
In 2019, Russian banks paid 935 million rubles to customers written off from their accounts without consent. This amount compensates for approximately 15% of the funds lost by customers as a result of unauthorized operations, according to the annual report of the finser (center for monitoring and response to computer attacks in the credit and financial sector of the Bank of Russia). Its data leads to RBC .
Previously, the regulator never disclosed data on the share of compensation, and the amount only once, according to the results of the third quarter of 2018, when the banks returned 230 million rubles to the victims. Last year, banks held 576.5 thousand transactions, which were subsequently recognized as unauthorized. We are talking about the translations of individuals and legal entities made without their consent with the help of payment cards and other electronic means of payment, including electronic wallets. The total amount of such operations amounted to 6.42 billion rubles.
As follows from the financial report, the suppressing share (99.2%) of unauthorized operations was carried out on individuals. The average amount of one transaction amounted to 10 thousand rubles. Most often, such transfers are made through ATMs and terminals, distance banking services (online cabinets or mobile applications), as well as through payment of goods and services on the Internet (the so-called CNP transactions).
The low level of compensation by banks of the stolen funds is due to the fact that in most cases, customers trust fraudsters and themselves give them confidential information, thereby violating the requirements of the contract with the bank. And if the client himself has compromised the data of cards or remote banking services, the bank may not return the money to him. The report claims that the Central Bank is considering changing the procedure for payments to the victims, but no details are given.
Last year, 69% of all thefts of citizens were carried out using social engineering, or psychological methods for luring personal data. Due to the new form of bank reporting, this indicator was lower than in 2018 - then it amounted to 97%. A decrease in the influence of society can also be explained by the growth of cyber graminess of the population. The Central Bank recommends to banks to better inform citizens about the lack of responsibility in cases where the client himself is to blame for the data transfer of his card.
Most often, scammers use social methods to write off money through a mobile application or Internet bank - here its share is 88.9%. This is due to the fact that larger amounts are available in remote banking services than in other channels. Specialists recorded 160.8 thousand similar thefts totaling 2.27 billion rubles. Of this money, banks returned only 162.3 million rubles to customers, that is, every 14th ruble.
With the help of society, scammers conducted two -thirds of unauthorized operations to pay for goods and services on the Internet. This channel accounted for the most transfers without the consent of customers - 371.1 thousand transactions with a volume of 2.97 billion rubles. However, the level of compensation was higher: 653.2 million rubles, or every fifth stolen ruble.
The smallest proportion of society - 22.4% - is recorded when using payment cards without the consent of the client. In total, according to the results of 2019, 40 thousand such cases were discovered. The total amount of damage to theft through ATMs and terminals exceeded 525 million rubles. Banks returned only 10% of the stolen funds to the victims (54.4 million rubles). In relations with legal entities, scammers prefer to mislead employees of companies in order to access the remote banking service system using viruses.
In 2019, banks reported in the Central Bank about 877 cases when their employees received unauthorized access to information in customer accounts and transferred funds without permission. The damage from such thefts amounted to 24.5 million rubles. Earlier, the finser did not report such incidents, only isolated cases when the cashiers transferred the funds of employers into third -party accounts fell into the reports. In 14 cases, bank employees gained access to the software of ATMs and electronic terminals and managed to steal 13.5 million rubles.
The number of computer attacks on banks in 2019 fell 15 times: organizations reported 58 incidents with a damage of 23.2 million rubles. The hackers made another 15 attacks on ATMs, in total, kidnapping 33.1 million rubles. The total damage from unauthorized access of unauthorized persons (including their own employees) to the information systems of banks amounted to 103.8 million rubles.
They contribute to fraud and various kinds of data leaks: so, on February 11, Alfa-Credit credit broker, who collects applications for loans and helps to choose and get a loan at the bank, got into the village. They were contained in the Mongodb database management system with open code used by some companies for internal tasks. The database contained more than 44 thousand records that included the name of the client, the amount and type of loan requested, the phone number, email address, city and region of residence. Several people from the base confirmed that they submitted an application for a loan through Alfa Credit. A source close to the broker confirmed the leak in the company, customer data were freely available for four days.
According to experts, the Mongodb databases are discovered due to the negligence of system administrators, as well as the technical personnel serving and customizing them. By default, Mongodb does not require a login and password to get access to it, and this base has not yet been exhibited for sale, but the time was in the public domain to detect and download these bases.
On February 6, it became known that more than 1.2 million customers of microfinance organizations appeared on the sale on a specialized website. The "sample" of the base containing about 800 records includes surnames, names, patronymic, phone numbers, email addresses, date of birth and passport data of Russians.
The seller does not disclose the name of the MFIs whose data he had, but most customers reported that they turned for loans to the company "Higher School". Also in the "Probe" there were data from customers of the microfinance companies "Buser" "Ekapusta", "Lime" and "Microcrass". They contacted MFIs from 2017 to the end of 2019. Part of the base contains irrelevant numbers of phones that are no longer serviced or replaced by the owner. Some participants in the base confirmed that their data in the database are correct, but claimed that they had never applied for loans.
It was reported that the source of leakage may be the database of partner companies that collect applications for loans on the Internet and sell their MFIs, the composite database of customers of several no longer functioning MFIs or the database of one MFIs, which is collected by pieces from different sources. According to experts, these data can be used both by other MFIs for attracting customers and scammers to create a scheme of deception under the pretext of obtaining "profitable" loans. In order not to become their victims, bank customers after calling are recommended to put the phone and call back to the bank at the official number.