• Home
  • News
  • Fortune 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Finance

A Cyber Gang Stole $1 Billion by Hacking Banks and ATMs. Now Police Say They’ve Caught the Mastermind

By
David Meyer
David Meyer
Down Arrow Button Icon
By
David Meyer
David Meyer
Down Arrow Button Icon
March 26, 2018, 7:43 AM ET

For the past five years, a gang of hackers known as Carbanak has been targeting banks around the world, stealing well over $1 billion in total. Now, thanks to a coordinated international investigation, the as-yet-unnamed leader of the gang has been caught in Spain.

According to the European Union Agency for Law Enforcement Cooperation (Europol), the gang targeted financial transfers and ATM networks from late 2013 by using a series of malware attacks called Anunak and Carbanak, before more recently adapting security-testing software called Cobalt Strike into heist-ready malware.

The malware was spread across networks by duping bank employees with “spear phishing” emails containing malicious attachments. It instructed ATMs to spew out money at pre-determined times, prompted the transfer of money into the gang’s accounts, and modified bank databases to inflate the balances of certain accounts.

“The criminal profits were also laundered via cryptocurrencies, by means of prepaid cards linked to the cryptocurrency wallets which were used to buy goods such as luxury cars and houses,” Europol said in a statement.

Europol said a host of organizations had been involved in the investigation, including the U.S. Federal Bureau of Investigation (FBI), the European Banking Federation (EBF), and the authorities in Spain, Romania, Belarus, and Taiwan.

“Public-private cooperation is essential when it comes to effectively fighting digital cross border crimes like the one that we are seeing here with the Carbanak gang,” said EBF chief Wim Mijs.

It doesn’t seem to be very clear how much money the Carbanak gang stole. It is now more than three years since the cybersecurity firm Kaspersky said the gang had stolen $1 billion. Europol said on Monday that the figure was “over €1 billion,” which equates to at least $1.24 billion.

Given that the gang’s sophisticated Cobalt malware campaign only began in 2016, it is “fair to say” that the total amount stolen must be significantly above €1 billion at this point, an EBF spokesman told Fortune.

About the Author
By David Meyer
LinkedIn icon
See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.