in (1) following a money trail, (2) getting source IP information, (3) user name and address, etc. 
We will only look at "following the money trail" - in this case the victim may know the name of the bank where the funds were fraudulently transferred. However, when the bank is advised about the same they may not take any action until there is an order for the same in compliance with their locally applicable laws and regulations.  
However it is time for these officials, across the world, to raise a red flag at their end when they receive a communication directly from the victim (or victim country LEA).
Imagine if a bank manager gets a mail from a victim who informs about a fraud which has been perpetrated and where the funds have been transferred to that particular branch of the bank. The branch Manager may not be able to stop the account from operating but he/she can inform the local LEA about the suspect transaction. In addition, he/she can proactively guide the foreign victim and LEA about the quickest procedure to get the legally appropriate instructions for necessary action. 
The only (simple) reason why this bank manager in a foreign country should stand up and raise a red flag on the account, on the account holder and the transaction(s) is .... it can happen to him/her too. 
Yes, there is no guarantee that this bank branch, anyplace in the world, may fall victim to a fraud or a bank client may fall victim - then this manager will be running the same hoops as the victim / LEA who had connected earlier. 
This is not a call to disclose information, neither a call to work against the law or invade the account holder's privacy. It is not an aggressive look into transactions which is done through Risk Management and AML practices. In these changing times, it is an acceptance of responsibility by the banking professionals to set up a simple deterrent control. Criminals will slow down on using accounts in foreign lands once they are aware that ANY transaction can be notified to LEA proactively. 

Saturday, December 20, 2014

Cyberwar ... a damp squib?

War.. The word conjures up images of people killing one another using warplanes, warships, tanks, cannons etc. Images of cities and countries totally destroyed ... then V Day... then POWs .. medals, martyrs, heros. This was war!

And cyber war? Is it really war ? Or, we diluting the devastating danger of war by terming cyber incidents as war?

No country has publicly declared the formation if a cyber army, or a new cadre. There is no school for cyber weaponry or tactics. In fact well known generals and leaders have publicly accepted that they do not know how to define cyber war. Yet the media and global voices scream cyber war every time a major hack takes place! No one knows whodiddit but everyone has a theory about whodunit!
Last year Sony was hit by non-state actors, and this winter all fingers are pointing at North Korea. Earlier, in autumn it was the blame-it-on Iran season and the summertime ogre was China! Others who have had their place in the sun are the Syrian Electronic Army, Russia, Georgia and others.

One shouldn't forget the private and state armies of India and Pakistan who are constantly engaged in the childish sport of website defacement. Every now and then we have reports about cyber war being staged by either party stating X hundred sites defaced and y hundred retaliated with !
Sabre rattling and finger pointing by all countries and the so called private armies and patriots. No government has stood up to say they are responsible for a website defacement or a data breach/theft from someplace.

Not a single country has declared war in the real sense of the word. American banks, corporations, government entities, critical infrastructure is under continuous attack (as per US-CERT) but America has not declared war against anyone ! Compare this with the same Americans who went to war because someone said the Iraqi's have WMDs. Then they went out and killed Osama bin Laden because of the WTC attack by the Talisman.
It is natural for any country to declare a state of war if their sovereign assets are compromised but look at this
The NSA - Prism program has compromised the assets of friendly and non-friendly states and (possibly) continues to do so. Yet all affected countries have just taken it easy and not spoken up or retaliated (except Brazil).
India Pakistan have border skirmishes every other day and hordes are killed by terrorists (non-state actors) and armies (state actors). However, even though, website defacement and data ex filtration is regularly announced by non-state players there is no "tough" talk or overt action!
In the past few days North Korea is (said to be) the country behind the SONY hack because of the movie 'The Interview'. The USA is said to be affected badly with the hack but there is no strike back! And, going back into history, there are other incidents when South Korea has been repeatedly been (supposedly) attacked by North Korea and there has been no counter-strike! Not even a word of warning, leave alone the 'stern warning' type of public statement.
This infographic shows a few landmark events but what about counter strikes, what about public warnings what about cease-and-desist statements... none!
So is cyberwar sabre brandishing just a damp squib? No one is sending their army/navy/airforce to any country. The US is not asking the aircraft carrier to park itself in the Pacific off the coast of North Korea or China inspite of numerous damning statements against both governments.
Why all this talk about war or elevating these malicious, larcenous crimes to the status of war? These are crimes that may have disastrous consequences; these are disasters that may happen due to oversight or lack of diligence; these are common covert statecraft activities like espionage, agent recruiting etc; these are events which have not been seen or imagined in totality .. and mankind is still struggling to put a name or sentence here.
Can we keep the word "war" out and stop glorifying common criminal intent - it will blow the hype out and allow proper thought to address the problem(s).
Until the internet is all pervasive and is as 'essential' as air / water / land / gravity and we can blast human beings as they walk and talk with precise thought!
Scarier times are ahead, but why build and live with FUD.
This article was published by me on Linked In

Wednesday, January 30, 2008

Societe Generale ... lies, lies and all lies

So Societe Generale lost 7.1 bn last week, then restated this to $ 5.x bn because 2.x bn was a loss from the sub-prime plague.

And it was a rogue trader who opened SG's purse but was it a rouge rat who cast the sub-prime spell on them ? Who has been blamed for this ?

Daniel Bouton, the bank Chairman, is on a panhandling trip to get $ 5.x bn and keeps his job, while his resignation is still on the desk. A moral resignation nevertheless which was honorably presented the moment the s%6t hit the ceiling.

Consider the lies which has been hogging the news :

First it was "Rogue trader defrauds the bank of $ 7.1 bn"

There was no defrauding the bank. This guy was doing his job, a and that too too independently. There was no one checking his work ! Cool........ give me the bank treasury and I will also play the stock exchange at will.
Hey what happened to the 7.1 bn - now it is only 5.1 bn ! the other 2 bn is actually the hit SG got from the sub-prime exposure and sorry the Chairman goofed up in his communication to the Prime Minister and the Central Bank and the public and shareholders at large.
Its okay this is just a couple of billion here or there ! So what if I just messed the European market a tad while squaring all holdings.

And he was "a junior trader, recently promoted from the back office. so he has intimate knowledge of the systems and easily circumvented controls"

Another white lie - he has been trading since 2005 (?) so that is pretty recent ! Three years on the trading desk and he contributed €1.5 bn to the bank kitty with his trading profits last year. Pretty cool performance for a junior trader and I am sure there was a lot of Champagne and partying at the end of the year when the numbers came in. Will you be surprised to find that the Chairman sent a case of Dom alongwith a card ?

The Chairman said that he did not know him...

OK we shall take it at face value. The Chairman is not supposed to know everyone in the bank. And considering how loose the controls at SG are, I am apt to believe that there are hundreds / thousands of traders betting the banks pants everyday and making a billion plus for the bank every year.

Now.......
The French government wants to protect this institution from takeover without realizing that it will be good for their health if this is allowed. At least the new owners will bring in a training program on 'Better Communication Skills for Chairmen"

I seem to be forgetting the information security and risk management aspect of this episode .... and will cover this in the next post.