New Online Threat Jeopardizes Credit Union Accounts

WASHINGTON - Authorities are investigating a new computer virus, traced to Russia, that has stolen PINs, passwords and identifying information and other personal data from thousands of credit union and bank accounts.

Processing Content

In a scenario eerily similar to numerous cases over the last few years, the account information is being sold over the Internet, then used by criminals all over the globe to either hack into credit union and bank accounts or make purchases on those accounts.

The malware, a trojan named Gozi, embeds itself in personal computer files after a user has visited vulnerable websites, then downloads the users' personal information on a server located in St. Petersburg, Russia, according to Don Jackson, a researcher for online security firm SecureWorks, who discovered the virus.

The information is then being sold over the Internet to individuals to access accounts and other purposes, said Jackson.

So far, more than 10,000 accounts at over 30 financial institutions, including as many as two dozen credit unions, have been compromised by the trojan. "These are real conservative estimates," he said.

Buyers of the stolen data who cannot speak Russian are being instructed to use AltaVista's Babelfish service to translate and navigate the site.

The information stolen contains everything from bank, credit union, retail and services account numbers, as well as Social Security Numbers and other personal information. The records retrieved included account numbers and passwords from customers of many of the top global banks and financial service companies, the top U.S. retailers, and the leading online retailers.

The stolen data also includes account information and passwords for employees working at state, federal and local government agencies, as well as law enforcement agencies.

SecureWorks has notified law enforcement agencies and is working with them to shut down the operation. The subscription service selling the stolen data was disabled on March 12, however, the server hosting the data is still receiving stolen information. Account and login information from more than 300 companies and organizations was stolen through the infected home PCs.

The Gozi trojan is unwittingly being downloaded by victims from interactive websites, installing itself on the victims' personal computers, then stealing encrypted data and sending it to the server in Russia, according to Jackson.

The Trojan was first introduced in the U.S. in December and was undetected for six weeks, he said.

Affected CUs are being urged to take defensive steps, like putting a patch on accounts, forcing password resets, notifying members that their computer is infected, notifying members that the data they enter on websites is being stolen, offering advice on how to patch and clean systems and notifying local law enforcement.

Credit union members and bank customers are being urged to maintain their anti-virus software and keep their computer patches up to date and to monitor their credit reports to determine if anyone has been accessing their accounts or taking out new credit cards on their accounts.


For reprint and licensing requests for this article, click here.
Technology
MORE FROM AMERICAN BANKER
Load More