Mobile and online banks are extremely vulnerable to fraudsters, and the system for sending one-time passwords via SMS can be relatively easily compromised, writes Kommersant , citing cybersecurity experts. In 2015, the share of banking systems with critical vulnerabilities was 90%, in 2017 it was already 56%.
Specialists from Bi.Zone, a subsidiary of Sberbank created to combat cyber threats, spoke about the most common vulnerabilities of Russian online banks. The list was supplemented by employees of other companies in the field of information security. It included:
- Sending one-time passwords via SMS to enter your personal account in a mobile or online bank. It's a "vicious way," says Arkady Litvinenko, Bi.Zone's lead penetration tester. So, using a fake power of attorney or a scan of the victim's passport, you can get a duplicate SIM card, and devices for intercepting SMS are relatively inexpensive - from $700.
- Another SMS vulnerability is related to transaction confirmation. Most often, banks use four-digit one-time passwords from SMS, and if the password is entered incorrectly three times, the operation is blocked. But you can do the opposite: sort through transactions with a password (for example, 5555), creating a lot of operations to debit funds from the client's account. “With the selection of 16,000 transactions, the probability of guessing the password is 99%,” Litvinenko notes. It will be difficult for the client not to notice 16 thousand SMS from the bank with a one-time password, but this method cannot be completely ruled out: the victim may be on vacation or just sleeping.
- You can also get access to your personal account in the online bank through phishing emails and other malware , adds Luka Safonov, head of the practical security analysis laboratory of the Jet Infosystems Center for Information Security.
- For the sake of customer convenience, some banks do not limit the user's session when entering a mobile bank or make it very long - in this case, fraudsters can gain access to a mobile bank, for example, if a bank client uses public Wi-Fi, experts point out.
- Another dangerous moment is when the mobile banking application (also for the convenience of the client) remembers the pin code for entering the application and inserts it automatically. “Hacking or stealing a phone plus automatic password entry gives an attacker access to a bank account,” Litvinenko says. However, the code can be set by the same selection method, he clarifies.
- Nevertheless, the share of banking systems with critical vulnerabilities is consistently decreasing - in 2015 they were 90%, in 2017 - already 56%. The average cost of a hacker's "entry" into a mobile bank is about $22.
Artem Gubenko