Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [ISN] Hackers attack Mashreqbank |
|---|---|
| Date: | Tue, 5 Jul 2005 02:26:22 -0500 (CDT) |
http://www.itp.net/news/details.php?id=16534 By Peter Branton 3 July, 2005 Mashreqbank suspended some of its online banking services last week, citing the threat of hacking attacks. The bank said it had detected evidence it was being targeted by hackers. Customers were sent an urgent e-mail warning to change their passwords from a safe PC and the bank temporarily suspended third-party payments online. A spokesperson for the bank said that any such attacks had been unsuccessful, with no customer accounts in danger. "Let me stress none of our customers' bank accounts have been compromised for international wire transfers and this is a precautionary measure only," the spokesperson said. In a statement, Mashreqbank said that its IT security officers had detected a large number of failed attempts at logging in to access accounts for funds transfer from unconventional IP addresses. This activity "normally indicates hackers" the statement said. "Online banking still remains a very secure channel and the temporary suspension of online third party funds transfers will be reactivated within a day or two," said the bank's spokesperson. "The e-mail alert is part of our continuous efforts to enhance safety for online banking services, which we normally do on a regular basis, in addition to regular updates on security measures that we post on our web site," the statement said. Mashreqbank customers last week received an e-mail alert, stating the bank had detected a "heightened level of internet hacking activity" in recent weeks. The alert advised them to change their password from a PC that "you are sure has been verified not to have any viruses or spyware installed." Users may have installed malicious programs which could capture their login ID or password, the alert said. Temporary restrictions on third party transfers were put in place to ensure that we had time to alert you to specific hacking activity," the e-mail alert added. According to security experts, financial institutions in the region are coming under increasing attack from hackers and other cyber-criminals, although banks are notoriously reluctant to come forward and discuss such issues. Earlier in the year, security firm Symantec warned that few banks in the region were aware of how vulnerable their systems were (see IT Weekly 26 March - 1 April 2005). "Banks in the Middle East are not doing enough to protect their systems against security attacks," Kevin Isaac, regional director for Symantec Middle East and Africa, said at the time. He said then that he was aware of a number of banks that had been attacked this year, although he declined to name the banks involved. Justin Doo, managing director of Trend Micro Middle East and Africa, said that Mashreqbank should be lauded for speaking out about the security concerns and not "brushing them under the carpet" as others had done, he claimed. "It does make a big difference when someone is prepared to step forward and say something. Far too many firms fail to come forward on this," he said. "I think that this highlights the fact that as internet usage increases in this region, we will see more focus here from malicious attackers. Internet usage here is growing faster than awareness of the dangers," he claimed. _________________________________________ Attend the Black Hat Briefings and Training, Las Vegas July 23-28 - 2,000+ international security experts, 10 tracks, no vendor pitches. www.blackhat.com
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [ISN] Hacker logs onto FWP hunter database, but no information stolen, InfoSec News |
|---|---|
| Next by Date: | [ISN] Michigan Aims to Block Spam Sent to Kids, InfoSec News |
| Previous by Thread: | [ISN] The coming Web security woes, InfoSec News |
| Next by Thread: | [ISN] Michigan Aims to Block Spam Sent to Kids, InfoSec News |
| Indexes: | [Date] [Thread] [Top] [All Lists] |