Third-party software vulnerability results in Mexican bank heist
Third-party software vulnerability results in Mexican bank heist

Mexican authorities are investigating suspects for a bank hack that siphoned hundreds of millions of pesos out of at least five banks.

A vulnerability in software developed by a third party and used to connect payment systems is suspected to have been compromised allowing the money to be illegally siphoned from “fake accounts”, Banxico, Mexico's central bank, Head of Operations Lorenza Martinez told Reuters.

Threat actors sent hundreds of false orders to the money around in amounts ranging from tens of thousands to hundreds of thousands of pesos from various banks to accounts that were then emptied in cash withdrawals from dozens of branch offices.

One source reports that the thieves made off with more than 300 million pesos or £11.2 million while others have reported as much as 400 million pesos (£15 million) may have been stolen.

Authorities are still investigating whether or not the attackers have help from inside the bank.

“The successful attacks on Mexican banks represent an enormous failure of third-party risk management,” CyberGRX chief information officer Fred Kneip told SC Media. “As the SWIFT Network learned after an attack on a member bank led to a costly breach, it only takes one vulnerability for attackers to gain access to your network and ride in on a trusted connection.”

Kneip went on to say that cyber-criminals are increasingly targeting third parties – suppliers, contractors, vendors and, in this case, a software provider used by the central bank's SPEI interbank transfer system – to breach high-value networks. 

To effectively mitigate the persistent and potentially damaging threats posed by attackers institutions must collaborate and share information at all levels.