Big Data. Big Decisions
InformationWeek
Special Coverage Series


PNC Bank Hit By Crowdsourced Hacktivist Attacks

Financial services website disrupted by DDoS attacks launched to protest anti-Muslim film, following similar attacks against Wells Fargo, U.S. Bank, and Bank of America.

After attacking the websites of Wells Fargo and U.S. Bank earlier this week, Muslim hacktivists Thursday also claimed credit for disrupting the PNC Financial Services Group website.

The attacks were carried out under the banner of "Operation Ababil," which last week disrupted the websites of Bank of America and JPMorgan Chase. This week's banking attacks--against Wells Fargo Tuesday, U.S. Bank Wednesday, and PNC Bank Thursday--had been previewed in a Pastebin post uploaded by a hacktivist group calling itself Cyber fighters of Izz ad-din Al qassam.

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

Likewise, a Thursday post to the Hilf-Ol-Fozoul blog--which has promoted Operation Ababil and shared links to distributed denial-of-service (DDoS) tools--credited the Cyber fighters of Izz ad-din Al qassam with having organized the recent banking website attacks.

[ Could an international agreement stop international cyber warfare? The Case For A Cyber Arms Treaty. ]

PNC didn't immediately respond to an emailed request for comment about the attacks. But PNC spokesman Fred Solomon told Threatpost Thursday that "traffic to our sites is heavy today and it's of a similar pattern to that seen by other banks of late."

The Cyber fighters of Izz ad-din Al qassam have said that the attacks against U.S. financial services websites are being launched in retaliation for the release of the Innocence of Muslims film that mocks the founder of Islam. A 14-minute clip of the film, uploaded to YouTube by its director, a man going by the name Sam Bacile, helped trigger numerous riots across the Middle East.

But former U.S. government officials, speaking anonymously, have accused the Iranian government of being behind the attacks against financial institutions, which they said began about a year ago. The Iranian government, however, has denied any involvement.

Meanwhile, Dmitri Alperovich, CTO of security firm CrowdStrike, doesn't think the attacks are just about protesting online, not least because the name of the group involved is the same as the military branch of Hamas. "I don't buy that their motivation is in response to the video; this group has been carrying out attacks for months," he told Threatpost. "Their motivation is to send a message that this is what they're capable of."

Regardless of whoever's organizing the financial website DDoS attacks, the campaign appears to be crowdsourced and receiving grassroots-level support, according to Atif Mushtaq, a security researcher at FireEye. "When I heard about this DDoS, the first things I wanted to find was the nature of the DDoS attack," said Mushtaq via email. "Like, is it being done using some botnet, or is it a community based action? If it is being done using some botnet, then who is operating this botnet--is it a simple 'pay for DDOS' scenario where attacker(s) rent a botnet to attack someone, or [have] attackers built their own botnet?"

According to Mushtaq, "it's most likely a community-based action, not a botnet," based in part on a September 18 post on the blog titled "Come and support Prophet Muhammed on the Internet," which urged to people to download attack tools--via included file-sharing websites--and use them to attack the Bank of America and New York Stock Exchange websites, in support of the Cyber fighters of Izz ad-din Al qassam. "They are asking people to download a RAR file containing an HTML file, and run it from their desktop," said Mushtaq. "From this point onwards DDoS will be handled by these scripts alone."

If protesting online is the goal of the attacks, what might convince the hacktivists involved to wrap up their campaign? A post to the Hilf-Ol-Fozoul blog called on U.S. authorities to "punish the cast and crew, the publisher included," of Innocence of Muslims film, at which time it said "this story will end."

The U.S. government has already been moving to distance itself from the film. Earlier this week, in an address to the United Nations General Assembly, President Barack Obama criticized the video as being "crude and disgusting" and reiterated that the U.S. government had no hand in creating it. "It is an insult not only to Muslims, but to America as well," he said, but noted that the film was likewise protected by U.S. law. "I know there are some who ask why don't we just ban such a video. The answer is enshrined in our laws. Our Constitution protects the right to practice free speech."

Thursday, however, the alleged filmmaker behind the Innocence of the Muslims was arrested in Los Angeles. Authorities have accused the man, Nakoula Basseley Nakoula, of violating the terms of his 2010 conviction for banking fraud. According to news reports, during his case law enforcement officials alleged that Nakoula had opened credit card and bank accounts using other people's names, written checks in other people's names, and then attempted to deposit those checks and withdraw the money.

After pleading guilty to a bank fraud charge, Nakoula served 21 months in prison, and was released in June 2011. But as part of his probation, he's barred from using a computer unless under supervision. Authorities said they suspect that Nakoula--a Christian who's originally from Egypt--said he was Sam Bacile when speaking with news media about the film.



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.

Follow InformationWeek

By The Numbers

What Are Your Primary Concerns About Using Big Data Software?

Base: 417 respondents at organizations using or planning to deploy data analytics, BI or statistical analysis software
Data: InformationWeek 2013 Analytics, Business Intelligence and Information Management Survey of 541 business technology professionals, October 2012

What Do You Think?

What's your attitude about SQL analysis on top of Hadoop?
We want fast, standard SQL analysis capabilities on Hadoop ASAP
Hadoop is for unstructured data; SQL is for relational databases
We'll give SQL on Hadoop a try, but relational DBs will remain the mainstay
Given strong SQL support on Hadoop, we'd nix the data warehouse
We're not interested in Hadoop
No opinion



Related Content

From Our Sponsor

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Business leaders often need a visual snapshot of data to quickly grasp and use it. This paper identifies five challenges in presenting data and how visual analytics can resolve them. Solutions are suggested to overcome the challenges of: speed, data clarity, data quality, displaying meaningful results, and dealing with outliers.

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Today's competitive advantage requires a deeper understanding of your business, your market and your customers. As an IT executive, you can drive that knowledge transformation. In this white paper, learn how to make decisions as a strategic business leader and three steps to begin an analytics initiative within your enterprise.

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

High-performance data visualization turns sophisticated analyses into meaningful graphics, leading to faster and smarter decision making. In this white paper, learn how visual analytics can transform big data, with additional features such as real-time functionality, mobile compatibility, robust applications for technical groups and accessibility for nontechnical users.

Big Data: Lessons from the Leaders

Big Data: Lessons from the Leaders

Financial performance, competitive advantage, operational efficiency, strategic decision making - every business goal can extract value from big data, and the time for doubt or inaction has long passed. In this Economist Intelligence Unit report, in-depth interviews with data pioneers reveal the link between the effective use of big data and the bottom line among other results.

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Which came first, the data or the decision? This white paper makes the case for having a decision in mind, then tailoring big data's volume, variety and velocity to achieve business results such as overcoming customer dissatisfaction or creating well-informed strategies in real time.

Informationweek Reports

Research: The Big Data Management Challenge

Research: The Big Data Management Challenge

The challenge of big data is real, but most organizations don't differentiate 'big data' from traditional data, and nearly 90% of respondents to our survey use conventional databases as the primary means of handling data. We'll help you understand what constitutes big data (it's not just size) and the numerous management challenges it poses.