Introduction The Cosmos Bank cyberattack, which occurred in August 2018, is one of the most sophisticated bank heists in India. Hackers stole approximately ₹94.42 crore (about $13.5 million) using advanced techniques that targeted the bank’s internal systems and exploited global financial networks. This case demonstrates the vulnerabilities in banking cybersecurity and the need for robust systems to counter such threats.
Attack Timeline 1. Stage 1: Malware Deployment o Hackers installed malware on Cosmos Bank's ATM switch servers. o This malware intercepted and manipulated transaction messages, allowing fraudulent withdrawals. 2. Stage 2: International ATM Cashouts o Using cloned debit cards, attackers withdrew $11.5 million from ATMs across 28 countries. o Approximately 12,000 international transactions were conducted within a short span. 3. Stage 3: SWIFT Transfer Fraud o The hackers transferred ₹13.92 crore to an account in Hong Kong via the SWIFT messaging system. o The SWIFT transfer bypassed traditional security mechanisms
Methods Used by Hackers 1. ATM Switch Compromise: o Attackers severed the connection between the ATM switch and the core banking system (CBS), enabling transactions to be authorized without verification. 2. ISO 8583 Exploitation: o The attackers manipulated the ISO 8583 messaging standard, which governs card-based transactions. Fake transaction replies were generated to bypass fraud detection systems. 3. Cloned Debit Cards: o Over 450 cloned debit cards were used for fraudulent withdrawals at multiple locations. 4. SWIFT Exploitation: o Unauthorized SWIFT messages were sent to transfer funds to international accounts.
Impact . Financial Loss: ₹94.42 crore was stolen, affecting the bank’s operational stability. • Reputation Damage: The incident highlighted severe security lapses, damaging customer trust. • Operational Disruption: The cyberattack forced the bank to overhaul its cybersecurity protocols.
Investigation and Attribution . Culprits: The Lazarus Group, a North Korea-linked hacking syndicate, is suspected of orchestrating the attack. • Global Operation: Transactions involved mules in multiple countries, making it one of the largest coordinated financial frauds.
Lessons Learned 1. Enhanced Security for Core Banking Systems: o Regular security audits and updates for ATM and SWIFT systems are critical. 2. Real-time Fraud Detection: o Banks must implement AI-driven systems to monitor and detect unusual transaction patterns in real time. 3. Global Collaboration: o Cooperation between international financial institutions is essential to track and block cross-border fraudulent activities. 4. Employee Training: o Comprehensive cybersecurity training can help bank employees identify and mitigate potential threats.
Conclusion The Cosmos Bank cyberattack served as a wake-up call for the Indian banking sector and global financial institutions. It underlined the importance of robust cybersecurity frameworks, advanced fraud detection systems, and international collaboration to prevent such incidents in the future SkyFlok ,Tata Communications , https://www.youtube.com/watch?v=MtstTtfvGZQ