Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Tracking & Law Enforcement

FBI Arrests Fourteen in $1 Million ‘Gone in 60 Seconds’ Casino Heist

The FBI has arrested 14 people after an investigation concluded that they managed to scam more than $1 million dollars from Citibank by exploiting a security protocol used by the financial firm. The crafty scam was best described as Gone in 60 seconds – after the heist film, according to the feds.

The FBI has arrested 14 people after an investigation concluded that they managed to scam more than $1 million dollars from Citibank by exploiting a security protocol used by the financial firm. The crafty scam was best described as Gone in 60 seconds – after the heist film, according to the feds.

According to court records, Ara Keshishyan, 29, of Fillmore, California, has been charged with initiating the scam itself. He started by recruiting help, and supplied his accomplices with seed money that was placed into recently opened bank accounts. Once the money was in the accounts, Keshishyan and the others traveled to various casinos in California and Nevada in order to complete the scam itself.

“When inside the casino, the conspirators, including Keshishyan, used cash advance kiosks at casinos in California and Nevada to withdraw (all within 60 seconds) several times the amount of money deposited into the accounts, by exploiting the Citibank security gap they discovered,” an FBI statement explains.

RelatedEnterprises Struggle With Business Logic Attacks

Once the cash was collected, the helpers took their cut and gambled it. In addition to the losses suffered by Citibank, the casinos often provided the fraudsters with free rooms and drinks due to their lavish spending habits. While the crew kept the withdrawals below $10,000 in order to avoid red flags that would federal transaction reporting, Citibank auditors noticed something was off and alerted the authorities anyway.

All 14 people are charged with conspiracy to commit bank fraud and conspiracy to illegally structure financial transactions to avoid reporting requirements. In addition, Keshishyan is charged with 14 counts of bank fraud.

In somewhat related news, the FBI recently announced an expansion to its cybercrime division. While the casino heist isn’t strictly in the realm of cybercrime, it did exploit a vulnerability in Citibank’s security processes, making it an example of the types of advanced crime that the agency wishes to get ahead of.

Advertisement. Scroll to continue reading.

One of the main goals in the cybercrime division’s expansion is to define the attribution piece, said Richard McFeely, executive assistant director of the Bureau’s Criminal, Cyber, Response, and Services Branch.

“The attribution piece is: who is conducting the attack or the exploitation and what is their motive,” McFeely explained. “In order to get to that, we’ve got to do all the necessary analysis to determine who is at the other end of the keyboard perpetrating these actions.”

The Cyber Division’s main focus now is on cyber intrusions, working closely with the Bureau’s Counterterrorism and Counterintelligence Divisions, the agency said.

Written By

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

SecurityWeek’s Threat Detection and Incident Response Summit brings together security practitioners from around the world to share war stories on breaches, APT attacks and threat intelligence.

Register

Securityweek’s CISO Forum will address issues and challenges that are top of mind for today’s security leaders and what the future looks like as chief defenders of the enterprise.

Register

Expert Insights

Related Content

Cybercrime

No one combatting cybercrime knows everything, but everyone in the battle has some intelligence to contribute to the larger knowledge base.

Cybercrime

The FBI dismantled the network of the prolific Hive ransomware gang and seized infrastructure in Los Angeles that was used for the operation.

Ransomware

The Hive ransomware website has been seized as part of an operation that involved law enforcement in 10 countries.

Cybercrime

Spanish Court agreed to extradite Joseph James O’Connor to he U.S., who allegedly took part in the July 2020 hacking of Twitter accounts of...

Ransomware

US government reminds the public that a reward of up to $10 million is offered for information on cybercriminals, including members of the Hive...

Privacy

Employees of Chinese tech giant ByteDance improperly accessed data from social media platform TikTok to track journalists in a bid to identify the source...

Cybercrime

A hacker who reportedly posed as the CEO of a financial institution claims to have obtained access to the more than 80,000-member database of...

Application Security

Virtualization technology giant Citrix on Tuesday scrambled out an emergency patch to cover a zero-day flaw in its networking product line and warned that...