{"id":8916,"date":"2020-05-05T22:29:31","date_gmt":"2020-05-05T22:29:31","guid":{"rendered":"https:\/\/www.bankvault.com\/?p=8916"},"modified":"2020-06-04T20:14:59","modified_gmt":"2020-06-04T20:14:59","slug":"cyber-criminals-take-money-directly-from-a-solicitors-trust-account","status":"publish","type":"post","link":"https:\/\/www.bankvault.com\/cyber-criminals-take-money-directly-from-a-solicitors-trust-account\/","title":{"rendered":"Cybercriminals Take Money Directly from Solicitor\u2019s Trust<\/br>Queensland Law Society"},"content":{"rendered":"\t\t
\n\t\t\t\t\t\t
\n\t\t\t\t\t\t
\n\t\t\t\t\t
\n\t\t\t
\n\t\t\t\t\t\t
\n\t\t\t\t
\n\t\t\t\t\t

How Does this Happen? Isn't 2FA Infallible?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t
\n\t\t\t\t
\n\t\t\t\t\t\t\t\t\t

Here is a link to the Queensland Law Society article were several million dollars was hijacked.<\/a><\/p><\/div>

Lets go straight to the point on the techniques hackers use to steal money directly from bank accounts.<\/p>

Most people assume 2FA is infallible. They can’t imagine how it could possibly be defeated. It dramatically improves your security but it\u2019s just another hurdle for cybercriminals and there is a variety of techniques. Here is one called a Man-in-the-Browser.<\/p>

We all click web hotlinks. Browsers are designed for this and to run JavaScript. It\u2019s legitimate code and bad code is undetectable. Symantec published that a MitB, on average, is there 10-months before the hacker stings their victim. They get to know everything, including bank login details and so are only one step away from tricking you to reveal, or use, your 2FA. Being programmers, they also automate their system so it can be replicated to 100,000 machines.<\/p>

The next time you login to your bank to pay the bills the JavaScript simply changes the destination bank account numbers behind your screen, and moves the decimal point. What you see and what’s behind the screen are completely different. \u00a0You authorize the transaction with your FOB, SMS text,j Google Authenticate or Biometrics. One-time-pass-codes are issued once but can be used many times in the next 35 seconds. Your money is gone, and you now have to prove to the bank that you’re not defrauding them.<\/p>

These investigations take a really long time. Your cash flow stopped instantly and the two most precious assets on any balance sheet are (i) Cash at Bank, and (ii) Reputation. Both are gone in 24 hours.<\/p>

If you are a Trustee you\u2019re personally liable within 24 hours. Our governments shut down your business at 48 hours.<\/p>

Well done to the Queensland Law Society for publishing this.<\/p>

#2FA<\/strong> #cyberheist<\/strong> #accounttakeover<\/strong> #ATO<\/strong> #banksecurity<\/strong> #FOB<\/strong> #MitM<\/strong> #JavaScript<\/strong> #BankVault<\/strong><\/p><\/td><\/tr><\/tbody><\/table><\/td><\/tr><\/tbody><\/table><\/td><\/tr><\/tbody><\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t

\n\t\t\t\t\t\t
\n\t\t\t\t\t
\n\t\t\t
\n\t\t\t\t\t\t
\n\t\t\t\t
\n\t\t\t\t\t\t\t\t\t

Password Manager<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t

\n\t\t\t\t
\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\"\"\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t
\n\t\t\t\t\t\t
\n\t\t\t\t\t
\n\t\t\t
\n\t\t\t\t\t\t
\n\t\t\t\t
\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\"\"\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t
\n\t\t\t
\n\t\t\t\t\t\t
\n\t\t\t\t\t\t
\n\t\t\t\t\t
\n\t\t\t
\n\t\t\t\t\t\t
\n\t\t\t\t
\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\"\"\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t
\n\t\t\t\t
\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\"\"\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t
\n\t\t\t\t
\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\"\"\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t
\n\t\t\t\t
\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\"\"\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t
\n\t\t\t\t\t\t
\n\t\t\t\t\t
\n\t\t\t
\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t
\n\t\t\t\t\t\t
\n\t\t\t\t\t
\n\t\t\t
\n\t\t\t\t\t\t
\n\t\t\t\t
\n\t\t\t\t\t\t\t\t\t

BankVault.com<\/strong><\/p>

BankVault is a cybersecurity innovator releasing technologies to secure users from any hacker malware on the users devices or network. The products are browser based web services which completely sidestep user devices and any potential malware that may exist on them. BankVault is used by individuals and institutions to so people can take control of their own security.\u00a0 \u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t

\n\t\t\t\t\t\t
\n\t\t\t\t\t
\n\t\t\t
\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"

How Does this Happen? Isn’t 2FA Infallible? Here is a link to the Queensland Law Society article were several million dollars was hijacked. Lets go straight to the point on the techniques hackers use to steal money directly from bank accounts. Most people assume 2FA is infallible. They can’t imagine how it could possibly be […]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[417,37,252,418],"tags":[],"class_list":["post-8916","post","type-post","status-publish","format-standard","hentry","category-blogs","category-security-news","category-alerts","category-stories"],"yoast_head":"\nCybercriminals Take Money Directly from Solicitor\u2019s TrustQueensland Law Society - BankVault<\/title>\n<meta name=\"description\" content=\"How does this happen? Isn't 2FA Infallible? Here is a link to the Queensland Law Society article. Several million dollars were hijacked. Lets go straight to the point on the techniques hackers use to steal money directly from bank accounts.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.bankvault.com\/cyber-criminals-take-money-directly-from-a-solicitors-trust-account\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cybercriminals Take Money Directly from Solicitor\u2019s TrustQueensland Law Society - BankVault\" \/>\n<meta property=\"og:description\" content=\"How does this happen? Isn't 2FA Infallible? Here is a link to the Queensland Law Society article. Several million dollars were hijacked. Lets go straight to the point on the techniques hackers use to steal money directly from bank accounts.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.bankvault.com\/cyber-criminals-take-money-directly-from-a-solicitors-trust-account\/\" \/>\n<meta property=\"og:site_name\" content=\"BankVault\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/BankVaultOnline\/\" \/>\n<meta property=\"article:published_time\" content=\"2020-05-05T22:29:31+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-06-04T20:14:59+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.bankvault.com\/wp-content\/uploads\/2020\/03\/BankVault-Mockups-Rev4-Login-Laptop-Keyboard2.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1703\" \/>\n\t<meta property=\"og:image:height\" content=\"1156\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@bankvaultonline\" \/>\n<meta name=\"twitter:site\" content=\"@bankvaultonline\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cybercriminals Take Money Directly from Solicitor\u2019s TrustQueensland Law Society - BankVault","description":"How does this happen? Isn't 2FA Infallible? Here is a link to the Queensland Law Society article. Several million dollars were hijacked. Lets go straight to the point on the techniques hackers use to steal money directly from bank accounts.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.bankvault.com\/cyber-criminals-take-money-directly-from-a-solicitors-trust-account\/","og_locale":"en_US","og_type":"article","og_title":"Cybercriminals Take Money Directly from Solicitor\u2019s TrustQueensland Law Society - BankVault","og_description":"How does this happen? Isn't 2FA Infallible? Here is a link to the Queensland Law Society article. Several million dollars were hijacked. Lets go straight to the point on the techniques hackers use to steal money directly from bank accounts.","og_url":"https:\/\/www.bankvault.com\/cyber-criminals-take-money-directly-from-a-solicitors-trust-account\/","og_site_name":"BankVault","article_publisher":"https:\/\/www.facebook.com\/BankVaultOnline\/","article_published_time":"2020-05-05T22:29:31+00:00","article_modified_time":"2020-06-04T20:14:59+00:00","og_image":[{"width":1703,"height":1156,"url":"https:\/\/www.bankvault.com\/wp-content\/uploads\/2020\/03\/BankVault-Mockups-Rev4-Login-Laptop-Keyboard2.png","type":"image\/png"}],"author":"admin","twitter_card":"summary_large_image","twitter_creator":"@bankvaultonline","twitter_site":"@bankvaultonline","twitter_misc":{"Written by":"admin","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.bankvault.com\/cyber-criminals-take-money-directly-from-a-solicitors-trust-account\/#article","isPartOf":{"@id":"https:\/\/www.bankvault.com\/cyber-criminals-take-money-directly-from-a-solicitors-trust-account\/"},"author":{"name":"admin","@id":"https:\/\/www.bankvault.com\/#\/schema\/person\/cc6b22bacd62c30488277e3800f1c96b"},"headline":"Cybercriminals Take Money Directly from Solicitor\u2019s TrustQueensland Law Society","datePublished":"2020-05-05T22:29:31+00:00","dateModified":"2020-06-04T20:14:59+00:00","mainEntityOfPage":{"@id":"https:\/\/www.bankvault.com\/cyber-criminals-take-money-directly-from-a-solicitors-trust-account\/"},"wordCount":395,"commentCount":0,"publisher":{"@id":"https:\/\/www.bankvault.com\/#organization"},"image":{"@id":"https:\/\/www.bankvault.com\/cyber-criminals-take-money-directly-from-a-solicitors-trust-account\/#primaryimage"},"thumbnailUrl":"https:\/\/www.bankvault.com\/wp-content\/uploads\/2020\/03\/BankVault-Mockups-Rev4-Login-Laptop-Keyboard2-1024x695.png","articleSection":["blogs","IT security news","Latest Cybersecurity Threats","Stories"],"inLanguage":"en-AU","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.bankvault.com\/cyber-criminals-take-money-directly-from-a-solicitors-trust-account\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.bankvault.com\/cyber-criminals-take-money-directly-from-a-solicitors-trust-account\/","url":"https:\/\/www.bankvault.com\/cyber-criminals-take-money-directly-from-a-solicitors-trust-account\/","name":"Cybercriminals Take Money Directly from Solicitor\u2019s TrustQueensland Law Society - BankVault","isPartOf":{"@id":"https:\/\/www.bankvault.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.bankvault.com\/cyber-criminals-take-money-directly-from-a-solicitors-trust-account\/#primaryimage"},"image":{"@id":"https:\/\/www.bankvault.com\/cyber-criminals-take-money-directly-from-a-solicitors-trust-account\/#primaryimage"},"thumbnailUrl":"https:\/\/www.bankvault.com\/wp-content\/uploads\/2020\/03\/BankVault-Mockups-Rev4-Login-Laptop-Keyboard2-1024x695.png","datePublished":"2020-05-05T22:29:31+00:00","dateModified":"2020-06-04T20:14:59+00:00","description":"How does this happen? Isn't 2FA Infallible? Here is a link to the Queensland Law Society article. Several million dollars were hijacked. Lets go straight to the point on the techniques hackers use to steal money directly from bank accounts.","breadcrumb":{"@id":"https:\/\/www.bankvault.com\/cyber-criminals-take-money-directly-from-a-solicitors-trust-account\/#breadcrumb"},"inLanguage":"en-AU","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.bankvault.com\/cyber-criminals-take-money-directly-from-a-solicitors-trust-account\/"]}]},{"@type":"ImageObject","inLanguage":"en-AU","@id":"https:\/\/www.bankvault.com\/cyber-criminals-take-money-directly-from-a-solicitors-trust-account\/#primaryimage","url":"https:\/\/www.bankvault.com\/wp-content\/uploads\/2020\/03\/BankVault-Mockups-Rev4-Login-Laptop-Keyboard2.png","contentUrl":"https:\/\/www.bankvault.com\/wp-content\/uploads\/2020\/03\/BankVault-Mockups-Rev4-Login-Laptop-Keyboard2.png","width":1703,"height":1156},{"@type":"BreadcrumbList","@id":"https:\/\/www.bankvault.com\/cyber-criminals-take-money-directly-from-a-solicitors-trust-account\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.bankvault.com\/"},{"@type":"ListItem","position":2,"name":"Cybercriminals Take Money Directly from Solicitor\u2019s TrustQueensland Law Society"}]},{"@type":"WebSite","@id":"https:\/\/www.bankvault.com\/#website","url":"https:\/\/www.bankvault.com\/","name":"BankVault","description":"cybersecurity","publisher":{"@id":"https:\/\/www.bankvault.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.bankvault.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-AU"},{"@type":"Organization","@id":"https:\/\/www.bankvault.com\/#organization","name":"BankVault","url":"https:\/\/www.bankvault.com\/","logo":{"@type":"ImageObject","inLanguage":"en-AU","@id":"https:\/\/www.bankvault.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.bankvault.com\/wp-content\/uploads\/2018\/11\/BankVault-Logo-Light.png","contentUrl":"https:\/\/www.bankvault.com\/wp-content\/uploads\/2018\/11\/BankVault-Logo-Light.png","width":1212,"height":275,"caption":"BankVault"},"image":{"@id":"https:\/\/www.bankvault.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/BankVaultOnline\/","https:\/\/x.com\/bankvaultonline"]},{"@type":"Person","@id":"https:\/\/www.bankvault.com\/#\/schema\/person\/cc6b22bacd62c30488277e3800f1c96b","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-AU","@id":"https:\/\/www.bankvault.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/a0a2420c114d7683d6d1ad16771159f8?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a0a2420c114d7683d6d1ad16771159f8?s=96&d=mm&r=g","caption":"admin"},"url":"https:\/\/www.bankvault.com\/author\/admin\/"}]}},"_links":{"self":[{"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/posts\/8916","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/comments?post=8916"}],"version-history":[{"count":109,"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/posts\/8916\/revisions"}],"predecessor-version":[{"id":9121,"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/posts\/8916\/revisions\/9121"}],"wp:attachment":[{"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/media?parent=8916"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/categories?post=8916"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/tags?post=8916"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}