Details of a long-running cybercrime campaign against banks emerged when The New York Times reported on research by Kaspersky Lab, which formally presented its findings on 16 February 2015. The security firm said the Carbanak group had targeted around 100 financial institutions, with losses that could reach US$1bn.
What happened
- Attackers gained a foothold through phishing emails opened by bank staff, then installed the Carbanak malware to study internal systems, in some cases for months.
- Money was reportedly taken by transferring funds to accounts controlled by the gang, by temporarily inflating customer balances and moving the difference, and by remotely instructing ATMs to dispense cash to waiting accomplices.
- Kaspersky said individual banks lost up to around US$10m each, with victims in Russia, the United States, Europe, and Asia.
- The investigation involved Interpol and European law enforcement agencies.
Why it mattered
Carbanak showed that criminal groups were adopting the patient, targeted techniques previously associated with espionage, and aiming them directly at banks’ own systems rather than their customers.
Lessons for organisations
Treat phishing-resistant controls, privileged-access monitoring, and anomaly detection on payment and ATM systems as core defences, and assume a determined attacker may already be inside the network.
Sources: Kaspersky, The Register
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.