Absolutely all surveyed online applications of Russian banks have vulnerabilities, and in more than half of the cases they can lead to theft, writes Kommersant with reference to a study by Positive Technologies. Dozens of Russian banks appear in the study, but which ones are not disclosed in the publication. Attackers know and actively exploit vulnerabilities.
The scale of the problem. The discovered vulnerabilities can be used to access customer information in 100% of cases, and to steal their funds in 54% of cases.
Money. According to FinCERT of the Central Bank, in 2018, 1.47 billion rubles were stolen from corporate clients of Russian banks alone, and in 46% of cases, the money was stolen through access to banking applications. The volume of unauthorized transactions using payment cards of citizens in 2018 increased by 44%, to 1.38 billion rubles.
What are the reasons. The most alarming trend in the security of banking applications is the violation of the logic of their work. The number of online banks where such a vulnerability was identified increased 5 times, from 6% to 31%. It is she who makes possible the most dangerous frauds, such as converting rubles from the victim's account into dollars at a 1:1 rate.
The problem is that many banking applications are self-written: their authors do not have enough qualifications in terms of secure development, experts say. There are three times fewer vulnerabilities in ready-made online banks.
Read also Iranian phishers were able to hack Yahoo! and Gmail
What to do. Industry experts call the situation critical. A possible solution lies in the general implementation of secure application development standards (SSDLC) and program code analysis procedures, which are now available to a few Russian banks.
Why is it important. There are more and more reasons not to fully trust online banks. If there is a vulnerability in the application, then two-factor authentication will not save you from losing funds.