Cybercriminal Offers a “How To” Guide for Robbing Banks; Uses Cayman National Bank as the Example

Stu Sjouwerman | Jan 10, 2020

PhineasPhisherThis latest document from notorious hacker Phineas Phisher, along with a leaked report from PwC, shows how easy it is for a bank to be hacked and defrauded.

You might think that stealing money from a bank is tough – you need to gain access to the network, figure out how money is transferred, what security they use, what monitoring is in place, and how to insert your own transactions into the process.

But the recently-released “how-to” manifesto from Phineas Phisher documents every step taken as he opportunistically hacked the Cayman National Bank back in 2016. Using little more than a network scan looking for VPNs with a known vulnerability, Phisher was able to gain access to the bank. He was able to maintain access without detection for months even before attempting his first transaction. According to a leaked forensics report from PwC (WARNING: the link points to a PDF that some AV solutions don’t trust… proceed with caution), Phisher was about to compromise seven systems, leverage internal credentials, and attain “unrestricted administrative access” to the bank’s network.

According to Phisher, the only reason he picked this bank is because he got a hit on his network scan, saw it was a Cayman bank, and “thought it would be fun”. Scary stuff.

Banks looking to protect themselves from such attacks should consider the following precautions:

  • Patch all known vulnerabilities. Vulnerability scanning and management would also be appropriate.
  • Implement least privilege. Phisher was about to laterally move; restricting what accounts can do will slow down an attacker’s movement.
  • Train users to be vigilant with Security Awareness Training. According to PwC, at least 4 user endpoints were compromised during this hack. Teaching users to watch for unusual application activity or malicious emails can help stop an attack in its tracks.

The casual nature of this attack should make banks worried; if this is what a hacker can do “for fun”, think about what can happen when a hacker is attacking your bank on purpose.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.