You are here: silicon.com > Software > Security Strategy

Security Strategy

£220m Sumitomo sting: Was it an inside job?

Foiled robbery whiffs of collusion...

Tags: sumitomo, bank, spyware

By Will Sturgeon

Published: 18 March 2005 16:40 GMT

IT security experts have suggested the foiled Sumitomo bank robbers who attempted to steal £220m from the London-based office of the Japanese investment bank may have had links to the inside of the organisation – possibly even employees past or present.

The attempted heist relied on a piece of key-logging spyware installed on a machine on which access codes and passwords were entered. The application relayed that information to the outside world but one expert said it's unlikely it could have found its way onto the system unaided.

Peter Dorrington, director of fraud solutions at SAS, told silicon.com: "This key-logger had to be within the organisation and it seems it was installed on a specifically targeted machine. It must have been within the organisation and the first big question the bank has to ask is how it got there."

He said investigators will have to consider the likelihood that it was "an inside job", adding that irrespective of all the perimeter security businesses have in place "if somebody effectively walked this through the front door then those defences were instantly by-passed".

Simon Perry, VP security strategy at Computer Associates, told silicon.com: "It's very dangerous to speculate on an ongoing investigation; however, the scope of the proposed theft would tend to indicate that they would have had someone on the inside."

Dorrington added: "It's very unlikely this was some 'fire and forget' random broadcast. This was clearly targeted and very carefully planned."

Perry agreed that it was unlikely to have been somebody just getting lucky infecting random computers and businesses with spyware and striking gold.

"It almost certainly wasn't a random blast out of spyware with the hope of a coincidental install on the critical machines and it almost certainly wasn't a browse-by download from a website that someone surfed from one of those machines."

The investigation is ongoing.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
Embedded and Desktop Applications C++ Engineer - South Wales

My client, a market leading producer of fruit machines and arcade games are seeking an experienced software engineer to join their development team. ...

Software Engineer - C++, C#, .NET - High Speed Processing

Director of Engineering, as the Software Engineer your responsibilities will include: - Assisting with the development and testing of custom designs ...

Marketing Director - Software, Technology, Telecoms, Mobile, Gaming

s technologies will be widely marketed.Experience in the Mobile Phone Markets would be an advantage.The company's extensive R & D results now have to ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: