Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Hacked Files Suggest NSA Penetrated SWIFT, Mideast Banks

Files released by the mysterious hacker Shadow Brokers suggested Friday the US National Security Agency had penetrated the SWIFT banking network and monitored a number of Middle East banks.

Files released by the mysterious hacker Shadow Brokers suggested Friday the US National Security Agency had penetrated the SWIFT banking network and monitored a number of Middle East banks.

The files, according to computer security analysts, also showed the NSA had found and exploited numerous vulnerabilities in a range of Microsoft Windows products widely used on computers around the world.

Analysts generally accepted the files, which show someone exploiting so-called “zero-day” or hitherto unknown vulnerabilities in common software and hardware, came from the NSA.

They are believed stolen from a hyper-secret hacking unit dubbed the “Equation Group” at the key US signals intelligence agency.

“The tools and exploits released today have been specifically designed to target earlier versions of Windows operating system,” said security specialist Pierluigi Paganini on the Security Affairs website.

They “suggest the NSA was targeting the SWIFT banking system of several banks around the world.”

The files appear to indicate that the NSA had infiltrated two of SWIFT’s service bureaus, including EastNets, which provides technology services in the Middle East for the Belgium-based SWIFT and for individual financial institutions.

Via that entry point the agency appears to have monitored transactions involving several banks and financial institutions in Kuwait, Dubai, Bahrain, Jordan, Yemen and Qatar.

Advertisement. Scroll to continue reading.

In a statement on its website EastNets rejected the allegations. 

“The reports of an alleged hacker-compromised EastNets Service Bureau network is totally false and unfounded,” it said.

“We can confirm that no EastNets customer data has been compromised in any way.”

SWIFT said in a statement that the allegations involve only its service bureaus and not its own network.

“There is no impact on SWIFT’s infrastructure or data, however we understand that communications between these service bureaus and their customers may previously have been accessed by unauthorized third parties.”

“We have no evidence to suggest that there has ever been any unauthorized access to our network or messaging services.”

Shadow Brokers first surfaced last year offering for sale a suite of hacking tools from the NSA. There were no takers at the price stated of tens of millions of dollars, and since then the hacker or hackers have leaked bits of the trove for free.

Analysts say many of the exploits revealed appear to be three years old or more, but have some unknown vulnerabilities that could still be used by other hackers.

No one has yet discovered the identity of Shadow Brokers, or of the hackers that gained access to the NSA materials.

Written By

AFP 2023

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this event as we dive into threat hunting tools and frameworks, and explore value of threat intelligence data in the defender’s security stack.

Register

Learn how integrating BAS and Automated Penetration Testing empowers security teams to quickly identify and validate threats, enabling prompt response and remediation.

Register

People on the Move

Madhu Gottumukkala has been named Deputy Director of the cybersecurity agency CISA.

Wendi Whitmore has taken the role of Chief Security Intelligence Officer at Palo Alto Networks.

Phil Venables, former CISO of Google Cloud, has joined Ballistic Ventures as a Venture Partner.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.