Somaliland

Dahabshiil Suffers Mysterious Hack Attack

July 22, 2012   ·   14 Comments

Dahabshiil Anonymous

Hargeisa (Somalilandpress) A group claiming to be the Hackactivists group Anonymous have breached Dahabshiil servers and compromised sensitive information. The group has published sensitive information online that includes balance statement of Dahbshiil, accounts information and identification of Dahabshiil clients. The Anonymous group is accusing the largest money transfer company in East Africa of having ties to terrorist organizations including Al-Qaeda and Al-Shabab.

In a press release, Dahabshiil has acknowledged the breach but denied that Anonymous is behind the hack. Dahabshiil did not say who is behind this operation. Also the bank denied any links to terrorism activities. In official email from the Dahabshiil, spokesperson stated, “Dahabshiil adheres to all industry standards in keeping confidential the details of its customers’ instructions and their unique transaction references. Furthermore, the company places the highest importance on its compliance procedures and has policies in place which are approved by the relevant authorities, including the FSA in the UK.”

Dahabshiil denied the breach two days, but in follow-up statement yesterday, the bank acknowledged the compromise. It is not clear the extent of the breach. But it looks the Bank has suffered a major blow. Anonymous has published account information of clients in different parts of the world. The leaked information includes database that contains account holders names, account numbers, phone numbers, addresses, email accounts and account balance. Somalilandpress is able to verify the authenticity of leaked information. Leaked accounts belong to Dahabshiil clients in Somaliland, Somalia, Djibouti and number of European countries. However, transactions and accounts activity seem limited between early 2000s to mid 2011. It is not clear when the hack took place. Anonymous claims that have had access to Dahahbiil’s server for months, but decided recently “to destroy them… and publish sensitive data” to proof to the Bank they have access to local files.

It is not clear why the group is targeting Dahbshiil, which the backbone of Somali economy as the country has not had a functioning government and central bank for more than two decades. Anonymous has accused Dahabshiil to have ties to international terrorism and extremism. The group announced on its tubmlr account that, “representatives of the movement Anonymous reported the establishment of a special group called “iWot” (as “Internet War On Terror”), whose activities will focus on the identification and publication of information about individuals, firms and organizations that are directly related to terrorism, strongly supporting it…We officially declare war on terror. This is a call to action to monitor and / or destruction of businesses and institutions that work with the terrorists, rogue states, etc.,”

It looks like Dahabshiil is the first target on their list. The only evidence the group showed of this allegation is a wikileak document in which a Somali detainee is convicted of facilitating finance of Al Qaeda activities using money transferred through Hawala systems before 911 attacks. Dahabshiil uses what is known as Hawala which is based on local banking customs. In Hawala money moves within framework of trusted agents and business owners. It is not confirmed if the terrorist suspect used Dahabshiil to transfer to Al Qaeda.

Currently the bank operators across the globe including in the United States, UK and many western countries, which have strict money transfer regulations. Because of the collapse of Somali government and its national institutions, Dahabshiil and other smaller money transfer companies have become the bloodline of many Somalis. Dahabshiil is also used by development, aid and security NGOs who depend on the bank speedy and reliable services especially in conflict zones like in Somalia. All international NGOs are not immune from this breach.

It is not clear why Anonymous will launch these attacks under pretense of “fighting terrorism.” Anonymous became famous during Arab Spring and the rise of wikileaks. It targeted large banks and government agencies in the United States after Wikileaks founder was jailed in London for rape allegation. It is not clear who leads this group and how they are organized their campaigns. What to adds to the mystery of this operation is usually Anonymous group has been champion of the “people” and against big companies. Dahabshiil is far from capitalist bank and its clients are poor working people who sent small remittance to sustain large population in countries like Somalia and South Sudan.

In addition to account information, the leaked information included statement balance of Dahabshiil operation, architecture of remittance database, and screen capture shots of database UI. It seems hackers have had complete access to all the network and database of the companies for sometime including emails. It is not clear how this hack is possible. Usually banks have sophisticated firewall and protection against attacks like this one. It appears Anonymous received internal cooperation from someone with access to important data or breached the system using what is known as “social engineering.” Social engineering is tricking staff of a company into performing actions or divulging confidential information. Typically, hacks disable access to portal or specific databases but don’t get complete remote access to whole network and personal terminals. The group claims they have destroyed “Gigs of data” and infected lots of documents with “cyber-bombs” waiting to explode in less than two months. What makes this leak worse is that the group published national identification of Dahabshiil clients. It includes citizens from Norway, Netherland, Finland, Somaliland, Yemen, etc. The release ID cards are for ordinary people from different parts of the world who are not terrorism suspects.

By

Tags:


Readers Comments (14)

  1. Kayse says:

    It is no mysterious nor does it have anything to do with terrorism. It is more of tribal anger more than terrorism. Everyone knows Dahabo is more liberal than many companies in Somalia and they work with many cross section societies of multi-faith.

    We all know certain groups used foreign groups to mislead them and convince them that Dahabo has links with terrorism which became all together.

    Dahabo is guilty of tribalism, greed and arrogance more than anything not to mention media abuse.

    It should back off from funding tribal wars, silencing media and responding to every little bird that twitts little anti-Dahabo messages.

    By far they are the most richest Somali company ever and congratulations to them, I personally am happy for them but they should stop interfering in Somali politics. We don't care what they do as long as they stop using weak Silaanyo and former terrorist member Hersi Gaab.

    Dahabo must cut ties with Hersi Gaab otherwise face more public anger.

    • Shiine says:

      Keyse caloosha ayaa ku xanuunaysa.
      Dahabo magac wannaagsan oo soomaali ah
      Weeye ragana looma bixiyo,
      Dahabshiilna wixii damiirleh dadnimadana garanayaa
      Way jecel yihiin waana loo og yahay wuxuu u Qabtay
      Ummadda soomaaliyeed,

  2. Aydid Somalilander says:

    We know, those who are behind this. They are those who were anti Somaliland and they have previously tried many tricks to make Somaliland and it's people look bad in the eyes of the world communities and failed. I am sure they will fail with this attack as well.

    My advice to Dahab shiil company, is to not stop until you find out who is behind this garbage and should be brought to full court of justice for black mailing. I am very sure that Dahab shiil has nothing to do with terrorist this criminals were accusing them of, if they were, the CIA and the British Spies would have destroyed its businesses long time ago just the way they did to AL-Barakat.
    I am sure Dahab Shiil and Somaliland government knows those behind this and they should be hunted and brought to their knees. They should report this black mailing to USA homeland security and the British government security agents. Whoever committed this crime did so to all Somali speaking people and they shouldn't get away with this.

    • Garmaqaate says:

      Don't be rude Aydid. Some people could be against Somaliland but its brutal to accuse Somalis of attacking Dahabshiil servers. To mind you, Dahabshiil is not a Somaliland based company anymore, it's an international agency and almost every Somali uses it in a way or another.

    • mohamed says:

      aydid.
      you must be another idoit,most somalis They don’t talk about somaliland cuz for Them it does not exist.

      secondly did know most of dahabshiil revenue come from rest of somalia. if They boycott dahabshill will collase over night.

      • mohamed says:

        corection…collapse.

  3. So sad to see what happened to Dahabshiil.. frankly that seems to me "Dahabshiil Bad buu Galay"… The question is even if Dahabshiil defends and survives from that cyber attack it wont from the rush withdrawals of customers…. though it is in the early stages but we will see what happens… I hope for the best for dahabshiil but they should anticipate the worst and prepare for it well..

    • Husein Haji says:

      salam alaykum . it can be managed walal .. they can do .. just add more cash on fire walls .. that is all ..

  4. Nasiir says:

    Somalilanders all over the world already know the culprit are Somalilandpress and Mooryan Kayse for the Dahabshiil Hackmailing.

    • muqtaar says:

      somali exists put lander.

  5. abcd nairobi says:

    Whatever happened to Dahabshiil system is just like a passing cloud, because this kind of problem can happen to any institution. For those customers whose information was printed in the media without their consent, this is not a crime because whatever little money they have saved with Dahbshiil Bank is not illegal and as such there is nothing to fear. The confidence that exist between Dahabshiil and their clients over many years can not be eroded by this minor issue. The company has come in the open to defend themselves and assuring their customers that everything is under control and that's enough. Through thick and thin Dahabshiil company operations will not be affected by this minor incident although the prophets of doom think they have achieved a credit . The rest is for the long arm of the law to take its place and sooner than later we shall hear of people being put behind bars for the crime that has taken place. Big International Companies like Dahabshiil who operate all over the World should expect this kind of problems and criticism to be part of their diet. Take an example of Micro- soft computer company how many times have they been affected by this kind of issues?

  6. Mohamd says:

    Dudes, I can confirm it had nothing to do with major hacking groups who are active and genuine. These people behind the hack against Dahabshiil were agents who abused the company's trust using IT knowledge to be vindictive against the company as the desperate attempts to paint it as a "middle eastern bank" and "terrorists".

    Sadly, they think they can use hacking as a form of "Isbaaro"/piracy when you read the warnings and even the deadlines they claim to give the company to "stop" its "support for terrorism".

    I checked this when it broke on day one, and I still stand by this. If Dahabshiil wants to avoid a similar breach of trust, they should vet their agents and make sure they provide them with fingerprint authentication rather than just user names..

  7. anonymous says:

    Dahabshiil needs to hire couple of digital forensic analyst to get to the bottom of this. The forensic specialists will be able to determine who did this, what user ID was used, where they connect from, what data was touched and what they did with it. The information they gather will determine if it was done by a highly skilled group like anonymous or if it was an internal job. I also advise dahabshiil to hire professional IT security staff that is separate than the regular IT department. Companies like Dahabshiil spend millions of dollars to secure their infrastructure. Alternatively, you can outsource your IT to companies that provide Managed Services. Although it is more beneficial to go with the first option, however, going with the second option is still better than having nothing in place.

    As the company grows, it is more affordable to build and implement a proper security policies, standards and specifications now than later. Having a good policies in place will make it possible to become in compliant with different regulatory requirements such as PCI, SOX…

    Abti, let me know if you need help with this.

  8. Leyla says:

    to even suggest 'Anonymous' was behind this so called attack is almost laughable! Anyone who worked for Dahabshiil knows he/she can steal few customer accounts statements and later publish. This is nothing more than a wake up call for Dahabshiil.


You must be logged in to post a comment.

More in Somaliland (619 of 1555 articles)
Brisbane, Australia