In 1934, John Dillinger became "Public Enemy No. 1" between lighting cigarettes and robbing several banks. By 2018, however, walking into a bank's front door with a gun is no longer the primary method of robbing a bank or stealing funds.

For hackers, the internet is the getaway car and malware is the weapon. Thanks to technology, stealing money or data is easier today than in the 1930s. Financial institutions, like other industries, are under attack from hackers, but the difference is that financial institutions have direct access to cash. For hackers, profit takes many forms: data itself is a "currency" worth stealing.

Although hackers lack the 1930s aesthetic of Dillinger or Willie Sutton Jr., their relentless pursuit of profit shows a certain "indescribable quality"; robbing people with a computer is far easier than putting on a mask and walking into a bank.

Why target banks?

According to Itay Kozuch, director of threat research at IntSights, speaking with CIO Dive, banks and financial institutions are the top targets on the dark web. Banks are easier to calculate because "you don't always need to rob the bank itself." There are three main attack patterns among dark web denizens:

  • Direct attacks on banks
  • Stealing bank customer information through phishing schemes and fraudulent emails
  • Exploiting vulnerabilities in vendors within the bank's supply chain

Each method has its pros and cons. Kozuch noted that direct attacks on banks are the hardest to execute, but large cybercrime groups have succeeded. Spear phishing targeting individual customers is a simpler strategy and can still indirectly "rob" the bank. If hackers illegally obtain bank customer credentials and commit fraud, customers typically have the right to be compensated for stolen funds from the bank through insurance. Exploiting the supply chain is a common method because the targets are usually smaller and more vulnerable vendors. Kozuch said hackers often focus on marketing or law firms that banks work with.

Because that's where the money is

According to a Bitglass report, in 2018, nearly three-quarters of data breaches at financial companies were caused by hacking and malware. Financial institutions such as Goldman Sachs, Fidelity Investments, JPMorgan Chase, and RBC Royal Bank all suffered data breaches this year.

These are large banking institutions with government-level defense resources. But Mark Sangster, vice president and industry security strategist at eSentire, told CIO Dive that regional banks, hedge funds, and private investment entities are easier targets. If investment firms aren't careful, hackers can execute fraudulent redemptions. For example, a manufacturing company was defrauded of about $1.3 million through fake invoices, Sangster said. The last fake bill sent by the scammers was for $650,000, and the company paid it. Afterward, the company's bank flagged the wire account as suspicious and asked if the company still wanted to complete the transfer. The manufacturer said "yes." Fortunately for the company, the FBI had flagged multiple suspicious accounts, and the funds were eventually recovered.

Most criminals seeking a quick cyber heist are overestimated in their "exploits." Sangster said everyone is "focused on 'Ocean's Eleven'-style events," but "they're not like that." Criminals use simple tools, similar to walking in the front door with a mask, using the company's tools against the company. Remote management tools that allow remote employees to access internal systems are a trusted gateway, but no one really monitors them. Sangster said when these functions are manipulated, it comes down to the perception of "trusted identity." It's like "dressing up as a bank guard" and slipping in through the back door as if nothing is wrong.

Whether the heist is carried out by low-end or high-end criminals, there are always victims. Banks are robbed because "that's where the money is," but Sutton's motto is now outdated. Money-driven malicious actors no longer need to rob banks. Christine Meyers, director of product marketing at Alert Logic, told CIO Dive that anything with vulnerabilities can become a "cash terminal."

The modern heist

The immediacy of profit for hackers is also changing. They areevolving the kill chain, making it more efficient and automated, which also involves bypassing dark web markets—moving into mining and cryptocurrency. Matt Downing, principal threat researcher at Alert Logic, said in an interview: "Mining, overall, you're targeting the entire internet." The shift from stealing traditional currency to cryptocurrency is changing the risk landscape. Meyers said if you can bypass the step of extracting data, "you can go straight from attack to profit."

Bitcoin and cryptocurrency mining allow hackers to directly cash out. Downing noted that miners are typical of moral ambiguity because they can disguise it as a "victimless crime," since they are stealing resources. They can also operate in a fairly covert manner. Traditional bank robberies have declined over the years because the risk isn't worth the reward—like the deadly shootouts with law enforcement in Dillinger's case.

Meyers said fraudulent wire transfers, credit card theft, or "using a series of mule accounts to hide funds to drain dormant accounts" are common types of bank theft. In digital heists, high-level skills are not always a prerequisite. The new kill chain model compresses multiple steps, making it harder for companies to fully mitigate threats and easier for attackers to exploit vulnerabilities. Miners can use attack scripts found in chat rooms. In recent years, hackers have shifted to more mainstream channels like chat rooms. Messaging platforms are used for transactions and manipulation due to encryption.

Who opens the safe

Since almost every organization in nearly every industry has data, hackers tend to look for the best return on investment. Kozuch said sometimes stolen data is just "interesting information" that can be used for extortion. Rich Bolstridge, chief financial strategist at Akamai, said in an interview that data breaches can lead to "data dumps," including personally identifiable information, credentials, and more. These dumps can be organized in plain text, compiled into dictionaries, and sold on the dark web. Kozuch said the hottest product on the dark web is stolen credit cards. But almost everything is related to money, so any data has a price tag.

Although profit is a common goal for thieves, their methods vary. Sangster said "smash-and-grab" criminals focus on quick returns, even if the value is lower. The second type of criminal comes from more organized crime groups, "like the Mafia." The last type is nation-state actors. Nation-state actors often have stronger resources and can produce more stunning results.

In 2013, nation-state hackers stole from another country's economy in a roundabout way. According to reports,Chinese hackers stolethe metal detector designs of Codan, an Australian communications and mining technology manufacturer. After the heist, "cheap knockoffs" were sold in Africa, causing the company's sales to decline. In digital heists, attribution is not always obvious, but "calling cards" still exist. Sangster said hackers can leave markers in code to indicate presence, even if it can't be directly traced back to them.

Like old-school robbers, some hackers crave fame. During his reign as one of the greatest bank robbers of all time, Dillinger declared: "You're being robbed by the John Dillinger gang, and this is the best!"