FBI fingers China over online bank fraud

By
Follow google news

The FBI has pointed the finger at Chinese criminals over a spate of phishing and malware attacks.

The alleged attacks saw funds transferred from the accounts of small businesses to unknown recipients in China. The criminals tried to send $US20 million ($A18.32 million) - of which the FBI knows - to accounts near the Chinese-Russian border, with some $11 million of the funds making it through the stop-checks in the international banking system.

FBI fingers China over online bank fraud

“Between March 2010 and April 2011, the FBI identified incidents in which the online banking credentials of small-to-medium sized businesses were compromised and used to initiate wire transfers to Chinese economic and trade companies,” the FBI said in a warning.

“In a typical scenario, the computer of a person within a company who can initiate funds transfers on behalf of the business is compromised by either a phishing email or by visiting a malicious website. The malware harvests the user’s corporate online banking credentials.”

According to the officials, when a compromised user tried to log on to the banking site, they were stalled with a phoney log-in page that said the accounts were unavailable, while the crooks accessed the account and transferred money to intermediary banks.

The funds were then shifted again to legitimate company accounts in China, although the FBI said it was unclear what happened to the money once it arrived.

“It is unknown who is behind these unauthorised transfers, if the Chinese accounts were the final transfer destination or if the funds were transferred elsewhere, or why the legitimate companies received the unauthorised funds,” the FBI said.

The money transfers ranged from $US50,000 to $US985,000 and company accounts were accessed using a number of malware tools, including ZeuS, Backdoor.bot, and Spybot.

This article originally appeared at pcpro.co.uk

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © Alphr, Dennis Publishing
Tags:

Most Read Articles

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

Health and Aged Care CISO retires

Health and Aged Care CISO retires

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Log In

  |  Forgot your password?