Jump to content

Internet Banking


Neutrino
 Share

Recommended Posts

50 smartphone users in Singapore hit by malware targeting mobile banking customers
The malware disguised itself as an operating system update or an update for messaging app WhatsApp to trick customers into entering their credit card information, says the Association of Banks in Singapore.

 

for details:

http://www.channelnewsasia.com/news/singapore/50-android-users-in/2308976.html

↡ Advertisement
  • Praise 5
Link to post
Share on other sites

Be warned, don't anyhow click a link.

 

 

http://www.straitstimes.com/tech/mobile-banking-users-lose-thousands-of-dollars-to-hackers

 

Mobile banking users in Singapore have lost thousands of dollars after they fell victim to malicious software targeting Android smartphones.
 

The Association of Banks in Singapore (ABS) yesterday issued a warning against the malicious program, hidden in a pop-up window that prompts users to update their software.

 

Some 50 mobile customers of major retail banks here reported losses of up to "several thousand dollars" after clicking on the dubious link, prompting ABS to issue the warning.

 

"ABS would like to remind mobile banking customers that smartphones are as susceptible to malware as desktop computers or laptops," said Mrs Ong-Ang Ai Boon, director of ABS.

 

"Now, criminals have turned to targeting Android phone users... as banks are pushing out more banking apps for user convenience."

 

The dubious pop-up window is believed to have appeared after mobile phone users visited websites infected with malware.

It prompts unsuspecting users to click on an embedded link to update their WhatsApp messaging software or battery management module.

 

People who clicked on the link were asked to enter their credit card details to complete the software upgrade. After doing so, users were greeted with the Android green robot logo with the message: "System update in progress..."

 

It is at this point that cyber criminals take control of the phone, using the credit card details entered and one-time passwords received via SMS for making fraudulent online transactions.

 

Some users have lost several thousand dollars from online transactions which appear to originate in Eastern Europe, according to Mrs Ong-Ang. Items purchased include airline tickets.

 

ST_20151202_ITBANK02_1882239.jpg?itok=Ai

  • Praise 3
Link to post
Share on other sites

Just go to official bank website to make online banking transactions....

for online shopping, just be cautious ...

 

With advanced tech, the experts are creating even higher tech malware .... sometimes, just wonder if queuing up at banks is still better than click at smart phone ....

  • Praise 8
Link to post
Share on other sites

Just go to official bank website to make online banking transactions....

for online shopping, just be cautious ...

 

With advanced tech, the experts are creating even higher tech malware .... sometimes, just wonder if queuing up at banks is still better than click at smart phone ....

My former IT Head doesn't want to have anything to do with internet banking. Queues up at the banks and we laugh at him saying he so old fashioned and being IT saavy some more!!

 

He just laughed it off and said don't come crying when you wake up one morning to find your funds all gone [sweatdrop]  

  • Praise 11
Link to post
Share on other sites

On a related note, it should be common knowledge that many functions one would use regularly can now be relegated to a simple SMS token rather than having to use the dedicated bank provided token. Only specialised functions require that token still.

 

There are Android apps (and I presume iPhone apps as well) that allow the display of message text on a locked phone. An example is Textra (which is a wonderful SMS app, by the way). So even though my phone has a fingerprint scanner, etc., when the bank sends an OTP through, it can be immediately seen on the locked screen. I always viewed this as a great convenience, but now I'm wondering if it's a liability and whether I should turn off the feature.

 

Granted, if someone does steal my phone (and somehow my other login details), they wouldn't be able to do too much damage. While they can look at my account info and transfer funds to payees already in the system, they can't create any new payee without the token.

 

What do you guys think?

Edited by Turboflat4
  • Praise 2
Link to post
Share on other sites

On a related note, it should be common knowledge that many functions one would use regularly can now be relegated to a simple SMS token rather than having to use the dedicated bank provided token. Only specialised functions require that token still.

 

There are Android apps (and I presume iPhone apps as well) that allow the display of message text on a locked phone. An example is Textra (which is a wonderful SMS app, by the way). So even though my phone has a fingerprint scanner, etc., when the bank sends an OTP through, it can be immediately seen on the locked screen. I always viewed this as a great convenience, but now I'm wondering if it's a liability and whether I should turn off the feature.

 

Granted, if someone does steal my phone (and somehow my other login details), they wouldn't be able to do too much damage. While they can look at my account info and transfer funds to payees already in the system, they can't create any new payee without the token.

 

What do you guys think?

 

What if it is an existing payee who takes your phone?

  • Praise 1
Link to post
Share on other sites

On a related note, it should be common knowledge that many functions one would use regularly can now be relegated to a simple SMS token rather than having to use the dedicated bank provided token. Only specialised functions require that token still.

 

There are Android apps (and I presume iPhone apps as well) that allow the display of message text on a locked phone. An example is Textra (which is a wonderful SMS app, by the way). So even though my phone has a fingerprint scanner, etc., when the bank sends an OTP through, it can be immediately seen on the locked screen. I always viewed this as a great convenience, but now I'm wondering if it's a liability and whether I should turn off the feature.

 

Granted, if someone does steal my phone (and somehow my other login details), they wouldn't be able to do too much damage. While they can look at my account info and transfer funds to payees already in the system, they can't create any new payee without the token.

 

What do you guys think?

 

Most of the time banking is secured. The only vulnerability is often the user. That is something nobody can fix.

  • Praise 5
Link to post
Share on other sites

What if it is an existing payee who takes your phone?

I considered that. But I prune the payee list regularly for that reason. The only ones on it long term are ones I trust implicitly (generally family).

Link to post
Share on other sites

Most of the time banking is secured. The only vulnerability is often the user. That is something nobody can fix.

This is true, but my question was not whether there is a risk with my existing system (I'm aware there is) but whether there is more risk than I'm thinking of (i.e. Stuff I've missed).

 

It's also to bring people awareness of this risk in case they haven't thought of it.

 

I might just disable the feature. It's easy to unlock the phone with a fingerprint anyway.

Edited by Turboflat4
Link to post
Share on other sites

Be warned, don't anyhow click a link.

 

update their WhatsApp messaging software or battery management module.

 

People who clicked on the link were asked to enter their credit card details to complete the software upgrade. After doing so, users were greeted with the Android green robot logo with the message: "System update in progress..."

 

Update software/firmware don't need to enter credit card details. Smart phone users should be smarter than that.

  • Praise 3
Link to post
Share on other sites

Update software/firmware don't need to enter credit card details. Smart phone users should be smarter than that.

 

Precisely its smart phone, that's why we leave all the smartness to the phone ....

have seen adults using the calculator in the phone just to add up 2 digits plus 2 digits ....

Link to post
Share on other sites

Had received similar prompt to update 'Whatsapp' application several times. Had clicked the update option (I think) & countdown timer appeared which requested me to continue if I don't want to lose my data. Nothing happened after reached 0. 

 

Have ignore that message henceforth.

 

  • Praise 2
Link to post
Share on other sites

Internet Banking Security - been in these for years (on compliances) to see the growth of technologies that even the best can be deterred, sabotaged or compromised on its safety features . . .  my best advice to everyone here performing transactions via Internet Banking; try to be quick and finish off your executions fast and careful with auto screen shots or notifications archived, then log off straightaway.

Avoid keeping your login 'alive' for too long . . .  this is especially for those international ones!

This also explains why our local ones are shut off by default when not attended/being accesses.

and its also recommended NOT to transact on phones app for banking - utmost for verifications only.

 

Cheers!

Edited by A_korusawa
Link to post
Share on other sites

Update software/firmware don't need to enter credit card details. Smart phone users should be smarter than that.

Yup, anything that prompt me to enter such stuff except I'm doing a purchasing transaction will be ignored by me and closed...I'm not buying anything, so no reason to enter those info. Period. Even if I'm buying something online, my first choice of payment is PayPal..not 100% fool prove but better than I key in my cc number unnecessarily..

  • Praise 2
Link to post
Share on other sites

On a related note, it should be common knowledge that many functions one would use regularly can now be relegated to a simple SMS token rather than having to use the dedicated bank provided token. Only specialised functions require that token still.

 

There are Android apps (and I presume iPhone apps as well) that allow the display of message text on a locked phone. An example is Textra (which is a wonderful SMS app, by the way). So even though my phone has a fingerprint scanner, etc., when the bank sends an OTP through, it can be immediately seen on the locked screen. I always viewed this as a great convenience, but now I'm wondering if it's a liability and whether I should turn off the feature.

 

Granted, if someone does steal my phone (and somehow my other login details), they wouldn't be able to do too much damage. While they can look at my account info and transfer funds to payees already in the system, they can't create any new payee without the token.

 

What do you guys think?

 

hmm good point.

Yeah the msg popup does tend to render locked phones irrelevant. Though i don't even lock my phone lol.

  • Praise 2
Link to post
Share on other sites

My former IT Head doesn't want to have anything to do with internet banking. Queues up at the banks and we laugh at him saying he so old fashioned and being IT saavy some more!!

 

He just laughed it off and said don't come crying when you wake up one morning to find your funds all gone [sweatdrop]

Coz he work in IT department, surely seen a lot of cases of the IT security loophole until he scared. So go for the traditional way is much safer. Haha Edited by Yewheng
Link to post
Share on other sites

On a related note, it should be common knowledge that many functions one would use regularly can now be relegated to a simple SMS token rather than having to use the dedicated bank provided token. Only specialised functions require that token still.

 

There are Android apps (and I presume iPhone apps as well) that allow the display of message text on a locked phone. An example is Textra (which is a wonderful SMS app, by the way). So even though my phone has a fingerprint scanner, etc., when the bank sends an OTP through, it can be immediately seen on the locked screen. I always viewed this as a great convenience, but now I'm wondering if it's a liability and whether I should turn off the feature.

 

Granted, if someone does steal my phone (and somehow my other login details), they wouldn't be able to do too much damage. While they can look at my account info and transfer funds to payees already in the system, they can't create any new payee without the token.

 

What do you guys think?

I'm using tokens for all my transactions that require OTP.

 

There's also limit to the amount that can be transferred per customer for each bank. The default limit cam be lowered.

 

So all the talk about "all your money disappearing from your account" (even by the savvy IT Head) is just pure BS or too much Hollywood movies.

 

Anyhow, these days, if someone uses his phone for bank OTPs, then they shd treat the phone like a credit card, call your Telco to suspend the phone line as you would if a credit card is misplaced.

 

My disclaimer: I have an OCD with regards to Internet Banking. I log in almost daily to see the available credit on all my credit cards so I have no issue with the banks existing IT security setup for their customers.

 

Just wondering, driving a car may mean ending up dead through no fault of ours in a car accident. So do we insist on riding a horse?

  • Praise 2
Link to post
Share on other sites

I'm using tokens for all my transactions that require OTP.

 

There's also limit to the amount that can be transferred per customer for each bank. The default limit cam be lowered.

 

So all the talk about "all your money disappearing from your account" (even by the savvy IT Head) is just pure BS or too much Hollywood movies.

 

Anyhow, these days, if someone uses his phone for bank OTPs, then they shd treat the phone like a credit card, call your Telco to suspend the phone line as you would if a credit card is misplaced.

 

My disclaimer: I have an OCD with regards to Internet Banking. I log in almost daily to see the available credit on all my credit cards so I have no issue with the banks existing IT security setup for their customers.

 

Just wondering, driving a car may mean ending up dead through no fault of ours in a car accident. So do we insist on riding a horse

 

my solution is to leave my OTP at my house.

I don't use mobile banking apps anyway.

 

I only use my home and work pc to access IB to reduce chance of getting keylogged.

↡ Advertisement
  • Praise 1
Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
 Share

×
×
  • Create New...