لومړۍ 200 کرښې.
It's Friday,
and it is, of course, the Muslim prayer day.
Everyone's off, except for the skeleton staff
at the Bangladeshi Bank,
including Zubair Bin Huda, who is the duty manager.
He's part of the elite team of employees
who run the SWIFT banking system,
which is a highly secure banking system
that sends money around the world.
Now, Bin Huda goes, as he does every day,
to the SWIFT printer
to check up on the transactions from the day before.
There are usually printouts
of transactions that came in overnight.
The SWIFT software would print out a ledger every single day,
an audit trace of every single transaction that occurred
on paper.
But when they came in on February 5th morning,
as they usually do,
they found there were no SWIFT messages at all.
In fact, the printer's shut down. It won't work.
They try and turn it on.
Nothing will kick it back into life.
He assumes it was simply a technical error,
shrugs, goes home for the night,
comes back in on Saturday morning
to check the system again.
The next day,
they somehow manually get the printer to work.
This deputy head manager walks in the room,
the printer starts working, and these weird messages come out.
The printer starts spewing out
all of these transactions,
including individual requests to the Fed in New York
for $1 billion.
At that moment, it's panic stations.
When I was growing up, the biggest crime in Britain
ever recorded was the Great Train Robbery.
It was an extraordinary thing. They stole about £2.5 million.
That's about $4 million.
And that story ran literally for 30 years.
Four million dollars.
What you're about to hear
is the story of an attempt to steal...
a billion dollars
It's told by world-leading
cybersecurity and legal experts and journalists:
the very people who uncovered the facts
and threaded them together
to reveal how dangerous the world of cybercrime is today.
So, there are four big threats
to the world and to the human race.
One of them we've just experienced,
that's the pandemic.
Then you've got weapons of mass destruction.
You've got climate change.
But barrelling down towards us before those is cyber.
This is the possibility
of our overdependency on network technologies
being undermined, either by malfunctioning of the system...
New problems are emerging
the day after an Amazon web service outage.
Massive and mysterious, a global outage...
...or by a targeted attack.
More than a thousand companies
have been crippled by this attack so far.
Sounds like we're looking at a 2022 with more hacks,
more lost money.
So, when I started hunting hackers in the early 1990s...
our enemy was really simple.
All the malware, all the viruses,
all the attacks were done by teenage boys.
What will your parents think?
I've been doing this job for two decades now.
When we first started,
the people writing viruses and malware
were doing it for fun,
to get their name in lights, to say, "Look what I can do."
No flash, please.
When I started analysing viruses, they looked like this.
Malware was still spread on floppy disks.
They were spreading at the speed of people travelling the world
and carrying the viruses with them.
Michelangelo has proven less harmful than feared.
All the stuff you've got in there you may really want,
it's just gone?
Then the internet came around, and suddenly,
malware outbreaks could go around the world in seconds.
For the last 36 hours,
the ILOVEYOU virus has been creating havoc around the world.
Experts have reason to worry. The first attack, July 19th,
infected about 300,000 systems in nine hours.
First of all, the guys who make a living doing security
and are trying to protect themselves
are scared shitless of you, because you can just ruin 'em.
After the period of time
where hackers were just doing things for fun,
some of them realised that they could use it to make money.
Prior to, like, the 2000s...
cyber was primarily around a disruption of websites...
defacement of a webpage.
Just as we got around 2000, the dot-com boom, the explosion,
we started into what would become
financially motivated hackers.
This really flourished, especially in Eastern European,
Russia, CIS bloc countries.
This was the time of gangster capitalism,
when everyone's world in Eastern Europe was falling apart,
where organised crime and...
former members of the intelligence services
were taking hold of the economy.
So you had a lot of young people in the 1990s
who were very good mathematicians, physicists,
computer scientists,
who simply took the logic and the morality
of gangster capitalism online.
Virus writers were writing viruses
to infect Windows computers,
and those computers were then sold to email spammers,
who were using those machines to send Viagra spam
or what have you, basically making money.
And that changed everything.
People at that time began to use online banking,
and they began to steal people's online banking credentials,
from there, also get credit card numbers,
and use that to basically transfer funds.
Just in hundreds of dollars at a time from these individuals.
They eventually realised that going after individuals
was much more difficult
than just going after the banks themselves.
Get into databases,
those databases held credit card numbers.
Take those numbers and then sell them on the black market.
Originally, the internet was set up at the Pentagon...
just to be able to share resources between computers.
And it was really never designed to have
banking attached to it,
critical infrastructure attached to it.
It was really designed for availability.
It was never designed for security.
Whereas in the early 1990s
when there was only 30,000 people connected to it
and several hundred systems, we've moved to a system
which essentially is the backbone of global finance.
The fact that it's able to do that...
the fact that it's able to sustain currently between
15 and 20 percent of GDP globally
tells us something about just how important
this infrastructure is.
Why did people move into the internet
to seek economic opportunity?
Because that's where the economic opportunity was,
untethered by norms,
untethered by national boundaries,
and essentially limited only by the creativity
that these individuals had.
The user nagged the Federal Reserve Bank
with 35 payment instructions worth $951 million.
We'd just never heard of such a thing before.
We'd been investigating cybercrime
for a couple of decades at that point.
You see cyber criminals go in,
and they try to transfer a few hundred thousands of dollars,
maybe a million, a couple of million.
But conducting a cyber-attack to try to steal one billion?
That was an order of magnitude that we had never seen before.
It was clear from early on
that it was one of the biggest cyber heists in the world.
When we first started hearing rumours
about something affecting SWIFT network,
I didn't understand how big it was.
But when we started realising
this is at a completely different scale,
it just blew my mind.
Once they realised
that the money actually was really gone,
then the panic began to set in.
They lost $81 million instantly to a bank in the Philippines.
They see the $81 million has already gone
and that nearly $900 million extra has been requested.
They basically try to figure out what to do next.
They have no idea what to do.
They hunted for ways to contact the New York Fed.
Desperate calls are made by them.
And it goes to an answering machine.
You've reached the Federal Reserve Bank...
Because it's Saturday in New York,
and nobody's picking up the phone.
- Please call back... - It's a complete shitshow.
Total disorganisation, at both ends, I would stress.
The New York Times Magazine was planning a true-crime issue,
and my editor came to me
and asked I was interested in doing it.
I looked into it a bit.
There definitely were some intriguing elements,
and made me pay attention.
The Federal Reserve has pretty much
depended on the SWIFT banking system,
and since there has rarely been a hack, if ever,
of the SWIFT banking system...
No comments yet. Be the first to leave one.