48 comments

[ 3.3 ms ] story [ 106 ms ] thread
Sounds like Office Space.
More like Superman III.
It doesn't sound like either of those movies. They just shaved off dollar amounts less than 1 cent from millions of transactions. This guy just had the machines spit out extra money when he entered his ATM card.
Sounds like somebody has a case of the Mondays.
I think you have my stapler.....
Please, just stop.

I mean, I love quoting tangentially-related old movies too, I think it's totally the highest form of wit, but the url for fark.com is "fark.com".

"...some cash machine in Bumsville, Idaho spits out $700 into the middle of the street. I did that! That was me!"

"You did this from your house?"

"What are you, stoned or stupid? You hack a bank across state lines, you get nailed by the FBI!"

Man, I was JUST going to quote that. Well done.
Like father/BoA like son?
One would wonder if there were any code reviews in place or not? Any code that has monetary effects has to go through a series of code reviews (saying from my experience working with a client in banking industry) and tests. I would be curious as to how the 'bug' went undetected until deployment!
Any code that has monetary effects has to go through a series of code reviews

The article reported that he installed malware on select ATMs.

I acknowledge that this leaves a great deal to the imagination, but one suspects a code review would not catch the problem. The code was clean, the implementation on certain machines went awry.

In other words, he did some kind of internal hacking to install his code - illegally bypassing the code review process.
Maybe? I can only speculate that the hack wasn't in the code at all, but something he installed on the individual ATM.

"Oh, look: you can login to the ATM after installing the code. Hey what if I ..."

If so he didn't bypass the code review so much as skip around it, whistling a jaunty 'nope nothing illegal here' tune.

Ideally, any software that runs on the system would be digitally signed by the development shop, after their code review process. Otherwise anyone with direct physical access to the hardware (or to the distribution system for code updates) could add malware like this guy did.
People in charge of the BofA mortgage signature fraud should go to prison too.

http://www.cbsnews.com/8301-504803_162-20049744-10391709.htm...

But I guess it's a lot easier to prosecute people who can't afford expensive lawyers.

Also its more difficult to defraud people (or you know, legal entities with all of the same rights as people) who can afford expensive lawyers.
Prosecuting financial fraud is usually a great deal slower and more complex because it's more difficult to prove intent (compared to both incompetence and pursuit of legitimate profit), because it can involve so many more people (many of whom may not have been doing anything wrong at the individual level, but whose actions taken together were wrong at an institutional level), and because the rewards are more diffuse and indirect (unit profits lead to pay rises or career advancement for those involved, rather than bags of cash or deposits into secret accounts).

That's not to say that people can't or shouldn't be prosecuted, just that it's a more difficult undertaking. A recent example: http://www.housingwire.com/2011/04/19/ex-tbw-ceo-lee-farkas-...

Signing someone else's name at the behest of a department head is pretty clear fraud (and more obvious when it's 1000's of documents being signed with someone else's name and backdated). Watch the 60 Minutes segments.

Prosecutors don't want to take on the financial sector because it ruins their achievement record if they lose or it takes too long because the defendant can afford good lawyers. They stick to the people who cannot afford a defense.

No-one has been prosecuted for the financial crisis, I mean the economy was DESTROYED, we are years into it now.

> No-one has been prosecuted for the financial crisis, I mean the economy was DESTROYED, we are years into it now.

Why should they be proscecuted? We re-elected Barnie Frank.

I wonder how they'd have felt about it making phantom lines of credit instead. (Of course, with interest.)

"Oh, it's Programmer D! How's it goin', D? You want $1,000? OK! And since you don't have enough money just now, I'll just jot this down for you to pay back later."

And magically, when I deposit $5,000, it pays back a few hundred on my, er, his loan. :-)

Fine, more apropos- yeah, the guy was an idiot. I was going to pontificate on how one might actually pull this off, but there's always a problem: you're gonna make mistakes and eventually get caught.
Or, you won't and then no one will know how you did it.
If you don't mess up, nobody will know that you did it anything at all.

They don't seem to publish statistics on these things very often, but my gut tells me more people get away with crimes than don't.

On a related note: The Bank Of America ATMs are really, really great. Their ATMs and their online bill pay service are some great banking tech. They're the only reason I'm a BoA customer for my checking and cashflow accounts.

With their BillPay service, I can have BoA download e-bills from, say, credit card companies or utilities, and pay the amount of the bill on its due date. I never have to worry about it. I can set rules like "Pay my electric bill its full amount on its due date unless it's over $200" so I'm protected from crazy billing errors draining my account.

This guy was just a dumbass.

And yet they still use the Windows "ding" for everything, because of course there's no budget for sound design in an ATM project.

I hear those weirdly-out-of-place Windows sounds everywhere. It grates on me the same way Comic Sans grates on those who appreciate type.

Someone who does sound design could pick up this banner and impress everyone with set of free UI sounds that are classic and usable.

That is because those ATM's are running on top of embedded Windows. Mostly Embedded Windows XP.
Not only is it annoying but it broadcasts "You are using a Windows machine". Which to be also broadcasts "This machine is completely untrustworthy for financial purposes."

Oh, and a lot of them are Diebolds...

Which to be also broadcasts "This machine is completely untrustworthy for financial purposes."

Does it? I've never heard of anyone defrauding a BofA ATM except this guy. And this guy got caught.

Ha! The New Jersey Transit ticket kiosks at 8th street station in Philly make the same Windows ding noise. It sounds like a program is stuck on an error, and it's like a dog whistle to me.

That said, about your comment "Someone who does sound design could pick up this banner and impress everyone with set of free UI sounds that are classic and usable." -- I'm betting that's exactly what MS was trying to do. They commissioned Brian Eno to do the Windows 95 startup sound, and brought on Robert Fripp for Vista's startup sound (along with Tucker Martine and Steve Ball). Mind you, I'm not sure who's responsible for the various system sounds.

It's very easy to say "make classic, usable, impressive UI sounds" but incredibly difficult to actually do that.

Good point. I suppose the ubiquity of the sounds themselves helps to make them disconcerting.

Then again, maybe using Windows isn't a terribly positive association for some to have either.

Wow that is really some amateurish shilling. Almost all the major banks (e.g., Chase) offer the same bill paying functionality.
Says the guy who created an account 40 days ago?

I've got bank accounts a 4 other institutions: 2 credit unions (USAA and Alliant), and 2 regional banks (SunTrust and PNC).

None of them offer e-bill initiated payments.

I modded you down simply because I don't understand your tone.

I don't get his tone either, but do you know about USAA Web BillPay?
With their BillPay service, I can have BoA download e-bills from, say, credit card companies or utilities, and pay the amount of the bill on its due date. I never have to worry about it.

Really? I can't even figure out how to tell Bank of America to auto-pay my Bank of America credit card every month.

Yeah, first you have to go underneath the "Billpay" tab and add a "Pay To" account. After you do that, you'll get a little icon that displays if that account is eligible for E-Bills.

Once you request E-bills, you can setup an E-Bill Initiated Payment Plan.

Unless you're in Washington state like me. Then only about half of their total functionality works due to the antiquated system they still have in place.
I am one of these purgatory accounts in WA too. It's amazing to me, because their acquisition of Seafirst occured over 25 years ago. You'd think they could have sorted out the IT merger issues since then :P
How did he get caught?
That is a line from "Hackers" one of Angelina Jolie's first movies!
why was this modded down but hansy's comment wasn't
Regardless of whether that's also a line from a movie – and I did not recognize it as such – it's still a legitimate question. After reading the article, I too wondered exactly how he got caught. I can guess, but it'd be interesting to know.

In contrast, reflexively referencing a movie/celebrity isn't interesting.

Or he could actually be asking how he was caught.
I totally did not read Hansy's comment that way since it was posted in a weird place in the thread. I thought he/she was referring to line from "hackers"

Hansy, I apologize.

I'll laugh if it turns out he boasted about (indirectly) on HN. Unlikely, but not impossible - many criminals are undone by a burning desire for peer validation.
I'm just dying to know how exactly he did it and how they tracked him down. I've joked about this type of thing with friends, but it would be absolutely hilarious if he did something to the effect of putting his information within the malware which led cops right to his doorsteps. I have a feeling, this may be something at the level of a burglar leaving footprints in the snow right to his home... I mean, wouldn't they have locked him up and thrown away the keys if it were more of an Oceans 11 type plan & they had to chase him down spending tons of federal money? 400k & 27 months for what essentially is equivalent to bank robbery?
My guess is that when the money in the ATMs didn't reconcile.

It may be normal for a set of ATMs to be off by a few hundred a year, but anything higher than the norm would be enough to set off alarms.

After that, it just involves reviewing code checkins and camera footage.

Just a guess, though. Hell, maybe he used ATM card first before each "heist".

ATM fraud has a long and storied history. Kind of a must read for security types since some amount of 'loss' through the ATM network is planned for by the banks. At a surety conference hosted by First Data and SWIFT there was a lively discussion where everyone agreed that the old "tie a chain around it and take it with you" was the most difficult one to guard against. But at least it met the critical criteria of detection.

The serial numbers of every bill that goes into an ATM are recorded, the date they leave the ATM is also recorded, the serial numbers of every bill that enters a bank are recorded and their source. Cash is anonymous but it's life cycle is not.

Can anyone figure out where a year went here? He plead guilty in April 2010. Was he really just sentenced in May 2011?