{"id":21538,"date":"2018-05-24T12:49:29","date_gmt":"2018-05-24T11:49:29","guid":{"rendered":"http:\/\/www.intelligentcio.com\/eu\/2018\/05\/24\/huge-680-rise-in-mobile-app-fraud-transactions-since-2015-rsa-finds\/"},"modified":"2018-05-29T11:10:36","modified_gmt":"2018-05-29T10:10:36","slug":"huge-680-rise-in-mobile-app-fraud-transactions-since-2015-rsa-finds","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2018\/05\/24\/huge-680-rise-in-mobile-app-fraud-transactions-since-2015-rsa-finds\/","title":{"rendered":"Huge 680% rise in mobile app fraud transactions since 2015"},"content":{"rendered":"<p>RSA Security has released its Q1 2018 Fraud Report, providing analysis of consumer fraud data from the RSA Fraud and Risk Intelligence team.<\/p>\n<p>The report offers a snapshot of the cyberfraud environment from behind enemy lines, showing that the number of fraudulent transactions originating from a mobile app during the quarter has increased by 200% since 2015. Analysis from the team also indicated that abuse of social media platforms is a growing problem, with social media replacing the dark web as the top hacker marketplace.<\/p>\n<p>Key stats include:<\/p>\n<ul>\n<li><strong>\u2018Appy hunting<\/strong> \u2013 the proportion of fraudulent transactions carried out on a mobile app has jumped from just 5% in 2015 to 39% in the first quarter of 2018 \u2013 the volume of fraudulent transactions has risen by 680% overall and by 63% since Q1 2017<\/li>\n<li><strong>Down goes the desktop<\/strong> \u2013 use of traditional web browsers for fraudulent transactions is on the decline, dropping from 62% to 35% since 2015<\/li>\n<li><strong>Burner phones rife<\/strong> \u2013 82% of observed fraudulent e-commerce transactions originated from a new device in Q1 2018, as hackers try to avoid detection<\/li>\n<li><strong>New profiles and devices used for cash out <\/strong>\u2013 Fraudsters used a new account and new device in 32% of all the fraudulent transactions seen during the quarter, suggesting that many are attempting to use stolen identities to create \u2018money mule\u2019 accounts as part of their cashing out process<\/li>\n<li><strong>Phishing remains at number one for cybercriminals<\/strong> \u2013 despite being one of the oldest online fraud tactics, phishing accounted for 48% of all fraud attacks observed in Q1 2018<\/li>\n<li><strong>Trojans still siphoning credentials<\/strong> \u2013 financial Trojan malware was present in one in every four fraud attacks observed in Q1 2018<\/li>\n<li><strong>Cards being compromised<\/strong> \u2013 RSA recovered more than 3.1 million unique compromised cards and card previews from reliable online sources in the quarter \u2013 these all included CVV numbers<\/li>\n<\/ul>\n<p>\u201cThere has been a sharp rise in the volume of legitimate transactions carried out over mobile apps, so it\u2019s only natural that hackers have followed suit in targeting mobile channels for fraud,\u201d said Daniel Cohen, Director at the RSA Fraud and Risk Intelligence Unit.<\/p>\n<p>\u201cUnfortunately, many mobile apps fail to build security from the ground up. This means cybercriminals and fraudsters are able to slip through the cracks, hijacking mobile applications and siphoning off credentials and funds. As mobile-related fraud continues to grow, consumers and businesses alike need to be aware of the risks.\u201d<\/p>\n<p>Mobile\u2019s influence doesn\u2019t stop with malicious apps, the increasing availability of social media on mobile devices has created a thriving cybercriminal ecosystem, with more than four out of five hackers using new devices to carry out fraudulent transactions and avoid being caught.<\/p>\n<p>\u201cSocial media provides the perfect control station for cybercriminals, who can easily create profiles using fake details to operate on the platforms before collaborating with other fraudsters in closed groups, or peddling stolen wares in online marketplaces,\u201d explains Cohen.<\/p>\n<p>\u201cSocial media\u2019s scalability, anonymity and reach is providing cybercriminals with the perfect disguise; they can jump between accounts and devices at will, rarely using the same device twice.<\/p>\n<p>\u201cThis makes it much easier to dodge the authorities and continue scamming. Reddit has recently banned a number of subreddits dedicated to fraud, where hackers were exchanging contacts, advertising services and sharing reliable sources of dark web fraud forums.\u201d<\/p>\n<p>In light of these findings, RSA has provided a number of recommendations to help consumers and businesses alike avoid falling victim to cyberfraud:<\/p>\n<ul>\n<li><strong>The devil\u2019s in the download <\/strong>\u2013 with one in 20 fraud attacks associated with a rogue mobile app, people must practice caution when downloading new apps, making sure to verify the publisher and pay close attention to what permissions each app requests<\/li>\n<li><strong>It\u2019s who you know <\/strong>\u2013 avoiding clicking on links in text messages or emails from unfamiliar senders will significantly lower the chances of having bank details stolen, or malware being installed on devices<\/li>\n<li><strong>Safe housekeeping <\/strong>\u2013 smaller purchases will often be made first to test the waters, so monitoring bank accounts for suspicious purchasing activity is vital to catch fraudsters early in the act<\/li>\n<li><strong>Educate yourself and your employees <\/strong>\u2013 free initiatives such as <a href=\"https:\/\/www.actionfraud.police.uk\/\">ActionFraud<\/a> offer a number of helpful tools to keep consumers safe, while the <a href=\"https:\/\/www.cyberessentials.ncsc.gov.uk\/\">Cyber Essentials<\/a> scheme offers a similar service to businesses<\/li>\n<li><strong>Create a device identification process for your business <\/strong>\u2013 take a business-driven approach to security by linking device identification to a clear risk strategy, for example, ask users on new devices to re-authenticate to reduce the risk of fraud<\/li>\n<\/ul>\n<p>\u201cWe all need to take a share of the responsibility for reducing and preventing fraud \u2013 from the consumer, through to the banks and social media platforms. After all, fraud is not going away any time soon and can be very costly, to individuals and businesses alike,\u201d explains Cohen.<\/p>\n<p>\u201cWe need to get better at spotting it, by being more aware of it. Social media and mobile devices have made it easier than ever for fraudsters to be successful, but there are often tell-tale signs that something is up. Stay vigilant and don\u2019t always trust what you see online!\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>RSA Security has released its Q1 2018 Fraud Report, providing analysis of consumer fraud data from the RSA Fraud and Risk Intelligence team. The report offers a snapshot of the cyberfraud environment from behind enemy lines, showing that the number of fraudulent transactions originating from a mobile app during the quarter has increased by 200% [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":21705,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[14,6617],"tags":[7114,7115,1257,7116,7117,7118,7119,7120],"class_list":["post-21538","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-more-news","category-research","tag-actionfraud","tag-consumer-fraud-data","tag-cybercriminals","tag-cyberfraud","tag-daniel-cohen","tag-rsa-fraud-and-risk-intelligence","tag-rsa-security","tag-social-media"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/21538","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=21538"}],"version-history":[{"count":2,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/21538\/revisions"}],"predecessor-version":[{"id":21544,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/21538\/revisions\/21544"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/21705"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=21538"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=21538"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=21538"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}