Skip to main content

When the going gets tough …

Following posts (ATMmarketplace, realtime.ir and comForte Lounge, as well as commentaries to LinkedIn groups) on the $45 Million heist from ATMs, it is appropriate to wrap-up this story with input from a party directly involved …

It is rare that I am ever at a loss for words, especially after alighting from a car following a quick dash through the countryside. However, this past weekend, the Memorial Day long weekend, I participated in our club’s three-stage fun “rally” deep in Moab, Utah’s, surrounding national parks where I proceeded to head in the wrong direction. However, there was nothing wrong with what we saw as we traversed the landscape!

Margo and I were new to this club so when the instructions arrived, we saw there was incorrect information provided and confused as we were with what we saw, we pressed on regardless only to turn an easy, 53 plus mile segment, into a marathon 250 plus miles. I had to really drive hard to redeem some of my self-esteem so that I could face my fellow drivers later in the day.

On the other hand, I hadn’t given up electing to correct my error and to aggressively pursue making amends for my mistake. While this is easily said and done, when it comes to games, events of this past week highlighted the importance of taking similar actions in business. I have to believe almost everyone has heard by now that following the acquisition of Chrysler by FIAT among the very first decisions made by the new parent was to give the green light to the Chrysler division, SRT, for the development of a new Viper high performance car – a “halo product” for the reinvigorated manufacturer.

However,
when one magazine secured a new SRT Viper to test it on the famous Mazda Raceway Laguna Seca course in Monterey, California, its performance wasn’t quite up to the expectations, with the new SRT Viper failing to match the lap times of a previous generation Corvette ZR1. Ouch! How did the SRT CEO, Ralph Gilles respond? According to the magazine, Gilles response to the bad news was a showcase for what we should expect from our business leaders.

True, the initial response by Gilles was that GM and Corvette cheated, but then the magazine reported, “Here’s the important part. People like Ralph Gilles get where they are (president and CEO of SRT and vice president of Design for Chrysler) because when the going gets tough, they roll up their sleeves and do something”. A well-worn cliché for sure, but then the reporter went on to add, “In this case, Gilles pushed a new car out the gates in just nine weeks … Ralph tweeting (the magazine’s) editor-in-chief and me, ‘You forced me to build this!’”

Yes, this new Viper, what SRT now calls the Viper TA (Track Attack), was able to circulate Laguna Seca faster than the much-lauded Corvette ZR1. However, when it comes to IT, there have also been headlines of late that have drawn equally a hands-on response, and one that is worth recognizing.

Readers who check out my postings to other blogs would have been hard pressed to miss the column inches I have devoted to following up on the recent fraudulent raids perpetrated on the global ATM network. As I observed in my first post to comForte Lounge, Are you still sure you are secure?,  there was a global raid on ATMs with criminal gangs fraudulently pilfering $45 million in two separate attacks; the first on December 21, 2012, that netted $5 million, with the second on February 14, 2013, a much bigger attack, that netted an additional $40 million.

I devoted all of my most recent post to ATMmarketplace, Cruising to EMV eventuality? , to the same topic where I referenced a USA Today reporter who quoted Brooklyn U.S. Attorney, Loretta Lynch, as having said “
In the place of guns and masks, this cybercrime organization used laptops and the Internet. Moving as swiftly as data over the Internet, the organization worked its way from the computer systems of international corporations to the streets of New York City.”

Lastly, in the post to realtime.ir, We need to step up our monitoring – the crooks are getting smarter!, I referenced a May 9, 2013, article in the New York Times where the reporter said, “Beyond the sheer amount of money involved, law enforcement officials said, the thefts underscored the vulnerability of financial institutions around the world to clever criminals working to stay ahead of the latest technologies designed to thwart them.” What also came out in these reports were references to social media exploitation with the possibility that this was the first ever reported “crowd-sourced criminal attack” on a financial institution.  

These raids,
on the world’s ATMs, represented theft of an unparalleled nature. Caught up in the storyline, unfortunately, were our good friends at ElectraCard Systems (ECS), out of Pune, India. ECS were the payment processor supporting RAKBANK out of the United Arab Emirates where criminals helped themselves to $5 Million. Central to the theft were prepaid cards that criminals had manipulated to allow unlimited withdrawals – no matter how much cash was withdrawn from an ATM with these prepaid cards, there was always more cash available.

With ECS now very much in the headlines, I reached out to the ECS executives for further information. What impressed me, as I began a dialogue with ECS, is how quickly they have responded to news of their involvement. As soon as the second raid took place, this time on the Bank of Muscat, operating out of Oman, where $40 Million was stolen, ECS issued a press release. Yes, ECS had been involved in the first, smaller, attack and yes, ECS now knew how it was perpetrated and yes, ECS was working with agencies around the world even as ECS carried out a forensic exercise to determine the impact on card holders as well as users of ECS software. Furthermore, in accordance with agreements in place, ECS was pursuing recertification with the likes of VISA and MasterCard to ensure no further damage.

In an interview I had with ECS Senior VP, Madhu Gopinath, as the news was breaking, he told me “When it comes to open-loop prepaid cards, there’s a fine line between growing a marketplace, embracing new populations of users, and the risks involved.” Madhu then gave me the link to the ECS  press release on Sunday, where ECS had assured users that “the PIN and magnetic stripe data seem to have been compromised outside the ECS processing environment.”

I now fully understand how the attack succeeded, but as I have already told others, the fact that I do know doesn’t obligate me to share any of the details. For the NonStop community what I can talk about is that even as the ECS product, Electra, runs today on NonStop, on this occasion, ECS was supporting RAKBANK from an implementation running on Unix. Having said this, I have to also admit that I don’t think the choice of platform would have produced a different result – NonStop could have just as easily been compromised.

However, what really impressed me was how ECS CEO, Ramesh Mengawade, like SRT’s CEO, Gilles, moved quickly – calling in the authorities, issuing a press release, and giving commentators like myself immediate access to key executives, including Madhu. At no time did ECS tried to duck key questions or ignore any of my requests. On the contrary, Madhu was quick to assure me that, “
No other clients were impacted, and no end-customers or individuals were affected at all; some of our customers just use our software; there was absolutely no impact to them.”

It is easy to get lost, just as it’s easy to accept inaccurate information. When it comes to money, there will always be those within our society only too willing to try to steal it. However, when fraudulent activities on this scale are uncovered, it isn’t always easy to confront the marketplace. Particularly when you are obliged not to discuss specifics, even as criminal investigations remain on-going, and your ability to provide explanations may be limited.

With this in mind, it is refreshing to see just how forthcoming ECS has been, and I have to believe such willingness to be as transparent as they have been encourages others to do so in the future. Not all of us feel comfortable rolling up our sleeves even as the going gets tough, but on the other hand, isn’t that what we expect from all of our industry leaders?
 

Comments

Popular posts from this blog

If it’s June then it’s time for HPE Discover 2021.

  For the NonStop community there has always been an annual event that proved hard to resist; with changing times these events are virtual – but can we anticipate change down the road? Just recently Margo and I chose to return home via US Highway 129. It may not ring any bells, but for those who prefer to call it the Tail of the Dragon – 318 curves in 11 miles – it represents the epitome of mountain excitement. For Margo and me, having now driven the tail in both directions, driving hard through all these turns never gets old. Business took us to Florida for an extended week of meetings that were mostly conversations. Not everything went to plan and we didn’t get to see some folks, but just to have an opportunity to hit the road and meet in person certainly made the 4,500 miles excursion worthwhile. The mere fact that we made touring in a roadster work for us and we were comfortable in doing so, well, that was a real trick with a car better suited to day trips. This is all just a p

The folly that was Tandem Computers and the path that led me to NonStop ...

With the arrival of 2018 I am celebrating thirty years of association with NonStop and before that, Tandem Computers. And yes, a lot has changed but the fundamentals are still very much intact! The arrival of 2018 has a lot of meaning for me, but perhaps nothing more significant than my journey with Tandem and later NonStop can be traced all the way back to 1988 – yes, some thirty years ago. But I am getting a little ahead of myself and there is much to tell before that eventful year came around. And a lot was happening well before 1988. For nearly ten years I had really enjoyed working with Nixdorf Computers and before that, with The Computer Software Company (TCSC) out of Richmond Virginia. It was back in 1979 that I first heard about Nixdorf’s interests in acquiring TCSC which they eventually did and in so doing, thrust me headlong into a turbulent period where I was barely at home – flying to meetings after meetings in Europe and the US. All those years ago there was

An era ends!

I have just spent a couple of days back on the old Tandem Computers Cupertino campus. Staying at a nearby hotel, this offered me an opportunity to take an early morning walk around the streets once so densely populated with Tandem Computers buildings – and it was kind of sad to see so many of them empty. It was also a little amusing to see many of them now adorned with Apple tombstone markers and with the Apple logo splashed liberally around. The photo at the top of this posting is of Tandem Way – the exit off Tantau Avenue that leads to what was once Jimmy’s headquarters building. I looked for the Tandem flag flying from the flagpole – but that one has been absent for many years now. When I arrived at Tandem in late ’88 I have just missed the “Billion Dollar Party” but everyone continued to talk about it. There was hardly an employee on the campus not wearing the black sweatshirt given to everyone at the party. And it wasn’t too long before the obelisk, with every employee’s signature