Crime bosses plot smarter fraud attacks on banks

More sophisticated cyber-skimming attacks on the way

By Steve Ranger, 18 October 2005 13:10

NEWS Banks have been warned to prepare for a new wave of more sophisticated fraud attacks from organised criminals.

Fraudsters will start developing more sophisticated attacks as they move on from simple phishing frauds, according to John Meakin, group head of information security at Standard Chartered Bank.

Speaking at the Financial Services IT Summit in London he said: "We don't have a monopoly on the security expertise - the thing about organised crime is that they have the money and the leverage.

"They pick off the easy stuff first and that means soft targets and simple mechanisms - and you can't get more simple than phishing."

And while banks are too difficult a target at the moment he added: "Looking into the future there is no question that in five years time they will be looking to keep up that revenue stream which means more sophisticated targets and technologies."

Last week Lloyds TSB revealed it is trialling token-based authentication for its online banking customers. Although last year UK banks lost a relatively small £12m to internet banking-related fraud, the fear is that as credit card anti-fraud plans are put in place, fraudsters may turn towards online banking.

Meakin warned that one area of threat is continuing vulnerabilities in browser technologies which make 'man-in-the-middle' attacks possible. This is where an attacker can interfere with the communications between the browser and a website to their own ends.

But Richard Hackworth, head of group IT security at HSBC Holdings, said some of the flaws in current software are being fixed by vendors who are more aware of security issues now. "A lot of the problems we have today are the result of weaknesses in the technology we buy. I believe we are seeing a determined push to remedy those weaknesses," he said.

Standard Chartered's Meakin added that one way to guard against attacks is increased monitoring. "You need to be monitoring so that you prevent [less obvious] damage," he said. "If you monitor, even if it's a new threat that we've never seen before we can see the affect its having on the network."

Comments

There are 3 comments. Join the discussion

  1. 1. Doug Trumpshaw

    Did anyone else think what a splendid name "Richard Hackworth" is for the head of group IT security at HSBC?

  2. 2. raz

    Then do what most people in IT do...don't touch internet banking with a barge pole! Gives them less excuse to close branches where you talk to 'real' people...

  3. 3. anonymous

    this is simple two-factor authentification with no more change.

    we must stop this bad tactics to win more money.

Post your comment

In order to post a comment you need to be registered and logged in.

Log in or create your silicon.com account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ