Tips for keeping your id and password safe
video by BankAtlantic
Security threats to online banking
Identity theft in online financial transactions is big business, and it can cost you your business. Several e-brokerages were hard-hit by massive fraud not long ago, illustrating the problem. Different types of attacks based on stolen identity or diversion of commands do billions of dollars worth of damage each year, according to Gartner. Interception services catch hundreds of thousands of "phishing" attempts each month in the UK alone, but many more go undetected. There are numerous case of fraud that each run into millions of dollars. Enterprising hackers stole identities of online brokerages using "man in the browser malware. A different scheme intercepted utilities payments made through a bank, and increased the sum. The thieves then requested that the banks send refunds to their own bank accounts.
A system that intends to provide comprehensive protection must be prepared to meet an ever-growing variety of threats posed by ingenious schemes. It must be adaptable, and it must be able to take into account customer histories, location, the type of transaction being made and other factors.
The currently known types of attacks on customer computer security that must be met include:
Man-in-the-browser – A "Trojan horse" changes the contents of the form that the customer submits to the bank website. The change is not noticeable in the form itself. It takes place only in computer memory. It takes place before SSL encoding.
Man in the Middle - Rogue software is put in place at some point between the customer computer and the bank web sites and intercepts all the information transmitted between the customer and the bank.
Key Logging – Software implanted in the customer's computer that records all the keystrokes of the customer, providing a complete record of user IDs, passwords, pin codes, account numbers and transactions. Sometimes this is integrated with additional rogue software, and usually it sends the information it has collected to the hacker.
Session Hijacking – The session is hijacked by unauthorized use of the cookies deposited by the banking site.
Pharming – Pharming is diversion of traffic from a legitimate site to a rogue web site.
Phishing – Customer identity details are stolen. Typically, this is carried out in a place and context removed from the bank web site, such as a fraudulent e-mail asking for information.
Site Cloaking – Cloaking fools search engines by disguising one web site as another.
Cross-Site Scripting – A script is injected to one web site or web log, but it is operated at a different web site.
OS command injection – Injection of operating system commands to be carried out at the web site.
SQL Injection – Injection of SQL queries to be executed at the web site.
Cookie tampering – Information in the cookie is changed to allow an attack.
Form Tampering (read-only and hidden fields) – Changes are made in hidden or read-only fields in the HTML form.
Outbound Data Theft – Data sent from the web site are intercepted for use in attacks. For example, that may include data about the software installed at the site, version number etc.
Application Denial of Service - Numerous types of attacks make use of the possibility of entering rogue information in input fields.
The above survey only highlights the major sources of attacks, which are constantly multiplying.
IDentiWall Protects against online Security Threats
Made4Biz IDentiWall provides a robust, scalable, upgradeable security solution for online financial transactions through the public Internet and virtual private networks. Its theft-proof authorization mechanism alerts victims and security personnel to ongoing attempts to use stolen identities. It combats attacks based on phishing, man-in-the-browser software, code injection and other hacker strategies.
The heart of the system is an innovative mechanism for dual-network authentication and verification, taking advantage of customers' wireless telephones to provide a one-time password for each entry using SMS. This innovation makes possible a system that is easy to use, requires no new hardware and no changes to banking software or customer computer software.
IDentiWall builds on this functionality to provide a complete out of the box system that is robust, scalable, maintainable, and ready to meet threats that will emerge with developing technologies as well as existing ones.
A sophisticated database and policy mechanism make it possible to use user location, past behavior and other information to optimize the response to attacks. A syndication mechanism ensures that financial institutions and their IDentiWall systems are alerted to general threats, and an investigative workbench allows tracking and surveillance.
IDentiWall is ideal for online e-banking, brokerages and e-shopping. IDentiWall supports a hacking and phishing-proof new e-shopping method.
More about IDentiWall
IDentiWall Architecture - This schema will help you understand what IDentiWall does and how it does it
IDentiWall Technology - This table outlines the sophisticated technologies underlying IDentiWall
IDentiWall versus Smartcards and Tokens - How does IDentiWall measure up against other types of solutions?
IDentiWall versus in-house development - Read this before you try to develop your own system - don't say we didn't warn you!
IDentiWall Announcement
Made4Biz Security announces IDentiWall secure e-Banking - [June 1, 2008] IDentiWall secure e-banking is an extension of IDentiWall VPN, providing the ultimate security solution for online financial transactions More
IDentiWall Authentication
Strong Authentication Transaction VerificationIDentiWall Solutions
Restricted web site solution Secure ebanking solution IDentiWall for Insurance Companies Firewall/VPN port management
5 steps to keep your online bank account secure
Although your bank has an obligation to safeguard all your personal financial details, there are constant security threats that can affect your bank account. Online banking is convenient and can save a lot of time in your transactions, on the other hand, illegal access to bank accounts is one of the fastest growing crimes nowadays. As a costumer, most of the responsibility for keeping your account safe relies on you, so take a look at this little guide and discover how you can protect yourself from online banking fraud.
1.Log in to your account on a regular basis
Make sure you check your account at least once a week, even if you haven’t made any transaction. Go through all the information in the last few days and check that everything is correct, if you see that there’s a discrepancy in your balance then contact your bank immediately.
2.Use your own computer
Avoid using public computers to access your bank account. Public computers may contain software as keystroke loggers which can monitor what you’re typing on the keyboard. If you use another computer then make sure you delete the temporary internet files and clear all your browsing history.
3.Protect all your password information
Do not store your passwords or PINs on your computer, if you have problems remembering them write them down on a piece of paper and keep them somewhere safe. Remember not to share this information at any time and to change PINs and passwords at least every three months.
Never save this information on your internet browser, even if you are using your own computer. When you finish checking your online private banking account, make sure you click on the ‘log out’ button to terminate your session.
4.Maintain your computer’s security
Make sure you have an updated security software installed on your computer. Anti-virus, anti-spam and spyware software are essential for those who engage in online financial transactions.
5.Check for secure connections
Never access your account through an emailed link or a link outside the bank’s site. Most internet users receive phishing e-mails that look like they come from their bank, these e-mails require the recipient to log in through a link in order to acquire information such as usernames, passwords or credit card details.
Always access your account through your bank’s site and make sure that the page your visiting starts with ‘https’, the ‘s’ means that the URL is on a secure server.
Just remember to follow these tips and stay informed about new improvements on financial fraud security. New threats are emerging every day, so if you see something suspicious while using your online bank account then make sure you contact your bank and tell them about it.
Have you been victim of an online financial fraud? Do you want to share your tips on online security? Tell us about it in the comments section below!
Related posts:
browser plug-in
Trusteer works with hundreds of leading banks around the world to keep your online bank account safe from online fraudsters. Trusteer Rapport has been downloaded by tens of millions of customers. It picks up where anti-virus and firewalls leave off, preventing new, sophisticated attacks that anti-virus and firewalls are not always updated to protect you from. To download Rapport now, click here
What’s at Stake?
Criminals are after your money and identity. Inevitably, your online bank account has access to both. If criminals manage to access your online bank account, they can not only access your private information but also transfer money out of your account. Although banks take various measures to protect you against this threat, one of the biggest risks is actually the computer used to bank with. Here are two sophisticated attacks that criminals use to access your online bank account using your computer:
- Malicious software (or malware) - automatically and silently downloaded onto the computer when browsing the Internet, malware silently captures login information and transfers it to criminals while users log-in to their bank’s website. It is also capable of silently changing the transactions executed as directed by criminals
- Phishing - criminals build fake websites that look very similar to the bank’s website. They do this to lure users into visiting these fake websites and submitting their online banking log-in information. This data is later used to access their online bank account
Why Your Current Computer Security is Not Enough
Anti-virus, firewalls and other security software are important but unfortunately not enough. Various studies and recent incidents show that these tools are not always effective in preventing criminals from taking money from your account. As criminals become more sophisticated, your bank strongly recommends additional layers of protection on your computer to enable safe online banking.
Trusteer Rapport - Dedicated Online Banking Security
Trusteer Rapport takes a unique approach that adds real value on top of your current security software. When you connect to your bank online, Rapport does three main things in the background to make it extremely difficult for criminals to target you:
- Rapport verifies that you are really connected to the bank’s genuine website as opposed to a fake website created by criminals. Although this sounds trivial, it’s not obvious that you reach a genuine website when you type your bank’s address into your web browser
- Once verification is complete, Rapport locks down communication between your computer and the bank’s website. This prevents criminals from hijacking your online connection with the bank
- Rapport protects your computer and internet connection by creating a tunnel for safe communication with your bank, preventing criminals from using malware to steal your log-in data and tamper with transactions
Rapport takes several additional steps in the background to further improve security. If you are interested in reading about them, click here. For a complete FAQ about Rapport, please click here.
To download Rapport now, click here.
Free online virus scan
Free Online Virus ScanBitdefender QuickScan uses in-the-cloud scanning technology to detect active malware on your system, in under a minute. Because it focuses on active e-threats, the product uses just a fraction of the system resources needed by a regular virus scan and requires no time-consuming virus signature updates, as the detection process is performed by remote Bitdefender servers.
Key Features
- Fast. Bitdefender Quickscan runs in the cloud as a lightning-fast virus and spyware detection tool, providing an alternative to the time consuming traditional virus scanners.
- Light. Based on award-winning antivirus Bitdefender technologies, Quickscan detects viruses and spyware without slowing down your PC, as most operations are performed remotely on Bitdefender servers.
- Easy to use. The Quickscan service can be accessed from any Internet-connected PC. You don't need to install software, perform updates or do any configuration tasks. But if you'd like to use it without visiting our website, you can also install it as a browser extension or widget.
- Always up-to-date. There is no need for annoying virus signature updates, as the scanning process takes place directly from our servers.
- QuickScan only detects viruses and spyware which are active in memory or present in files that are run at system startup. Inactive virus bodies are not scanned for and therefore not detected. To run a full system virus scan you can use one of the Bitdefender security solutions.
- Double-check the security status of your PC even if you already have an antivirus program installed!
The 10 best online bank security tools
Statistics can hide dangerous currents, especially when it comes to the often invisible crime of online bank fraud....
Stay informed about online banking security
Online private banking
Online Banking Demo
Take a look at what Online Banking can offer
Private Clients
If you are a Private banking client of Adam & Company, you can download an application form.
Company Clients
If you are a Company banking client of Adam & Company, you can download an application form.
3rd Party Access
If you already use Adam Online Banking and wish to grant someone 3rd Party Access, you can download the application form.
New clients
If you wish to become a client of Adam & Company, please complete this form or contact us on +44 (0)131 225 8484.