Don’t do SECURITY. Do business SECURELY.

Carbanak gang reported to have stolen up to US$1bn from banks worldwide

Kaspersky Lab says a criminal group used phishing and bank-grade malware to steal from around 100 financial institutions, with total losses possibly reaching US$1bn.

Details of a long-running cybercrime campaign against banks emerged when The New York Times reported on research by Kaspersky Lab, which formally presented its findings on 16 February 2015. The security firm said the Carbanak group had targeted around 100 financial institutions, with losses that could reach US$1bn.

What happened

  • Attackers gained a foothold through phishing emails opened by bank staff, then installed the Carbanak malware to study internal systems, in some cases for months.
  • Money was reportedly taken by transferring funds to accounts controlled by the gang, by temporarily inflating customer balances and moving the difference, and by remotely instructing ATMs to dispense cash to waiting accomplices.
  • Kaspersky said individual banks lost up to around US$10m each, with victims in Russia, the United States, Europe, and Asia.
  • The investigation involved Interpol and European law enforcement agencies.

Why it mattered

Carbanak showed that criminal groups were adopting the patient, targeted techniques previously associated with espionage, and aiming them directly at banks’ own systems rather than their customers.

Lessons for organisations

Treat phishing-resistant controls, privileged-access monitoring, and anomaly detection on payment and ATM systems as core defences, and assume a determined attacker may already be inside the network.

Sources: Kaspersky, The Register

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights