Fool us Once, fool us twice Hacking Norwegian Banks

Per Thorsheim

DEF CON 32 Creator Stage · Day 1 · Creator Stage

Overview

In a revealing presentation at DEF CON 32, security expert Per Thorsheim, joined by Cecilia, exposed a critical vulnerability within Norway's highly digitized banking system. Their talk, "Fool us Once, fool us twice: Hacking Norwegian Banks using paper ID," delved into how a seemingly innocuous legacy process—the paper-based Power of Attorney (PoA)—could entirely bypass the sophisticated digital security mechanisms designed to protect customer accounts. The presentation highlighted a stark disconnect between robust online defenses and a glaring weakness in physical, human-centric processes, demonstrating how an attacker could gain full control over a bank account with minimal effort and forged documents.

Watch on YouTube

Visual summary for Fool us Once, fool us twice Hacking Norwegian Banks by Per Thorsheim
Visual summary for Fool us Once, fool us twice Hacking Norwegian Banks by Per Thorsheim

Key moments

  1. 0:00 Speakers' unique backgrounds and talk overview
  2. 2:00 Understanding abuseability and ethical hacking principles
  3. 3:00 Context: Norway's digital, transparent, trusting society
  4. 4:40 Explaining power of attorney vs. digital ID (Bank ID)
  5. 6:00 Identifying the critical paper form vulnerability
  6. 6:50 Banks' security measures are not always your security
  7. 7:30 How publicly available SSNs enabled the hack

Fool us Once, fool us twice Hacking Norwegian Banks

Speakers: Per Thorsheim

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=IIH4qR_X3Hs

Overview

In a revealing presentation at DEF CON 32, security expert Per Thorsheim, joined by Cecilia, exposed a critical vulnerability within Norway's highly digitized banking system. Their talk, "Fool us Once, fool us twice: Hacking Norwegian Banks using paper ID," delved into how a seemingly innocuous legacy process—the paper-based Power of Attorney (PoA)—could entirely bypass the sophisticated digital security mechanisms designed to protect customer accounts. The presentation highlighted a stark disconnect between robust online defenses and a glaring weakness in physical, human-centric processes, demonstrating how an attacker could gain full control over a bank account with minimal effort and forged documents.

The core of their research centered on the concept of abuseability, a term championed by Cecilia, which focuses on how software and systems can be maliciously exploited to cause personal harm, often by individuals with pre-existing relationships with the victim. This talk is not merely about financial fraud; it's a profound exploration into how system design, even in a high-trust society like Norway, can inadvertently create pathways for abuse. Thorsheim and Cecilia's work serves as a crucial reminder that security is only as strong as its weakest link, and often, that link lies where digital sophistication meets analog oversight.

The implications of their findings extend far beyond Norway, offering a cautionary tale for any organization that relies on a hybrid of digital and paper-based processes for sensitive operations. It underscores the necessity of applying the same rigorous security scrutiny to all interaction channels, regardless of their perceived modernity or historical context. For individuals, it's a stark warning about the limitations of institutional security and the importance of personal vigilance, even when dealing with trusted financial institutions.

Background

▶ Watch: Speakers' unique backgrounds and talk overview (0:00)

Norway stands out as one of the most digitally advanced and high-trust societies in the world. As Per Thorsheim noted, cash is virtually obsolete, most interactions with government, healthcare, insurance, and banking are conducted online, and the average Norwegian hasn't used a physical pen in years. This digital reliance is underpinned by BankID, a national digital identity system that serves as a legally binding form of identification, equivalent to a physical signature. Banks explicitly advise users never to share their BankID credentials, instead promoting the use of Power of Attorney (PoA) for granting others access to finances. This advice aims to protect users while facilitating legitimate financial delegation.

The problem, however, stems from the necessity of accommodating individuals who cannot access or use BankID. This includes new arrivals to Norway, such as Ukrainian refugees, who lack a credit history and thus cannot immediately obtain a BankID. It also encompasses disabled individuals or those under legal guardianship, for whom a BankID might be inappropriate due to the potential for misuse. For these specific demographics, Norwegian banks maintain a paper-based Power of Attorney form. This form, intended as an inclusive alternative, became the Achilles' heel of the entire system.

The speakers, driven by Cecilia's "abuseability" perspective—asking how software could be used to "mess up someone's life"—and Per's extensive background in information security, decided to investigate this paper process. Per, having previously served as a CISO for BankID, possessed intimate knowledge of the digital identity system's robust security. Their hypothesis was that while digital banking was heavily secured, the legacy paper system might present an overlooked vulnerability. This investigation was conducted under the principles of responsible disclosure, ensuring that any identified vulnerabilities were addressed with the banks before public disclosure, aiming to fix problems rather than create recipes for malicious actors.

Key Findings

▶ Watch: Context: Norway's digital, transparent, trusting society (3:00)

The central discovery of Thorsheim and Cecilia's research was the profound vulnerability embedded within the paper-based Power of Attorney (PoA) system used by Norwegian banks. Despite Norway's hyper-digital environment and the robust security surrounding its BankID digital identity, the analog PoA process proved startlingly easy to exploit, allowing for comprehensive account takeover with minimal effort.

Their initial finding, demonstrated through a proof of concept with a major Norwegian bank, revealed that obtaining a victim's name, address, social security number, and bank account number was sufficient to forge a PoA. Per noted that social security numbers in Norway, while often treated as secrets, are "absolutely not secrets" and are predictable. Services even existed to verify these numbers, unbeknownst to the service providers themselves. With this information, Cecilia was able to forge the necessary signatures – those of the account owner, the designated PoA holder (herself), and two witnesses – on a paper form. Upon submission, this forged document granted her full, "all or nothing" access to Per's bank account. This access included viewing 10 years of bank statements, controlling joint finances, and the ability to move money, for example, to foreign accounts in places like Aruba. Notably, it did not grant the ability to pay bills, a peculiar limitation that didn't diminish the severity of the overall access.

A critical aspect of this initial finding was the complete lack of transparency for the account owner. All transactions initiated by Cecilia via the PoA appeared on Per's statements as if he had conducted them. Furthermore, Per received no notification that a Power of Attorney had been granted on his account. This created an insidious scenario where a victim would be entirely unaware of the compromise, potentially leading to self-doubt and "gaslighting" when encountering unexpected transactions ("Did I buy that online? Is this early dementia?"). When confronted, the bank's initial response was dismissive: "if you trust that person, that's your problem, not ours."

Following responsible disclosure, the speakers tested a second bank to assess improvements. While some progress was observed – specifically, transactions carried out by Cecilia were now correctly attributed to her name on Per's account statements – the fundamental flaws persisted. The PoA still granted "all or nothing" access, and crucially, the account owner still received no notification when a PoA was established. This meant that while detection of transactions became marginally easier, the initial compromise of granting PoA remained silent and covert. The overarching conclusion was that protecting oneself from this type of fraud or abuse, especially from a trusted individual, was "pretty much impossible" due to the lack of notification and the difficulty in discerning legitimate from fraudulent activity.

Technical Deep Dive

▶ Watch: Explaining power of attorney vs. digital ID (Bank ID) (4:40)

The technical vulnerability uncovered by Thorsheim and Cecilia was not a flaw in sophisticated cryptographic protocols or complex network architectures, but rather a profound weakness in the human element and legacy analog processes interfacing with a highly digital system. The attack vector was the paper-based Power of Attorney (PoA) form, designed to provide an alternative for individuals unable to use Norway's secure digital identity, BankID.

The exploit leveraged the relative ease of information gathering in a transparent society like Norway. To complete the paper PoA form, an attacker required:

  1. Victim's Name and Address: Readily available through public records, such as phone books.
  2. Victim's Social Security Number: Per Thorsheim explicitly stated these are "not secrets," are predictable, and could even be verified using online services that were unaware of their own security implications.
  3. Victim's Bank Account Number: Implied to be obtainable through various means, though the talk didn't detail specific methods for this.

With these pieces of information, the attacker (Cecilia, in their proof of concept) proceeded to forge signatures. The paper form required signatures from the account owner (Per), the individual being granted PoA (Cecilia), and two witnesses. The core of the technical bypass lay in the banks' apparent reliance on superficial verification of these paper documents. There was no robust system in place to authenticate the account owner's consent or the authenticity of the signatures. This meant that all the advanced digital security measures, multi-factor authentication, and identity verification associated with BankID were completely circumvented by the simple act of submitting a forged paper form.

Upon successful submission and processing by the bank, the forged PoA granted "all or nothing" access to the victim's bank account. This was a critical design flaw, as there was no granular control over permissions. The PoA holder could:

  • View up to 10 years of bank statements, providing a detailed financial history.
  • Access and control joint finances.
  • Move funds between accounts, including transferring money to international accounts (e.g., Aruba).

Crucially, the PoA holder could not pay bills from the account, a specific limitation that, while odd, did not prevent significant financial harm.

The most insidious technical flaw related to detection and attribution:

  • First Bank (before disclosure): Transactions made by the PoA holder appeared in the account owner's statement as if performed by the owner themselves. This complete lack of proper attribution made it virtually impossible for the victim to detect fraudulent activity without extreme vigilance and suspicion. Furthermore, the account owner received no notification that a Power of Attorney had been granted on their account. This silent compromise was a major contributor to the "abuseability" aspect, as it facilitated covert financial abuse.
  • Second Bank (after responsible disclosure): Following the initial disclosure, the second bank had made a partial improvement. Transactions performed by the PoA holder were now correctly attributed to the PoA holder's name on the account statements. While this was an improvement, making detection slightly easier, the fundamental problem of no notification upon the establishment of a PoA persisted. An account owner would still be unaware that someone else had been granted access until they meticulously reviewed their statements and noticed unfamiliar names associated with transactions.

In essence, the technical deep dive reveals a classic case of a security boundary mismatch. The digital boundary was robust, but the interface to the physical world, relying on trust and outdated verification methods, created a gaping hole. The banks' internal processes for handling paper forms failed to incorporate the same level of scrutiny and verification applied to their digital channels, leading to a profound vulnerability that leveraged social engineering and forgery to bypass an otherwise secure system.

Demo / Proof of Concept

▶ Watch: Banks' security measures are not always your security (6:50)

The core of Thorsheim and Cecilia's presentation was a compelling, real-world demonstration of the vulnerability through a direct proof of concept. This was not a simulated attack but an actual exploitation of the banking system.

Cecilia, acting as the attacker, successfully obtained a Power of Attorney over Per Thorsheim's personal bank account by submitting a forged paper form. This involved:

  1. Information Gathering: Acquiring Per's name, address, social security number, and bank account number.
  2. Forgery: Filling out the official paper PoA form provided by a Norwegian bank and forging the required signatures: Per's signature as the account owner, Cecilia's signature as the designated PoA holder, and the signatures of two witnesses.
  3. Submission: Submitting the completed, forged paper form to the bank.

Upon processing by the bank, Cecilia was granted full access to Per's account. This demonstrated unequivocally that the paper-based system, despite the highly digitized nature of Norwegian banking, lacked adequate verification mechanisms to prevent such an attack. The success of this initial PoC highlighted the severe security gap.

Following this successful exploit and subsequent responsible disclosure to the first bank, the speakers performed a second proof of concept with another Norwegian bank. This was done to assess if other institutions had similar vulnerabilities or if any improvements had been made across the industry after their findings were shared. While the second bank had implemented a minor improvement – transactions made by the PoA holder were now correctly attributed to the PoA holder's name on the account statements – the fundamental issue of easy forging and lack of notification to the account owner remained. This second demonstration underscored that the problem was systemic, not isolated to a single institution, and that the core vulnerability persisted despite partial fixes.

The real-world nature of these demonstrations made the findings particularly impactful, illustrating the practical feasibility and the significant risk posed by this overlooked attack vector.

Defensive Implications

▶ Watch: How publicly available SSNs enabled the hack (7:30)

The findings from "Fool us Once, fool us twice" carry significant defensive implications for both financial institutions and individual account holders, particularly in digitally advanced societies.

For Financial Institutions and Organizations:

  1. Holistic Security Review for All Channels: Banks must extend the same rigorous security scrutiny, threat modeling, and abuseability analysis to all legacy, paper-based, or manual processes as they do to their digital systems. Any process that can alter account permissions or access must be treated as a critical security boundary.
  2. Robust Verification for Critical Changes: Implement strong, multi-factor verification for any action that grants third-party access to an account, regardless of the submission method. For paper-based Power of Attorney forms, this could involve:
  • Out-of-band verification: Contacting the account owner via a registered, secure channel (e.g., BankID login, registered phone number, secure email) to confirm consent.
  • In-person verification: Requiring the account owner to present valid, strong identification (passport, national ID) at a branch.
  • Biometric authentication: If applicable, using biometric data for verification.
  1. Mandatory and Immediate Notifications: Account holders must receive immediate, explicit notifications through multiple secure channels (e.g., SMS, email, in-app alert, physical mail) whenever a Power of Attorney is granted or modified on their account. This notification should include details of the access granted and clear instructions on how to revoke it if unauthorized.
  2. Granular Access Controls: Move away from "all or nothing" access for Power of Attorney. Implement granular permission structures that allow account owners to specify precisely what actions a PoA holder can perform (e.g., view only, specific transaction limits, payments to pre-approved recipients).
  3. Enhanced Attribution and Logging: Ensure that all transactions and account modifications are accurately attributed to the specific user who initiated them, whether it's the primary account holder or a PoA holder. This is crucial for forensic analysis and for enabling account holders to detect suspicious activity.
  4. Employee Training and Awareness: Train staff who process paper forms to recognize potential signs of fraud, understand the implications of granting access, and follow stringent verification protocols.
  5. Regular Audits of Legacy Systems: Conduct periodic audits of all non-digital processes and their integration points with digital systems to identify and mitigate vulnerabilities that might be overlooked in the focus on digital security.

For Individuals:

  1. Be Skeptical of Trust: Even in high-trust societies, individuals must remain vigilant. Recognize that bank security measures primarily protect the bank, and your interests, particularly in cases of personal abuse, might not always align perfectly with theirs.
  2. Diversify Financial Holdings: If you must grant Power of Attorney or share access to an account, consider spreading your funds across multiple accounts or even different banks. This limits the potential financial damage if one account is compromised.
  3. Utilize Dedicated Accounts: Instead of granting access to your primary banking account, create a separate, dedicated account with limited funds for shared purposes or for the PoA holder to manage.
  4. Monitor Your Accounts Diligently: Regularly review all bank statements and transaction histories. Be suspicious of any unfamiliar transactions, even if they appear to be attributed to you. If your bank offers transaction alerts, enable them.
  5. Understand Your Bank's Security Policies: Familiarize yourself with how your bank handles Power of Attorney and other critical account changes. Ask specific questions about notification procedures and verification steps.
  6. Protect Personal Information: While some information (like name/address) might be public, be mindful of sharing your social security number, bank account numbers, and other sensitive details that could be used for forgery.

By addressing these defensive implications, both institutions and individuals can significantly reduce the risk posed by the often-overlooked vulnerabilities in legacy systems and human-centric processes.

Key Takeaways

  • Legacy Processes Undermine Digital Security: Even in highly advanced digital societies, outdated paper-based or manual processes can bypass sophisticated digital security measures, creating critical vulnerabilities.
  • Abuseability is a Critical Threat Model: Security analysis must extend beyond traditional fraud to include "abuseability"—how systems can be exploited by individuals (e.g., ex-spouses, stalkers) to cause personal harm, often leveraging existing trust or relationships.
  • Verification Must Be Robust Across All Channels: Reliance on superficial verification methods, such as easily forged signatures on paper forms, is a profound security weakness that can lead to complete account compromise.
  • Mandatory Notifications for Account Changes: Banks must implement immediate, multi-channel notifications to account holders for any significant account changes, especially those granting third-party access like Power of Attorney, to enable timely detection of unauthorized activity.
  • Granular Access Controls are Essential: "All or nothing" access for Power of Attorney is inherently risky. Systems should provide granular permissions, allowing account owners to precisely define and limit the actions a PoA holder can perform.
  • Individual Vigilance Remains Paramount: Account holders should take proactive measures, such as spreading finances across multiple accounts or using dedicated accounts for shared access, as bank security priorities may not always fully protect individuals against specific forms of abuse.

About the Speaker(s)

Per Thorsheim is a seasoned information security expert from Norway, with a distinguished career spanning 30 years in the field. He possesses a "healthy obsession" with passwords and has held significant roles, including CISO positions for major Norwegian corporations (which he notes would be considered small by US standards). His deep expertise extends to Norway's national digital identity system, BankID, where he previously served as a CISO, providing him with an intimate understanding of its architecture and security mechanisms.

Cecilia brings a unique, multidisciplinary perspective to information security. With a background in psychology and a master's degree in the philosophy of technology, she transitioned into security after years as a software tester. Her approach is characterized by a focus on "abuseability"—a concept she champions, which involves actively questioning how software and systems can be misused to "mess up someone's life." Cecilia emphasizes her love for humans and her motivation to identify and fix these potential pathways for harm, rather than to exploit them maliciously.

All talks from DEF CON 32 Creator Stage