Russian Trojan Jeopardizes CU Accounts

WASHINGTON – Federal authorities are tracing a new virus, traced to Russia, that has stolen PIN and identifying information and other personal data from thousands of credit union and bank accounts. The malware, a Trojan named Gozi, embeds itself in personal computer files after a user has visited vulnerable websites, then downloads the users personal information on a server located in St. Petersburg, Russia, according to Don Jackson, a researcher for SecureWorks, who discovered the virus. The information is then being sold over the Internet to individuals to access accounts and other purposes, Jackson told The Credit Union Journal yesterday. So far, more than 10,000 accounts at over 30 financial institutions, including as many as two dozen credit unions, have been compromised by the Trojan. “These are real conservative estimates,” he said. SecureWorks has notified law enforcement agencies and is working with them shut down the operation. The subscription service selling the stolen data was disabled on March 12, however, the server hosting the data is still receiving stolen information. Account and login information from more than 300 companies and organizations was stolen through the infected home PCs.

Processing Content

For reprint and licensing requests for this article, click here.
MORE FROM AMERICAN BANKER
Load More