Get all your news in one place.
100’s of premium titles.
One app.
Start reading
The Independent UK
The Independent UK
National
Anthony Cuthbertson

ATM hackers steal £10m across 28 countries in audacious bank heist

Hackers with suspected ties to North Korea have syphoned more than 940 million rupees (£10.5 million) from ATMs around the world in a highly-coordinated attack.

The heist on Cosmos Bank took place across several days, beginning on 11 August, just a day after the FBI warned cyber criminals could be planning a highly-coordinated attack on cash machines.

Hackers carried out the attack by infecting the bank's debit card payment system with malware, which allowed them to self-approve transactions. Fake cards were then used to withdraw money through roughly 14,800 ATM transactions across 28 countries.

Indian media, who first reported the breach, linked the attack to similar hacks previously carried out by Lazarus, a prolific hacking group with ties to North Korea.

"In two days, hackers withdrew [funds] from various ATMs in 28 countries, including Canada, Hong Kong and a few ATMs in India," Cosmos Bank chairman Milind Kale told local reporters.

"We appeal customers to remain calm and not to get panic as savings, term deposits, recurring accounts of all the stakeholders are fully safe.[sic]"

Due to the number of countries involved, Mr Kale warned that it would take "coordinated efforts of all the agencies" in order to recover the stolen money.

A warning sent from the FBI to banks and financial institutions earlier this month stated: "The FBI has obtained unspecified reporting indicating cyber criminals are planning to conduct a global Automated Teller Machine (ATM) cash-out scheme in the coming days, likely associated with an unknown card issuer breach and commonly referred to as an 'unlimited operation'."

An attack on cash machines around the world could be imminent (Getty Images/iStockphoto)

A similar attack on the National Bank of Blacksburg, first reported by security expert Brian Krebs, resulted in losses of $2.4 million in 2016. It also involved withdrawals from hundreds of ATMs.

Mr Krebs explained in a blog post how the attacks tend to happen, saying that they usually take place on weekends after the banks close for business on Saturday.

"The 2016 unlimited operation against National Bank began Saturday, May 28, 2016 and continued through the following Monday. That particular Monday was Memorial Day, a federal holiday in the United States, meaning bank branches were closed for more than two days after the heist began."

The FBI has advised banks and financial institutions to keep their security software up-to-date and introduce stronger protections in order to prevent similar attacks in the future.

Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.