Channels

Photo: Reuters
Bank Leumi. Did not succumb to threats
Photo: Reuters

Hackers attempt blackmail of Bank Leumi

Muslim elements demand immediate ransom, threatening to crash Leumi websites. Bank stresses no harm caused to clients' accounts

Muslim elements launched an aggressive service lockout attack on Bank Leumi's websites last week and threatened to crash the site unless the bank transfers them large sums of money.

 

The bank did not succumb to the demands which came through by an email from Germany and managed to thwart the attack with a series of actions. The bank stressed Saturday that its customers' accounts have remained unharmed.

 

Last Wednesday, anonymous sources launched a massive assault against the Leumi Group's websites by a lockout attack in which they flooded Leumi's websites with 40,000 communication requests per second.

 

The Bank's information security personnel noticed the assault which slowed the website down, recruited international specialists and managed to thwart the attack. During the event, the site was off the air for 30 minutes.

 

Later in the day, a ransom email arrived at Bank Leumi's headquarters in Switzerland threatening that unless the bank immediately transfers an undisclosed sum of money they will crash the website. The bank did not succumb to the ransom demand and IT specialists brought in to deal with the attack reached the conclusion that the assault was carried out by Muslim elements.

 

Measures taken to protect the website slowed down the website even more; consequently the bank's IT personnel disabled the site and uploaded it in a different configuration which blocks such assaults.

 

The bank's customers accessing the site at the time of the attack were redirected to a different URL where they were requested to enter a password in order to enter the website. Following the ransom email from the anonymous source – most likely sent as a diversion – the entire event was reported to the Bank of Israel and to the Israel Police.

 

Bank Leumi confirmed the information and commented that "the Bank dealt with the assault in line with what was practiced in the Bank's information security division's drills as part of the bank's measures for dealing with such attacks and on the basis of knowledge gathered from similar events in Israel and the world.

 

These measures were laid down to ensure the website is operational during denial of service attacks and to enable the bank's customers' to perform the desired actions on the website while circumventing the assault."

 

Click here to read this report in Hebrew

 

 


פרסום ראשון: 09.04.11, 18:55
 new comment
Warning:
This will delete your current comment