BankInfoSecurity.com - Information Security News, Regulations, & Education

Bank Information Security Articles

Fraudsters Take Aim At Mobile Banking

Credit
Eligible
As a BankInfoSecurity.com annual member, this content can be used toward your membership credits and transcript tracking. Click For More Info
New Phishing Schemes Target Mobile Customers with Bogus Apps
January 18, 2010 - Linda McGlasson, Managing Editor
Share

Comment on this article

Symptomatic of a new fraud trend targeting mobile banking, at least two banking institutions have posted messages on their websites, alerting members to be wary of a bogus application distributed on mobile phone platforms.

Bayport Credit Union of Newport News, VA, and First Technology Credit Union of Portland, OR, warned members about a mobile banking application that had appeared on the Android Marketplace, part of the Android mobile phone platform. Android is a subsidiary of Google. More than 50 fraudulent banking apps began appearing in the Android Marketplace in mid-December, industry experts say. The apps didn't contain malware, but instead attempted to get users to enter their passwords, account numbers or other personal information.

Google says it has removed the malicious applications, which targeted customers of Barclays Bank, Chase, Wells Fargo, Bank of America, Wachovia and Deutsche Bank, among others.

Todd Lindemann, AVP of Electronic and Card Services at Mountain America Credit Union, Salt Lake City, UT, says that the malicious applications first came to his attention when MShift, a vendor providing mobile phone banking services for the credit union, investigated reports of mobile phone banking applications being hosted on an application site for Droid phones. What was more troubling to Lindemann was that his credit union had just launched its own iPhone application in November. The alert that MShift sent to its customers in December states, "This phishing attack has been launched from the Android Marketplace and is impacting over 50 financial institutions worldwide, including those that currently do not offer mobile banking solutions, much less an Android download."

Click to Get Updates on the Latest Information Security News

MShift advised its clients to inform their customers of this potential phishing threat and "direct any of your customers that have downloaded this application from the Android Marketplace that the Android downloadable provided by Droid09 is NOT an authorized or legitimate downloadable application of your institution."

This attempt to grab bank account numbers and passwords by phishers highlights the security concerns of many institutions that both offer mobile banking to customers and rely on mobile phones, especially smart phones such as the iPhone and the Droid, to be connected to their staff.

Best Practices for Securing Mobile

Beyond phishing concerns, there are some best practices that cell phone users should keep in mind when using their phone, whether for business or for personal use. Simon Bransfield-Garth, CEO of Cellcrypt, a cell phone encryption company based in London, offers these tips for institutions and their customers:

  • Make No Assumptions - Never assume that voice calls are confidential (like fax or email), especially when calling internationally where some countries' phone operators have no encryption security in place at all. Check your signal, calls on 3G are more secure than 2G but often falls back to 2G when 3G is unavailable.

  • Ensure Physical Security - Keep your phone safe and do not leave it lying around. Skilled attackers can take just a few moments to install a malicious program, compromise the security of the SIM card or install a special battery with a bug in it, all of which can later be used to help intercept calls.

  • Protect PINs - Use and protect your phone and voicemail PINs in the same way as your bankcard PIN. Never leave confidential messages in voicemails or send confidential texts. Texts in particular are easy to read on the phone and mobile phone voicemails can often be accessed from any phone with the PIN.

  • Be Mindful of Malware - Be vigilant to prevent malicious software on your phone. Be wary of texts, system messages or events on your phone that you did not ask for, initiate or expect. Turn off Bluetooth if you are not using it.

  • Take Precautions - Consider installing antivirus/antimalware software. And if you strongly suspect your calls are being listened to, then turn off the phone when you don't need it and remove the battery as an extreme precaution. Also, use voice call encryption software on your phone to secure your sensitive calls that works worldwide and is as easy to use as making a normal phone call.

1 | 2


Next Related Article:


Question
Question
?What security threats have you brought to the attention of your mobile banking customers?
Here's your chance to be a part of the dialogue and engage with your peers! Just enter your comment to the right, click submit to send it to our Editor. All entries are posted anonymously.
Please login if you would like to post a comment on this question.

"The article points out that as mobile commerce increases it will become a tasty target for hackers. A key flaw to any mobile banking or mobile commerce platform is that they all are secure until they reach the device. Their security rests solely on a PIN or password, something that history has shown to be extremely weak security.
Security starts at the first step, and in this case financial institutions must use gateways that validate the user of a device is who they say they are, not simply someone who stole a purse that contained the mobile device and of course the written down PIN.