Hacked files suggest US National Security Agency penetrated Swift, Mideast banks

Files released by the hacker Shadow Brokers appear to indicate that the US National Security Agency had infiltrated two of Swift's service bureaus. PHOTO: REUTERS

WASHINGTON (AFP) - Files released by the mysterious hacker Shadow Brokers suggested Friday (April 14) the US National Security Agency (NSA) had penetrated the Swift banking network and monitored a number of Middle East banks.

The files, according to computer security analysts, also showed the NSA had found and exploited numerous vulnerabilities in a range of Microsoft Windows products widely used on computers around the world.

Analysts generally accepted the files, which show someone exploiting so-called "zero-day" or hitherto unknown vulnerabilities in common software and hardware, came from the NSA.

They are believed stolen from a hyper-secret hacking unit dubbed the "Equation Group" at the key US signals intelligence agency.

"The tools and exploits released today have been specifically designed to target earlier versions of Windows operating system," said security specialist Pierluigi Paganini on the Security Affairs website.

They "suggest the NSA was targeting the Swift banking system of several banks around the world."

The files appear to indicate that the NSA had infiltrated two of Swift's service bureaus, including EastNets, which provides technology services in the Middle East for the Belgium-based Swift and for individual financial institutions.

Via that entry point the agency appears to have monitored transactions involving several banks and financial institutions in Kuwait, Dubai, Bahrain, Jordan, Yemen and Qatar.

In a statement on its website EastNets rejected the allegations.

"The reports of an alleged hacker-compromised EastNets Service Bureau network is totally false and unfounded," it said.

"We can confirm that no EastNets customer data has been compromised in any way." Swift said in a statement that the allegations involve only its service bureaus and not its own network.

"There is no impact on Swift's infrastructure or data, however we understand that communications between these service bureaus and their customers may previously have been accessed by unauthorized third parties."

"We have no evidence to suggest that there has ever been any unauthorised access to our network or messaging services."

Shadow Brokers first surfaced last year offering for sale a suite of hacking tools from the NSA. There were no takers at the price stated of tens of millions of dollars, and since then the hacker or hackers have leaked bits of the trove for free.

Analysts say many of the exploits revealed appear to be three years old or more, but have some unknown vulnerabilities that could still be used by other hackers.

No one has yet discovered the identity of Shadow Brokers, or of the hackers that gained access to the NSA materials.

Join ST's Telegram channel and get the latest breaking news delivered to you.