Skip to main content
banner image
venafi logo

Second Attack on SWIFT Shows that Encryption Attacks Are Not Going Away Anytime Soon

Second Attack on SWIFT Shows that Encryption Attacks Are Not Going Away Anytime Soon

generic_blog_banner_image
November 7, 2016 | Scott Carter

Global financial systems using SWIFT have now been attacked by a second group. This exploit follows on the heels of an earlier attack which spirited $81 million from a Bangladeshi bank. Vulnerable encryption is likely the entry point for both attacks, which used a back-door Trojan developed for the Dark Web by the Ordinaff group. According to Symantec, Ordinaff connects to a remote host and can download RC4 encrypted files and execute them. 

Once hackers are able to eavesdrop on encrypted traffic, they can then monitor SWIFT messages sent to infected computers for bank account numbers or other keywords relating to specific transactions.  International Business Times summarizes the attack in the following way: “When a message that contains a targeted text string is intercepted, the hackers use a ‘suppressor’ component to drive it out of the local file system to prevent it from being seen or recovered by the intended recipient.”

Both of these attacks to the SWIFT system highlight the need to rethink outdated security systems, especially when it comes to inspecting encrypted traffic. In an article in Information Security Buzz, Venafi Chief Strategy Officer, Kevin Bocek comments, “The SWIFT system was state-of-the-art when it was created two decades ago, but in cybersecurity and fraud prevention, 20 years might as well be a millennium. A complete rethink of outdated payments architectures, including SWIFT, is long overdue.”

Find out why the SWIFT attacks should be a wakeup call for organizations everywhere. Read the rest of the article to learn why Kevin Bocek recommends that you reinforce the systems of trust in your organization. 

Subscribe to our Weekly Blog Updates!

Join thousands of other security professionals

Get top blogs delivered to your inbox every week

See Popular Tags

You might also like

Déjà Vu at LinkedIn: Second TLS Certificate Expiry in 2 Years

Déjà Vu at LinkedIn: Second TLS Certificate Expiry in 2 Years

Prepare this presentation and send it to me, once approved you can teach entire team.

Overheard at Machine Identity Protection Global Summit 2019

machine identity protection

Leaders Underscore the Critical Nature of Machine Identity Protection at Inaugural Global Summit

About the author

Scott Carter
Scott Carter

Scott Carter writes for Venafi's blog and is an expert in machine identity protection.

Read Posts by Author
get-started-overlay close-overlay cross icon
get-started-overlay close-overlay cross icon
Venafi Risk assessment Form Image

Sign up for Venafi Cloud


Venafi Cloud manages and protects certificates



* Please fill in this field Please enter valid email address
* Please fill in this field Password must be
At least 8 characters long
At least one digit
At last one lowercase letter
At least one uppercase letter
At least one special character
(@%+^!#$?:,(){}[]~`-_)
* Please fill in this field
* Please fill in this field
* Please fill in this field
*

End User License Agreement needs to be viewed and accepted



Already have an account? Login Here

×
get-started-overlay close-overlay cross icon

How can we help you?

Thank you!

Venafi will reach out to you within 24 hours. If you need an immediate answer please use our chat to get a live person.

In the meantime, please explore more of our solutions

Explore Solutions

learn more

Email Us a Question

learn more

Chat With Us

learn more
Chat