Wednesday, June 12, 2013
A Vulnerable Age: Fraud Against Seniors Often Is Routed Through Banks
Sunday, February 24, 2013
Major Banks Aid in Payday Loans Banned by States
Monday, January 7, 2013
Bits Blog: U.S. Banks Again Hit by Wave of Cyberattacks
For the last week, hackers have — once again — attacked the online banking sites of several American banks.
The attacks appear to be the second stage of a campaign that began in September, when a hacker group calling itself Izz ad-Din al-Qassam Cyber Fighters took credit for a series of attacks on the Web sites of Bank of America, Citigroup, U.S. Bank, Wells Fargo and PNC that caused intermittent delays.
The group said it had attacked the banks in retaliation for an anti-Islam video that mocked the Prophet Muhammad and pledged to continue its campaign until the video was removed from the Internet. They called the campaign Operation Ababil, a Koran reference to the swallows Allah sent to attack an army of elephants dispatched by the King of Yemen to attack Mecca in 571 A.D.
In an online post on Tuesday, the group said that it had resumed Operation Ababil and that, over the last several weeks, it had focused on nine banks: JPMorgan Chase, Bank of America, Citigroup, Wells Fargo, U.S. Bancorp, PNC, BB&T, Suntrust and Regions Financial.
“Our aim of this operation is removal of that insulting and absurd film,” the hackers wrote in an online post.
Of the nine banks, representatives of PNC, BB&T and Citigroup confirmed that their online banking sites had experienced intermittent disruptions because of a high volume of Web traffic, but they said that bank accounts and customer information had not been affected. Though they were not mentioned in the group’s online hit list, Capital One and Fifth Third Bank also experienced brief disruptions.
Customers at Bank of America, Wells Fargo, U.S. Bancorp and JPMorgan did not appear to have had any trouble reaching their accounts.
In an e-mail to customers, PNC said it had experienced “an unusually high volume of traffic” to its site. “This volume of traffic is consistent with threatened cyberattacks on the U.S. banking system and is designed to cause access delays for legitimate Internet customers,” the statement said.
Debra DeCourcy, a spokeswoman for Fifth Third Bank, said that from 11 a.m. to 3 p.m. on Thursday, Fifth Third also had a high volume of traffic to its site. “We believe it was a denial of service attack designed to disrupt access to our site,” Ms. DeCourcy said. “This was an access issue, not a security issue: No customer information or data was compromised.”
In a denial of service attack, hackers bombard a site with traffic until it collapses under the load. Though banks take great pains to absorb large volumes of traffic, many experienced unprecedented levels. Typically such attacks are deployed through a Web application, in which hackers recruit volunteers to click on a link that sends signals from their computers to a victim’s site, or through botnets, networks of infected computers and devices that do hackers’ work for them.
But security researchers who studied the attacks on banking sites last fall said hackers had used a new weapon: data centers.
Researchers at Radware who investigated the attacks for several banks found that the traffic was coming from data centers around the world that had been infected with a sophisticated form of malware that was designed to evade detection by antivirus solutions. The attackers used those infected servers to simultaneously fire traffic at each banking site until it slowed or collapsed. By infecting data centers instead of computers, attackers obtained the horsepower to mount an enormous denial of service attack.
Jenny Shearer, a spokeswoman for the Federal Bureau of Investigation, declined to comment on the source of the attacks on Friday.
In an online post, hackers said the attacks had not been sponsored by a country.
Government and intelligence officials have blamed Iran for the fall attacks and for a destructive cyberattack on computers at Saudi Aramco in August, though they have not presented any evidence to back up their claims. Tracing cyberattacks back to one particular country is difficult, security experts say, because traffic can be routed through different Internet addresses to mask their true origin.
Security researchers still do not know how the data centers used in the first wave of attacks were infected in the first place, how widespread the infection rate was and — perhaps most troubling — whether the servers could be used to damage other sensitive targets in the future.
On Tuesday, the hackers said they had no intention of halting their campaign. “Officials of American banks must expect our massive attacks,” they wrote. “From now on, none of the U.S. banks will be safe.”
Tuesday, October 23, 2012
DealBook: In London, Nimble Start-Ups Offer Alternatives to Stodgy Banks
Hazel Thompson for The New York TimesAnil Stocker, a co-founder of MarketInvoice, a new financial firm based in London.LONDON — When Hiroki Takeuchi joined McKinsey & Company in 2008, he had a front-row seat to the upheaval in finance.
After the collapse of Lehman Brothers, Mr. Takeuchi, a 26-year-old Oxford graduate, worked with some of the world’s biggest banks trying to figure out how to adjust to new regulations and a changed market. Then he quit.
For Mr. Takeuchi, memories of friends building successful start-ups at college outweighed the lucrative rewards offered by the blue-chip consulting firm. He joined forces with two McKinsey consultants, feverishly writing code out of his parents’ house on a minimal budget to create his own technology start-up.
The result was GoCardless, a London-based company that allows small businesses to set up monthly payments to suppliers at a fraction of the cost that banks charge. The business has secured $1.5 million in seed capital from a number of well-known investors, including the American early-stage venture capital firm Y Combinator.
“The whole idea of bank payments is broken,” said Mr. Takeuchi at the start-up’s office in a dilapidated building on the outskirts of London’s financial district. “There’s an opportunity here, and we’re looking to grab it.”
Hazel Thompson for The New York TimesHiroki Takeuchi, co-founder of GoCardless, a new financial firm based in London.London’s fast-growing start-up scene is trying to disrupt the financial status quo. As consumers’ trust in banks deteriorates because of a series of recent scandals, young companies are pressing their newcomer advantage. Firms are offering services like low-cost foreign currency exchange and new ways for small business to borrow cash.
Backed by venture capital firms like Index Ventures, the financial start-ups are taking on entrenched incumbents by using technology to pare back costs and improve the customer experience. Local authorities do not directly regulate many of the firms, but the young companies often use traditional banks and other financial firms for their back-office functions, like processing payments, which are monitored by British regulators.
“Start-ups are taking advantage of London’s position as a global financial center,” said Adam Valkin, a partner at the European venture capital firm Accel Partners. “They are innovating in ways that banks just can’t do.”
The growth of finance entrepreneurs comes as London’s start-up community continues to flourish. Many parts of East London have transformed into a mini version of Silicon Valley, with the likes of Google opening shared office space to support fledgling companies. Finance, technology and fashion start-ups have been able to tap into the large talent pool of young, multilingual professionals eager to work for the firms.
Many companies are following the lead of Wonga.com, an online lender founded in 2006 that has sought to fill a void left by banks by offering short-term, high-interest loans to consumers and small businesses. The company has been criticized for charging high interest rates to vulnerable consumers. The typical annual percentage rate on the company’s loans is more than 4,000 percent, though Wonga.com says it only offers lending for a maximum of 30 days.
To cut down on costs, the start-up relies on publicly available online data to determine whether an applicant is creditworthy. Loans can take as little as 15 minutes to arrange, and the company has branched out from consumer lending into the small-business market as individuals look for alternatives to banks.
The tactics are paying off. Last year, the online lender reported a 269 percent rise in its net profit, to £45.8 million, or $73 million, after its loans increased fourfold compared with the previous year. Now, Wonga is now contemplating a multibillion-dollar initial public offering on Nasdaq, profiting from lending to consumers that are perceived as too risky for banks.
For many workers in London’s financial services sector, successes like Wonga have turned the idea of starting a business into an increasingly attractive option. With investment banking activities on the wane, job prospects in the industry have remained poor since the beginning of the financial crisis, and the financial sector here is expected to lose 25,000 jobs this year.
Anil Stocker has seen the layoffs up close.
Mr. Stocker, a 28-year-old Cambridge graduate, left Lehman Brothers a few months before it collapsed in 2008. A year later, he resigned from the American investment bank Cogent Partners to co-found MarketInvoice with two friends who worked at JPMorgan Chase and Goldman Sachs.
The start-up helps small businesses gain access to capital by selling their supplier invoices to investors at a discount.
“The finance industry will have to completely change, and we are just at the beginning,” Mr. Stocker said.
MarketInvoice wants to exploit an underserved market in the banking sector. As firms have pulled back on lending, small business have been denied credit because they are deemed too much of a financial risk.
To help these companies access cash, Mr. Stocker and his partners began an online marketplace where small businesses can auction their long-term supply contracts to money managers for the highest price. Many of these invoices can take up to 90 days to pay out, so companies are willing to sell them at a discount to get hold of short-term capital.
Starting the business has not been easy. It took MarketInvoice’s founders — who were still working for banks — almost a year to devise the business plan, and a further six months to raise $1.4 million from investors. The start-up auctioned its first supplier contract for £40,000, or $64,000, in early 2011, but only hit the £1 million mark nine months later.
“No one wanted to be the first company to use our system,” Mr. Stocker said. “At the beginning, you live or die by your reputation.”
London’s finance start-ups also are attracting entrepreneurs with a technology background.
Taavet Hinrikus, a 31-year-old Estonian who was Skype’s first employee, dreamed up his business while still working for the Internet calling service. In 2006, the company moved him to London from Tallinn, Estonia, where he rose to become Skype’s director of strategy. But Mr. Hinrikus grew frustrated after losing 5 percent of his salary to bank charges every time he moved money from Estonia to Britain.
After meeting fellow compatriots in London who wanted to transfer cash back Estonia, Mr. Hinrikus created a system in which individuals could move money to each other’s accounts. By agreeing to swap currencies at a set rate, Mr. Hinrikus said he saved thousands of dollars in bank fees.
“We had to find our own way to avoid the charges,” he said.
With his business partner, Kristo Kaarmann, a former management consultant, Mr. Hinrikus built a Web site that connects people looking to exchange British pounds with euros. Their start-up, called TransferWise, acts as an intermediary for the money transfers and has expanded into other European currencies.
Not everything has gone to plan. The start-up had to wait 18 months to receive its license to operate from British regulators.
Yet in its first 12 months, Mr. Hinrikus said TransferWise has helped people to exchange around $10 million of foreign currencies that has avoided costly bank charges. The start-up also has raised $1.3 million in seed capital from investors, including PayPal’s co-founder Max Levchin.
“Banks aren’t doing a good job at innovating for consumers,” said Robert Dighero, a partner in the London-based venture capital firm Passion Capital. “Start-ups are nibbling away at some of their most profitable businesses.”
Tuesday, October 2, 2012
Cyberattacks on 6 American Banks Frustrate Customers
Sunday, September 30, 2012
Bits Blog: Hackers May Have Had Help With Attacks on U.S. Banks
The hackers claiming responsibility for cyberattacks on American banks over the past week must have had substantial help to disrupt and take down major banking sites, security researchers say.
Bank of America, JPMorgan Chase, Citigroup, U.S. Bancorp, Wells Fargo and PNC all experienced disruptions and delays on their banking sites over the past week because of denial of service or DDoS attacks, in which hackers clog a Web site with data requests until it slows or collapses under the load.
A hacker group, which calls itself the Izz ad-Din al-Qassam Cyber Fighters, took credit for the attacks in online posts. They enlisted volunteers for the attacks with messages on various sites. On one blog, they called on volunteers to visit two Web addresses that would cause their computers to instantly start flooding targets — including the New York Stock Exchange, Nasdaq and Bank of America — with hundreds of data requests each second. This week, hackers asked volunteers to attack banks according to a defined timetable: Wells Fargo on Tuesday, U.S. Bancorp on Wednesday and PNC on Thursday.
Representatives for Wells Fargo, U.S. Bank and PNC all confirmed Wednesday that their Web sites had experienced disruptions because of unexpected volumes of traffic. Both the New York Stock Exchange and Nasdaq saw a slowdown, but no serious disruption, on their Web sites.
Security researchers say the attack methods being peddled by hackers — the custom-built Web sites — were too basic to have generated the disruptions.
“The number of users you need to break those targets is very high,” said Jaime Blasco, a security researcher at AlienVault who has been investigating the attacks. “They must have had help from other sources.”
Those additional sources, Mr. Blasco said, would have to be a well-resourced group, like a nation state, or botnets — networks of infected zombie computers that do the bidding of cybercriminals. Botnets can be rented via black market schemes that are common in the Internet underground, or loaned out by cybercriminals or governments.
Last week, Senator Joseph I. Lieberman, chairman of the Senate Homeland Security Committee, said in an interview that he believed the attacks on the banks were being sponsored by Iran’s government.
Mr. Blasco said security researchers had noticed an increase in the use of botnets out of Iran recently. But he said he had not been able to track the origin of the attack to Iran. Attacks can be routed through various I.P. addresses to mask their true origin, making attribution “nearly impossible,” Mr. Blasco said.
In the hackers’ post, they said their attacks were not sponsored by Iran, and said they “strongly reject the American officials’ insidious attempts to deceive public opinion.”
They said they conducted the attacks in retaliation for a video, made by amateur filmmakers in the United States, that mocks the Prophet Muhammad.
“Insult to the prophet is not acceptable, especially when it is the last prophet Muhammad,” the hackers said in their post.
They pledged to continue to attack American banking sites and targets in other countries, including France, Israel and the United Kingdom, until the video was pulled offline.