Guard against cyber threats for a safe digital banking experience
With the advent of and introduction of the customer enabling cum friendly banking technology to improve customer experience the cyber threat landscape has increased proportionally. Through a mix of social engineering and the easy availability of hacking tools, it has become possible for cybercriminals to target victims and gain access to online banking accounts. Time and again we hear in the news regarding individuals losing lakhs after falling gully to cybercriminals. Sometimes it is negligence, misinformation, or greed on the part of the bank customers that causes them to be the victim of cybercrime. In this article, we discuss some steps to guard against cyber threats and ensure a safe online banking experience for everyone.
- Avoid downloading illegitimate software
The threat from illegitimate software is much larger for Android than with Apple's iOS because if you want to install an application on iOS you have to either use the App Store or jailbreak the phone. Illegitimate mobile apps come in the format of mobile diagnostics, pop-ups, and free antivirus offerings but this software has the possibility of containing trojans or malware that can compromise the user's mobile device.
Guard: - Avoid downloading mobile apps from unknown/unauthentic sources or websites. Use APK scanning tools which are available online for free to test the APK before installation for possible threats.
2. Public Wireless networks
Hackers can set up public Wi-Fi networks that can appear to be from legitimate entities such as RailTel or Jio’s public Wi-Fi networks. When a user joins such free public wireless networks the attacker can listen to communication originating from the user and will try to extract sensitive information. Public Wi-Fi networks are ideal environments for a range of cybersecurity attacks, including rogue networks, man-in-the-middle attacks, viruses, and snooping or sniffing.
Guard: - It is a prudent measure to disable auto-join for open networks in the wifi setting menu. To prevent the likelihood of these attacks, remote users should turn off Wi-Fi auto-connect settings for public Wi-Fi networks. Ensuring SSL Connection by enabling the "Always Use HTTPS" option is also a good option.
3. Android OS Updates
Keeping the mobile operating system up-to-date is the best way to stay protected from threats. The update includes software patches and bug fixes for the mobile operating system which ensures better security.
Guard - Android IOS is updated automatically and in case it’s delayed the user can update manually by following the simple steps: - Go System>Advance>System Update. The Update status will be displayed on the screen any new updates available for OS will be shown and the same can be installed by the device user.
4. Android Security Apps
There is a possible threat of malware getting installed on the Android OS through the installation of apps from unknown sources. Such malware can track the user's activities on the mobile phone, record phone calls, read and save text messages, and track the location of the user. Mobile devices with the Android OS are prone to TrojanDroppers. The banking Trojans also enable attacks on the banking applications on the phone, which leads to the theft of data for use in stealing money and funds.
Guard - Installation of malware/virus detecting antivirus can be done via Google Play Store. Such antivirus scans the app before the installation begins thus creating a roadblock for malicious software to get installed on the device.
5. Private-Browsing
Firefox Focus/Chrome Incognito mode allows users to privately surf and guard against threats while using online banking services or doing a digital transaction. This is a useful feature that can be used on a public computer or another mobile device not belonging to the user. Although it doesn’t provide total anonymity to the user it’s much safer rather than using the conventional mode of browser which stores the user’s session data, cookies, and browsing history.
Guard: - Firefox Focus or Chrome can be used to leverage privacy.
6 Storage of passwords
Often users save passwords or other sensitive information like bank account numbers, ATM PINs, credit card details, and internet banking login details on the default notes application of mobile. E.g. Notes in Oneplus phone. It might surprise many that the data/information stored on these default notes applications is saved in raw format (Unencrypted) and can be read by other malicious mobile apps that have read/write permission.
Guard: - Avoid storing the password on Google Keep or any default notes application on mobile devices.
7. Avoid getting Spoofed
In website spoofing, cybercriminals impersonate a website that is similar to the original website. Usually, bank or financial websites are targeted for spoofing to obtain user login credentials or customer information. It is difficult for an average user to identify a spoofed website as it is similar in look and feel to the original website, thus the user believes the website to be legitimate and ends up compromising credentials.
Guard: - To identify a spoofed website, always check if the URL is misspelled or is a Homoglyph URL. Check for site information and site seal which will give cues regarding the genuineness of the website.
8. Phishing
Cybercriminals employ this social engineering technique to steal user credentials and credit card data. The attacker often masquerades as a trusted entity that intends to seek information, a User clicking on links in a phishing email lands on a bogus webpage that requests login credentials. Another technique in phishing users is to redirect to the genuine webpage but the malicious script is used to inject user session cookies making way for an XSS attack.
Guard:- The user should ascertain the sender's identity for e-mail messages. The email sender address should be checked for spelling mistakes or homographic URLs.
9. Sharing details on social media
People often share sensitive or private information about their bank account or credit card on social media sites like LinkedIn, and Facebook. etc to get the resolution for their queries/complaints/doubts. E.g. Bank customers share his passbook/bank account details on the bank’s profile page on LinkedIn or Facebook. Information once put up on social media sites is difficult to erase and it can be used by attackers to gain access or compromise the customer's online banking account causing financial loss.
Guard: - Care should be taken such that details regarding bank account or credit card or any other information that reveals individual financials should not be shared on social media sites or portals.