• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Consumer Group Slams Bank App Fraud Failings

You are here: Home / General Cyber Security News / Consumer Group Slams Bank App Fraud Failings
May 4, 2023

A leading buyer legal rights team has identified as on the UK’s large street banking companies to greatly enhance their account security in purchase to deal with mobile device fraud.

Which? claimed that attackers could shoulder surf buyers to acquire PINs that shoppers typically share involving the phone lock display screen and banking application. If they then steal the system, this knowledge could permit them to unlock the victim’s cellular banking account.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The group said banks should really have much better controls to restrict the problems fraudsters could do once inside a victim’s account, these kinds of as tightening the limits around location up new payees and resetting login information.

“In the Barclays app, the fraudster only wanted to enter debit card aspects, which are saved in the app, to increase a new payee, which means they did not have to have to bypass any extra security checks,” it argued.

“The financial institution sent a fraud warning by using SMS, which is of no use to the account holder if their phone has been stolen.”

Go through a lot more on banking fraud: Authorized Thrust Payments Surge to 75% of Banking Fraud.

Throughout the login reset course of action, some banking companies inquire customers to re-sign up for the app or go id checks this sort of as a selfie video clip. Nonetheless, others only request standard information that could be easily obtained by a fraudster, these kinds of as a a single-time passcode despatched via SMS or card particulars saved in the app, Which? added.

“Which? would like banking companies to stop relying on SMS to send out sensitive information and fraud warnings. In the occasion of a phone staying stolen, criminals can possibly look at messages despatched by SMS or only place the victim’s SIM into a unique phone and continue to obtain messages,” the rights team argued.

Which? also desires banking institutions and telcos to describe to consumers how they can improved safeguard themselves.

“For case in point, prospects can incorporate a special pin to their SIM and to disable preview notifications when a phone has been stolen to prevent the thief from observing messages with no having to unlock the phone,” it claimed. “Banks can also help their buyers protected their accounts rapidly by allowing them ‘distrust’ phones connected to their accounts.”

Cellular banking fraud losses stood at £15.7m for the initial 50 % of 2022, an 8% calendar year-on-12 months drop, according to UK Finance. They comprise around a quarter of full on the internet banking fraud losses.


Some parts of this posting are sourced from:
www.infosecurity-magazine.com

Previous Post: «Cyber Security News Malicious HTML Attachment Volumes Surge
Next Post: Meta Uncovers Massive Social Media Cyber Espionage Operations Across South Asia meta uncovers massive social media cyber espionage operations across south»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.