iTnews
  • Home
  • News
  • Technology
  • Security

Aussie bank account passwords stolen and sold for $900

By Negar Salek
May 15 2008 3:00PM
Follow google news

Cybercriminals are stealing bank login details from Australian online bankers and selling the data on European black markets for as much as €550 ($913).

A bundle package that includes personal information and personal bank details from Commonwealth Bank, ANZ, Suncorp and Bank West account holders is going for €550, according to McAfee Avert Labs’ research.

Prices depend on what’s on offer such as available balance, bank organisation and country. And as in the legitimate world, quality costs more.

“My investigations led me to visit a site proposing top-quality data for a higher price than usual,” wrote researcher Francois Paget, in the
Avert Labs blog.

“Additional information such as PIN and Transfer Pass-phrases are also given when necessary,” Paget said.

A bundle package from multiple US banks is on offer for €450, while stolen data from Spanish banks is the most expensive at €575.

To give an idea of the scope of the activity the research reveals that data from over 900 banks in North America and European countries exist in the trade.

The seller even offers some guarantees, promising to replace the data if the purchaser is unable - within 24 hours - to log into the account with details provided, wrote Paget.

SC notified the Commonwealth Bank upon accessing the research and the bank promptly referred the case to authorities.

According to the Commonwealth Bank’s spokesperson Michael Gleeson, the bank works closely with the Australian High Tech Crime Centre and the country's state police services.

“The security of our customers' details is of the utmost importance to the Commonwealth Bank. We are not sure if the site in question is genuine or a hoax but we are taking it very seriously,” Gleeson said.

ANZ Bank did not respond to calls for comment.

Despite the Commonwealth Bank's prompt measures, experts agree that end-users are, and if not more, at fault than the banks storing the data because of lax security practices.

According to Dave Marcus, security research and communications manager at McAfee’s Avert Labs, the end-user is ultimately the person whose machine was infected with malware in the first place.

“It is usually through password stealing Trojans that are downloaded onto the victims' machines. Other times it’s through a good phishing site or through targeted spear phishing site,” Marcus said.

He said most people still don’t actually get that it is the end-user who is the real victim and the end-user who is the ultimate target.

“The bank is [simply] used as the lure because they’re high profile,” he said.

Marcus praised the role of banks in fighting cyber theft and fraud, acknowledging that in this day and age banks do a very good job of raising awareness and invest in a lot of authentication.

“It [identity theft] happens more often than you would probably be comfortable knowing. These types of sites and then the selling of this type of information is very common in the underground,” Marcus said.

Paget's research did not specify the names of those affected.

Aussie bank account passwords stolen and sold for $900

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:
anz googlecommonwealth banknews banksecurity

Related Articles

  • Anthropic pulls Mythos-class models globally Anthropic pulls Mythos-class models globally
  • AudiA6 crypto launderers arrested, network taken down by police AudiA6 crypto launderers arrested, network taken down by police
  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
Join our WhatsApp Channel

Partner Content

CommBank creates opportunities for technologists to upskill  with frontier AI companies
Partner Content CommBank creates opportunities for technologists to upskill with frontier AI companies
Agile isn’t the problem: why projects still fail, and what’s missing
Partner Content Agile isn’t the problem: why projects still fail, and what’s missing
Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
Promoted Content Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic releases Mythos-class model for public use

Anthropic releases Mythos-class model for public use

Apple bumps up security in fresh operating system releases

Apple bumps up security in fresh operating system releases

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.