Virtual heists expose gaps in bank security
A data security firm has revealed it breached security at over a thousand US bank branches
BATON ROUGE, LA – Over a thousand US bank branches have had their information security compromised by researchers’ fake thefts of customers’ personal data. Louisiana-based technology security firm TraceSecurity says it broke through security in a variety of real world and virtual ways between 2003 and 2008.
These included hacking bank networks through the web, phishing, pharming and pre-text calling scams, in addition to entering the branch disguised as fire fighters or pest controllers and gaining access to restricted areas containing sensitive data.
The researchers said the physical disguise-based heists alone worked 95% of the time, allowing them to steal back-up tapes, loan applications, laptops, mobile phones and personal digital assistants (PDAs) without detection.
Successfully stolen data included social security numbers, account numbers, contact details, answers to secret questions, driver’s licence numbers and credit card numbers.
Jim Stickley, chief technology officer at TraceSecurity, says: “It takes only one branch location for all customers’ sensitive data to be at risk, and recent data breaches have shown these losses can amount to billions of dollars – a huge cost for what's usually a small, avoidable error.”
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@risk.net or view our subscription options here: http://subscriptions.risk.net/subscribe
You are currently unable to print this content. Please contact info@risk.net to find out more.
You are currently unable to copy this content. Please contact info@risk.net to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@risk.net
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@risk.net
More on Regulation
Lifeline keeps Europe’s hopes afloat for single-sided reporting
Despite Esma’s proposal for delegated reporting of trades, the industry may yet get its wish
EU’s plan to get competitive faces big legislative hurdles
Large and controversial legislative package may be too amorphous to deliver results quickly
FDIC relearns SVB lessons in resolution tinkering
Paring back requirements gets thumbs up from some, but concerns linger
Stablecoin consortia may be ‘interim’ step to solo bank issuance
Former Citi payments head and Ubyx founder says all G-Sibs will issue their own coins
Report once: will Esma’s €1bn reforms deliver the full picture?
Critics say plan to merge three reporting regimes will see scant returns, and won’t mesh with single-sided reporting
CFTC accused of ‘double standards’ on compute futures
Duffy questions ‘long review’ of CME’s contract when Kalshi already offers similar product
Europe’s banks can’t agree on how to fix the output floor
Some want market risk excluded, while others push for greater savings from credit modelling
SEC gunning to take over Cat in 2027
Regulator's bid for control of market surveillance apparatus splits industry participants