21
Section 3
STRATEGIC CONTEXT
CASE STUDY 2: ATTACK ON BANGLADESH
BANK’S SWIFT SYSTEM
The Society for Worldwide Interbank
Financial Telecommunication (SWIFT)
provides a network that enables financial
institutions worldwide to send and receive
information about financial transactions
in a secure way. As SWIFT sends
payment orders which must be settled
by correspondent accounts that the
institutions have with each other, there
has long been concern over any potential
for this process to be compromised by
cyber criminals or other malicious actors,
seeking to inject illegitimate payment
orders into the system or, in a worst case
scenario, seeking to disable or disrupt the
functionality of the SWIFT network itself.
In early February 2016, an attacker
accessed the SWIFT payment system
of the Bangladesh Bank and instructed
the New York Federal Reserve bank to
transfer money from Bangladesh Bank’s
account to accounts in the Philippines.
The attempted fraud was US$951 million.
30 transactions, worth US$850 million,
were prevented by the banking system;
however, five transactions worth US$101
million went through. US$20 million, traced
to Sri Lanka, has since been recovered.
The remaining US$81 million transferred
to the Philippines was laundered through
casinos and some of the funds were then
forwarded to Hong Kong.
The forensic investigation launched
by Bangladesh Bank discovered that
malware had been installed on the bank’s
systems and had been used to gather
intelligence on the procedures used
by the bank for international payments
and fund transfers. Further analysis by
BAE Systems of the malware linked
to the attack uncovered sophisticated
functionality for interacting with the local
SWIFT Alliance Access software running in
the Bangladesh Bank infrastructure. BAE
concluded ‘that criminals are conducting
more and more sophisticated attacks
against victim organisations, particularly in
the area of network intrusions’.
CASE STUDY 3: UKRAINE POWER GRID
ATTACK
A cyber attack on western Ukrainian
electricity distribution companies
Prykarpattya Oblenergo and Kyiv
Oblenergo on 23 December 2015
caused a major power outage, with
disruption to over 50 substations on
the distribution networks. The region
reportedly experienced a blackout for
several hours and many other customers
and areas sustained lesser disruptions to
their power supplies, affecting more than
220,000 consumers.
Use of the BlackEnergy3 malware has
been blamed by some for the attack, after
samples were identified on the network.
At least six months before the attack,
attackers had sent phishing emails to the
offices of power utility companies in the
Ukraine containing malicious Microsoft
Office documents. However, the malware
was not likely to have been responsible
for opening the circuit breakers which
resulted in the outage. It is probable that
the malware enabled the attackers to
gather credentials that allowed them to
gain direct remote control of aspects of
the network, which would subsequently
enable them to trigger the outage.
This Ukraine incident is the first confirmed
instance of a disruptive cyber attack on an
electricity network. Instances such as this
further demonstrate the need for good cyber
security practices across all of our Critical
National Infrastructure (CNI) to prevent
similar incidents occurring in the UK.
National Cyber Security Strategy 2016