Officers from the Metropolitan Police’s Police Central e-Crime Unit arrested 19 people in London suspected of using the Zeus banking trojan to steal from online bank accounts. Police said the network was believed to have taken around £6 million in three months.
What happened
- The dawn raids, carried out on 28 September 2010, were announced the following day.
- Zeus infected victims’ computers and captured online banking credentials, which were then used to move money out of accounts.
- UK banks worked with police on the investigation, which followed months of intelligence gathering on the network’s activities.
- Days later, US prosecutors charged dozens of people linked to Zeus-related money mule networks.
Why it mattered
The arrests were among the largest UK operations against banking malware at the time and highlighted the industrial scale of credential-stealing crime targeting ordinary customers and businesses. They also showed the value of close cooperation between banks and law enforcement.
Lessons for organisations
Protect payment and banking processes with multi-factor authentication, payment verification steps, and up-to-date endpoint protection. Cyber Essentials covers the baseline controls that make this type of malware harder to install.
Sources: The Register, Krebs on Security
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.