Showing posts with label theft. Show all posts
Showing posts with label theft. Show all posts

Wednesday, 24 June 2015

Study says, Effective coordination is the key to contain cyber attacks.

PUNE: Better communication and information about cyber security, right investment in skilled personnel and enabling technologies together with adoption of security measures will minimize the risk of current and emerging cyber threats, says a Websense - Ponemon Institute US report. 
The report: "Exposing the Cyber security Cracks: Roadblocks, Refresh and Raising the Human Security IQ," has focused on challenges IT executives face in dealing with cyber risks, amid communication issues between IT security professionals and executives, a desire to overhaul current security systems and limited security knowledge among executives and employees. 
The findings assume importance in the wake of rise in data thefts and the eventual financial losses suffered by customers of different business organizations such as banks that are encouraging use of IT and mobile technology driven services. 
Based on a survey of nearly 5,000 global IT security professionals (including 545 in India), the report reveals a knowledge and resource gap in the enterprise - leading to an increased level of vulnerability and risk of data security breaches. 
Web sense, Inc. is engaged in protecting organizations from cyber attacks and data theft while Ponemon Institute is dedicated to advancing responsible information and privacy management practices in business and government. 

Globally, 29% of respondents would do a complete overhaul of their current enterprise security system if they had the resources and opportunity, the survey showed. It said nearly half (47%) the respondents felt frequently disappointed with the level of protection a security solution they had procured while only 12% had never been disappointed in their security solutions. 
The report indicated that advanced persistent threats (APTs) and data exfiltration attacks rank among top fears for IT security professionals and 56% believed a data breach would trigger a change of security vendors. Encouragingly, 49% say they are planning to make significant investments and adjustments to their cyber security defenses in the next 12 months. 
Despite these concerns, a high 52% of companies do not provide cyber security education to their employees and less than half (42%) the employees have undergone a cyber threat modelling process in their present role, the report says, adding that of those that did, nearly all, (94%) found it to be important in terms of managing their cyber risk. 
"Advanced persistent threats and data exfiltration attacks rank the top fears for IT security professionals," said Larry Ponemon, chairman and founder of the Ponemon Institute. "These fears manifest because they believe their technology is in need of an overhaul and there is a widening gap in the knowledge and resource sharing among IT security professionals and executive staff. Encouragingly, the survey revealed plans for technology and education investment in place for the future," he added. 
Communication roadblocks are barriers to reducing the risk of a cyber attack, the survey said highlighting that 25% of cyber security teams never speak with their executive team about cyber security. Of those that did, 25% speak once a year and 18% speak twice while only one percent spoke weekly. 
Creating higher awareness among employee about IT threats and investing in training to help them combat such threats however seems to be a low priority for organizations the survey noted. Only 32% of respondents believe their company is investing enough in skilled personnel and technologies to be effective in executing its cyber security objectives or mission. In fact, 45% of companies represented in the research do not provide cyber security education to their employees, the survey revealed. 
Cyber law expert Vaishali Bhagwat told ToI that the human dimension in information security is almost ignored, yet the first to be blamed in case of a security breach incident. "Organisations run security awareness programmes to demonstrate compliance rather than deliver genuine behavior change in end users," Bhagwat said. "Security is never baked in as it is nobody's priority. In a market that is kind to the one who reaches there first, security is bound to go on the back burner unless some sanctions are imposed on organisations that release insecure products," Bhagwat said, adding, "Technology is pushed on to users without giving due consideration to human behavior and no significant efforts are being made to change human behavior so that it readily absorbs new technology to ensure its appropriate use." 
"This Ponemon Institute security survey highlights that a lack of communication, education and inadequate security systems is making it possible for cyber criminals to attack organizations across the globe," said John McCormack, Websense chief executive officer. "It's not surprising that many security professionals are disappointed with the level of protection their current solutions provide, as many still use legacy solutions that cannot disrupt the kill chain to prevent data theft." 

To learn about Identity theft visit: www.cibilconsultants.com

Source: Secondary

Saturday, 20 June 2015

Expert speaks on insiders role in online thefts

PUNE: It's not just clever tech planning but also inside information that apparently helped cyber thieves withdraw huge amounts of money from the accounts of people using the virtual funds transfer route.

Earlier this month, a businessman (Rajesh Bipinchandra Kamdar) was duped of Rs 19 lakh electronically in a cyberattack that targeted his bank account, where the fraudsters had blocked his cellphone sim to execute the fraud. As many as ten transactions were made from his bank account and the amounts were transferred to banks located in different parts of country. In a similar case earlier, Sanjay Govind Dhande (65), a former professor at IIT-Kanpur who now lives in Pune, also found Rs 19 lakh siphoned off from his bank account in a similar manner.

Cybercrime officials, who have leads on two of the four net-banking theft cases reported this month, revealed that in the case of the businessman who lost Rs 19 lakh, fraudsters submitted a copy of his passport to the mobile company to get another sim card issued. "The mobile company employee who issued a new sim in Kamdar's case has been traced, which will help us reach the fraudsters, who may be the same people in both cases as the IP address used in both cases is the same and has been traced to Nagpur," a cybercrime official said.

The official explained that once the second sim card was issued to the fraudster and it was activated, the first one in the victim's phone automatically got deactivated. "Investigations also revealed that the businessman's number had been diverted to another number (of a different mobile service provider) in Daund that had been deactivated six months ago. All calls made on his number were getting routed to this particular deactivated number," said the official, adding that in the meantime, Rs 19 lakh from his account were transferred to banks in Bhopal, Jaipur, Mumbai, New Delhi and Bangalore.

A cybercrime scrutiny expert said in many such internet banking related frauds, the cybercriminals usually have an insider in the mobile company as well as the bank. "The insider within a bank may provide the fraudster with information such as the 'fattest' account in the bank, the account number, user ID, the registered mobile number and even the prospective victim's KYC documents. The fraudster now knows the mobile company whose services the victim is using and arranges for an insider in that company to get the victim's KYC details. Without these insiders, such crimes are not possible," he said.

The expert added that the fraudster then uses these bogus documents to have another sim card issued to him. Once the sim is activated, he tries to reset the victim's online banking password for which the one-time-password is sent to the user's mobile number (which now the fraudster has via the duplicate sim).

Another cybercrime expert added that selling credentials of people is currently one of the biggest underground industry today, from where many fraudsters get the KYC details they seek. "There are also many duplicate sim card selling agents with vested interests within mobile service providers," the expert added.


A senior official from the cyber crime cell in the city told TOI there have been four to five such cases this month, where the victims' sim was blocked and cyber criminals transferred money from their bank accounts.

The official added that the money was transferred to 'fake beneficiary accounts' created by fraudsters in different banks across the country. "Fraudsters are able to create fake beneficiary accounts producing bogus KYC forms of people in whose names they open these accounts. Often, banks do not undertake KYC verification of each and every customer opening an account as it is a mammoth task," he said.

The official said that it is also very easy nowadays to hack into the victim's online banking username and password to execute such frauds. "If a prospective victim is using wi-fi, a seasoned hacker will know exactly how to get the information being punched in on the victim's computer even though he (victim) may be sitting somewhere else but in the same network," the official said.

Expert Speak:

"Upon receiving any alert of a bank transaction on the phone or upon having the sim suddenly deactivated, one should immediately visit the bank and ask the concerned authority to freeze all transactions. He should then lodge a complaint at the police station."

Sandip Gadiya, a cybercrime investigation expert

"Whenever people submit photocopies of pan cards or identification or address proofs, they have to make sure that it is going in trusted hands"

Sagar Rahurkar, a certified fraud examiner, said that

How the fraudsters did it?

Approached the mobile service providers, produced fake KYC documents of the victim and got a duplicate sim of the victim's number issued.

Activated the second sim card, because of which the original sim card with the victim got blocked.

Made several transactions, transferring victim's money into fake beneficiary accounts, in addition to online shopping transactions.

The criminals could hack into the victim's internet banking password to execute the crime.

'Banks should ensure safety of customer information'

"As financial institutions in India interact with more of their customers electronically, they face unique challenges in ensuring that every single new channel touching a customer is secure. This is vital with cyber threats growing in sophistication and increasing the numbers of financially motivated attacks, and exploiting security weaknesses across multiple channels of the bank and ATMs are no exception," said Anand Naik, managing director - Sales, India and SAARC, Symantec.


He added that cyber criminals are always looking for newer avenues namely social networks, unprotected mobile devices and unregulated usage of cloud services to not only attack an individual's identity but also their financial information. "These areas often lack security features such as encryption, access control, and manageability, providing a massive opportunity to cybercriminals. As banks shift from a branch-centric culture to a digital-centric approach to deliver great customer experience across multiple channels, they need to adopt an information-centric view of security. In fact, banks are mandated by RBI guidelines to implement comprehensive security measures such as two-factor authentication to protect customer information, identity and transactions," said Naik.

Improve your bad score and keep your good credit score intact. Consult us: Doctors for all your financial worries: Cibil Consultants

Source: Secondary

Tuesday, 16 June 2015

ATM Thefts

It's any time money not just for depositors but also for thieves.
If India puts not just a man on the moon but also the first ATM, the next day's headlines could announce that the money withdrawn by the country's first lunar bank customer was swiped seconds later by an anonymous compatriot who had managed to get there on his own steam.
ATM thefts are one area where India is not lagging behind the developed world. It's not just in Japan that there are reports of the yakuza (gangsters) using trucks with sophisticated construction equipment to uproot ATMs. India's Silicon Valley of Bangalore has also witnessed amateurish attempts to carry away ATMs, lock, stock and barrel.
And so what if, according to some media reports, India holds the record for the world's highest installed ATM some 4,000 metres above sea level and around the Nathu La Pass in Sikkim. There are also reports that the Agricultural Bank of China has installed the world's highest ATM at around 4,500 m in Tibet. There are no reports however of the highest ATM theft. Whether the record is jointly held by Chindia is not known.


ATMs are hitting the headlines for all the wrong reasons. It is not just the customer who no longer has to go to the bank to withdraw money but can swipe a smart card (with an embedded chip containing a unique number) at an ATM. Likewise, instead of holding up a bank like the gangster John Dillinger used to do in the days of the Great Depression in America, the 21st-century thief can source his daily requirements by swiping someone else's money at the nearest friendly neighborhood ATM which is open 24x7.
The ATM has not just enabled the individual customer to have transactions with his own account without accessing the bank's entire database. It has also decentralized bank thefts since the individual thief can operate at a micro level and swipe someone else's hard-earned money by circumventing the customer-identity integrity systems by attaching fake keypads or card-readers on ATMs, to record confidential data like the depositor's PIN. Technological devices have been developed to detect foreign objects on ATMs.

Learn about identity theft at www.cibilconsultants.com

Source: Secondary