BankInfoSecurity.com - Banking Information Security News, Regulations, & Education
BankInfoSecurity.com Banking Information Security Careers Banking Information Security Training Banking Information Security Blogs

Username:
Password:
Remember Username?
Register | Help
Agency Releases
Articles
Handbooks
Podcasts
Webinars
White Papers

Take the 2010 Banking Information Security Today Survey

Results to be Unveiled at RSA Conference on March 2
Bank Information Security RSS Syndication Bank Information Security Articles

Credit
Eligible
As a BankInfoSecurity.com annual member, this content can be used toward your membership credits and transcript tracking. Click For More Info
FDIC Warns of Online Fraud Against Banks, Small Businesses
Alert Cites Increase in ACH, Wire Transfer Fraud
August 26, 2009 - Linda McGlasson, Managing Editor


Comment on this article

Online crime is increasingly hitting small and mid-size companies in the U.S., draining those entities' bank accounts through fraudulent transfers. The problem has gotten so bad that a financial services group recently sent out a warning about the trend, and the Federal Deposit Insurance Corporation (FDIC) issued an alert today.

"In the past six months, financial institutions, security companies, the media and law enforcement agencies are all reporting a significant increase in funds transfer fraud involving the exploitation of valid banking credentials belonging to small and medium sized businesses," says a bulletin sent on Aug. 21 to member financial institutions by the Financial Services Information Sharing and Analysis Center, (FS-ISAC). The FS-ISAC is part of the government-private industry umbrella working with the Department of Homeland Security and Treasury Department to share information about critical threats to the country's infrastructure. The member-only alert described the problem and told its members to implement many of the precautions and monitoring currently used to detect consumer bank and credit card fraud.

The FS-ISAC notice -- and subsequent media attention -- in turn prompted the FDIC alert to warn banking institutions about this kind of fraud.

The Threat
The FDIC traces the fraud to compromised login credentials on online banking websites. Over the past year, the FDIC says, it has detected an increase in the number of reports and the amount of losses resulting from unauthorized electronic fund transfers (EFTs), such as automated clearing house (ACH) and wire transfers.

Click to Get Updates on the Latest Information Security News

In most of the cases, the fraudulent fund transfers were made from business customers that had their online business banking software credentials stolen or compromised.

"Web-based commercial EFT origination applications are being targeted by malicious software, including Trojan horse programs, key loggers and other spoofing techniques," says the FDIC's alert. These malware are designed to circumvent online authentication methods. Illicitly-obtained credentials can be used to initiate fraudulent ACH transactions and wire transfers, as well as take over commercial accounts. These types of malicious code, or "crimeware," can infect business customers' computers when the customer is visiting a Web site or opening an e-mail attachment.

Some types of crimeware are difficult to detect because of how they are installed and because they can lie dormant until the targeted online banking session login is initiated. These attacks could result in monetary losses to financial institutions and their business customers if not detected quickly.

The FDIC recommends that institutions and technology service providers use regulatory guidance on authentication and information security for high-risk transactions.

The Trend
Security experts familiar with online attacks have long warned of these dangers to institutions and their customers. While the institutions and business customers are not necessarily large or high-profile, the money that is being drained by the criminals can add up to significant amounts. One recent example: Dwelling House Savings and Loan Association, Pittsburgh, PA. The tiny institution failed after an ACH fraud event siphoned off a whopping $3 million.

This fraud trend bears some of the same trademarks of larger breaches, namely the collaboration among overseas hackers and people within the U.S. Paul Kocher, chief research scientist at Cryptography Research Inc., says it's interesting that Albert Gonzales, the hacker indicted in the Heartland Payment Systems breach, was allegedly cooperating with Russian counterparts. "International cooperation within fraud rings has been a growing trend for a long time," says Kocher. "What I always find frustrating is that perpetrators of fraud are much better than victims or law enforcement at forging international working relationships."



Next Related Article:
NY Bank Suffers Online Breach


Question
Question
?How have you shared this alert with your own business customers?
Here's your chance to be heard by your peers in the banking and finance industry! Your comments will be kept anonymous. Just enter your comment to the right and click submit to send it to our Editor.
Please login if you would like to post a comment on this question.


Search for Articles
in

 More on this Topic:

  Recent   Popular   Research  



Blogs Related Blog Entries
Linda McGlassonSocial Networking's 17 Golden Rules
"The agency outlines a number of risks and threats associated with using social networking sites, and has come up with a list of 17 golden rules to follow when visiting or posting anything."



BankInfoSecurity.com is your one-stop portal for the latest news, insights and education on the top information security issues facing U.S. financial institutions today. Through articles, webinars, podcasts, customized training and sponsored content, our team is committed to providing up-to-date information on the security regulations, threats, solutions, training and career trends that most impact banks, credit unions and other related enterprises. Also, please check out our companion site, CUInfoSecurity.com.
Terms of Service | Advertise | Archive | Site Map | Contact | Bank Information Security RSS Syndication RSS Syndication
Copyright © 2010 BankInfoSecurity.com an ISMG Corp. company.