![Risk.net](https://www.risk.net/sites/default/files/styles/print_logo/public/2018-09/print-logo.png?itok=1TpHrpuP)
Warnings issued over Man-in-the-Phone fraud attacks
Actimize has warned banks and banking customers of a new kind of attack vector - dubbed Man-in-the-Phone
LONDON - Ever-resourceful fraudsters have developed a new technique to gain access to personal consumer bank information. Man-in-the-Phone fraud attacks involve the fraudster calling the customer impersonating a bank representative to inform them that their savings, checking or card account may have been breached or compromised.
The fraudster advises the customer that in order to remedy the situation they should remain on the line and verify a few account details. At the same time, the fraudster initiates a call to the customer's bank and connects the customer with a real bank representative while the fraudster remains muted on the line. The bank requests authentication information, such as social security number, passwords and other personal information, which is then provided by the customer. Once the personal information is provided, the fraudster quickly ends the conference line and informs the customer that the issue has been resolved. Meanwhile, with the personal information gathered during the call, the fraudster can take over the customer's phone banking relationship and transfer money out of the customer's accounts.
"We help many of the largest retail banks, investment banks and brokerage firms protect themselves and their clients from all types of cross-channel fraud attacks," says Paul Henninger, director of fraud solutions at Actimize. "With our unique perspective into the operations of financial institutions around the world, we can spot trends as they occur. We've noticed an accelerating trend in Man-in-the-Phone attacks. We hope that by publicising this new trend, we can help reduce its impact on individuals and our banking clients."
Actimize recommends that banking customers never share account or personal information with anyone that calls and requests to 'verify' banking credentials. Customers should always tell such callers that they will call the bank to provide such information using the bank's phone number listed on the back of an ATM, debit or credit card. While this sounds obvious, many consumers do not take this simple precaution. The vendor also recommends banks combine cross channel behaviour profiling and anomaly detection technologies with better call centre processes and training. Call centre employees should be trained to listen more closely and ask who originated the call. Attacks may be thwarted or losses minimised if bank employees ask simple (but random instead of static) security questions at various points in the phone conversation when confirming personal credentials. Fraudsters are less likely to trick customers into sharing answers to several security questions.
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@risk.net or view our subscription options here: http://subscriptions.risk.net/subscribe
You are currently unable to print this content. Please contact info@risk.net to find out more.
You are currently unable to copy this content. Please contact info@risk.net to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@risk.net
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@risk.net
More on Regulation
Looming US Basel endgame redraft sparks calls to save IRB
Experts say 20 years of data makes credit risk models more appropriate than standardised approach
Cool heads must guide financial regulation of climate risk
Supervisors can’t simply rely on ‘magical thinking’ of market discipline, says Sergio Scandizzo
Markets worry EU’s reporting simplification will add to burden
Rather than reducing firms’ obligations, market participants fear it could end up increasing requirements
EU banks show basic instinct for credit valuation adjustments
Simpler approach to CVA appeals even to some already using more complex models for counterparty risk
Bank of England wants dynamic Emir for UK clearing houses
Review won’t just photocopy EU legislation, as BoE seeks to make rules simpler and adaptable
Big banks could be sidelined from future rescue deals – FSB
Exacerbation of too-big-to-fail means G-Sibs could already be too large to take extra assets
More guidance, less enforcement: the SEC under Paul Atkins
Current and former insiders expect clearer crypto rules and an end to regulatory violation sweeps
During Trump turbulence, value-at-risk may go pop
Trading risk models have been trained in quiet markets, and volatility is now looming