FinAi News

No products in the cart.

Subscribe
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
Log In
No Result
View All Result
  • Banking
  • Lending
  • Payments
  • Risk & Security
  • Strategy
FinAi News
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
BAN PLUS
Log In
No Result
View All Result
FinAi News
No Result
View All Result

How I Would Break Into Your Institution Part II

Melanie FriedrichsbyMelanie Friedrichs
June 7, 2013
in Risk & Security
Reading Time: 2 mins read
0
Share on Facebook

Originally posted by Sy Phul on blog.andera.com. Follow us on twitter @AnderaInc.

A couple of weeks ago I wrote a short post about my experience working as an ethical hacker before I came to Andera.  During that time, I infiltrated a financial institution using social engineering techniques, gaining me access to customer information.

Although I don’t have more bank break in stories to share, I did also hack into two other data rich institutions during my tenure as an ethical hacker: a university and a hospital.  Both types of institutions have loads of sensitive information that a hacker could resell on the black market.

Hospital University

Operation Animal House

Step 1: Find Vulnerability

The first step was to scan their system for vulnerabilities; I looked at different applications used by the university as well as the network at large.  After searching for some time, I found a vulnerability. Through this vulnerability, I was able to access the web application source code.

Extract Host Password

Step 2: Exploit Vulnerability

I found login credentials in the source code, and I used one of the credentials to remote control into the system. From there, I could download the encrypted windows password file I needed in order to compromise the host. I used a common hacker toolkit to decrypt the encryption and read the password in clear text. I used those credentials to access other servers on the network, where I found sensitive data. GAME OVER.

Mission Infirmary

Step 1: Phishing 

First, I gathered information, including email addresses, from their website and through Google searches to better understand the structure of the hospital. Using the information gathered, I wrote phishing emails to hospital personnel. It worked as a few of my targets clicked on the link in their email.

Step 2: Remote Control

Clicking the link in the phishing email automatically downloaded a software agent onto my targets’ machines.The software agents then “phoned home” to the command center (me) for further instructions.

ET Phone Homoe

I instructed the agents to log my target’s keystrokeswhich enabled me to collect passwords and access critical systems.  GAME OVER.

So what can your institution do?

First, patch the vulnerabilities in your network.

Second, implement anti-virus and spyware protection on your hosts.

Third, consider implementing intrusion detection and prevention systems on your network.

Fourth, educate your employees about phishing scams, and consider flagging messages from unknown senders. Most of us now know to avoid the obvious request for an unsecured international money transfer, but more sophisticated phishing scams may be harder to distinguish.

Tags: Security
Previous Post

The Hiring Forecasts of Small Firms: Will the Pace of Employment Growth Pick Up?

Next Post

Silicon Alley Takes a Run at Bank Innovation Prominence

Related Posts

a proxy browsing platform is used to keep a cybercriminal from gaining access
Risk & Security

‘Whack-a-mole’: Proxy browsers can protect FI networks from web-based attacks

September 4, 2026
Screengrab from DownDetector
Risk & Security

AI outages ripple through banking sector, raising resilience questions

September 3, 2026
a fake CAPTCHA being used to introduce malware to a victim's computer
Risk & Security

Stealthy browser attacks can put FI networks at risk

September 3, 2026
Next Post

Silicon Alley Takes a Run at Bank Innovation Prominence

Please login to join discussion

EMERGING FINTECH DIRECTORY

Emerging Fintech Directory

FinAi Podcast

SPONSORED

Build an Antifragile Strategy to Outperform the Market

July 14, 2026

How AI and Product Experts Turn Fuzzy Requirements Into Focused Dev-ready Roadmaps

April 19, 2026

Is Your Technology Supplier There for You?

April 1, 2026

  • About Us
  • Help Center
  • Contact Us
  • Privacy Terms
  • ADA Compliance
  • Advertise

Connect

twitter linkedin podcast podcast podcast podcast
© 2026 Royal Media
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Unlock This Article

Create your free FinAi News account to access this article and stay informed on how AI is transforming financial services including banking, lending, payments, and risk.

Yes, I'd like to receive FinAi News updates, breaking news, and exclusive AI insights for financial services leaders.

Continue Reading with FinAi News Premium - Less than $2/Day

Upgrade to FinAi News Premium for unlimited access to news, insights, trends, and intelligence on how AI is transforming financial services including banking, lending, payments, and risk.
Upgrade to FinAi News Premium Subscription
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account