From data breaches at big-box retailers to DDoS for bitcoin ransom scams, it seems like bankers are playing whac-a-mole just trying to keep up with all the cyber threats to today’s financial system.
First, the good news: When it comes to cybersecurity, banks pretty much have their own house in order. Though financial institutions are by no means invulnerable to attack, the industry is already so heavily regulated and audited that banks and credit unions have largely shored up their own internal defenses pretty much to the hilt.
But bankers still worry about their third-party relationships, said Barry Abramowitz, the chief information officer at Liberty Bank in Middletown.
He points out that it was a third-party relationship that compromised Target’s security in its infamous data breach during the holiday shopping season of 2013, and when a bank’s third parties work with third parties of their own, it’s easy to see why regulators have increasingly honed in on that aspect of cybersecurity.
“It’s kind of a waterfall of security that we’re being required to fully understand and fully vet – to the extent that we can, because it’s very difficult,” he said.
According to Matt Putvinski, the director of IT assurance and security services at Boston-based Wolf & Co., one of the latest schemes to trouble bankers are not attacks on their own systems, but phishing attacks on their business customers. Small businesses, he said, are particularly vulnerable.
“Hackers have figured out that it’s easier to trick banks’ customers to give them credentials,” he said.
With this particular type of fraud, the cybercriminals target a business. The miscreants use various social engineering techniques – maybe, for instance, sending a fake LinkedIn invitation – to collect whatever valuable information they can about a business. Sometimes they bide their time for weeks before going in for the kill. Maybe they’ll send an email to the company’s CFO that legitimately looks like it originated with the CEO, or maybe they’ll be bold enough to call up the bank directly to initiate a fraudulent wire transfer.
“The real concern around business takeover is that businesses tend to do a lot of wire transfers and once a wire transfer is executed, it’s very difficult to get the money back if it’s discovered to be fraudulent,” Abramowitz said. “And the window to get the money back is very, very short – sometimes a matter of hours.”
To safeguard against that particular type of fraud, he said Liberty Bank uses a mix of high and low tech, requiring a credentialed request through its online banking platform and then following that up with a manual telephone callback to initiate any type of wire transfer.
You might call it ironic, in a sense: The better the technology has gotten, the more adept thieves have become at using what information they can find to trick a bank’s or business’s employees the old-fashioned way.
“The phishing exercises are getting better and better,” Abramowitz said. “The perpetrators are doing such a good job of researching and executing these scams that their success rate is very high.”
EMV And More
On the retail side of the house, EMV received greater attention as a panacea to some types of fraud in the wake of the Target data breach two years ago. Though the Oct. 1 liability shift date has come and gone, the U.S. credit and debit portfolios are hardly up to the level their overseas counterparts have achieved, and Abramowitz thinks that some cunning thieves may even take advantage of the rush to get EMV out the door.
But as online shopping gobbles up an ever-greater share of consumers’ dollars, EMV may well be a moot point – and Putvinski thinks it’s just a matter of time before criminals figure out a way around that, too.
“Card not present is still always going to be an issue. The chip won’t help that,” he said. “At the end of the day, it will mitigate a lot of the fraud at point-of-sale until everybody implements it and then [hackers will] figure out another way to get into point-of-sale devices.”
Regulators have taken a largely prescriptive approach to cybersecurity. Many in the industry hail the FFIEC’s cybersecurity assessment tool as a good starting point for financial institutions to evaluate their own level of risk, and Putvinski praised the National Institute of Standards and Technology for a publication that he said should help bankers bake security into their own corporate culture.
Using this document, he said, “whenever somebody is developing a product or service, there’s some level of security or risk being discussed. I think this will definitely help organizations start helping people understand their role in security and what they’re supposed to be doing.”
Email: lalix@thewarrengroup.com





