Thursday 10 September 2026 ,
Thursday 10 September 2026 ,
Latest News
16 March, 2016 00:00 00 AM / LAST MODIFIED: 15 March, 2016 08:41:25 PM
Print

Combatting cybercrime

ATM frauds are just a part of the bigger world of Cybercrime. Cybercrime is a fast-growing phenomenon
Masihul Huq Chowdhury
Combatting cybercrime

On February 2016, the country witnessed ATM fraud whereby four people including a foreigner allegedly involved in an ATM skimming scam have been arrested in Dhaka. The other three arrested persons are staff of a private commercial bank. The instances of ATM card fraud in Bangladesh have forced almost all the 56 banks to take precautionary measures, including temporarily shutting down transactions through the national payment switch (NPS), to safeguard the interests of clients. Around 10 million cards are in use with some 7,000 plus ATM booths in Bangladesh.
Credit Card skimming is a regular part of credit card product and we are also witness to this with the launch of Credit Cards in the early 90s. The frauds or attempt to frauds in the Point of Sales (POS) using credit cards is a common event faced by the financial institutions who are in the business of credit cards in the country.  However, card skimming in ATM is a very regular story in both developed economies like USA and other developing countries in Africa, India. But it is for the first time that ATM frauds have officially been registered followed by these arrests in the country.
An Automated Teller Machine (ATM) is an electronic banking outlet, which allows customers to complete basic transactions without the aid of a branch representative or teller. There are two primary types of ATMs, the first one being only work as cash dispensing machine while the second one being capable of deposit, credit card, utility bills and other transactions including cash dispensing. These ATMs are connected with the National Payment System through fibre optical lines. ATMs have gained popularity primarily due to safety and convenience of carrying the virtual cash and also the over the counter transactions made easy with debit cards. With the increased users of smart phones (interconnected devices), the acceptance of digital wallet has also widened. The wide use of smart phones has increased the on line transactions. BKash is one of the successful digital transactions model.
Back in February of 2013, in two precision operations that involved people in more than two dozen countries acting in close coordination and with surgical precision, thieves stole $45 million from thousands of A.T.M.'s in a matter of hours. In New York City alone, the thieves responsible for A.T.M. withdrawals struck 2,904 machines over 10 hours starting on Feb. 19, withdrawing $2.4 million. It was indeed a brazen bank heist, but a 21st-century version in which the criminals never wore ski masks, threatened a teller or set foot in a vault.The operation included sophisticated computer experts operating in the shadowy world of Internet hacking, manipulating financial information with the stroke of a few keys, as well as common street criminals, who used that information to loot the ATMs. It was, prosecutors said, one of the largest heists in New York City history, rivaling the 1978 Lufthansa robbery, which inspired a scene in the movie “Goodfellas.”
One only has to look, for example, at there being one connected device (i.e. computer) per person on the entire planet in 2013. By 2015 it had risen to two devices per person, and by 2017 it has been projected to reach three per individual. As a result, the financial transactions over the Internet are increasing manifold which is expected to have manifold growth in the coming years. The sheer volumes and the value therefore attract the people engaged in Cybercrime to come up with more innovative ideas not only to catch up but remain ahead to break the firewalls created by the financial firms.
Cybercrime is a fast-growing area of crime. More and more criminals are exploiting the speed, convenience and anonymity of the Internet to commit a diverse range of criminal activities that know no borders, either physical or virtual, cause serious harm and pose very real threats to victims worldwide. Although there is no single universal definition of cybercrime, law enforcement generally makes a distinction between two main types of Internet-related crime:
•       Advanced cybercrime (or high-tech crime) – sophisticated attacks against computer hardware and software;
•    Cyber-enabled crime – many ‘traditional’ crimes have taken a new turn with the advent of the Internet, such as crime against children, financial crime and even terrorism.
Badly designed mobile apps are quickly becoming one of the biggest leaks exposing our personal data to cyber crooks, according to fresh security research from McAfee showing that threats are now being detected at the rate of five per second. To prove the point, McAfee researchers analysed two mobile banking Trojans. Over the period, they successfully managed to steal and use the credit card information from over 13,000 customers, intercepting 170,000 text messages. The report also found that the number of threats detected worldwide has hit a level of 327 per minute - or five threats every second.
There are three primary ways when a bank is under attack by the financial fraudster. The employees of the bank or suppliers/customers are generally under the threat through following ways:
1. Phishing : A tactic that hackers use to get sensitive information (like bank details) from the bank. One needs to look out for emails threatening to lock the computer while visiting a specific website and make a card payment. Cyber criminals also use these emails to put malware on the systems, opening them up to further attacks.
2. Spear Phishing : This takes phishing to a whole new level by targeting individuals with links to financial organisations. The scammers gather information about the bank or bank's employees from social networking sites, before sending an email addressed to an employee that appears to be from a trusted source, designed to exploit the network access or infect the system with malware.
3. Malware : Infecting the customer and banking systems, malware is potentially the most significant threat to the financial sector. Cyber criminals install malicious software on the computer, stealing data and monitoring the keystrokes to gain access to various key passwords.
Along with Payment fraud come the Money Laundering and Counterfeiting the securities. As regards cybercrime, combatting attacks and staying resilient, firms need not only to take and put ‘preventative’ controls in place – i.e. buying solutions to try and stop it happening in the first place. But perhaps more importantly they need ‘reactive’ controls – alongside with detective controls – to know what actions to take when a cyber attack is identified.
Adaptation to new regulatory regimes was ascribed as the “top challenge” facing firms. Cybercrime is nevertheless rising up the agenda for financial firms as well as across other industry sectors. Over the past year various regulatory bodies have been seeking to address the thorny issue of how market infrastructures can remain resilient in the face of the growing cybercrime threat. It used to be a matter of concern just to IT heads within trading firms, but now it’s focussing the minds of senior individuals right up to the CEO and board level.
The Banks are being bound to ensure that proper anti skimming equipments are attached with the ATMs to ensure the protection of the customers interest by the Central Bank after the recent scam. While the Banks are in the process of setting up this compliance, ATM users for their relative safety need to keep in mind while using an ATM. The ATMs must be fully functional - not tampered, no error sign; the place is comfortable - no suspicious movement of people; securing the PIN - not to share it with any one; Report - if there is any irregularity seen in transaction, one must report immediately to help line of the bank.
The digital space for financial transactions is destined to grow with the convenience, speed and cost factor. The Central Bank's initiatives to modernise and on time payment services like BACPS (Bangladesh Automated Clearing and Payments System), BEFTN (Bangladesh Electronic Fund Transfer Network), RTGS (Real Time Gross Settlement) have enabled the banks' customers to have real time solution suiting their requirements. The increased traffic in various on line sites are really encouraging which ensures that the businesses have embraced the real time solutions not only for the reasons that it ensures convenience and speed but also comes along with the solutions including daily reconciliation of their respective bank accounts and also lower the cost of doing business. However, control and maintenance of proper sanity of these system lie with the service providers. The February ATM episode is rather an eye opener for the banks to take adequate measures specially the human resource to be well trained in order to fight the menace arising out of the cyber crimes. It is not only for the sake of the customers but also to ensure own protection from financial and reputation losses of their own.
This is quite challenging task to protect the financial institutions from the threat of cyber attacks as these are always evolving and the attackers are always in the go for invention of something new. But a general approach may enable the financial institutions to embark a safer path to have a cover from the attacks of the cyber criminals.
1. Classify, encrypt and protection of 'high-value targets' : This is what the government already does. Businesses need to encrypt safe data, decide who needs access to what information and build its strongest walls around individuals or information that might be most appealing to cybercriminals.
2. Planning ahead : Generally the time to unearth an attempt to cyber crime requires 210 days (7months) from the date of attack. Therefore, it should always be on the compulsion for the financial institutions to remain on alert before to address the eventual cyber attack.
3. Awareness and action oriented top management : "Most companies say, 'Oh, I have a CIO, they will take care of it". But this is really dangerous. Rather, the Top executives in every department of a business need to be involved and working together to ensure security remains a priority. This is of prior importance by the top management that the financial institutions must use the authentic and genuine source for the software packages and not the pirated or unsupported ones.
4. Not each and every information needs to go in system:  "Air gaps" need to be created by leaving some information on computers that are not (preferably cannot be) connected to the Internet, or keeping the most precious information offline entirely. In this way, the cyber criminals won't be able to get the most important information
5. Test assumptions : It is always better to get the security check from the cyber specialists as to how the cyber criminals may attack the system and have the gap documents ready to properly work around on a regular basis. This will allow the financial institutions to get prepared and take adequate measures as and when required.
Firewalls are not always functional. Thus the sanity check of the system is always of paramount importance to safeguard.

The writer, a banker by profession, has worked both in local and overseas market with various foreign and local banks in different positions

 

Comments

More Op-ed stories
Turkey’s approach to the Syrian war When Syrian rebels from eastern Syria decided to join a US-backed effort to fight ISIL last year, Turkey advised them against it. The push against that move was an example, among many, of Ankara’s…

Copyright © All right reserved.

Editor : M. Shamsur Rahman

Published by the Editor on behalf of Independent Publications Limited at Media Printers, 446/H, Tejgaon I/A, Dhaka-1215.
Editorial, News & Commercial Offices : Beximco Media Complex, 149-150 Tejgaon I/A, Dhaka-1208, Bangladesh. GPO Box No. 934, Dhaka-1000.

Editor : M. Shamsur Rahman
Published by the Editor on behalf of Independent Publications Limited at Media Printers, 446/H, Tejgaon I/A, Dhaka-1215.
Editorial, News & Commercial Offices : Beximco Media Complex, 149-150 Tejgaon I/A, Dhaka-1208, Bangladesh. GPO Box No. 934, Dhaka-1000.

Disclaimer & Privacy Policy
....................................................
About Us
....................................................
Contact Us
....................................................
Advertisement
....................................................
Subscription

Powered by : Frog Hosting