Virtual heists expose gaps in bank security
A data security firm has revealed it breached security at over a thousand US bank branches
BATON ROUGE, LA – Over a thousand US bank branches have had their information security compromised by researchers’ fake thefts of customers’ personal data. Louisiana-based technology security firm TraceSecurity says it broke through security in a variety of real world and virtual ways between 2003 and 2008.
These included hacking bank networks through the web, phishing, pharming and pre-text calling scams, in addition to entering the branch disguised as fire fighters or pest controllers and gaining access to restricted areas containing sensitive data.
The researchers said the physical disguise-based heists alone worked 95% of the time, allowing them to steal back-up tapes, loan applications, laptops, mobile phones and personal digital assistants (PDAs) without detection.
Successfully stolen data included social security numbers, account numbers, contact details, answers to secret questions, driver’s licence numbers and credit card numbers.
Jim Stickley, chief technology officer at TraceSecurity, says: “It takes only one branch location for all customers’ sensitive data to be at risk, and recent data breaches have shown these losses can amount to billions of dollars – a huge cost for what's usually a small, avoidable error.”
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@risk.net or view our subscription options here: http://subscriptions.risk.net/subscribe
You are currently unable to print this content. Please contact info@risk.net to find out more.
You are currently unable to copy this content. Please contact info@risk.net to find out more.
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. Printing this content is for the sole use of the Authorised User (named subscriber), as outlined in our terms and conditions - https://www.infopro-insight.com/terms-conditions/insight-subscriptions/
If you would like to purchase additional rights please email info@risk.net
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. Copying this content is for the sole use of the Authorised User (named subscriber), as outlined in our terms and conditions - https://www.infopro-insight.com/terms-conditions/insight-subscriptions/
If you would like to purchase additional rights please email info@risk.net
More on Regulation
Industry calls for major rethink of Basel III rules
Isda AGM: Divergence on implementation suggests rules could be flawed, bankers say
Saudi Arabia poised to become clean netting jurisdiction
Isda AGM: Netting regulation awaiting final approvals from regulators
Japanese megabanks shun internal models as FRTB bites
Isda AGM: All in-scope banks opt for standardised approach to market risk; Nomura eyes IMA in 2025
CFTC chair backs easing of G-Sib surcharge in Basel endgame
Isda AGM: Fed’s proposed surcharge changes could hike client clearing cost by 80%
UK investment firms feeling the heat on prudential rules
Signs firms are falling behind FCA’s expectations on wind-down and liquidity risk management
The American way: a stress-test substitute for Basel’s IRRBB?
Bankers divided over new CCAR scenario designed to bridge supervisory gap exposed by SVB failure
Industry warns CFTC against rushing to regulate AI for trading
Vote on workplan pulled amid calls to avoid duplicating rules from other regulatory agencies
Bank of Communications moves early to meet TLAC requirements
China Construction Bank becomes last China G-Sib to release TLAC plans
Most read
- Top 10 operational risks for 2024
- Top 10 op risks: third parties stoke cyber risk
- Japanese megabanks shun internal models as FRTB bites