Live data from Hacker News

How Hackers Stole $100M from the New York Fed

zerohedge.com

81–87 of 87 posts

Re: How Hackers Stole $100M from the New York Fed

#83
post #13

Earlier quoted context omitted.

I'm surprised they haven't started putting RFID tags in every chip so they can track exactly how much each player spends at each game. Combined with proper record keeping, if chips were ever stolen, you could flag them and make sure they can't be redeemed for cash. Maybe in Vegas?

Play craps? You'll cycle chips pretty much all of your chips, and chips you throw to one side get replaced with chips from another side when making field bets -- for example. Typical player tracking is done through comp cards, where they account for your buy-ins at the table, and buy out at the cashier.

OK, now try doing that with $100MM of chips.

Re: How Hackers Stole $100M from the New York Fed

#84
post #52

From the Filipino source here: http://business.inquirer.net/207742/100-m-laundering-via-ph-... > a total of $100 million that was brought into the country’s banking system, sold to a black market foreign exchange broker, transferred to at least three large local casinos, sold back to the money broker and moved out to overseas accounts. Here's how I think that this heist went and I am just speculating here based solel…

Why would you mix a money stealing operation with a money counterfitting one? It doesn't make sense. And we are talking huge sums here, the fake money would quickly show up everywhere in that area.

https://en.m.wikipedia.org/wiki/Money_laundering

Having money in an account is useless as long as it can be traced to the fraudulent transfer. So you move the money through a casino or any other large scale cash flow, such as counterfeiting (buy fake money for cents in the fake dollar and then sell it at a loss somewhere else)

Re: How Hackers Stole $100M from the New York Fed

#85

Earlier quoted context omitted.

So casino buys chips from itself, gambles with itself, then exchanges the chips to cash where exactly? That makes no sense.

The implication in the article is that the casinos weren't directly involved in the money laundering. Those who were perpetrating it brought the money into the casinos (ie bought chips with "dirty" money), engaged in otherwise legitimate looking behavior at the casinos, and then cashed out the chips for cash. Apparently, the loop on this was tight enough not to fool investigators.

No, the article says the money was wired to the casinos.

Re: How Hackers Stole $100M from the New York Fed

#86

So SWIFT, the backbone of international monetary transfers, doesn't have some sort of automated way to verify that requests are legitimate? It would seem to me that once a request is received, the only secure thing to do would be to send a hash of the request back to a known system belonging to the originator to verify that the request was authorized. If SWIFT security is really as bad as this incident seems to sugge…

At least in consumer usage, SWIFT transfers are "push", not pull as you may be used to with American ACH. So the concept of verifying a request doesn't make sense.

It sort of sounds (from the public information) like the Bangladeshi bank's credentials were compromised and used to make fraudulent transfer requests to the NY Fed.

That's not really a problem with SWIFT. Arguably the NY Fed should have flagged the requests as suspicious, but that's probably a best-effort kinda thing.

Re: How Hackers Stole $100M from the New York Fed

#87
post #81

The page this article is on is a exhibit A of how broken the internet has become.

This is pretty much the only reason I still use Safari. The Read mode gives me a clean article. Sad that its become necessary really.

Firefox has a read-mode as well: https://support.mozilla.org/en-US/kb/firefox-reader-view-clu...
Post reply on HN