Bank attack used key-loggers costing just £20

£220m theft attempt used battery-sized bugging devices

Written by Peter Warren

The hacker attack on Sumitomo Mitsui bank last month involved the use of keyboard logging devices costing as little as £20 each, according to sources.

Computing has learned that the attempt to steal an estimated £220m from the London office of the Japanese bank relied on battery-sized hardware bugging devices plugged into PCs? USB ports.

Users? keyboards were connected to these key-loggers, which recorded details of everything typed into the system.

Sources claim that cleaning staff ? or people posing as cleaners ? were able to attach the devices to machines. When the plot was uncovered, bank investigators found some of the devices still attached to the back of PCs.

The bugging kits, known as hardware key-loggers, can be bought from spy shops for about £20.

They are difficult to detect unless someone physically examines the back of the machine.

The devices can then download passwords and other data used to gain access to the computer system.

?It is known that people have been using devices such as these because you can buy them from shops. It is highly likely that they have been used in other scenarios,? said Paul Docherty, technical director of consultancy Portcullis Computer Security.

Many banks are now believed to be permanently connecting keyboards and other devices into their computers to prevent similar attacks. Sources say some banks have also banned wireless keyboards in offices.

?This type of scam has been going on for a while. This is an old, old issue, and people have been talking about it being a weakness for at least two years now,? said a source.

Sumitomo is now believed to have deployed sophisticated software that monitors the electrical current in computer systems and can tell if they are being tampered with. A spokesman for the bank declined to comment on the investigation.

Tags:

reader comments

related articles

 

Hacked bank unifies defences

Sumitomo Mitsui takes integrated view of cyber and physical threats 24 Jan 2008

Apacs hails drop in online banking fraud

Losses fall by a third to just £22.6 million, according to the latest figures 12 Mar 2008

Cyber-criminals move with the times

Adware giving way to more serious threats 08 Jul 2008

related whitepapers

today's top stories

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Got the Knowledge?

Last week the civil service published a new strategy to help government seize the opportunities and meet the challenges of managing knowledge... 01 Dec 2008

Q&A - ntl:Telewest Business managing director Stephen Beynon

The cable provider's chief talks about the future of next-generation broadband access in the UK 28 Nov 2008

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

India will remain open for business - but that's not the real story

One of the duties I have to fulfil as a director of the National Outsourcing Association is to talk to the media... 28 Nov 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

ntl:Telewest's Stephen BeynonAnalysis

Q&A - ntl:Telewest Business managing director Stephen Beynon

The cable provider's chief talks about the future of next-generation broadband access in the UK 28 Nov 2008

cowboyFeatures

Guns for hire

David Neal explores the world of interim CIOs and discovers why more firms are turning to them to spur on IT-led change 27 Nov 2008

Advertisement

Primary Navigation