In recent hours, inaccurate reports have been circulating regarding a hacker attack that was carried out in conjunction with the General Secretariat of the Hellenic Republic and Greek Banks. More specifically, reports that are rapidly being circulated on the internet report that a hacker attack was carried out on the largest systemic Greek Banks (National Bank, Piraeus Bank, AlphaBank, Eurobank and Attica Bank), which, combined with a previous data breach by the General Secretariat of the Hellenic Republic, led to losses of millions of euros.
SecNews, due to the numerous questions it received from readers who were concerned about the possibility of such a thing having taken place, began an investigation/reportage in order to determine what exactly has happened and whether the events have exactly the dimension presented in the publications. We recall that SecNews, the first in the past to have made public and sharply criticized the security of systems in Banks, services and public and private sector bodies.
Following valid updates that we received mainly from banking industry executives and investigators of the case, who know important details about the issue, we found that:
- The alleged attacks exclusively concerned attacks against users and in no case attacks on bank or GSIS information systems
- The two cases are seemingly unrelated and in no way appear to be related, at least at first glance (except that they have a time coincidence and similar Phishing methodology).
- The attacks were isolated and concerned exclusively incorrect handling by users and not omissions by the relevant service executives
- No information systems were affected, only user terminals that do not fall under the jurisdiction of the Banks in any way, while they are the exclusive responsibility of the users.
- This is a category of attacks known to all Banks both in Greece and abroad for at least the last 6 years. Similar attacks are carried out against their customers, almost on a daily basis, so it is not some new type of methodology, as was incorrectly reported on websites.
Additionally, as conveyed to us by the relevant executives:
- As soon as the malicious messages leading to foreign servers were identified, the process chosen by each Bank began and within 10 minutes there was a nationwide update to the Banks and the relevant actions were taken by security executives.
- were immediately shut down and therefore the spread of malicious messages stopped.
- Even in the few cases where a monetary transaction occurred due to incorrect user handling, the Banks, in the context of social responsibility and citizen protection, proceeded to block the transactions and identify the IBAN of the malicious fraudster. The monetary transactions concerned transactions of a few euros and in no case of millions of euros as was incorrectly reported.
- In addition, the Banks, as they are required to, informed the Bank of Greece and the Central Bank in accordance with their procedures.
Regarding the actions taken by the General Security Service, we have not had any assessment or relevant information communicated as of the time of writing these lines.
In the relevant diagrams, we present to you in the most detailed way how electronic fraudsters unsuccessfully tried to transfer money from Greek Banks, using the so-called "mules".
Essentially, we have one of the well-known, recurring “phishing” attacks that we see in our mailboxes every day, where the attacker sends messages to unsuspecting users with altered content that resembles known services. In this case, the attackers had sent unsuspecting users e-mails containing the logos of the Greek National Bank and almost all Greek Banks.
At the same time, the Cybercrime Unit had identified the relevant forged messages at their inception, from information received via the communication e-mail ccu@cybercrimeunit.gov.gr as well as via the national Cyberalert hotline 11188. After receiving the relevant information, it became the reference point for Banks and unsuspecting victims for the immediate identification and cessation of the Phishing campaign. It had also made the relevant announcements in the previous days, as a result of which the spread of malicious messages has been reduced to an absolute minimum.
It seems that the “hackers” chose to spread the forged e-mails with “eloquent” titles such as tax refund etc., with the aim of reaching a large number of users who would believe that the messages had come from the GGPS. It is worth mentioning that users often receive similar messages as if they were apparently coming from Facebook, Google, other well-known services and even foreign banks that they may not even have an account with.
Therefore, in no case, as you incorrectly state in the relevant publications, was data interception carried out through the information systems of the services involved. The data interception was carried out, as they tell us, on individual users, FROM THEIR PERSONAL COMPUTERS, after they opened the malicious/forged messages at their own risk.
In addition, almost all banks have adopted the use of tokens for financial transactions (two/multi factor authentication).
So even if the malicious actors have somehow intercepted the password, it is extremely difficult and complicated for them to carry out financial transactions, when they should also have the double authentication that Banks provide as modern security measures in ebanking systems (token or use of a mobile phone).
Even in the cases of individual victims of the attack on the Banks, already as we are able to know, the authorities have identified and blocked the IBAN accounts that the attackers tried to execute transactions.It seems that the digital traces of the electronic fraudsters lead to Belarus, while the “mules” that were identified were in Germany, Austria and the United Kingdom.
Therefore, according to the report and exclusive information from SecNews, there is no concern about a hit on Banks or the General Security Service with the aim of intercepting data or carrying out transactions to the detriment of consumers/citizens
Perhaps the only concern that arises, and should be a primary concern for all of us, is the issue of information and awareness. It is inconceivable that when attacks like these are frequently announced by all the media and websites, there are still our fellow citizens who easily fall victim tocyber crooks, who, with childish techniques (which no one calls “hacking”), try to target innocent users.
We suggest that the Banks strengthen their part of informing the public, which we believe is lagging behind, with relevant promotional videos or even relevant ads on their mobile applications or on their central websites. In addition, road events and relevant Leaflets that can target large groups of the population so that there is substantial and massive information for the public.
An unbreakable rule, however: Services or Banks will never contact you via email to ask for access codes, data renewal or other services.
SecNews thanks the relevant Bank executives/SecNews readers for the valid, detailed and immediate information.
