[updated January 10, 2021]
The financial services industry is built on trust. In the past, this trust was physically embodied by heavy bank vaults made from multiple layers of steel. Today, however, attackers and thieves don’t need lock picks to steal from financial firms and damage the public’s trust in their services.
Because of the potential value of the information in their IT systems, financial institutions are frequent targets for cyber criminals. As a result, information security in the banking and financial industry is a top priority for security teams, executives, and the board of directors.
By studying recent financial services data breaches, security professionals at these organizations can learn how to create cybersecurity programs that exceed regulatory requirements and truly keep customers’ information and property safe.
Here are four recent data breaches that banks and financial services firms can learn from:
2019 Capital One Data Breach
What happened
In March, 2019, a hacker gained access to the Social Security numbers, account numbers, credit scores, names and addresses, and other information of more than 100 million Capital One customer accounts stored in the Amazon Web Services (AWS) cloud.
In August, 2020, Capital One was ordered to pay $80 million for careless network security practices, with the U.S. Treasury Department ruling that the bank had “failed to establish effective risk management when it migrated information technology operations to a cloud-based service.” The bank’s own internal audit had also failed to identify numerous weaknesses in its management of the cloud environment, according to The Associated Press.
How did the breach originate?
The hacker, Paige Thompson (a former software engineer for AWS), exploited a vulnerability exposed by a misconfigured Web Application Firewall. Thompson’s attack method is not unique and exploited what has been described as “...the most serious vulnerability facing organizations using public clouds.”
Key takeaways
The Capital One case shone a spotlight on a pervasive challenge in security organizations — that people and cultural problems can compound cyber risk. Although technical failings were at the heart of the breach, a series of overlooked issues produced perfect storm conditions for the attack. Indeed, employees of the bank raised concerns about cybersecurity, specifically high turnover of security personnel and a failure to install software to monitor and defend against attacks.
The attack also raised questions about who owns security in the cloud. The AWS shared responsibility model makes it clear that while AWS assumes responsibility for the cloud infrastructure, customers are responsible for the security of their own data. That means they’re responsible for regularly patching and updating software, ensuring systems are configured correctly, and other management tasks. This is where Capital One went awry.
To avoid the same fate, information security professionals in the banking and financial industry must do everything they can to ensure their security postures are as robust as possible. This means going beyond point in time AWS audits to better visualize and assess risk across their expanding digital ecosystems, continuously monitor security performance on-premise and in the cloud, and implement a robust third-party risk management program.
Read more about lessons learned from the Capital One breach.
2018 Cyber Attack of Mexican Banks
What happened
In April 2018, three Mexican banks experienced what they described as security “incidents” while accessing SPEI, the country’s interbank electronic transfer system. Cyber criminals belonging to a group known as the Bandidos Revolutions Team were able to siphon hundreds of millions in pesos from several banks. The hack was the largest cyber attack in Mexican history.
How did the breach originate?
To pull off the attack, thieves created phantom orders that wired funds to bogus accounts which were then emptied via ATMs. The group used the same tactics as a North Korean cyber crime syndicate whose attempts to pull off a $110 million bank heist in Mexico were thwarted by authorities in January, 2018.
Reuters later reported that the problem had to do with software developed by third-party providers to connect to the central bank’s SPEI interbank transfer system.