• On The Insider: Jonas Brothers Breakup?
October 10, 2008 1:30 PM PDT

World Bank under cyberattack?

by Robert Vamosi
  • Font size
  • Print
  • 4 comments

The computer network used by the World Bank Group has suffered a series of at least six intrusions since mid-2007, according to a report.

The World Bank Group was first notified of the intrusions by the FBI in September 2007, when the bureau was investigating another cybercrime case involving transactions out of Johannesburg, South Africa. Fox News said it has an internal memo (PDF) describing the initial intrusion to World Bank Group employees.

The World Bank Group did not respond to a request for comment.

The World Bank Group, based in Washington, D.C., is not a traditional bank. It is made up of the International Bank for Reconstruction and Development and the International Development Association, and it provides a vital source of financial and technical assistance to developing countries around the world, according to its Web site. The World Bank board represents 185 member nations and currently budgets $25 billion annually in antipoverty campaigns.

Up to 40 servers have been penetrated in a series of attacks, according to Fox News, including one attack on a server that held contract-procurement data. Two of the attacks appear to come from the same block of IP addresses originating in China. But Graham Cluley, senior technology consultant at Sophos, told CNET News that doesn't mean the attackers are in China--only that they are using compromised machines located in that country.

"Ideally, if you're a large organization or financial organization, then you would have a team of penetration testers testing your system to the limit looking for those weaknesses, looking for those holes," Cluley said. "It's much better that you find them before a criminally minded hacker does."

Apparently, the World Bank Group does not conduct its own security-assessment testing, a requirement of financial institutions in the United States and other countries.

Fox News also published a more recent memo from August 19, 2008 (PDF) in which World Bank Group staff were told to change personal passwords and start using security "tokens" or cards to access the organization's applications remotely. These tokens, such as the two-factor tokens being used by VeriSign, are synced with an internal server and display password strings that are valid only for a minute or so.

Cluley questioned why these attacks aren't more of a priority with World Bank staff. "Every bank on High Street (in London) already has that requirement of its customers," he said. "Every firm with critical data should be giving its employees (password tokens) because otherwise compromise is just as simple as having a key-logging piece of spyware on the desktop."

It is unclear how the intrusions occurred, when they started, or whether they are even related.

Fox said that outside forensics teams have since been brought in to investigate. In an e-mail to CNET News, a representative for Mandiant, a U.S.-based digital forensics company, confirmed that the World Bank is a client but would not elaborate on the work done on its behalf.

"Regardless of the facts," Cluley said, "every organization needs to learn that this can happen to big organizations and small ones, and make sure they have proper security and encryption in place."

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
advertisement
Click here!
Recent posts from Security
McAfee warns about '12 Scams of Christmas'
Cisco launches iPhone security app
Town to photograph every car that enters and leaves
New Firefox 3.6 beta aims to cut crashes
Facebook adopts new privacy policy
T-Mobile UK says workers sold customer data
FAQ: Recognizing phishing e-mails
Report: Countries prepping for cyberwar
Add a Comment (Log in or register) (4 Comments)
  • prev
  • 1
  • next
by billspaced October 10, 2008 2:30 PM PDT
Sheesh, first the real-world attacks (by the shorts!), now the cyber-attacks! Anybody lending conspiracy theories to our financial market turmoil?
Reply to this comment
by HackerForums October 11, 2008 5:19 PM PDT
It's funny, I happened to be on this Conspiracy SkypeCast when SkyeCast was still active and the host was saying the market was going to crash at the end of Sept or Beginning of Oct. It seems he was on the money. He mentioned ties to the NWO, the Federal Reserve and some other parties involved in some conspiracy to make a global currency. Now I have to wonder....

http://www.hackerforums.org
by ferretboy88 October 10, 2008 7:42 PM PDT
Find them and hang them.
Reply to this comment
by dimeji_ayo2000 September 9, 2009 2:46 AM PDT
scientists and technologists please keep on more research on how to eradicate cyber crime because it became very rapid everywhere in the whole world...........xxxxxx
Reply to this comment
(4 Comments)
  • prev
  • 1
  • next
advertisement

The 411 on early-termination fees

Verizon Wireless has doubled its early-termination fees for smartphones, but what does it mean for the rest of the industry?

Google has its own plan for Netbooks

No, the search giant isn't saying it will build a Netbook. But it sure knows what it would like one running Chrome OS to resemble, and that's a little different from the Netbook of today.
• Screenshot tour of Chrome OS

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right