O banco central mexicano é a última vítima dos hackers da SWIFT. Isto foi relatado por funcionários do banco e que disseram que nesta semana os hackers atingiram o sistema de pagamentos e roubaram milhões de dólares.
O ataque foi descoberto no final de abril e apresenta muitas semelhanças com ataques anteriores contra os sistemas SWIFT.
De acordo com Alejandro Diaz de Leon, responsável do banco central mexicano, os criminosos conseguiram transacionar cerca 20 milhões de dólares de forma ilícita.
“Central bank Governor Alejandro Diaz de Leon said on Monday that the country had seen an unprecedented attack on payment system connections and that he hoped that measures being taken would stop future incidents.” reported the Reuters.
“A source close to the government’s investigation said more than 300 million had been siphoned out of banks, but it was not clear how much had subsequently been taken out in cash withdrawals.”
Segundo relatos, o banco central do México após os mais recentes ataques criou uma divisão de segurança — equipa de incident handling — e instituiu um período de espera de um dia em transferências de fundos em que o montante envolvido seja superior a 2.500 dólares.
“Perhaps, some financial institutions perceived the attacks in Bangladesh as something very distant,” said Alejandro Diaz de Leon who believes that some Mexican banks may not have invested in sufficient security measures.
“But criminals look for vulnerability and once they see it they are going to exploit it.”

Pedro Tavares is a professional in the field of information security working as an Ethical Hacker/Pentester, Malware Researcher and also a Security Evangelist. He is also a founding member at CSIRT.UBI and Editor-in-Chief of the security computer blog seguranca-informatica.pt.
In recent years he has invested in the field of information security, exploring and analyzing a wide range of topics, such as pentesting (Kali Linux), malware, exploitation, hacking, IoT and security in Active Directory networks. He is also Freelance Writer (Infosec. Resources Institute and Cyber Defense Magazine) and developer of the 0xSI_f33d – a feed that compiles phishing and malware campaigns targeting Portuguese citizens.
Read more here.

