Showing posts with label Bank. Show all posts
Showing posts with label Bank. Show all posts

Saturday, March 1, 2008

Forgotten IT chores may have led to bank meltdown

While the protection of CII may often be focused on protection from external threats and internal threats, some of the simple and basic practices pertaining to security must be followed to ensure that there are no loopholes in the system that can be exploited. Employees should generally be trusted (if not you have a big problem in your organisation). However segregation of responsibilities and implementing management controls are still important practices that must be enforced.

In January 2008, a French Bank incurred huge losses due to poor enforcement of internal controls and segregation of responsibilities. The losses were result of an employee ... who was doing his job!!.

The huge losses reported by French bank Société Générale, apparently caused by a rogue trader with inside knowledge of the bank's procedures, don't necessarily point to an IT systems failure but rather to poor management of those systems, analysts say.

The bank has accused 31-year-old employee Jerome Kerviel of creating a fraudulent trading position in the bank's computers that ultimately caused it to lose around €4.9 billion (US$7.3 billion).

Kerviel achieved this by, among other things, misappropriating computer passwords, the bank said. It has revealed few other technical details of what caused the losses.

Management of passwords, including rescinding the old passwords of employees who move to different positions within the bank, or modifying the level of access those passwords allow, is often a task given to the lowest-level IT worker.

"It's dull and routine 99 percent of the time, but a vital backstop," said Bob McDowall, senior analyst at the TowerGroup. Senior IT managers should conduct more frequent reviews of password policies, he said.

In some cases, it may not have been the security of the passwords themselves that posed a problem, but rather the access those passwords allowed, said Ian Walden, professor of information and communications law at Queen Mary, University of London.

Organizations tend to think of access as being binary in nature: you get access to it all, or you don't, Walden said. In reality, there are many more levels of access. "In modern, complicated systems, the granularity has to be much more sophisticated."

To make the best use of systems with advanced access controls, the IT department must have a thorough understanding of how the business works and where there is risk.

IT departments and business managers have yet to find a way to wrap security into business processes so it is not an impediment, Walden said. >> More..

Monday, November 12, 2007

US regional bank hacked

Hackers infiltrated the systems of Commerce Bank and accessed the records of 20 customers, the US regional bank said in October 2007.

The attack by persons unknown was partially thwarted - but not before a database of 3,000 records was hacked into and the data of 20 exposed. Compromised data included personal information such as names, addresses, Social Security numbers, phone numbers and, in a few cases, Commerce Bank account numbers, the Columbia Business Journal reports

Security staff shut down the attack and called in police to investigate after uncovering the breach a week ago. The FBI is investigating.

The method used in the attack is unclear, and something the bank will be keen that it stays unclear, to avoid the possibility of copycat attacks. There are many avenues of assault, of which one common tactic is to exploit web application vulnerabilities by using SQL injection attacksto access information of back-end databases. >> More ..

Sunday, October 7, 2007

Bank of India site hacked, serves up 22 exploits

The Bank of India Web site was hacked sometime Wednesday night (U.S. time) and seeded with a wide, wild array of malware that infected any users running unpatched browsers, security researchers said Friday.

See this link for the full news.