{"id":317515,"date":"2019-03-16T15:52:33","date_gmt":"2019-03-16T19:52:33","guid":{"rendered":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/uncategorized\/heres-how-hackers-stole-15-million-from-mexican-banks.php"},"modified":"2019-03-16T15:52:33","modified_gmt":"2019-03-16T19:52:33","slug":"heres-how-hackers-stole-15-million-from-mexican-banks","status":"publish","type":"post","link":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/futurism\/heres-how-hackers-stole-15-million-from-mexican-banks.php","title":{"rendered":"Here\u2019s How Hackers Stole $15 Million From Mexican Banks"},"content":{"rendered":"<p><\/p><div><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"158\" src=\"https:\/\/wp-assets.futurism.com\/2019\/03\/hackers-stole-20-million-mexican-bank-300x158.png\" class=\"attachment-medium size-medium wp-post-image\" alt=\"In April, bank hackers stole the equivalent of $20 million from Mexico's central bank thanks to a network rife with security flaws.\" style=\"padding-left:10px; padding-right: 10px;\"><\/div><h2>Ocean&rsquo;s O<span lang=\"es\" tabindex=\"0\">nce<\/span><\/h2><p>In April 2018, hackers stole the equivalent of <a href=\"https:\/\/www.reuters.com\/article\/us-mexico-cyber\/mexico-central-bank-says-hackers-siphoned-15-million-from-five-companies-idUSKCN1IH38Q\" target=\"_blank\" rel=\"noopener\">$15 million from Mexican banks<\/a> &mdash; and now we know how they probably did it.<\/p><p>Penetration tester and security advisor Josu Loza was one of the experts called in to respond to the April heist,&nbsp;and&nbsp;on March 8 he <a href=\"https:\/\/youtu.be\/wnxRZy0K6Bw\" target=\"_blank\" rel=\"noopener\">presented his findings<\/a> at the RSA Security conference in&nbsp;San Francisco.<\/p><p>Based on his analysis, Mexico&rsquo;s central bank wasn&rsquo;t doing nearly enough to protect its clients&rsquo; money &mdash; but other financial institutions could avoid the same fate if they&rsquo;re willing to work together.<\/p><h2>Easy Money<\/h2><p>On Friday, <em>Wired<\/em> published a <a href=\"https:\/\/www.wired.com\/story\/mexico-bank-hack\/\" target=\"_blank\" rel=\"noopener\">story<\/a> detailing the information Loza shared with the audience at RSA&rsquo;s conference. Based on his assessment, the success of the heist was due to a combination of expert bank hackers willing to spend months planning their crime and a banking network rife with security holes.<\/p><p>During the presentation, Loza made the case that&nbsp;the hackers might have accessed the Banco de M&eacute;xico&rsquo;s internal servers from the public internet, or perhaps launched phishing attacks on bank executives or employees to gain access.<\/p><p>Regardless of how they first got access, Loza said, the main problem was putting too many eggs in one security basket.&nbsp;Because many of the networks lacked adequate segmentation and access controls, he argued, a single breach could provide the bank hackers with extensive access.<\/p><p>That enabled them&nbsp;to lay the groundwork to eventually make numerous money transfers in smaller amounts, perhaps $5,000 or so, to accounts under their control. They&rsquo;d then pay hundreds of &ldquo;cash mules&rdquo; each a small sum&nbsp;&mdash;&nbsp;Loza estimated that $260 might be enough&nbsp;&mdash; to withdraw the money for them.<\/p><h2>Cyber Insecurity<\/h2><p>The bank hackers are still at large, but the <a href=\"https:\/\/futurism.com\/the-byte\/hacker-drain-1-million-cash-atm\" target=\"_blank\" rel=\"noopener\">heist<\/a> appears to have served as a wake-up call for the&nbsp;Banco de M&eacute;xico.<\/p><p>&ldquo;From last year to today the focus has been implementing controls. Control, control, control,&rdquo; Lazo said during his presentation, according to <em>Wired<\/em>. &ldquo;And I think the attacks aren&rsquo;t happening today because of it.&rdquo;<\/p><p>He also noted the need for companies to collaborate to defend against cyberattacks.<\/p><p>&ldquo;Mexican people need to start to work together. All the institutions need to cooperate more,&rdquo; Loza said. &ldquo;The main problem on cybersecurity is that we don&rsquo;t share knowledge and information or talk about attacks enough. People don&rsquo;t want to make details about incidents public.&rdquo;<\/p><p><strong>READ MORE:&nbsp;<\/strong><a href=\"https:\/\/www.wired.com\/story\/mexico-bank-hack\/\" target=\"_blank\" rel=\"noopener\">HOW HACKERS PULLED OFF A $20 MILLION MEXICAN BANK HEIST<\/a> [<em>Wired<\/em>]<\/p><p><strong>More on hacking:<\/strong> <em><a href=\"https:\/\/futurism.com\/the-byte\/hacker-drain-1-million-cash-atm\" target=\"_blank\" rel=\"noopener\">Hacker Figures out How to Drain $1 Million in Cash From ATM<\/a><\/em><\/p><p>The post <a rel=\"nofollow\" href=\"https:\/\/futurism.com\/hackers-stole-20-million-mexican-bank\/\">Here&rsquo;s How Hackers Stole $15 Million From Mexican Banks<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/futurism.com\">Futurism<\/a>.<\/p><p>See the original post:<br><a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/futurism.com\/hackers-stole-20-million-mexican-bank\/\" title=\"Here&rsquo;s How Hackers Stole $15 Million From Mexican Banks\">Here&rsquo;s How Hackers Stole $15 Million From Mexican Banks<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p> Ocean\u2019s O nce In April 2018, hackers stole the equivalent of $15 million from Mexican banks \u2014 and now we know how they probably did it. Penetration tester and security advisor Josu Loza was one of the experts called in to respond to the April heist,\u00a0and\u00a0on March 8 he presented his findings at the RSA Security conference in\u00a0San Francisco. Based on his analysis, Mexico\u2019s central bank wasn\u2019t doing nearly enough to protect its clients\u2019 money \u2014 but other financial institutions could avoid the same fate if they\u2019re willing to work together <a href=\"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/futurism\/heres-how-hackers-stole-15-million-from-mexican-banks.php\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"limit_modified_date":"","last_modified_date":"","_lmt_disableupdate":"","_lmt_disable":"","footnotes":""},"categories":[11],"tags":[],"class_list":["post-317515","post","type-post","status-publish","format-standard","hentry","category-futurism"],"modified_by":null,"_links":{"self":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts\/317515"}],"collection":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/comments?post=317515"}],"version-history":[{"count":0,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts\/317515\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/media?parent=317515"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/categories?post=317515"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/tags?post=317515"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}