A Mysterious E-Mailer Calling Himself 'Oyvind' Warns 1 CU That Its Credit Card Database Will Be Hacked

He seemed neither a sick man, nor a spiteful man, the underground informant who said he was from Norway and who warned an East Coast credit union last year that a hacking ring was rallying to steal its credit card information.

Processing Content

In an exclusive interview, the credit union has now shared with the Credit Union Journal details surrounding the mysterious contact from a person using the screen name "Øyvind" who warned the CU of an impending attempt to breach its security. Expressing concern that its members might be alarmed over security issues, the credit union requested that it not be identified.

"I was very surprised; there was nothing covert about our Norwegian friend," explained the credit union's network manager. "He didn't threaten us."

That despite the fact the informant admitted to the credit union: "I haven't been all that nice in my old times."

Øyvind first wrote the CU in January of 2006 anonymously, via the secure e-mail form at the credit union's website, and then again in April via direct e-mail.

In that April 18 communiqué, Øyvind said that "he was not a black-hat hacker, but an out-of-work tech professional hanging out in underworld places, and that he had communicated with an experienced money-launderer who was looking to recruit hackers to attack a number of financial institutions," according to the CU's network manager.

Øyvind wrote: "Today I got some information about a scammer trying to get hackers to do the dirty work for him by attacking your site to gain control over the 'db' (database) and get information about the users you might have, like login/password..."

"Our credit union was one of them," the network manager added.

Thus began a three-day e-mail correspondence between Øyvind and the network manager-and forwarded by the credit union to state police - in which Øyvind revealed that the credit union was on a list of potential targets shared by credit card hackers. Øyvind claimed the hackers could split up to $200,000 in stolen funds in three days' worth of database attacks.

That hackers solicit information online using Internet Relay Chat (IRC) channels - the Net's equivalent of CB radio - was not news. But the fact that his CU was specifically listed "brought home the threat," said the network manager.

The network manager followed up on Øyvind's claims, searching the Net for the IRC channels hackers were using to share the credit card data.

"You can actually Google for websites that cater to credit card-trading with links to IRCs," he said. "There are at least six or eight sites on the web."

Though the network manager found the CU's name on the list at a card-trading IRC, along with the other institutions, he said he hasn't seen any resulting attacks on the CU or the others on that particular list. "Why weren't we attacked?" asked the network manager. "We don't know. Maybe we weren't desirable enough."

In the meantime, Øyvind revealed something about the character of the Net's underbelly-the Norwegian was forthright and obliging, said the network manager.

"I was very conservative and reserved the first time I replied to [Øyvind], because I had no idea who he was," he said. "I became confident that he was not a direct threat. He wasn't hiding anything. I could verify that he was indeed coming from the domain shown in his e-mail. And he just very methodically and patiently explained everything he knew. It was as if he enjoyed the opportunity to give me all of the details."

Øyvind offered the intelligence in hope that the CU would pass him some cash, or at least boost his ego, added the network manager.

"i wouldn't say 'No' to a small repayment...But A thank you is more than enuff for my time, money spent..." Øyvind wrote.

"I thanked him sincerely, but the credit union was not in the position to compensate him financially," said the network manager.

The network manager said it's not feasible, nor that useful, to scan IRC servers on a daily basis as a preventive measure. "That's a full-time job," he said. "You can hire a service to do it for you, but it's not going to be cheap."

Øyvind's brief appearance was a reminder that CUs are just as susceptible to attacks as big banks.

"Everyone is being targeted," continued the network manager. "You need to go forth thinking 'The credit union is going to be attacked today' and try to be prepared. When you get an e-mail like this, it wakes you up. It didn't make us more secure, because we're always working to be as secure as we can, but it did make us more alert."

The network manager said he considered cultivating the relationship with Øyvind. "But it didn't seem appropriate. Most credit unions have very small technology and security teams, and we don't have the experience to work with someone like that. It would be hard to judge if the information you're getting is any good. You really need the training and experience that law enforcement has to do that."

Fairly quickly, Øyvind went the way of most moles and retreated into his underground hole. "He said he would keep an eye out for any attacks on us, but we never heard back from him again," said the network manager.


For reprint and licensing requests for this article, click here.
Technology
MORE FROM AMERICAN BANKER
Load More