CSIDB logo
Incident

Affin Bank

Incident posture

Attack window
Oct 2014
Location
Malaysia
Status
Historical
CIA posture
Available to members
Updated
2026-01-18 02:09

Linked entities

Victim
Affin Bank
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2014
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Latin American criminal group compromised 17 ATMs across multiple Malaysian banks, including Affin Bank, by physically accessing the machines to install "ulssm.exe" malware via compact discs, forcing system reboots that enabled unauthorized cash withdrawals totaling over $1.2 million. Surveillance footage identified 2-3 perpetrators conducting sequential transactions, with authorities recovering one fraudulent ATM card and confirming no customer data breach due to the system reset. Investigations remain active under local law enforcement, who suspect the perpetrators are still within the country.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In October 2014, a Latin American criminal group executed a coordinated attack on 17 ATMs across multiple Malaysian banks, including Affin Bank, United Overseas Bank, Al Rajhi Bank, and Bank of Islam. The attackers physically accessed the ATMs by opening the top panels without keys and inserted a compact disc containing the "ulssm.exe" malware into the machines' processing centers. This action forced the ATMs to reboot to their default settings, bypassing security protocols. Gang members, captured on CCTV footage as 2-3 Latin American males, conducted successive cash withdrawals from the compromised machines. The theft resulted in losses exceeding $1.2 million. Police confirmed the malware manipulation enabled unauthorized access but noted the system reset prevented customer data exposure. Investigators recovered one ATM card used in the transactions, linking it directly to the perpetrators.

Malaysian law enforcement, including the Bukit Aman Commercial Crime Investigation Department led by Comm Datuk Mortadza Nazarene and Selangor Commercial Crime Investigation Department personnel, initiated an active investigation into the incident. Authorities determined the suspects remained in Malaysia based on forensic and surveillance evidence. The investigation focused on the malware's functionality, the gang's entry methods, and their operational timeline across the targeted bank branches. No arrests were disclosed at the time of reporting. Financial impacts were confined to the stolen cash, with no secondary compromise of bank systems or customer accounts reported. Police emphasized the physical breach of ATM hardware as the attack vector, distinguishing it from network-based intrusions.

Sources

Sources available to members: 1 source.

CSIDB