ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
ADVERTISEMENT
Home Compliance and Risk

Fighting the Rise in Ransomware Attacks: The Value of Breaking Through Silos

December 20, 2021
Reading Time: 5 mins read
Fighting the Rise in Ransomware Attacks: The Value of Breaking Through Silos
ADVERTISEMENT

By Matthew Van Buskirk

The shift to remote work has had many positive effects on the lives of many people around the world. Unfortunately, this is also true for the creators of ransomware.

ABA’s Ransomware Toolkit provides tips and useful intelligence to defend against an increasing threat. With information on how to respond if your bank is a target.
Global ransomware attacks for the first half of 2021 surged 47 percent over 2020, which was already a banner year for these type of attacks. Notably, this trend disproportionately impacted banks, experiencing a 1,318 percent increase in attacks. The FBI and the Cybersecurity and Infrastructure Security Agency expect things to only get worse through the holidays as the seasonal increase in shopping and festive mood create a mix of opportunity and relaxed defenses for bad actors to exploit.

The White House has taken notice, forming a task force earlier in the year with a mandate to develop a national ransomware strategy. Among the proposed measures, perhaps the most aggressive is a plan to disincentivize fraudsters by choking off profits through a ban on all ransomware payments.

While this measure raises understandable concerns for businesses faced with the possible loss of access to critical information and systems, it also demonstrates a significant shift in thinking in the government.

A classic silo problem

Too often, we think to block criminal activity by focusing on the methodologies criminals use. To stop ransomware, we need better cybersecurity practices; to stop illegal fishing, we need better monitoring of fishing vessels; to stop human trafficking, we need more surveillance of people crossing the border.

rightwards arrow
View more
risk and compliance articles

The current model makes sense on the surface, and we certainly need to continue doing all of these things. But, as things stand, we are missing half of the picture. The techniques and tools needed to police these crimes are entirely different; they fall under the purview of various agencies and require specialized skills. The only common element across these and most other types of crime is the motivation—the criminals are in it to make money.

All too often, the payoff is the easy part. According to the UN, we catch less than 1 percent of money laundering today. The act of committing the crime itself poses the most significant risk for criminals. Once they have the money, the odds are good that they will be able to clean it and use it. They consider occasional asset seizures as a mere cost of doing business.

There is a systemic disconnect between the law enforcement experts who understand how the criminals commit the predicate crime and the financial industry experts who understand how the money moves. In organizational terms, it’s a classic silo problem.

This anecdote is especially relevant: A law enforcement agent training district attorneys in using SARs in support of investigations noted that a surprising number of them were unaware of FinCEN’s capabilities or the wealth of information available from financial institutions that could help them with prosecution. Al Capone was indicted for tax evasion, not for his myriad other crimes. How many similar arrests could happen if these information silos didn’t exist?

Law enforcement agencies understand the nuances of catching criminals based on the unique characteristics of each crime, but are much less familiar with techniques to follow money flows to put a larger picture together. The financial services industry faces the opposite challenge—it can see all of the money flows, but it rarely has the context needed to help differentiate between innocent activity and international organized crime.

FinCEN is aware of this gap and is taking steps to address it. In October, FinCEN’s Acting Director Himamauli Das spoke to the need to enhance public-private partnerships, noting that combatting ransomware is a “shared effort.”

As I wrote here in January, the AMLA gave FinCEN a mandate to modernize. Eleven months later, FinCEN is still buried in tasks related to that mandate. With only 300 employees, FinCEN may have the most challenging ratio of work to be done to resources available to do the work of any regulatory agency.

Elevating new thinking

Over the past two years, the explosive growth in ransomware has helped shine a spotlight on the money motive in crime. The banking industry should do its utmost to elevate this conversation and support FinCEN in its efforts to adopt new thinking. Other than asking Congress to give them more money, what can we do? Here are three suggestions:

Reach out to support the creation of information feedback loops. A much more significant portion of the law enforcement community needs to understand what the financial industry can do to help. Likewise, the financial sector needs more context from law enforcement to understand the complete picture of what they are seeing. In a D.C. region fusion center meeting that I attended recently, a federal prosecutor spoke about creating a tip line that banks can use to help call attention to SARs warranting immediate attention. Consider reaching out to your local federal district attorney’s office and asking if they have something similar.

Leverage privacy-enhancing technologies to enable privacy-safe information sharing. Encryption techniques can facilitate AML collaboration in a way that complies with data security laws. There are many startups developing this technology out there, and the UK Financial Conduct Authority has hosted multiple “tech sprints” exploring how this technology can work and invited US agencies to attend. Keep your eyes open for regulators here in the US to make similar moves as the AMLA roll-out continues.

Develop approaches in accordance with the anti-money laundering act of 2020. This legislation specified many elements intended to promote collaboration between the financial industry and law enforcement. These include both traditional write-ups of evolving patterns and machine-interpretable information that can feed directly into monitoring systems.

Modern criminals are tech-savvy, agile, and motivated by money. They often work in syndicates and share information through their networks. There is no better way to fight them than by joining forces to choke off their profits.

Of course, it is also important to continually enhance your cyber security defenses. Thankfully, the ransomware surge triggered the creation of many new tools to combat the scourge. ABA’s ransomware toolkit and the Cybersecurity and Infrastructure Agency Stop Ransomware site are great places to start.

Matthew Van Buskirk is the co-founder and co-CEO of Hummingbird, a regtech company. He can be reached at [email protected].

Tags: Anti-money launderingRansomwareRisk management
ShareTweetPin

Related Posts

CFPB releases mortgage servicing proposal, overhauls loss mitigation framework

CFPB ends pandemic-related mortgage foreclosure relief

Compliance and Risk
May 16, 2025

The CFPB issued an interim final rule ending protections for mortgagors experiencing hardships due to the COVID-19 pandemic.

CFPB warns against certain terms in financial service contracts

CFPB withdraws proposed ban on certain contract language for financial products

Compliance and Risk
May 15, 2025

The CFPB has withdrawn a proposed rule to prohibit contractual provisions in agreements for consumer financial products or services that waive “substantive” consumer legal rights and protections.

CFPB urges states to ban ‘junk fees,’ revamp consumer protection laws

Agencies update host-state loan-to-deposit ratios

Compliance and Risk
May 12, 2025

The federal banking agencies issued updated host-state loan-to-deposit ratios that they will use to determine compliance with Section 109 of the Riegle-Neal Interstate Banking and Branching Efficiency Act.

U.S. Supreme Court rules CFPB’s funding structure is constitutional

With Trump signing repeal of CFPB overdraft rule, ABA to drop lawsuit

Compliance and Risk
May 9, 2025

President Trump has signed into law an ABA-championed resolution overturning the CFPB’s limits on overdraft fees.

CFPB claims ‘complex’ pricing drives up cost of financial products

CFPB rescinds dozens of guidance documents

Compliance and Risk
May 9, 2025

The CFPB announced it is rescinding dozens of guidance documents on topics such as fair lending, overdraft fees, disclosure policies and consumer information requests to large banks and credit unions.

Former NCUA chair named acting OCC head

OCC rolls back controversial bank merger review rule

Community Banking
May 8, 2025

OCC issued an interim final rule restoring its streamlined process for reviewing bank merger applications and rescinding other changes criticized by banks and lawmakers.

NEWSBYTES

ABA DataBank: Higher costs, less credit

May 16, 2025

Survey: Customer satisfaction with personal loans holds steady

May 16, 2025

CFPB ends pandemic-related mortgage foreclosure relief

May 16, 2025

SPONSORED CONTENT

Choosing the Right Account Opening Platform: 10 Key Considerations for Long-Term Success

Choosing the Right Account Opening Platform: 10 Key Considerations for Long-Term Success

April 25, 2025
Outsourcing: Getting to Go/No-Go

Outsourcing: Getting to Go/No-Go

April 5, 2025
Six Payments Trends Driving the Future of Transactions

Six Payments Trends Driving the Future of Transactions

March 15, 2025
AI for Banks: A Starter Guide for Community and Regional Institutions

AI for Banks: A Starter Guide for Community and Regional Institutions

March 1, 2025

PODCASTS

Podcast: Accelerating banking for quick-service restaurants

May 8, 2025

How a Georgia community bank supports government-guaranteed lending nationwide

May 1, 2025

Podcast: Quantum computing’s shakeup in payments, cybersecurity

April 24, 2025
ADVERTISEMENT

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2025 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2025 American Bankers Association. All rights reserved.