Imagine waking up to find โ‚น0.20 missing from your bank account. Most people would dismiss it as a rounding error or bank charge. But what if this tiny deduction was happening across thousands of accounts simultaneously? This is the essence of a salami attack-a cybercrime technique where attackers steal imperceptible amounts that accumulate into substantial illegal gains over time.

Table of Contents

What are salami attacks?

A salami attack is a cybercrime method where criminals steal small amounts of money from financial accounts one at a time. The name comes from the analogy of slicing salami thinly-each slice appears insignificant, but together they form a substantial portion. These attacks target banking systems, payroll platforms, and online subscription services where small amounts are stolen from each account over extended periods to avoid detection.

The attack operates on a simple principle: the alterations are so minimal that individual victims rarely notice. When an attacker withdraws โ‚น0.01 from each account, no single account holder will likely report the discrepancy. However, when replicated across lakhs of accounts, the stolen amount becomes substantial.

How salami attacks work

Salami attacks typically follow a methodical process. Cybercriminals first gain unauthorized access to financial databases containing customer information like bank account details. Once inside, they introduce automated programs that make tiny deductions from multiple accounts. The incremental nature of the theft makes it less likely to raise suspicion, as individual losses appear trivial enough to ignore.

These attacks often exploit rounding vulnerabilities in financial systems. For instance, when calculating interest or transaction fees, systems round amounts to the nearest paisa. Attackers manipulate these calculations to consistently round down, diverting the excess fractions into accounts they control. The crime is closely associated with net banking and electronic data interchange, where automated processes handle millions of transactions daily.

Types of salami attacks

Salami slicing

Salami slicing occurs when attackers obtain customer information from online databases and systematically deduct very small amounts from each account. The sums naturally add up to large amounts of money taken from joint accounts invisibly. Because the amounts are minimal, most people don’t report the deduction. This technique demonstrates how imperceptible individual thefts can accumulate into significant fraud.

Penny shaving

Penny shaving involves manipulating financial transactions through rounding to the nearest currency unit. Attackers modify transaction calculations so the changes remain so small that individual transactions go undetected. This method exploits the mathematical processes in banking systems, where fractions of currency units exist beyond the standard two or three decimal places used for monetary registers.

Real cases of salami attacks

In August 2013, Amit Kumar Bhowmik, a senior lawyer at Pune High Court, lost โ‚น180 after receiving three unsolicited calls from an unknown number. He discovered he was charged โ‚น60 for each call when checking his billing account online. Despite filing a complaint with the Cybercrime Division, authorities struggled to track the perpetrators due to privacy policies.

Another documented case involved Vinod Kumar Pacchiyappan, a manager at SBI Cards and Payment Services. He filed a complaint suspecting insider employees had stolen customer KYC data to create fake credit cards, resulting in losses of approximately โ‚น38 lakh. In the United States, Willis Robinson was imprisoned after reprogramming cash registers at his workplace to charge only one cent per item while pocketing the remaining amount per transaction.

In India, salami attacks fall under the purview of the Information Technology Act, 2000. Those found guilty of such attacks face punishment under Section 66 of the IT Act, which stipulates imprisonment for up to three years, a fine up to โ‚น5 lakh, or both. This section applies when any person dishonestly or fraudulently commits acts referred to in Section 43 of the same Act.

Section 43 addresses unauthorized access to computer systems, downloading data, introducing viruses, or causing damage to computer resources. The penalty can extend up to โ‚น1 crore for violations depending on the severity. These provisions demonstrate India’s commitment to addressing computer-related financial crimes through stringent legal frameworks.

Why salami attacks are difficult to detect

The primary challenge in detecting salami attacks lies in their design. Each individual transaction appears legitimate and falls below the threshold that would trigger automated fraud detection systems. Financial institutions handle millions of transactions daily, making manual verification impossible. The most effective way to identify a salami attack is checking each line of code through glass-box testing, an exhaustive process that ensures transparency.

Additionally, victims themselves contribute to the problem by not reporting small discrepancies. When account holders notice minor deductions, they often attribute them to service charges, rounding errors, or other legitimate fees. This collective inattention creates an environment where attackers can operate undetected for extended periods.

Prevention and protection measures

Organizations must implement comprehensive security measures to prevent salami attacks. Regular audits of financial systems help identify unusual patterns in transaction data. Installing robust security protocols and employing AI-driven anomaly detection systems can flag suspicious activities even when individual transactions appear normal.

For individuals, vigilance is key. Monitor bank statements weekly and scrutinize even the smallest deductions. Set up transaction alerts through banking apps to receive notifications for all account activities. Use strong, unique passwords and enable two-factor authentication on financial accounts. If you notice unexplained charges, report them immediately to your bank and file complaints with cybercrime authorities.

Financial institutions should regularly update their security systems and strengthen firewalls. Implementing real-time transaction monitoring and conducting periodic code reviews can help identify vulnerabilities before attackers exploit them. Employee training programs should emphasize recognizing and reporting suspicious system behaviors.

The importance of meticulous auditing

Salami attacks underscore the critical need for meticulous auditing in digital financial environments. Organizations handling large volumes of transactions must establish multiple layers of verification. This includes automated systems that analyze transaction patterns, regular manual reviews by security personnel, and external audits by independent cybersecurity firms.

The cumulative nature of these attacks means that even successful detection can occur too late. By the time patterns emerge, attackers may have already siphoned significant amounts. Therefore, preventive measures through robust auditing frameworks prove more effective than reactive responses. Organizations should implement continuous monitoring systems that track not just individual transactions but also aggregate patterns across accounts.

What do you think? Have you ever noticed unexplained small charges on your bank statement that you dismissed? How can financial institutions balance transaction processing efficiency with the level of scrutiny needed to detect salami attacks?

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://www.geeksforgeeks.org/ethical-hacking/what-is-salami-attack/
  2. https://codedamn.com/news/cyber-security/salami-attack-what-it-is-and-how-to-avoid-it
  3. https://www.shiksha.com/online-courses/articles/salami-attack-how-to-protect-against-it/
  4. https://ijirl.com/wp-content/uploads/2022/01/THE-ASPECTS-OF-PROBING-INTO-THE-ONLINE-FRAUD-OF-'SALAMI-SLICING-ATTACK.pdf
  5. https://www.linkedin.com/pulse/salami-attack-ajish-mathew-thomas
  6. https://cleartax.in/s/it-act-2000
  7. https://thelawgist.org/computer-related-offences/

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Regulation of Cyberspace

1 Domestic Laws- Backgrounder

  1. Challenges to Laws
  2. Information Technology Act 2000
  3. Critiques of the I.T. Act
  4. Proposed Amendments to the I.T. Act

2 Information Technology Act โ€“ Part-I

  1. Statement of Objects and Reasons
  2. Application of the Act โ€“ The Extra-Territorial Effect
  3. Digital Signatures
  4. E-governance

3 Information Technology Act โ€“ Part-II

  1. Adjudication (Chapter IX)
  2. Penalties and Offences (Chapter IX & XI)
  3. Network Service Provider Liability (Chapter XII)
  4. Amendments to Certain Statutes

4 International Treaties, Conventions and Protocols Concerning Cyberspace

  1. United Nations Commission on International Trade Law
  2. World Summit on Information Society
  3. United Nations Commission on Trade and Development
  4. Council of Europe
  5. World Trade Organization
  6. World Intellectual Property Organization

5 Guidelines Issued by Various Ministries

  1. Broadband Policy 2004
  2. .IN Internet Domain Name โ€“ Policy Framework
  3. Draft Policy Guidelines on Web-site Development Hosting and Maintenance
  4. New Telecom Policy 1999 (NTP 1999)
  5. Information Technology Security Guidelines
  6. SEBI Guidelines on Internet-based Trading and Services
  7. Guidelines for Setting up of International Gateways for Internet

6 Introduction to Computer Wrongs

  1. Computer Wrongs
  2. Classification of Computer Crimes
  3. Technology-neutral and Technology-based Laws
  4. Regulation Versus Freedom on the Internet
  5. Information Technology Act 2000
  6. Convention on Cyber Crime โ€“ Council of Europe

7 Conventional Crimes Through Computer

  1. Cyber Defamation
  2. Digital Forgery
  3. Cyber Pornography
  4. Cyber Stalking/Harassment
  5. Online Gambling
  6. Online Sale of Illegal Articles

8 Crimes and Torts Committed on a Computer Network and Relating to Electronic Mail

  1. Hacking/Unauthorized Access
  2. Denial of Service
  3. Crimes Relating to Electronic Mail: E-mail Spamming/E-mail Bombing
  4. Crimes Relating to Electronic Mail: E-mail Spoofing

9 Crimes Relating to Data Alteration/Destruction

  1. Internet Fraud and Financial Crimes
  2. Virus Worms Trojan Horses and Logic Bombs
  3. Theft of Internet Hours
  4. Salami Attacks
  5. Data Diddling
  6. Steganography

10 Issues of Jurisdiction and Applicable Law in Cyberspace

  1. Jurisdiction in Cyberspace
  2. Theories of Jurisdiction in Criminal Cases
  3. General Jurisdiction in Computer Crimes
  4. Application of โ€˜Effectsโ€™ Doctrine in Computer Crimes
  5. Convention on Cyber Crime โ€“ Council of Europe
  6. Applicable Law in Computer Crimes

11 Enforcement Issues in Cyberspace

  1. Prevention
  2. Detection of Crime
  3. Use of Cyber Forensics
  4. On-going Efforts in India

12 Online Dispute Resolution

  1. Internet Fraud and Financial Crimes
  2. Theories of Jurisdiction in Criminal Cases
  3. Prevention
  4. Online Dispute Resolution (ODR)