Showing posts with label Credit Cards. Show all posts
Showing posts with label Credit Cards. Show all posts

Thursday, 26 January 2017

Banking Trojans – What Are They & How Can you Stay Protected?



Meghan O’Leary, CMO of BOHH Labs
With more people relying on the Internet, computers and phones for their banking activities, this makes their accounts more vulnerable to security risks and cybercriminals have noticed. One specific tool hackers use for banking attacks are called Banking Trojans.
Banking Trojans are a type of malware used by hackers to attempt to steal confidential information about users using online banking and payment systems. What this type of Trojan does is it redirects the traffic from a bank’s website to another a website that the hacker has access to. This works because the Trojan typically looks like a normal piece of software, but it has a backdoor for hackers, so once it is installed, the hacker can get access to the computer’s system and files. Basically, once a hacker has backdoor access, they have remote control of your computer and can send, steal, receive, delete and so on files from your computer.
Once the hacker infects the computer system with a Banking Trojan, it is all a matter of the waiting game. When a user takes part in an online baking activity, the software starts creating folders and editing registry entries each time the computer system is started. The Trojan also searches for specific cookie files that are related to financial websites that have been stored on the computer and can get information like login credentials and other access to the user’s information.
There are many ways a hacker will use a Banker Trojan to steal your information. Some of the most common methods include:
  • Phishing (stealing information by impersonating a legitimate bank)
  • Logging keystrokes to send captured data to remote servers
  • Man-in-the-Middle attacks
  • Stealing information from a clipboard
  • Intercepting passwords
  • Bypassing two-factor authentication
  • Changing DNS settings to redirect users to malicious versions of legitimate banking sites
Now that you have a better understanding of what a Banking Trojan is and what it can do, there are some measures you can take as users to help ensure your information stays protected. Below are a few best practices tips to follow when online banking to help minimize your chances of become a victim to a Banker Trojan.
  • Read and be familiar with your bank and credit card policies. If you receive a suspicious online notification, verify with your bank or credit card company before taking action.
  • Don’t save personal information, bank account numbers and passwords on your phone or computers.
  • Check for encryption on bank websites. Look for a small lock icon somewhere on your browser, and URLs that begin with “https:” This means the site is secured and your data is encrypted.
  • Make sure your security software is up-to-date, regardless of if you are using a computer or mobile device.
  • Change your passwords and PIN number frequently.
  • Be careful of what you post on social media. This may sound silly, but by posting personal information about yourself on your social tools can give criminals easy access to find more information about you and use it to their advantage.
  • Monitor your accounts. Regularly check in on your accounts to ensure all transactions are your own. If you find fraudulent or suspicious activity, immediately report it to your bank and they will put a hold on your card/take measures to secure your account and typically will cover your loss.

Monday, 17 October 2016

How the Banks are Underwriting the Cloud


OK, so let’s start out by saying that I am neither a bank apologist nor someone who believes that banks do not have a lot to answer for.
Now that is said, let me move on.
When was the last time you had to have a replacement Credit or Debit card because your current one was compromised? Maybe the new one just appeared in the post? Or maybe you had noticed a few dollars that you could not account for on your statement? Whichever it was, any loss sustained was not paid for by you! No, your financial institution took that charge.
Chances are, they were also not at fault for the loss; It could have been the online store that you had been using or maybe your card details were stolen during a shopping trip on High Street. Or maybe you were using a free Wi-Fi service and went on to your favorite shopping site. During that visit, your computer could very easily have been compromised by that very helpful guy or gal sitting behind you…
Whatever the reason, it is unlikely that the banks were actually to blame. It is more likely that they are the true victims. We as the customer are inconvenienced, but that is all. The banks are out of pocket by 2 or 3 dollars, as well as the costs of the replacement card. Not a lot really, until you multiply that by the number of cards they replace each year. You then get to a very large number. So why are they doing it? My answer is going to have to be a guess as I have asked the question on a number of occasions but I have never received a real answer. This is understandable as the banks do not want to publicize how much online fraud really costs, especially as we all jump to the conclusion that it is they, not us, at fault. So here is my guess; Cloud banking and online purchasing is a growing business with billions of dollars of transactions taking place each year. The banks need this business as at the end of the day it streamlines how they work and cuts costs. But this is currently coming at an even larger expense, the reimbursement of fraudulent transactions. I believe the banks are betting on these being reduced over time and the cost savings then coming in to play.
If we really want a Cloud banking infrastructure and to be able to purchase on-line securely with little or no worries about having our transactions interrupted, then we need to help the bank! Yes, I know it is not a natural thing to want to do. But think about the consequences. The figures I have been speaking of are huge. At some point the banks will have to start to recharge them, so I am actually asking us all to help ourselves. Here are a few things we can do to make life a little safer:
Public Wi-Fi: If you do use the Wi-Fi in your local coffee shop, DO NOT use it to make purchases, input passwords or do anything private, unless you have installed and turned on a Virtual Private Network (VPN) which encrypts all data.
Connecting: When you connect to a public Wi-Fi, make sure that you know it is a real one. For example, if you see an Open Connection named “Freds Open Wi-Fi” or “My Favorite Coffee House Free Wi-Fi” or Even “Connect to Me Now!” Do not connect to it. It is more than likely not a safe one to use.
Only ever connect to your bank from your own home, office or mobile network connection. This does not guarantee security but makes it far more likely.
Passwords: Finally, be very careful with your passwords. They are important to you. In a lot of cases, they are your life. Do not give them out, keep them secure and make sure that every web site that you use understands the importance of security and is not just paying lip service to the word. If you do hear that a web site has had your (Remember it is your) password stolen, make sure that you change it straight away and go to all of your other accounts with the same password and change that too. Then go back to the site and demand an apology and recompense. That maybe the only way that some of these site will actually learn that our data is not just important, it is OURS!