News

Group IB blames ATMs cyberattacks throughout Europe on Cobalt

Thursday 24 November 2016 00:26 CET | News

Group IB, a Russian cyber security company, has released a report saying it believed the ATMs cyberattacks throughout Europe were conducted by Cobalt, a criminal group.

It named them after a security-testing tool known as Cobalt Strike, which the thieves used in the heists to help them move from computers in the bank network that were infected with tainted emails to specialized servers that control ATMs. Buhtrap stole money through fraudulent wire transfers, not ATM jackpotting.

Group IB declined to name banks that were “jackpotted,” a term used to describe forcing ATMs to spit out cash, but said the victims were located in Armenia, Belarus, Bulgaria, Estonia, Georgia, Kyrgyzstan, Moldova, the Netherlands, Poland, Romania, Russia, Spain, Britain and Malaysia.

Even though the ATM Security Association declined to comment on Group IBs findings, the security company believes that Cobalt is linked to a well-known cybercrime group dubbed Buhtrap, which stole USD 28 million from Russian banks from August 2015 to January 2016, because the two groups use similar tools and techniques.

Members of the group, which works to improve ATM security, include ATM maker Diebold Nixdorf as well as banks ABN Amro, Bank of America Corp, Royal Bank of Scotland and Wells Fargo.

Diebold Nixdorf, a large ATM maker, said they were aware of the attacks and have been working with customers to mitigate the threat. The newly disclosed heists across Europe follow the hacking of ATMs in Taiwan and Thailand that were widely reported over the 2016 summer.


Free Headlines in your E-mail

Every day we send out a free e-mail with the most important headlines of the last 24 hours.

Subscribe now

Keywords: online security, online fraud, fraud prevention, card fraud prevention, cyber security company, banking, payment fraud, digital identity, Cobalt, Group IB, ATMs
Categories: Fraud & Financial Crime
Companies:
Countries: World
This article is part of category

Fraud & Financial Crime






Industry Events