By Tom Bergin and Nathan Layne LONDON/CHICAGO (Reuters) - Shortly after 7 p.m. on January 12, 2015, a message from a secure computer terminal at Banco del Austro (BDA) in Ecuador instructed San Francisco-based Wells Fargo to transfer money to bank accounts in Hong Kong. Wells Fargo complied. Over 10 days, Wells approved a total of at least 12 transfers of BDA funds requested over the secure SWIFT system. The SWIFT network - which allows banks to process billions of dollars in transfers each day - is considered the backbone of international banking. In all, Wells Fargo transferred $12 million of BDA's money to accounts across the globe. Both banks now believe those funds were stolen by unidentified hackers, according to documents in a BDA lawsuit filed against Wells Fargo in New York this year. The two banks declined requests for comment from Reuters. BDA is suing Wells Fargo on the basis that the U.S. bank should have flagged the transactions as suspicious. Wells Fargo has countered that security lapses in BDA’s own operations caused the Ecuadorean bank’s losses. Hackers had secured a BDA employee’s SWIFT logon credentials, Wells Fargo said in a February court filing. SWIFT, an acronym for the Society for Worldwide Interbank Financial Telecommunication, is not a party to the lawsuit. Neither bank reported the theft to SWIFT, which said it first learned about the cyber attack from a Reuters inquiry. "We were not aware,” SWIFT said in a statement responding to Reuters inquiries. “We need to be informed by customers of such frauds if they relate to our products and services, so that we can inform and support the wider community. We have been in touch with the bank concerned to get more information, and are reminding customers of their obligations to share such information with us." SWIFT says it requires customer to notify SWIFT of problems that can affect the "confidentiality, integrity, or availability of SWIFT service.” SWIFT, however, has no rule specifically requiring client banks to report hacking thefts. Banks often do not report such attacks out of concern they make the institution appear vulnerable, former SWIFT employees and cyber security experts told Reuters. The Ecuador case illuminates a central problem with preventing such fraudulent transfers: Neither SWIFT nor its client banks have a full picture of the frequency or the details of cyber thefts made through the network, according to more than dozen former SWIFT executives, users and cyber security experts interviewed by Reuters. The case - details of which have not been previously reported - raises new questions about the oversight of the SWIFT network and its communications with member banks about cyber thefts and risks. The network has faced intense scrutiny since cyber thieves stole $81 million in February from a Bangladesh central bank account at the Federal Reserve Bank of New York. It’s unclear what SWIFT tells its member banks when it does find out about cyber thefts, which are typically first discovered by the bank that has been defrauded. SWIFT spokeswoman Natasha de Terán said that the organization “was transparent with its users” but declined to elaborate. SWIFT declined to answer specific questions about its policies for disclosing breaches. On Friday, following the publication of this Reuters story, SWIFT urged all of its users to notify the network of cyber attacks. "It is essential that you share critical security information related to SWIFT with us," SWIFT said in a communication to users. Reuters was unable to determine the number or frequency of cyber attacks involving the SWIFT system, or how often the banks report them to SWIFT officials. The lack of disclosure may foster over confidence in SWIFT network security by banks, which routinely approve transfer requests made through the messaging network without additional verification, former SWIFT employees and cyber security experts said. The criminals behind such heists are exploiting banks’ willingness to approve SWIFT requests at face value, rather than making additional manual or automated checks, said John Doyle, who held a variety of senior roles at SWIFT between 1980 and 2005. “SWIFT doesn’t replace prudent banking practice” he said, noting that banks should verify the authenticity of withdrawal or transfer requests, as they would for money transfers outside the SWIFT system. SWIFT commits to checking the codes on messages sent into its system, to ensure the message has originated from a client’s terminal, and to send it to the intended recipient quickly and securely, former SWIFT executives and cyber security experts said. But once cyber-thieves obtain legitimate codes and credentials, they said, SWIFT has no way of knowing they are not the true account holders. The Bank for International Settlements, a trade body for central banks, said in a November report that increased information sharing on cyber attacks is crucial to helping financial institutions manage the risk. “The more they share the better,” said Leo Taddeo, chief security officer at Cryptzone and a former special agent in charge with the FBI's cyber crime division in New York. SYSTEMIC RISK SWIFT, a cooperative owned and governed by representatives of the banks it serves, was founded in 1973 and operates a secure messaging network that has been considered reliable for four decades. But recent attacks involving the Belgium-based cooperative have underscored how the network's central role in global finance also presents systemic risk. SWIFT is not regulated, but a group of ten central banks from developed nations, led by the National Bank of Belgium, oversee the organization. Among its stated guidelines is a requirement to provide clients with enough information to enable them “to manage adequately the risks related to their use of SWIFT.” However, some former SWIFT employees said that the cooperative struggles to keep banks informed on risks of cyber fraud because of a lack of cooperation from the banks themselves. SWIFT’s 25-member board of directors is filled with representatives of larger banks. “The banks are not going to tell us too much,” said Doyle, the former SWIFT executive. “They wouldn’t like to destabilize confidence in their institution.” Banks also fear notifying SWIFT or law enforcement of security breaches because that could lead to regulatory investigations that highlight failures of risk management or compliance that could embarrass top managers, said Hugh Cumberland, a former SWIFT marketing executive who is now a senior associate with cyber security firm Post-Quantum. Cases of unauthorized money transfers rarely become public, in part because disagreements are usually settled bilaterally or through arbitration, which is typically private, said Salvatore Scanio, a lawyer at Washington, D.C.-based Ludwig & Robinson. Scanio said he consulted on a dispute involving millions of dollars of stolen funds and the sending of fraudulent SWIFT messages similar to the BDA attack. He declined to name the parties or provide other details. Theoretically, SWIFT could require its customers, mainly banks, to inform it of any attacks - given that no bank could risk the threat of exclusion from the network, said Liven Lambert, the head of human resources at SWIFT for a year-and-a-half through May 2015. But such a rule would require the agreement of its board, which is mainly made up of senior executives from the back office divisions of the largest western banks, who would be unlikely to approve such a policy, Lambert said. FIGHT OVER LIABILITY This week, Vietnam's Tie Thong Bank said its SWIFT account, too, was used in an attempted hack last year. That effort failed, but it is another sign that cyber-criminals are increasingly targeting the messaging network. In the Ecuadorean case, Wells Fargo denies any liability for the fraudulent transfers from BDA accounts. Wells Fargo said in court records that it did not verify the authenticity of the BDA transfer requests because they came through SWIFT, which Wells called "among the most widely used and secure" systems for money transfers. BDA is seeking recovery of the money, plus interest. Wells Fargo is attempting to have the case thrown out. New York-based Citi bank also transferred $1.8 million in response to fraudulent requests made through BDA’s SWIFT terminal, according to the BDA lawsuit against Wells Fargo. Citi bank repaid the $1.8 million to BDA, according to a BDA court filing in April. Citi bank declined to comment. For its part, Wells Fargo refunded to BDA $958,700 out of the $1,486,230 it transferred to an account in the name of a Jose Mariano Castillo at Wells Fargo in Los Angeles, according to the lawsuit. Reuters could not locate Castillo or verify his existence. ANATOMY OF A CYBER HEIST The BDA-Wells Fargo case is unusual in that one bank took its correspondent bank to court, thus making the details public, said Scanio, the Washington attorney. BDA acknowledged in a January court filing that it took more than a week after the first fraudulent transfer request for BDA to discover the missing money. After obtaining a BDA employee’s SWIFT logon, the thieves then fished out previously canceled or rejected payment requests that remained in BDA’s SWIFT out box. They then altered the amounts and destinations on the transfer requests and reissued them, both banks said in filings. While Wells Fargo has claimed in court filings that failures of security at BDA are to blame for the breach, BDA has alleged that Wells could easily have spotted and rejected the unusual transfers. BDA noted that the payment requests were made outside of its normal business hours and involved unusually large amounts. The BDA theft and others underscore the need for banks on both sides of such transactions – often for massive sums – to rely less on SWIFT for security and strengthen their own verification protocols, Cumberland said. “This image of the SWIFT network and the surrounding ecosystem being secure and impenetrable has encouraged complacency,” he said. (Additional reporting by Jim Finkle in Boston and Alexandra Valencia in Quito; Editing by David Greising and Brian Thevenot)
Our goal is to create a safe and engaging place for users to connect over interests and passions. In order to improve our community experience, we are temporarily suspending article commenting
- Men's Health
Steve, 35, from Scarborough in the UK reacts to seeing himself without his full face and head tattoos for the first time in 20 years on webseries Transformed.
- NY Daily News
9-year-old Brooklyn girl cried ‘Mommy, help me,’ as she died after hours of beatings and abuse: prosecutors
“Mommy, help me,” 9-year-old Shalom Guifarro begged as she lay dying in her family’s Brooklyn apartment, after enduring hours of abuse — allegedly at the hands of the same person the child wished would save her. The heartbreaking details of the little girl’s final hours were detailed by prosecutors at her mother Shemene Cato’s arraignment in Brooklyn Criminal Court Tuesday, where she was ...
- The Hollywood Reporter
Marnie Schulenburg, the soap opera actress who portrayed Alison Stewart on CBS’ As the World Turns and Jo Sullivan on the One Life to Live reboot, has died after a battle with stage 4 metastatic breast cancer. She was 37. Schulenburg died Tuesday in Bloomfield, New Jersey, her rep Kyle Luker at Industry Entertainment told The […]
- Fort Worth Star-Telegram
The fish are prized among fisherman – but very few have seen one like this.
The late night host mocked the former president's pull for Dr. Mehmet Oz in the state's Republican primary.
"Dammit. It better not be fake. It might be fake," the popular podcaster blurted in an awkward moment that's gone viral.
- Business Insider
Fiona Hill says Putin got 'frustrated many times' with Trump because the Russian leader 'had to keep explaining things' to him
Putin's frustration over Trump's poor understanding of geopolitics played into Moscow's decision on the timing of Russia's war in Ukraine, Hill said.
Amber Heard said James Franco made a late-night visit to her apartment after a fight with Johnny Depp because she 'exhausted' her support network
She said she "exhausted my support network with my usual friends, and I was happy to welcome as much friendship at that time as I could possibly get."
The North Carolina congressman, who lost his primary bid Tuesday, joked about Cheney's removal as chair of the House Republican Conference in 2021.
- Business Insider
Trump pressed Dr. Oz to declare victory in his Senate race and claimed his GOP opponents are cheating 'with the ballots that they just happened to find'
Trump's pressure on Dr. Oz comes amid high-profile endorsement flops like Rep. Madison Cawthorn's shocking loss in North Carolina earlier this week.
- Business Insider
After multiple claims that Putin may be suffering seriously from cancer, Insider compiled a 10-year timeline of the Russian president's health.
- Business Insider
Billionaire founder of crypto exchange Binance says he's 'poor again' after its luna holdings — once worth $1.6 billion — crashed and are now worth just $2,200
It's likely that Changpeng Zhao meant it as a joke as he remains a billionaire, but luna's meltdown has stung investors worldwide.
Washing your hair is crucial for scalp and hair health—but how often you shampoo really depends on various factors. Here’s a quick guide on what to know.
- Nets Wire
Bleacher Report has a blockbuster trade idea for the Brooklyn Nets involving Ben Simmons.
- Town & Country
Kate, Duchess of Cambridge, Prince Edward, Sophie, Countess of Wessex, and Princess Alexandra stepped in for Queen Elizabeth at the second Buckingham Palace Garden Party of 2022.
A former choir teacher of a local high school is facing criminal charges after court documents say she had an inappropriate relationship with a student.
- Good Housekeeping
'Today' show fourth hour cohost Jenna Bush Hager shared footage of her hilarious wardrobe incident and fans shared their thoughts on Instagram.
- Nets Wire
Kevin Durant tweeted in response to Patrick Beverley's nuclear NBA commentary on ESPN.
- Rock Hill Herald
Exclusive: Jacob Matthew Morgan, now 24, could be released from prison in December even after he was denied parole in a case that has garnered national attention.
Moments after Johnny Depp and Amber Heard tied the knot he said, 'We're married now. I can punch her in the face and nobody can do anything about it,' a former friend of Heard's testifies
iO Tillett Wright on Tuesday said he witnessed Depp and Heard argue with each other but never saw either get physically violent with the other.