Share

Cyber crooks may have stolen billions in Brazil

Washington - Cyber criminals may have stolen billions of dollars from a popular Brazilian online payment system using malicious software that caused the funds to be sent to accounts controlled by fraudsters, according to a research report released on Wednesday.

EMC's RSA Security said cyber criminals have been using software known as Eupuds to steal funds from customers of Brazil's widely used Boleto Bancário payment system, redirecting them to fraudulent accounts.

RSA estimates that fraudsters sought to siphon off as much as 8.6 billion reais ($3.9bn) from more than 192 000 accounts, though the actual amount stolen could be less because researchers were unable to confirm which Boletos were actually paid out.

They said they believe the operation is still ongoing and have offered to help Brazilian authorities crack down on the operation, which may have begun as early as late 2012.

RSA said it met with members of Febraban, the group that represents the banking industry in Brazil.

'Vulnerabilities'

A representative for Febraban declined to comment on the report, saying the group was not granted access to its content.

The malware currently only targets Boleto transactions processed on PCs running Microsoft's Windows software.

"We're concerned that the attackers will be able to develop the malware for other platforms," said Jason Rader, director of cyber threat intelligence with RSA.

"These attackers have online and offline techniques, and they've understood vulnerabilities in these operating systems."

Brazilians use Boletos to process online payments for items including utility bills, rent, online purchases and small business transactions.

When a computer infected with the Eupuds software is used to process a Boleto payment, it is very difficult for the customer to detect that the account has been modified because the validation screens often display the original inputs to make the fraudulent Boleto look authentic, according to RSA.
We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.16
-0.3%
Rand - Pound
23.83
-0.2%
Rand - Euro
20.48
-0.2%
Rand - Aus dollar
12.46
-0.5%
Rand - Yen
0.12
-0.2%
Platinum
921.40
+0.1%
Palladium
1,026.50
+0.1%
Gold
2,314.47
-0.3%
Silver
27.10
-0.8%
Brent Crude
88.42
+1.6%
Top 40
68,521
+0.7%
All Share
74,488
+0.7%
Resource 10
59,636
+0.0%
Industrial 25
104,286
+1.4%
Financial 15
15,911
+0.1%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders