Data Loss Prevention Blog Secure your digital data with data loss prevention
  • Home
  • Popular
  • News
  • Featured
  • Products
  • Blog
  • Knowledge Base
  • Newsletter Signup
  • Posts
  • Comments

Bank account frauds – Hacking or End Point Data Loss?

By
Dipanjan
Published: July 27, 2009Posted in: Blog, Featured, News, PopularTags: bank account, dataresolve, e-fraud, End Point Security, hacking, kolkata trader, times of india, uhook, usb disk security
Bank account frauds – Hacking or End Point Data Loss?
  • Comments [3]
  • Digg it!
  • Facebook

The recent theft of money from the bank account of a Kolkata Trader shows clearly that loss of critical data is as critical as losing money.

From the words of times of India:-

“On June 24, someone who goes by the name Praveen Rai walked out of two branch offices of State Bank of India in Mumbai, pocketing a cool Rs 90,000 that he had allegedly siphoned off the account of a Kolkata-based trader. The crime shook not only the businessman, but also the city’s police and e-fraud experts. For, the next target could be you. Or just about anyone doing e-banking. Police are desperately looking for Rai, who is believed to be in the early 30s. They also have a photograph of him (the one he submitted to open the SBI account), but more than a month after the crime, there is no trace of him. The victim, trader Akhilesh Bagla, is probably the first from the city to have had his account hacked. But it opens the risk of a racket operating in the web world. ”

Now, if we look into the incident closely, it turns out that at some point of time, the culprits had access to the bank account details of the victim including the internet banking id and password.

How did they get access to such information?

Either the victim himself gave them the information or the information came from somewhere else. It might be suspected that, an insider trading of confidential information happened. And a usb thumb drive could have been one of the tools used by the culprits to achieve their mission. The possibility of using an email could also not be ruled out. But, most of the businesses now a days use their own in-house emailing system along with monitoring all inbound and outbound emails.

Some of our so called IT security experts comment that “I think the bank account was hacked”.

But, there is a very simple logic to make you understand that any kind of hacking or network penetration was not attempted in this case. Why would a hacker take so much pain to gain access to the gateways of SBI, penetrate into the network and then, when he has access to all the bank accounts selects only one of them to steal some 2.6 Laks of money.

So, what we conclude now is that, there was loss of information somewhere which was only limited to a particular bank account which led to this incident. And , if we want to avoid such incidents to happen in future we need to fix all our security holes both at the network level and at the end points.

Share this at your favorite social network:
  • Digg
  • del.icio.us
  • StumbleUpon
  • Technorati
  • Live
  • Sphinn
  • Facebook
  • Mixx
  • Google Bookmarks
  • Blogosphere News
  • MySpace
  • Reddit
  • Slashdot
  • TwitThis
  • BlinkList
  • feedmelinks
  • Internetmedia
  • muti
  • Netvibes
  • Comments [3]
  • Digg it!
  • Facebook

About the Author

3 Comments

  1. Urba
    Posted February 3, 2010 at 11:51 PM

    There is no perfect defense. The more a person resists, the more damage gets in response. Thanks for arctikle.

  2. Nick
    Posted February 25, 2010 at 12:51 AM

    Dear Urba, i fully agree with you that there is no perfect defense, but, the reason companies are going for different kind of data security implementations is because at least they dont want to make everything open. Its better to have even 90% security than having zero.

Trackbacks / Pings

  1. In Data Loss Situations, Bring Bloggers into the Fold

Leave a Reply




XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Cancel Reply

CAPTCHA Image Audio Version
Reload Image
  • Try uHook Enterprise Endpoint Security
    uhook enterprise

    uHook Enterprise

    [Try][buy]

    Download Product Data-Sheet

    Protect your business data from insider threat & thefts
    Only allow whitelisted removable devices in your computers
    View reports of data copied on removable devices (USB, SD Cards, IPODs, Cell Phones etc) from anywhere
    Allow policy based access of removable devices
    Generate audit logs of device access and data access based on users
    Get instant email alerts of malicious activities
    256-Bit SSL encrypted access to web based management console
    Optional SaaS based server control
    On demand agent deployment - pay as you grow
    No need for dedicated server or appliance installation in house
    Manage physically located offices from one single admin console
    Block viruses, spyware, trojans, rootkits and malware from infecting your computers from alien portable stoarge devices
  • most recent comments
    • Nick on uHook USB Disk Security Personal v 2.2
    • Nick on Bank account frauds – Hacking or End Point Data Loss?
    • Nick on Data loss through defunct payment gateway
    • Sneha on uHook USB Disk Security V2.2 Released!
    • payment gateway - StartTags.com on Data loss through defunct payment gateway
  • RSS Data Loss Incidents Recently
    • Missing external drive exposes 35000 guard members names, Social Security numbers March 8, 2010
    • 12,000 patients exposed after a former employee was found in possession of a limited amount of patient billing data March 7, 2010
    • Hotel systems may have been hacked, disclosing credit and debit card numbers March 7, 2010
    • UWMC patient financial information compromised March 6, 2010
    • Names, addresses, medical information and some Social Security numbers of 12,500 on stolen laptop March 6, 2010
    • Customers full name, address, credit card number, three-digit CCV security code exposed in order confirmation emails March 6, 2010
    • Spreadsheet containing patient information, including Social Security numbers, addresses, telephone numbers exposed on file sharing network March 2, 2010
    • Hackers steal guest names, credit card numbers, expiration dates and other data from cards' magnetic stripe February 28, 2010
    • Dozens of customers debit and credit card numbers, with expiry dates improperly discarded February 25, 2010
    • Mailing error exposes 600,000 customers Social Security numbers on outside of envelope February 25, 2010
  • Copyright

    Copyright Data Loss Prevention Blog. All Rights Reserved.