Showing posts with label banking. Show all posts
Showing posts with label banking. Show all posts

Wednesday, 15 July 2015

Credit Scoring: A Tool To Aid Bank Lending

It Is important for banks to look beyond their existing customer base and reach out to the vast number of micro and small enterprises (MSEs) which are deprived of bank credit. Alongside extending the reach of their banking services, there would be a need to improve and customize the products offered, fine tune the pricing aspects, and enhance the quality and efficiency of services. For this, banks need to have a proper business plan and delivery model that would harness the benefits of technology. The costs of banking transactions need to be dramatically reduced just as in so many other fields such as telecom, after the advent of technology.

Alternate appraisal techniques
We need to appreciate that the credit process in case of micro and small entrepreneurs cannot be identical to that of large corporations, where the borrower is able to provide detailed information about business plans and the firm’s financial statements and the lender carefully reviews the data using analytics that are time-consuming and expensive.
                                                                                                  Pliers, Wire, Hands, Wire Sculpture
In view of the relatively small size of the loan, banks do not find it worthwhile to conduct an elaborate appraisal of SME credit proposals both in terms of value and profit. Therefore, in order that the banks can quickly conduct the appraisal of SME loan proposals without expending too much resources, it would be imperative to ensure the efficiency of the appraisal process.
Financial institutions in the developed countries use different lending techniques to provide funding to small firms. The banks, in these countries, use a version of a computerised loan-evaluation system, referred to as credit scoring, to assess would-be borrowers. The credit scoring approach, using computer technology and mass production methods, was originally designed to handle consumer loans, but are now being used effectively for lending to small businesses by predicting their potential loan delinquency. Credit scoring offers a modern alternative for the traditional method of evaluating loans for small businesses.
To expedite the credit flow to the MSEs, RBI, as a proactive measure, issued guidelines in May 2009, advising banks to start using scoring models for making lending decisions in case of all advances up to
R2 crore. However, despite, our instructions having been issued nearly five years back, we find that the use of credit scoring model in the real sense has not really taken off in India. Our assessment is that perhaps the lack of conceptual clarity on the subject could be one reason for the banks’ reluctance in using the credit scoring model. In fact, very often credit scoring is misunderstood or confused with credit rating.
What is credit scoring?
Credit scoring is a statistical technique that combines several financial characteristics to form a single score for assessing a borrower’s credit worthiness. The score does not predict a company’s ability to pay, but rather its willingness to pay in a timely fashion. The probabilities of delinquency, as estimated by the model, are based on the analysis of previous applicants with similar characteristics. Credit scorecards are “tools used to predict the behaviour of new applicants based on the performance of previous applicants” (US Comptroller of the Currency, 1998). Scorecards can also be used to predict the performance of existing accounts, based on the past experience of accounts with similar characteristics.
Credit scoring is a model applied by banks in their assessment and approval or decline of the loan requests by SMEs. As there is a strong link between the payment behaviour of the business owner and that of the business, SME credit scores usually include financial characteristics from both the business and the business owner. Credit scoring is based upon information like how the repayment of the previous loans has gone, what is the current income level of the enterprise, what are the outstanding debts, if any?
It focuses on the credit history of the enterprise. As part of the process, the lenders see whether the enterprise/business owner has the reliability and honesty to repay the loan. It also examines how the enterprise has used credit before, its record for repayment of bills, including utility bills, how long the enterprise has been in existence, assets possessed by the enterprise and sustainability and viability of the activities that the unit is engaged in. Credit scoring model draws inputs from historical information on the performance of loans with similar characteristics.
Credit scores have been widely used for many years in consumer credit markets e.g., mortgages, credit cards, and auto loans. In the mid-1990s, Fair Isaac and Company introduced one of the first credit scoring models developed exclusively for SMEs, the Small Business Scoring Service (SBSS). Since then, many SME banks in the US, as well as in Canada, the U.K., and Japan, have implemented some type of credit scoring for SME borrowers.
Different from credit rating
Credit scoring and credit rating are two entirely distinct concepts and to be employed in distinctly different scenarios. Credit scoring is a statistical technique that combines several predetermined characteristics to form a single score to assess a borrower’s credit worthiness. Any two identical applications will always receive the same score. Credit rating, on the other hand, is based more on the experience and judgment of the credit officer and uses financial indicators as the key. The objective of scoring is to replicate the manual analysis and approval of loans at a lower cost, with greater speed, while the use of credit rating is reliant on the manual analysis by credit officers to supplement the rating provided by the tool.
To put it simply, credit scoring uses a retail lending approach to credit screening/decision making and is recommended for smaller ticket-size loans, where adequate reliable financial data about the borrower is not available. Credit rating is a more appropriate tool for larger, mid-segment or corporate loans, which have relevant financial data/business plans that provide the basis for further credit analysis and information.
Benefits of credit scoring
When used appropriately, credit scoring can benefit multiple stakeholders, including lenders, borrowers, and the overall economy. For the lender, scoring leads to process automation, which facilitates process improvements, leading to many byproducts such as improved management information, control and consistency. It also increases the profitability of SME lending by reducing the time and cost required to approve loans and increasing revenues by expanding lending opportunities.
A study in the US estimated that the cost of evaluating micro loan applications in the US using credit scoring was reduced to around $100 compared to a range of $500-$1,800 prior to the introduction of credit scoring. The time saving involved meant that banks could focus more time on marginal applications, existing loans that are showing signs of distress and processing more loan applications.
The Bank of England has also acknowledged that there is some evidence of banks being more willing to lend on an unsecured basis when using credit scoring, which potentially improves the access to bank finance for very small and start-up SMEs.
For the borrower, the benefits from credit scoring include increased access to credit and, in some cases, lower borrowing costs. In its study of SME credit scoring’s impact on access to credit, the Federal Reserve Bank (FRB) of Atlanta found that, in general, the use of credit scoring increased the amount of credit banks extended to the SMEs. It found that banks using scoring were more likely to lend in low-income areas.
Given the extent of exclusion in the SME sector and the criticality of the sector for the economy, banks urgently need to step up lending to the sector. For evaluating loan proposals and for facilitating SME financing, banks would need to employ low-cost and quick decision-making alternatives. The use of credit scoring models can go a long way in facilitating lending decisions by reducing costs and increasing service levels.
Visit: www.cibilconsultants.com
Source: Secondary

Online banking frauds can come to an end by new software

Scientists have developed a new software to prevent malware from sending spam emails and instant messages while blocking unauthorised money transfers.

Researchers at Georgia Tech have created a prototype software, Gyrus, that takes extra steps to prevent malware from sending spam emails and instant messages, and blocking unauthorised commands such as money transfers.
Current protection programmes might recognise the original user's intent to send email, transfer money or engage in other transactions but cannot verify the specifics such as email contents or amount of money.
Without context, it is impossible to properly verify the user's full intent, regardless of whether the software is protecting a financial transfer, an industrial control system or a wide range of other user-driven applications.
Gyrus is a transparent layer on top of the window of an application. The user experience with the application will be exactly the same as when Gyrus is not installed or activated.
Of course, if Gyrus detects that user-intended data has tampered with, it will block the traffic and also notify the user.
The research is based on the observation that for most text-based applications, the user's intent will be displayed entirely on screen, as text, and the user will make modifications if what is on screen is not what he or she wants.
Users help Gyrus do its job by establishing pre-defined rules that help the software determine whether commands - authorised or not - fit with established user intentions.

The idea of defining correct behaviour of an application by capturing user intent is not entirely new, but previous attempts in this space use an overly simplistic model of the user's behaviour.
For example, they might infer a user's intent based on a single mouse click without capturing any associated context so the attackers can easily disguise attacks as a benign behaviour.

           Man holding tablet pc and credit card indoor, Shopping Online
Instead, Gyrus captures richer semantics including both user actions and text contents, along with applications semantics, to make the system send only user-intended network traffic. Gyrus indirectly but correctly determines user intent from the screen that is displayed to the user.
There are two key components to Gyrus' approach. First, it captures the user's intent and interactions with an application. Second, it verifies that the resulting output can be mapped back to the user's intention. As a result, the application ensures accurate transactions even in the presence of malware.

To learn about Identity theft, visit- www.cibilconsultants.com
Source: Secondary

Sunday, 12 July 2015

SIM card block? It could be online fraud!

Online banking cheating cases on the rise in city, warn experts


A 35-year-old software engineer working with an information technology (IT) company in Chinchwad got an SMS that her ICICI Bank debit card had been used to make purchases worth Rs93,000. She almost fainted because she had never made any such transaction. But her nightmare did not end there. A short while later she received another SMS saying her debit card had been used to make another purchases of Rs 5,000.

The cases of online banking and mobile transactions are on the rise in the city. The officers of the cyber crime cell (CCC) of Pune police claimed people are not aware about fraudsters and their tricks. As a result, the cases have increased in the city.

The CCC officers said that people do not have adequate knowledge of safety and security measures for online transactions. They said as many as 60 such cases are being registered at different police stations in the city.

Fraudsters are using the technique of blocking the SIM card of the victims’ cellphones to ensure they don’t get alerts from the bank. Senior police inspector Sarjerao Babar of CCC told dna, “The present modus operandi of the fraudsters is to block the SIM card with the help of the telecom company employees. Thereafter, they send an application to the telecom company for a new SIM card on the victim’s name. Once the fraudsters get the new SIM card, they get the bank alerts.”

On that basis, fraudsters submit fake know your customer (KYC) forms on the name of the victim and open new accounts in their name and make transactions. “Thereafter, the fraudsters immediately transfer money to their different accounts,” Babar said.

Analysing the causes for the rise in number of cyber crimes in Pune, Babar said, “As more people use the Internet and cellphones for banking, the number of people falling prey to cyber crimes is increasing. People carrying out bank transactions using the Internet are falling prey to economic offenders on the prowl.”

Deputy commissioner of police (cyber) Sanjay Shinde told dna, “People do not have adequate knowledge of safety and security measures to be taken while carrying out online transactions. We have been trying to spread awareness by giving safety tips in dos and dont’s format. However, many Internet users do not pay enough attention to our advice. In recent cases, we have observed that if the SIM card was blocked, the victims could have contacted the nearest telecom office and get a confirmation on it, but they did not. As a result, the fraud took place.”

                       
Shinde said they had asked bank authorities to create awareness among customers about the latest security measures. “But the banks are slowly proactive in security aspects related to mobile banking,” Shinde said.

Besides, a major chunk of cyber crimes pertain to credit /debit card frauds.

Banks authorities asked to step on it

Deputy commissioner of police (cyber) Sanjay Shinde claimed that they had asked bank authorities to create awareness among customers about the latest security measures and to be vigilant during submission of KYC forms to weed out fake accounts. “But the banks are slow in responding to security aspects related to mobile banking,” he said.

Online shopping tips:
  1.  Shop with merchants you know and trust
  2.  Check whether the shopping website is secure
  3.  Be cautious of unsolicited phone calls or emails from merchants
  4.  Read merchant’s refund and exchange policies before making any purchase
  5.  Do not share your password
  6.  Always print and keep the order confirmation documents
  7.  Read the privacy statement
  8.  Never enter your personal information on a pop-up screen.
Internet Banking tips:
  1.  Keep your passwords/PIN codes safe and memorize them
  2.  Check if the online banking website is secure
  3.  Log out immediately after you complete your online transaction
  4.  Do not copy or click on any links that are not from a known source
  5.  Do not respond to emails asking for personal or banking related information
  6.  Read privacy and policy statements to ensure that no unauthorized transaction has taken place
  7.  Check your account statements regularly

To learn about Identity Theft, visit- www.cibilconsultants.com
Source: Secondary

Wednesday, 24 June 2015

How to fight Credit card fraud?

Regulatory policy wonks in India are engaged in intense combat — this time, over whether the Reserve Bank of India (RBI) has gone overboard with seeking to secure online and offline credit card payments. The RBI has made it mandatory to validate offline credit card payments in India with a 'PIN' (personal identification number) and online Indian payments with an 'OTP' (one-time password) to be generated by SMS on the mobile phone.
Thanks to these measures, India has one of the most secure credit card and online payment systems in the world. Some have attacked the security measures as being retrograde. The main charge is that the two-stage validation process wastes time. The argument is that the benefits gained from the security measure do not out-weigh the cost of the additional time spent. Moreover, since the RBI does not regulate foreign payment gateways, it has exempted them from the security requirement — so, payments made even from India, through foreign payment gateways, do not have to comply with this security measure.
What this means for the consumer is that purchase of a book on Amazon.com would not require an OTP while purchase of the same book on Amazon.in would require it. Both sites enable storing your credit card information (if you are willing to trust their servers with your data). On Amazon.in, you need to enter your CVV/CSC number ("card verification value" or "card security code") — a number physically pre-printed on your card. Once your transaction is authenticated, you also have to get your OTP by sending a text message to your credit card issuer. An OTP gets sent to your phone within seconds of the SMS request and is valid for a single use, to be made within 30 minutes.

On Amazon.com, since the security feature is not mandatory, if your credit card data is stored on its server, you can complete your purchase with a single click (popularly branded as "1-Click Ordering"). Therefore, does it take longer to shop on an Indian site? Yes. Is that an unbearable time burden? No. And, does it make India a more secure place for electronic payments? Indeed.
According to The Nilson Report, a payments industry trade journal, the United States, accounts for nearly 47 per cent of the global credit card fraud even while contributing to just 23 per cent of the volume of global credit card payments. On the other hand, media reports quote Visa International as stating that India has the lowest online card fraud incidence. Yet, the size of credit card frauds is growing worldwide, and does pose a threat to confidence in the electronic payments system.
As India brings more of her people into the banking and electronic payment system, the scope for fraud too would increase. There is also the culture of general laxity with security that needs to be contended with. For example, after the RBI introduced the mandatory requirement to enter your PIN into the card reader in the store to effect an offline credit card payment, many restaurants did not deploy wireless card readers. Waiters would simply ask the guest for the PIN and many, lazy to get up from their tables, would gladly oblige. This is pretty much how most passwords are compromised — simply by asking.
Against this backdrop, the benefit of better security in online and offline credit card payments can outweigh the cost of spending a few more seconds getting an OTP on sms, or entering the PIN into a card reader. In a nation that has poor banking penetration and a propensity to stack currency notes under the mattress for safe-keeping, one blaring slanging match in a prime-time television debate can be enough to destroy confidence in the banking system.
On the other hand, India, home to 16 per cent of the global population, would do well to innovate and lead the change in how payments are made secure worldwide. After all, one should remember that even while shares of Chinese online retailer Alibaba.com got a fancy valuation for listing shares in the United States, Indian online retail companies such as Flipkart and Snapdeal snapped up spectacular valuations and attracted serious investments despite the payment security measures.

To know more about Identity Theft visit: www.cibilconsultants.com

Source: Secondary

India: Third Most Affected Nation By Online Banking Malware

Growing Internet penetration and rising popularity of online banking have made India a favorite among cyber criminals, who target online financial transactions using malware, security solutions provider Trend Micro said. According to the firm, India ranks third after Japan and the US in the tally of countries most affected by online banking malware during the April-June quarter of 2014.

Japan topped the list with the highest number of online banking malware infections this quarter due to VAWTRAK. In May alone, it saw 13,000 malware infections. The US saw about 5,000 malware infections during the month, followed by India at 3,000 attacks.
"India posed for cyber criminal expansion with an average of 2.5 million malware detection in a given month. Also, 33 per cent more malicious apps were downloaded and network traffic from affected computers continued to rise," TrendLabs Director Myla V Pilao told PTI. TrendLabs is Trend Micro's research and development center. These and many such incidents show that cyber criminals will always adapt to new trends and situations whether in the use of new malware or targeted attacks techniques to continue their attacks, she added. 

She said the severity of attacks has intensified against financial and banking institutions as well as retail outlets globally.
"Total attacks have exposed more than 10 million personal records as of July 2014 and that strongly indicates that organisations need to adopt a more strategic approach to safeguarding digital information," she said. Such incidents often lead  to stealing of consumer's personal information like customer names, passwords, email addresses, home addresses, phone numbers, and date of birth.
These types of personal privacy breaches have affected organisation's sales and earnings, while leaving customers unable to access accounts and dealing with service disruption, Pilao said. "The pace of change in technology sector has never been as rapid as it is now, and as a result we see firms struggling to keep up with the latest developments," she said. Pilao added that it is essential that Indian businesses treat information security as a principal constituent of business  strategy as time and again it has emerged as one of the top countries witnessing cyber crime. 
"The incidents observed during this quarter further establish the need for a more comprehensive approach to security," TrendLabs Director Myla V Pilao said. 
A report by another security solutions firm McAfee said India is the fourth most affected country in Asia, with 786 phishing domains and 1,557 servers hosting suspect content. Also with 145 spamming domains originate from India, the country is the eighth most affected country in the Asia Pacific region.
According to government's cyber security arm Computer Emergency Response Team-India (CERT-In), 62,189 cyber security incidents were reported in the first five months of the current calendar year. Also, till May this year, 9,174 Indian websites were hijacked by various hacker groups spread across the world.

Learn about identity theft at www.cibilconsultants.com

Source: Secondary

Monday, 22 June 2015

Most common cyber crime: Net banking fraud

GURGAON: Higher internet connectivity in Millennium City has also given cyber crimes a bigger playing field. Of the total 759 cases of online crime recorded in the past year by the police, 248 were related to bank fraud, making it the most common among cyber crime cases registered by the police.
According to data released on Saturday, a total of 759 complaints in the past year have kept the cyber crime cell busy. Of these, 248 are related to net banking/credit/debit card fraud, followed by 72 cases of abuse on social networking sites, 68 cases of email ID hacking and 59 complaints of SMS and call abuse.
Increased number of complaints on abuse on the internet led the police to inaugurate a new cyber crime cell in the city earlier this year. Officials blame the alarming numbers on advanced technological expertise and ease of access to information. "Unlike in the preceding years, this year the number of net banking-related crimes have surpassed social media-related complaints. The vulnerability of credit and debit cards and net banking has made it easy for criminals who are just a click away from easy money. They are difficult to investigate and this is why some of the most trying cases this year belong to this category," an officer of the cyber crime cell said.
Yet, it was this year that Inspector Suresh Kumar, head of the cyber crime cell, was adjudged cyber cop of year for his work on cases of online banking fraud. Under his leadership, the department continues to spread awareness on how to beat web criminals.
The cell has approached the problem by taking students into the loop and conducting awareness drives, since they are some of the most frequent users of the Internet and easiest targets.

Complaints received
Hacking of E-mail ID: 68
Defamatory / Offensive emails: 39
Phishing/Anonymous Mails: 07
Facebook Related Complaints: 72
Twitter Related Complaints: 02
Website Hacking: 03
Fake Website: 11
Lottery Fraud: 06
Net Banking/ Credit/Debit Card Fraud: 248
Fraud/ Cheating Through Internet: 64
Forgery through Computer: 01
Cheating Through Mobile: 32
ID Theft through Internet: 10
Posting Personal Information on Internet: 13
Data Theft: 22
Abusive/Offensive/Obscene calls & SMSes: 59
Sexual Harassment/Pornography: 07
Miscellaneous Complaints: 95

Protect yourself from Identity Theft. Visit www.cibilconsultants.com
Source: Secondary

How to keep your credit card safe online

RAIPUR: With hacking of Facebook, Gmail and other networking websites on rise, threat of credit card/debit card bank accounts also being hacked looms large in state. Online shopping has further increased this threat.

Monendra Sahu, an ethical hacker said, "For hackers, carding, which refers to credit card/debit card fraud is the new duplicity that has made significant rise in state. Hackers have been using credit card/debit card numbers of people to carry out financial transactions for their personal benefits".

Online shopping/banking by users provides the easiest way for hackers to swindle money. "Whenever a user buys anything from the website, he enters his card details to make payment. This becomes an easy gateway for the hacker to trace card details and he gets access to all users who have used that website, by hacking it." Monendra said.


"It has also been observed that the hacker traces around 1000 or even more credit card/debit card numbers and carries out his transaction withdrawing around Rs 4000-5000 from each account. However, this risk is a bit lesser in an online bank account as in this; the user directly enters the bank website."

In fact, with new techniques coming in, hackers have even evolved a technique of scheming, in which they implant a device in the ATM machine or the POS portal and get card details. "A device which can be stuck with Fevikwik, is used by the hackers. It becomes difficult to differentiate between the device and ATM machine."

"Majorly, in the old ATM machines, which can be easily opened from back-side, hackers can easily process it by a pen-drive. It's easier to open the machine and inject a processed pen-drive which will take the card details of users who have carried out their transaction throughout the day. However the newly developed machines aren't much vulnerable," he added.

"Hackers try to use cyber cafes, where they can get in touch with a large number of users and with an open wi-fi connection which it make things easier for them," he added.

Users guide

* Change the pin of ATM card after getting the pin. Try to have a locked Wi-fi network however LAN cable would be even more secure.

* Stop using free anti-virus.

* Always use updated system for your laptop/computer.


* Use websites with HTTPS communication protocol which give encrypted password.

Protect yourself from Identity Theft. Visit www.cibilconsultants.com

Source: Secondary

Social networking mail Id should not be used for online transactions

Chandigarh: Security software maker Symantec advised internet users not to use e-mail ids being used for social networking sites like Facebook, Twitter for carrying out online banking or business transactions in order to prevent stealing of financial data. 

"They (internet users) should be more cautious while on social networking sites. They should have separate e-mail id for social networking site and other e-mail id for carrying out transactions like banking," Symantec MD Shantanu Ghosh told reporters here while replying to a query steps needed to be protected from cyber attack on social networking sites. "

We have observed that on social networking sites, people usually share their detail including personal ones with their friends as well as with those whom they do not know much and here they face the risk (of being attacked)," he said. "


Cyber attackers then can try to get into your e-mail ids through malware on these sites and try to steal vital information like credit card information," he said. He said not to click on any "untrusted" link in their e-mails or social networking site as it also poses threat of stealing important financial information of the user. 

Ghosh also cited an example when a malware in the name of bollywood female actor Katrina Kaif video was received by internet users on their e-mail ids in India and later it was found that the malware was intended to steal credit card information of the user. Acknowledging that the number of malwares in the cyber world has grown to millions in India in last few years, he also stressed on be cautious on framing a secure password for their e-mail ids to avert any cyber attack. 

"Some users use e-mail password as wife's birth date or anniversary day or birth year and most of these details are available on their social networking site account and it can also be misused by cyber attackers," he said. He added that small and medium business in cities like Chandigarh, Surat, Jaipur are facing the threat of cyber attack because of less spending by small entrepreneurs on security technology and growing use of internet. 

"Small cities, including Chandigarh, are sharing good amount of malware activity...(because) these companies are not spending much on security technology which makes them vulnerable to cyber attack," Ghosh said. He said increasing use of broadband and low awareness among entrepreneurs about malwares are also some of the reasons behind their vulnerability of cyber attack. 



"Augmented by broadband penetration, smaller and emerging cities of India are exploring opportunities offered by the virtual world in turn creating a new lucrative pool of targets for cyber criminals to exploit," he said. As per the Symantec Internet Security, a sizeable 25 per cent of small and emerging cities like Chandigarh, Surat, Cochin, Jaipur are infected by malwares.

Protect yourself from Identity Theft. Visit www.cibilconsultants.com

Source: Secondary

Saturday, 20 June 2015

Expert speaks on insiders role in online thefts

PUNE: It's not just clever tech planning but also inside information that apparently helped cyber thieves withdraw huge amounts of money from the accounts of people using the virtual funds transfer route.

Earlier this month, a businessman (Rajesh Bipinchandra Kamdar) was duped of Rs 19 lakh electronically in a cyberattack that targeted his bank account, where the fraudsters had blocked his cellphone sim to execute the fraud. As many as ten transactions were made from his bank account and the amounts were transferred to banks located in different parts of country. In a similar case earlier, Sanjay Govind Dhande (65), a former professor at IIT-Kanpur who now lives in Pune, also found Rs 19 lakh siphoned off from his bank account in a similar manner.

Cybercrime officials, who have leads on two of the four net-banking theft cases reported this month, revealed that in the case of the businessman who lost Rs 19 lakh, fraudsters submitted a copy of his passport to the mobile company to get another sim card issued. "The mobile company employee who issued a new sim in Kamdar's case has been traced, which will help us reach the fraudsters, who may be the same people in both cases as the IP address used in both cases is the same and has been traced to Nagpur," a cybercrime official said.

The official explained that once the second sim card was issued to the fraudster and it was activated, the first one in the victim's phone automatically got deactivated. "Investigations also revealed that the businessman's number had been diverted to another number (of a different mobile service provider) in Daund that had been deactivated six months ago. All calls made on his number were getting routed to this particular deactivated number," said the official, adding that in the meantime, Rs 19 lakh from his account were transferred to banks in Bhopal, Jaipur, Mumbai, New Delhi and Bangalore.

A cybercrime scrutiny expert said in many such internet banking related frauds, the cybercriminals usually have an insider in the mobile company as well as the bank. "The insider within a bank may provide the fraudster with information such as the 'fattest' account in the bank, the account number, user ID, the registered mobile number and even the prospective victim's KYC documents. The fraudster now knows the mobile company whose services the victim is using and arranges for an insider in that company to get the victim's KYC details. Without these insiders, such crimes are not possible," he said.

The expert added that the fraudster then uses these bogus documents to have another sim card issued to him. Once the sim is activated, he tries to reset the victim's online banking password for which the one-time-password is sent to the user's mobile number (which now the fraudster has via the duplicate sim).

Another cybercrime expert added that selling credentials of people is currently one of the biggest underground industry today, from where many fraudsters get the KYC details they seek. "There are also many duplicate sim card selling agents with vested interests within mobile service providers," the expert added.


A senior official from the cyber crime cell in the city told TOI there have been four to five such cases this month, where the victims' sim was blocked and cyber criminals transferred money from their bank accounts.

The official added that the money was transferred to 'fake beneficiary accounts' created by fraudsters in different banks across the country. "Fraudsters are able to create fake beneficiary accounts producing bogus KYC forms of people in whose names they open these accounts. Often, banks do not undertake KYC verification of each and every customer opening an account as it is a mammoth task," he said.

The official said that it is also very easy nowadays to hack into the victim's online banking username and password to execute such frauds. "If a prospective victim is using wi-fi, a seasoned hacker will know exactly how to get the information being punched in on the victim's computer even though he (victim) may be sitting somewhere else but in the same network," the official said.

Expert Speak:

"Upon receiving any alert of a bank transaction on the phone or upon having the sim suddenly deactivated, one should immediately visit the bank and ask the concerned authority to freeze all transactions. He should then lodge a complaint at the police station."

Sandip Gadiya, a cybercrime investigation expert

"Whenever people submit photocopies of pan cards or identification or address proofs, they have to make sure that it is going in trusted hands"

Sagar Rahurkar, a certified fraud examiner, said that

How the fraudsters did it?

Approached the mobile service providers, produced fake KYC documents of the victim and got a duplicate sim of the victim's number issued.

Activated the second sim card, because of which the original sim card with the victim got blocked.

Made several transactions, transferring victim's money into fake beneficiary accounts, in addition to online shopping transactions.

The criminals could hack into the victim's internet banking password to execute the crime.

'Banks should ensure safety of customer information'

"As financial institutions in India interact with more of their customers electronically, they face unique challenges in ensuring that every single new channel touching a customer is secure. This is vital with cyber threats growing in sophistication and increasing the numbers of financially motivated attacks, and exploiting security weaknesses across multiple channels of the bank and ATMs are no exception," said Anand Naik, managing director - Sales, India and SAARC, Symantec.


He added that cyber criminals are always looking for newer avenues namely social networks, unprotected mobile devices and unregulated usage of cloud services to not only attack an individual's identity but also their financial information. "These areas often lack security features such as encryption, access control, and manageability, providing a massive opportunity to cybercriminals. As banks shift from a branch-centric culture to a digital-centric approach to deliver great customer experience across multiple channels, they need to adopt an information-centric view of security. In fact, banks are mandated by RBI guidelines to implement comprehensive security measures such as two-factor authentication to protect customer information, identity and transactions," said Naik.

Improve your bad score and keep your good credit score intact. Consult us: Doctors for all your financial worries: Cibil Consultants

Source: Secondary