0 comments | Print

AmEx website brazenly hacked

Published: Friday, Mar. 29, 2013 - 12:00 am | Page 6B

American Express customers trying to gain access to their online accounts Thursday were met with blank screens or an ominous ancient typeface. The company confirmed that its website had come under attack.

The assault was just the latest in an intensifying campaign of unusually powerful attacks on U.S. financial institutions that began in September and have taken dozens of them offline intermittently, costing millions of dollars.

JPMorgan Chase was taken offline by a similar attack earlier this month. And last week, a separate attack wiped data from South Korea's banks and television networks.

Corporate leaders have long feared online attacks aimed at financial fraud or economic espionage, but now a new threat has taken hold: attackers, possibly with state backing, who seem bent on destruction.

"The attacks have changed from espionage to destruction," said Alan Paller, director of research at SANS, a cybersecurity training organization. "Nations are actively testing how far they can go before we will respond."

Security experts who studied the attacks said it was part of the same campaign that took down the websites of JPMorgan Chase, Wells Fargo, Bank of America and others over the past six months. A group that calls itself the Izz ad-Din al-Qassam Cyber Fighters has claimed responsibility for those attacks.

The group says it is retaliating for an anti-Islamic video posted on YouTube last fall. But U.S. intelligence officials and industry investigators say they believe that the group is a convenient cover for Iran.

Just how tight the connection is – or whether the group is acting on direct orders from the Iranian government – is unclear. Government officials and bank executives have failed to produce a smoking gun.

North Korea is considered the most likely source of the South Korean attacks, although investigators are still struggling to follow the digital trail, a process that could take months. The North Korean government of Kim Jong Un has openly declared that it is seeking out online targets in its neighbor to the south to exact economic damage.

Representatives of American Express confirmed that the company was under attack Thursday and said it was working to get its consumer banking site back online. An FBI spokesman did not respond Thursday to a request for comment about the American Express attack.

Spokesmen for JPMorgan Chase said they would not talk about the recent attack.

The largest contingent of instigators of attacks in the private sector, government officials and researchers say, remains Chinese hackers intent on stealing corporate secrets. But the U.S. and South Korean bank attacks underscore a growing fear that the two countries now worrying banks, oil producers and governments may be Iran and North Korea, not because of their skill but because of their brazenness.

Neither country is a superstar in this area. But the appeal of digital weapons is similar to that of nuclear capability: It is a way for an outgunned, outfinanced nation to even the playing field.

"These countries are pursuing cyberweapons the same way they are pursuing nuclear weapons," said James Lewis, a cybersecurity expert at the Center for Strategic and International Studies in Washington. "It's primitive; it's not top of the line, but it's good enough and they are committed to getting it."

When hackers believed by U.S. intelligence officials to be Iranians hit the world's largest oil producer, Saudi Aramco, last year, they did not just erase data on 30,000 Aramco computers; they replaced the date with an image of a burning U.S. flag.

In the assault on South Korea last week, some affected computers displayed an ominous image of skulls.

© Copyright The Sacramento Bee. All rights reserved.



About Comments

Reader comments on Sacbee.com are the opinions of the writer, not The Sacramento Bee. If you see an objectionable comment, click the "Report Abuse" link below it. We will delete comments containing inappropriate links, obscenities, hate speech, and personal attacks. Flagrant or repeat violators will be banned. See more about comments here.

What You Should Know About Comments on Sacbee.com

Sacbee.com is happy to provide a forum for reader interaction, discussion, feedback and reaction to our stories. However, we reserve the right to delete inappropriate comments or ban users who can't play nice. (See our full terms of service here.)

Here are some rules of the road:

• Keep your comments civil. Don't insult one another or the subjects of our articles. If you think a comment violates our guidelines click the "Report Abuse" link to notify the moderators. Responding to the comment will only encourage bad behavior.

• Don't use profanities, vulgarities or hate speech. This is a general interest news site. Sometimes, there are children present. Don't say anything in a way you wouldn't want your own child to hear.

• Do not attack other users; focus your comments on issues, not individuals.

• Stay on topic. Only post comments relevant to the article at hand.

• Do not copy and paste outside material into the comment box.

• Don't repeat the same comment over and over. We heard you the first time.

• Do not use the commenting system for advertising. That's spam and it isn't allowed.

• Don't use all capital letters. That's akin to yelling and not appreciated by the audience.

• Don't flag other users' comments just because you don't agree with their point of view. Please only flag comments that violate these guidelines.

You should also know that The Sacramento Bee does not screen comments before they are posted. You are more likely to see inappropriate comments before our staff does, so we ask that you click the "Report Abuse" link to submit those comments for moderator review. You also may notify us via email at feedback@sacbee.com. Note the headline on which the comment is made and tell us the profile name of the user who made the comment. Remember, comment moderation is subjective. You may find some material objectionable that we won't and vice versa.

If you submit a comment, the user name of your account will appear along with it. Users cannot remove their own comments once they have submitted them.

hide comments
Sacramento Bee Job listing powered by Careerbuilder.com
Quick Job Search
Buy
Used Cars
Dealer and private-party ads
Make:

Model:

Price Range:
to
Search within:
miles of ZIP

Advanced Search | 1982 & Older



Find 'n' Save Daily DealGet the Deal!

Local Deals