{"id":41134,"date":"2024-11-29T10:28:33","date_gmt":"2024-11-29T10:28:33","guid":{"rendered":"https:\/\/www.intelligentcio.com\/apac\/?p=41134"},"modified":"2024-12-11T14:33:18","modified_gmt":"2024-12-11T14:33:18","slug":"knowing-is-half-the-battle-how-to-defend-against-bank-fraud","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/apac\/2024\/11\/29\/knowing-is-half-the-battle-how-to-defend-against-bank-fraud\/","title":{"rendered":"Knowing is half the battle: How to defend against bank fraud"},"content":{"rendered":"\n<p><strong><em>Jasie Fon, Regional VP Asia, Ping Identity, says there\u2019s no way to \u2018set and forget\u2019 user security online.<\/em><\/strong><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"653\" height=\"1024\" src=\"https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2024\/11\/Jasie-Fon-www-653x1024.jpg\" alt=\"\" class=\"wp-image-41135\" style=\"width:230px;height:auto\" srcset=\"https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2024\/11\/Jasie-Fon-www-653x1024.jpg 653w, https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2024\/11\/Jasie-Fon-www-191x300.jpg 191w, https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2024\/11\/Jasie-Fon-www-768x1204.jpg 768w, https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2024\/11\/Jasie-Fon-www-980x1536.jpg 980w, https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2024\/11\/Jasie-Fon-www.jpg 1121w\" sizes=\"auto, (max-width: 653px) 100vw, 653px\" \/><figcaption class=\"wp-element-caption\"><strong>Jasie Fon, Regional VP Asia, Ping Identity<\/strong><\/figcaption><\/figure><\/div>\n\n\n<p>Bank fraud &#8211; like depositing a fake cheque &#8211; used to be more complicated. Today, though, sophisticated bank fraud can be executed simply through a PC connected to the internet. In 2023 alone, the Anti-Scam Command (ASCom) had to freeze over 19,600 bank accounts worth over SGD100 million.<\/p>\n\n\n\n<p>Ping Identity&#8217;s most recent consumer survey reveals that Singapore consumers expressed greater concern over identity fraud as they gained greater awareness. According to the survey, 42% have fallen victim to identity fraud, with financial identity fraud, account takeover and impersonation being the most common fraud types experienced by respondents &#8211; while 96% of consumers indicate that they receive spam calls; 46% receive spam calls once a week.<\/p>\n\n\n\n<p>It\u2019s now much easier for criminals to siphon off substantial sums of money from individuals and exact reputational harm on institutions. To guarantee that adequate security measures are established, it\u2019s crucial for both consumers and businesses to have knowledge of the various types of bank fraud being used by malicious individuals. Let&#8217;s have a look at some of the more common types of fraud being used by criminals to trick businesses and consumers:<\/p>\n\n\n\n<p><strong>Phishing attacks<\/strong><\/p>\n\n\n\n<p>Criminals can gain login credentials through the use of fake emails, texts, or phone calls. Typically, the account holder is lured into providing their account details to someone pretending to be a bank staff member. This is what&#8217;s commonly known as phishing. There were around 4,100 phishing attempts reported to the Singapore Cyber Emergency Response Team (SingCERT) in 2023. Of these, 63% were mimicking institutions in the banking and financial services sector.<\/p>\n\n\n\n<p><strong>Credential stuffing<\/strong><\/p>\n\n\n\n<p>This scam is used by criminals who purchase stolen credentials off the dark web, a part of the internet that lets people hide their identity and location from law enforcement. The data is usually incomplete, so the attacker uses programs to \u2018stuff\u2019 usernames and passwords into different websites in large quantities, hoping for a match. Success rates are low, but attackers work with large volumes of data to achieve their aim.<\/p>\n\n\n\n<p><strong>Session hijacking<\/strong><\/p>\n\n\n\n<p>The criminal will seize control of a customer&#8217;s ongoing online session through stolen session cookies \u2014 small files used to identify your computer but used for only one online session. Stolen data is usually acquired through third-party browser extensions, devices infected with malware, or even public Wi-Fi networks.<\/p>\n\n\n\n<p><strong>Password spraying<\/strong><\/p>\n\n\n\n<p>Instead of focusing on getting the right login information, hackers might use bots (automated applications) to match various usernames with commonly used passwords. This operation is done at a large scale, so hackers can ultimately identify correct combinations and obtain access to accounts.<\/p>\n\n\n\n<p>Due to thousands of breaches over the past few years, a large number of passwords can be found on the dark web. No matter how complicated your password is, it is no longer sufficient to stop fraudsters from accessing your accounts. Because of this, rather than sticking with the traditional password, consider implementing passwordless authentication techniques like biometrics.<\/p>\n\n\n\n<p><strong>New account fraud<\/strong><\/p>\n\n\n\n<p>Existing bank accounts are not the only ones vulnerable to attacks. Another concern is the potential consequences of new account fraud. In this scam, the criminal could use another person&#8217;s identity to create a new account, or they could take it a step further by blending authentic and bogus identities to form a deceptive account. The criminal will most probably use counterfeit IDs, email addresses, or cheques to achieve this illusion of authenticity.<\/p>\n\n\n\n<p><strong>Putting Up Safeguards<\/strong><\/p>\n\n\n\n<p>Fortunately, there are proven methods to help reduce the risk of becoming a victim of fraud. These include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>User education<\/strong><\/li>\n<\/ul>\n\n\n\n<p>One of the most powerful security methods available is educating staff and customers about typical fraudulent schemes. One example is to include warnings in transactions and email messages. These warnings can serve as reminders to help them distinguish between what&#8217;s authentic and what could potentially be a fraudulent scheme.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Multi-factor authentication (MFA)<\/strong><\/li>\n<\/ul>\n\n\n\n<p>MFA asks users to provide multiple forms of identification. This might include something they are familiar with, like a password or pin, combined with something they possess, like a key fob or a device that creates a unique code. MFA can also utilize other methods like fingerprints, voice recognition, and facial scans.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Policy-based access control<\/strong><\/li>\n<\/ul>\n\n\n\n<p>This method enhances security by only allowing entry according to established guidelines. Authorisation is contingent on the bank&#8217;s selection of characteristics. Some examples are job position, level of access and period of time. Customers may need to take additional factors into consideration, such as their access location, in order to gain access.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Online Safety Is a Never-Ending Process<\/strong><\/li>\n<\/ul>\n\n\n\n<p>Ensuring user security online isn&#8217;t a one-time affair, and there&#8217;s no way to &#8216;set it and forget it.&#8217; More companies are using Customer Identity Access Management (CIAM) systems in response to their customers\u2019 complex digital needs. These advanced platforms help online businesses safely record and handle consumer identity while regulating access to applications and services. From a consumer\u2019s point of view, a well-executed CIAM system creates smooth engagement with different parts of a business without the need to repeatedly verify their identity.<\/p>\n\n\n\n<p>It\u2019s important to continually update security measures in order to provide users with the required protection level. Building trust between clients and banks is essential for preventing bank fraud. By adhering to these strategies and staying vigilant for new attack techniques, the chances of experiencing disruption and damage from a cybercriminal will significantly decrease.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Jasie Fon, Regional VP Asia, Ping Identity, says there\u2019s no way to \u2018set and forget\u2019 user security online. Bank fraud &#8211; like depositing a fake cheque &#8211; used to be more complicated. Today, though, sophisticated bank fraud can be executed simply through a PC connected to the internet. In 2023 alone, the Anti-Scam Command (ASCom) [&hellip;]<\/p>\n","protected":false},"author":58,"featured_media":41136,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1463,6,3559,31,52,59,1281,44,54],"tags":[7693,7692,7475,7695,340,1243,7691,69,7694],"class_list":["post-41134","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-apac","category-industry-verticals-banking-finance","category-cybersecurity","category-intelligent-technologies","category-main-story-newsletter","category-south-east-asia","category-tech","category-top-stories","category-used","tag-anti-scam-command-ascom","tag-bank-fraud","tag-jasie-fon","tag-multi-factor-authentication-mfa","tag-phishing","tag-ping-identity","tag-regional-vp-asia","tag-singapore","tag-singapore-cyber-emergency-response-team-singcert"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/41134","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/users\/58"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/comments?post=41134"}],"version-history":[{"count":2,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/41134\/revisions"}],"predecessor-version":[{"id":41420,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/41134\/revisions\/41420"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/media\/41136"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/media?parent=41134"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/categories?post=41134"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/tags?post=41134"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}