Live data from Hacker News

The Biggest Digital Heist in History Isn’t Over Yet

bloomberg.com

31–40 of 92 posts

Re: The Biggest Digital Heist in History Isn’t Over Yet

#31
One interesting bit is the "laundering through a bitcoin warehouse he bought in China".

I suspect this is actually a Bitcoin mining farm:

In goes dirty money, to buy mining hardware in bulk.

Out comes fresh, never-transacted-with Bitcoin block rewards.

It is fairly hard for authorities to trace the wash: in Bitcoin land, block rewards are the least-tainted kind of coins.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#32
post #15
post #8

I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…

Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…

>I would think it's easy to get in, and hard to not get caught.

Imagine you're an new employee at a big old company with a lot of legacy tech that's had mediocre maintenance and documentation over the years as is typical. You are going to leave footprints everywhere just learning to do your job. Imagine how many footprints you leave when you're an outsider who has to learn it all from scratch without documentation or assistance from other employees with historical knowledge. Now try getting anything done in that system without leaving tracks or triggering alerts when you hit some API that even the employees don't knows exists. The reason nobody ever gets caught is because insurance doesn't usually require a conviction before paying out and the effort required to determine who broke in is much higher than figuring out the exact sequence of events because you'd have to do the same investigation on every compromised system they used along the way.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#33
post #15
post #8

I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…

Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…

The door code for one of the US's top banks' offices used to be 0000. I wonder if they finally changed it? EA QAs their games better than a lot of financial institutions as well

Re: The Biggest Digital Heist in History Isn’t Over Yet

#34
post #14
post #7

Earlier quoted context omitted.

People are always shocked at the stupid mistakes that big criminal masterminds make. Like the Silk Road guy, "how could he possibly ask on stack overflow using his real name". And so on. There are ten thousands different mistakes that you can make, you need to guard against all of them. And against whatever unknown tech exists. In this story, that dropped bank card turns out to not be that significant. The real break…

... or the Russian FSB officer forgetting all about VPN and logging on from his office. [1] People make stupid mistakes. [1] https://news.ycombinator.com/item?id=16653671

guccifer, lone hacker = russian authorities

Re: The Biggest Digital Heist in History Isn’t Over Yet

#35
post #15
post #8

I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…

Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…

It is and it is (sorta). I worked in the bank industry for many years and I could have stolen money a hundred different ways without getting caught.

The problem is that in the end the money has to go somewhere or be spent (why else steal it?). Also to live a legal life (house,car,boat) you have to have a source of income/spending that does not set off red flags. If you are a high paid bank employee why even bother? Many (most?) financial type crimes have no statue of limitations so to get away you literally have to get away with it for the rest of your life. The other side is even if you get away you will spend the rest of your life wondering if today is the day you get caught. To be honest I think that is why so many white collar crimes are so brazen looking. I think they would rather go to jail for a few years be done with it and live the rest of their lives with the money they have "lost".

Unless you live in a country like Russia where stealing money from the US is basically legal. Then go for it.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#36

One interesting bit is the "laundering through a bitcoin warehouse he bought in China". I suspect this is actually a Bitcoin mining farm: In goes dirty money, to buy mining hardware in bulk. Out comes fresh, never-transacted-with Bitcoin block rewards. It is fairly hard for authorities to trace the wash: in Bitcoin land, block rewards are the least-tainted kind of coins.

> It is fairly hard for authorities to trace the wash: in Bitcoin land, block rewards are the least-tainted kind of coins.

Also, the most anonymous.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#37
post #8

I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…

That particular quote concerned Katana's ability to move money between banks, not his "hacking" prowess. In fact, the article even refers to their methods as "class spear-phishing", implying there wasn't anything special behind their methods.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#38
post #27

Earlier quoted context omitted.

They do say a lot of theft cash ended up converted to Bitcoin. So, at least a measurable chunk of the liquidity in the market is down to this...

The authorities often resell the bitcoins so they could reenter the market.

I've not heard any cases of bitcoins being "seized" by government authorities yet, although I see that happening in the future as probably inevitable.

Have any examples?

Re: The Biggest Digital Heist in History Isn’t Over Yet

#39
post #8

I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…

This is a problem with pretty much all media stories. There's money to made making things seem dramatic and spectacular and out of the ordinary...when most things just aren't.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#40

>> Someone had sent emails to the bank’s employees with Microsoft Word attachments, purporting to be from suppliers such as ATM manufacturers. It was a classic spear-phishing gambit. Microsoft Windows + Outlook Email + Attached word document = the Drake equation for internet security. No matter how secure each of these things are individually, when added together infection becomes inevitable. Why does outlook have to…

>> Why do we still tolerate this?

This is the real question. The thieves are just a symptom of the real infection: terrible, insecure client software. I'm not sure what the solution is but I am pretty sure it involves Microsoft having skin in the game somehow.

Post reply on HN