Overview
In a span of three hours, more than Rp 100 billion left a BI-FAST participant bank through a routine that looked legitimate to the national payment system.
DFI was appointed to investigate and reconstruct the perpetrators' movements. The weakness was not in BI-FAST itself, but in the bank-side systems connected to it. The reconstruction led to apprehension within weeks, making this one of the most significant payment fraud cases in Indonesia.
Attack chain
In 6 steps, reconstructed from forensic evidence.
Actor
TTP: how the attack worked
Mapped to MITRE ATT&CK for Enterprise, with tactical execution detail.
IoC: what to look for
Behavioural indicators that can be turned into monitoring rules. Match to system behaviours, not just static signatures.
Network connection hitting pattern threshold on non-facing bank IP connections.
A sudden spike in outgoing BI-FAST transfers outside normal settlement windows.
Many new beneficiary accounts appearing in the same short time frame.
Unscheduled access to the servers connecting the bank to BI-FAST.