Forget computers, phone crime is worrying banks
- 24 April, 2009 04:58
- Comments
Computer fraud may be a big problem for banks today, but the telephone is becoming a critical tool for fraudsters, bank executives say.
In addition to calling customers about suspicious transactions, banks use SMS (Short Message Service) to request that customers contact them. So, fraudsters have begun using a variety of techniques to try to trick the banks into thinking they're communicating with legitimate customers via the telephone. "Call-center authentication is, to me, the biggest pain point right now," said Stan Szwalbenest, remote channel risk director with JP Morgan Chase, speaking at the RSA conference in San Francisco this week.
Malware, phishing and cyberattacks may get talked about, but "we should never fool ourselves into thinking that's the only place [crime is happening]," he said. "The biggest risks I see are social engineering, and that's exactly how the crooks are getting in."
Social-engineering attacks occur when fraudsters trick bank customers or employees into divulging sensitive information, usually by pretending to be someone they are not.
Sometimes fraudsters will hack into a bank account and change the customer's contact phone number. Then, when a suspicious transaction posts to the account, the bank will call the fraudster instead of the customer.
In cybercrime forums there's even a job title for people who do this: confirmer. "There are companies that specialize in it," said David Shroyer, senior vice president for online security and enrollment with Bank of America. Fraudsters will sell the services of people who have the language skills to mimic legitimate customers, offering, for example, four males and six females who speak English, one with a Spanish accent. "They say, 'We can match the phone number where your real customer is calling from,' " he said.
In another scam, criminals activate automatic call-forwarding features to essentially take over their victim's telephone lines for a period of time.
"They're adapting to our adoption of different technology and different authentication methods," Shroyer said.
Large banks like JP Morgan have been working with telecommunication companies to be able to identify spoofed calls, and with a recent rash of so-called swatting attacks, where hackers call 911 from spoofed numbers to trick police into sending out emergency response teams, the U.S. Federal Communicaions Commission has recently taken a greater interest in call spoofing, Szwalbenest said.
Criminals are also using low-cost, corporate-grade telephone systems to run their automated call centers. They will call, e-mail and send SMSes to victims telling them to call phoney numbers in hopes that victims will think they're calling a real bank and provide account numbers and passwords.
This technique has lately been labeled "vishing." But in reality it has been used by con artists for decades, Szwalbenest said. "It's social engineering. That's all it is," he said. "It's been around for a long time." Consumers should be suspicious of "every call," he said.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
The 30 best Safari extensions -- so far
-
Apple and Google disagree over licensing of essential patents
-
Monash Uni reduces IT teams after consolidation project
-
FTC warns makers of background checking apps
-
QLD govt demands answers after pay glitch
-
Lowering your IT Costs with Oracle Database 11g Release 2
This white paper identifies the key capabilities in Oracle Database 11g Release 2 that enable IT professionals to successfully deliver more information, with higher quality of service, and at much lower cost, than they have been able to do in the past. -
Chapter 2: Protecting Enterprise VoIP Services
The enterprise network is a complex system, and implementing VoIP brings a new level of complexity into the mix. In addition, security threats are real and many and assuring QoS delivery is a technical challenge. In deploying VoIP, you’re integrating voice technology with the critical data infrastructure. Building process and documentation controls into network operations provides the information about the corporate nervous system to manage a secure operating environment. You use this information to build a layered defense into the network. By gathering knowledge and applying it to defend the network in depth, you can deliver secure, reliable, available VoIP service across the enterprise. -
Book 2 - The Practical Guide to Securing Assets
Keeping your information technology (IT) systems and information secure in the face of constant changes in hardware, software, threats, and regulations can seem like an impossible task. You must constantly monitor and evaluate asset security controls effectiveness in addition to monitoring regulatory and contractual security requirement compliance. To be effective, you must implement IT controls in context with your entire organisation assets. Read on.
-
Windows 7 for Seniors for Dummies®
-
MYOB Software for Dummies 6E Australian Edition
-
Office 2007 All-In-One Desk Reference for Dummies
-
Microsoft Office
-
Windows 7 for Dummies® Dvd+book Bundle
-
Computers for Seniors for Dummies, 2nd Edition
-
Office 2007 for Dummies
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies®











Comments
Post new comment