You are here: silicon.com > Software > Security Strategy

Security Strategy

Huge ID theft ring affects at least 50 banks

FBI thought to be on the case...

Tags: sunbelt, identity theft, id theft

By Ingrid Marson

Published: 9 August 2005 09:00 GMT

A major identity theft ring discovered last week has affected the customers of at least 50 banks, according to Sunbelt Software, the security firm that uncovered the operation.

The operation, which is thought to be under investigation by the FBI and Secret Service, is currently gathering personal data from compromised machines and sending them to a server where they are saved in a file.

Sunbelt Software said on Monday that in the two days it has been monitoring the file it has seen confidential financial details of the customers of the Bank of America, PayPal and up to 50 international banks, according to Eric Sites, the vice president of research and development at Sunbelt.

Sites said: "For almost every bank that is listed [in the file], it's possible to get into the person's account."

As well as passwords for online banking sites, information on credit cards has also been gathered. Sites said that Sunbelt had found one customer's credit card number, expiry date and security code as well as their name and address, which would allow anyone to use their credit card.

The data theft was initially reported to be carried out by a modified variant of a spyware application, called CoolWebSearch (CWS) but Sunbelt has now found that the activities are carried out by a mail zombie and a separate Trojan, which is downloaded at the same time as CWS.

The malicious code is hosted on a website that mainly hosts pornography, which Sites was unwilling to name. Users of Windows XP who have not installed SP2 are particularly vulnerable as the code will be automatically downloaded without the user's knowledge. Sunbelt is currently investigating whether users of earlier Windows versions, such as Windows 2000 and Windows ME, are also vulnerable.

"If you have an unpatched Windows machine, when you go to the URL it will automatically download everything from the website, including the Trojan. All you have to do is type in the URL and you're hosed," said Sites.

The Trojan is a new variant, so antivirus and anti-spyware vendors do not yet block it, according to Sites. Sunbelt plans to send information on the Trojan to security firms as soon as possible.

The Trojan carries out keylogging, and also gathers information stored by Internet Explorer's auto-complete function. This data includes any information that has been typed into forms, including usernames and passwords.

Two variants of the data-stealing Trojan have been found, one of which sends data to a publicly available server, which is being monitored by both Sunbelt and the Secret Service, according to Sites. He claimed this server will not be shut down straight away so that the FBI and Secret Service can track down the perpetrators.

Sunbelt believes the operation has only been running for a couple of weeks and has affected a "couple of thousand machines", according to Sites.

An FBI spokesperson was unable to confirm whether or not an investigation was taking place.

Ingrid Marson writes for ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...

Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech


  • Jobs
Development Manager - Client Onboarding - Technical Integration - FX - TRAIANA

Technical resource required to analyse external (client & market platform/ECN) integration requirements (potentially at client site) and to use the ...

Senior Project/Programme Managers urgently required - London

As an Operation Engineer you will be responsible for ensuring that routine and ad hoc maintenance activities are carried out on the Contact Centre ...

Storage Administrator, NAS, SAN, EMC, Hitachi

Essential experience includes: NAS, SAN, Hitachi SAN, EMC NAS, Solaris Operation Systems, Celerra, HDS storage builderDesirable skills include: ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: