Make us your home page
Instagram

Today’s top headlines delivered to you daily.

(View our Privacy Policy)

In 10 hours, $40 million snatched from ATMs

NEW YORK

It was a huge bank heist — but a 21st century version in which the thieves never wore ski masks, threatened a teller or set foot in a vault.

Yet, in two precision operations that involved operatives in more than two dozen countries acting in close coordination and with surgical precision, the organization was able to steal $45 million from thousands of ATMs in a matter of hours.

In New York City alone, a team of eight people struck 2,904 machines over 10 hours on Feb. 19, withdrawing $2.4 million.

On Thursday, federal prosecutors unsealed an indictment charging eight members of the New York crew — including their suspected ringleader who was found dead in the Dominican Republic on April 27 — offering a glimpse into what the authorities said was one of the most sophisticated and effective cybercrime attacks ever uncovered.

"In the place of guns and masks, this cybercrime organization used laptops and the Internet," said Loretta E. Lynch, the U.S. attorney in Brooklyn. "Moving as swiftly as data over the Internet, the organization worked its way from the computer systems of international corporations to the streets of New York City, with the defendants fanning out across Manhattan to steal millions of dollars from hundreds of ATMs in a matter of hours."

The indictment outlined how they were able to steal data from banks, relay that information to a far-flung network of "cashing crews," and then launder the stolen money by buying high-end luxury items like Rolex watches and expensive cars.

In the first theft, hackers were able to infiltrate the system of an unnamed Indian credit-card processing company that handles Visa and MasterCard prepaid debit cards.

The hackers — who are not named in the indictment — proceeded to remove the withdrawal limits on prepaid MasterCard debit accounts issued by the National Bank of Ras Al-Khaimah, also known as RakBank, in United Arab Emirates.

By eliminating the withdrawal limits, "even a few compromised bank account numbers can result in tremendous financial loss to the victim financial institution," the indictment states. And by using prepaid cards, the thieves were able to take money without draining the bank accounts of individuals, which might have set off alarms more quickly.

With five account numbers in hand, the hackers distributed the information to individuals in 20 countries who then encoded the information on magnetic stripe cards. Any plastic card with a magnetic stripe — an old hotel key card or an expired credit card — would do as long as it carried the account data and correct access codes.

On Dec. 21, the "cashing crews" made 4,500 ATM transactions worldwide, stealing $5 million, according to the indictment.

After pulling off the December theft, the organization grew more bold, and two months later they struck again — this time nabbing $40 million.

On Feb. 19, "cashing crews" stood at the ready at ATMs across Manhattan and in two dozen other countries waiting for word to spring into action.

This time, the hackers infiltrated a credit card processing company based in the United States that also handles Visa and MasterCard prepaid debit cards. The company's name was not revealed in the indictment.

After securing 12 account numbers for cards issued by the Bank of Muscat in Oman and raising the withdrawal limits, the cashing crews were set in motion. Starting at 3 p.m., the crews made 36,000 transactions and withdrew about $40 million from machines in the various countries in about 10 hours.

Surveillance photos of one suspect hitting various ATMs showed the man's backpack getting heavier and heavier, Lynch said, comparing the robbery to the caper at the center of the movie Ocean's Eleven.

The plundered ATMs were in Japan, Russia, Romania, Egypt, Colombia, Britain, Sri Lanka, Canada and several other countries, and law enforcement agencies from more than a dozen nations were involved in the investigation, U.S. prosecutors said. The crews in Japan seem to have been the most successful, stealing around $10 million, probably because some banks in Japan allow withdrawals of as much as $10,000 from a single bank machine.

"New technologies and the rapid growth of the Internet have eliminated the traditional borders of financial crimes and provided new opportunities for the criminal element to threaten the world's financial systems," said Steven Hughes, a Secret Service special agent who participated in the investigation. "However, as demonstrated by the charges and arrests announced today, the Secret Service and its law enforcement partners have adapted to these technological advancements and utilized cutting edge investigative techniques to thwart this cybercriminal activity."

The authorities did not immediately provide details about how they became aware of the operation or whether any other arrests have been made in connection with the case. The indictment suggests a far-reaching operation, but there are no details about the people responsible for conducting the hacking or who might be leading the global operation. Law enforcement agencies in more than a dozen countries have been involved in the investigation, prosecutors said.

The authorities said the leader of the New York crew was Alberto Lajud-Pena, 23, who also went by the name Prime. His body was found in the Dominican Republic on April 27 and prosecutors said they think he was killed. Seven other people have been arrested and charged with conspiracy to commit "access device fraud" and money laundering. The prosecutors said they were all American citizens and were based in Yonkers, N.Y.

Following one thief through Manhattan

Federal prosecutors released these images from video that show one thief withdrawing part of the $2.9 million stolen from ATMs in New York on Feb. 19.

Here's how the scheme worked

1. Using malware, hackers breach the worldwide card processors for Rakbank in the United Arab Emirates and the Bank of Muscat in Oman.

2. The criminals override security protocols and hunt for the prepaid debit card systems and delete limits on the accounts. It takes months to penetrate the systems, prosecutors said.

3. Access codes are created. Data is loaded onto any plastic card with a magnetic stripe.

4. Cells around the globe fan out and begin to make repeated cash machine withdrawals.

5. Hackers maintain unauthorized access to the banks to monitor the cashout, keeping withdrawals rolling until the breach is discovered and the systems shut down.

6. Cash is laundered and organizers are paid.

Source: U.S. Attorney's Office, Eastern District, Brooklyn

In 10 hours, $40 million snatched from ATMs 05/10/13 [Last modified: Friday, May 10, 2013 1:14pm]
Photo reprints | Article reprints

Copyright: For copyright information, please check with the distributor of this item, NY Times Syndication.
    

Join the discussion: Click to view comments, add yours

Loading...
  1. Review: Kenny Loggins, Michael McDonald team up to cool down the Clearwater Jazz Holiday

    Blogs

    A cool breeze swept through Coachman Park Saturday night. Couple of them, actually.

    Kenny Loggins performed at the Clearwater Jazz Holiday on Oct. 21, 2017.
  2. No. 16 USF hangs on at Tulane, off to first 7-0 start

    College

    NEW ORLEANS — After half a season of mismatches, USF found itself in a grudge match Saturday night.

    USF quarterback Quinton Flowers (9) runs for a touchdown against Tulane during the first half of an NCAA college football game in New Orleans, La., Saturday, Oct. 21, 2017. (AP Photo/Derick E. Hingle) LADH103
  3. Lightning buries Penguins (w/video)

    Lightning Strikes

    TAMPA — Ryan Callahan spent a lot of time last season rehabilitating his injured hip alongside Steven Stamkos, who was rehabbing a knee after season-ending surgery. During those hours, Callahan noticed two things about Stamkos: his hunger and his excitement to return this season.

    Tampa Bay Lightning defenseman Slater Koekkoek (29) advances the puck through the neutral zone during the first period of Saturday???‚??„?s (10/21/17) game between the Tampa Bay Lightning and the Pittsburgh Penguins at Amalie Arena in Tampa.
  4. Spain planning to strip Catalonia of its autonomy

    World

    BARCELONA, Spain — The escalating confrontation over Catalonia's independence drive took its most serious turn Saturday as Prime Minister Mariano Rajoy of Spain announced he would remove the leadership of the restive region and initiate a process of direct rule by the central government in Madrid.

    Demonstrators in Barcelona protest the decision to take control of Catalonia to derail the independence movement.
  5. Funeral held for soldier at center of political war of words (w/video)

    Nation

    COOPER CITY — Mourners remembered not only a U.S. soldier whose combat death in Africa led to a political fight between President Donald Trump and a Florida congresswoman but his three comrades who died with him.

    The casket of Sgt. La David T. Johnson of Miami Gardens, who was killed in an ambush in Niger. is wheeled out after a viewing at the Christ The Rock Church, Friday, Oct. 20, 2017  in Cooper City, Fla. (Pedro Portal/Miami Herald via AP) FLMIH102