Help Sitemap Home Skip Navigation Contact Us Disability Statement

 
 
Friday, 4th July 2008

Premium Article !

Your account has been frozen. For your available options click the below button.

Options

Premium Article !

To read this article in full you must have registered and have a Premium Content Subscription with the The Scotsman site.

Subscribe

Registered Article !

To read this article in full you must be registered with the site.

Banks tell clients to beware of anything phishy



Click on thumbnail to view image
Click on thumbnail to view image
Click on thumbnail to view image
Click on thumbnail to view image
Click on thumbnail to view image

Published Date: 21 April 2008
WHEN Scott Rodriguez answered a phone call from his bank, he could barely believe he had been the victim of a fraud.
The 25-year-old oil worker had previously had his credit cards cloned and was surprised when fraudsters hit again – this time using a high-tech computer bug to steal nearly £5,000 from his bank account.

The construction engineer, from Aberdeen, is
among an increasing number of consumers falling victim to online banking scams. Industry figures have revealed a 200 per cent jump in "phishing" e-mails that try to persuade users to disclose information about their internet bank accounts.

Mr Rodriguez used online banking for two personal accounts set up with Clydesdale Bank. Crooks managed to access his funds and sent them to an account in a foreign name held at NatWest Bank in the Notting Hill area of London.

Luckily employees spotted the theft in time and called the construction engineer to query the transaction.

Mr Rodriguez said: "I got a phone call from the bank asking me if I had made a transaction for £4,900. My card has been cloned before and I thought, 'you're joking, please don't tell me this has happened again'."

He has now closed down all his internet and telephone banking facilities to avoid falling victim again.

He was told hackers may have used a Trojan monitor or virus to infiltrate his home computer. The bug would have weaved itself into the PC and tricked him into opening what looks like legitimate software.

Trojans create a "back door" that gives unauthorised users access to personal documents and accounts by tracking all keys pressed so they can get passwords.

A Clydesdale Bank spokesman said Mr Rodriguez would be refunded the cash this week because the transaction was spotted early. He said: "Mr Rodriguez will not experience any financial loss as a result of this incident."

Industry body Apacs says the number of so-called phishing attacks had soared from 3,394 during the first three months of 2007 to 10,235 during the same period this year.

The scam involves fraudsters sending people e-mails claiming to be from their bank and asking them to click on a link that takes them to a website that looks identical to their bank's.

Victims are then asked to verify or update their personal security information, and the fraudster then uses these details to access accounts online and empty them of money.

Apacs said each single phishing incident recorded in its statistics could involve thousands or even millions of e-mails being sent to people.

It said that although online banking fraud had fallen by a third during 2007 to £22.6 million, fraudsters were still having some success in tricking people into giving them their security information.

The number of phishing attacks being carried out has been growing steadily since the beginning of last year.

Sandra Quinn, director of communications at Apacs, said: "Although online banking fraud losses fell last year, the fraudsters clearly aren't giving up.

"Phishing scams are continuing to rise and they are becoming ever more sophisticated, which is why we want to remind people to remain wise to them.

"The advice is quite simple: your bank will never send you e-mails asking you to disclose Pin numbers, log-in details or complete passwords – if you receive an e-mail of this nature you should delete it. If you think your details have been compromised contact your bank immediately."

The group said research had shown that 82 per cent of people were aware of phishing scams and said they would ignore or delete an e-mail asking for their details, but 29 per cent of people do not have up-to-date security software, which could help to protect them.

Meanwhile, a survey has found that more than one-third of consumers blame banks for fraud and nearly three-quarters say it is the sole responsibility of banks or credit card issuers to resolve any problems that arise with their accounts.

Seven in ten believe that card issuers also have a responsibility to minimise the risk of card fraud and the same proportion of those polled expect to be fully compensated should any financial fraud occur – regardless of whether they are at fault.

But the research, conducted by Life Assistance firm CPP, also shows that users are willing to take some responsibility for instances of fraud, with 74 per cent acknowledging that they share accountability for reducing the risk of card fraud and identity theft and more than half blaming individuals for fraudulent activity because they don't keep their personal details safe.

Despite this, one in five still don't check their bank statements thoroughly – a suggestion many consumers are not taking enough care when it comes to fighting fraud.

Banks and credit card firms have put extra security measures in place such as Chip and Pin and Verified or MasterCard SecureCode, but these will not be effective if consumers prove to be the "weakest link", says CPP.





The full article contains 847 words and appears in The Scotsman newspaper.
Page 1 of 1

 
1

Viccarion,

Boston 21/04/2008 09:04:39
As far as phishing is concerned, the problem is in people. 20% of those who do not care is too low, I think. People go on clicking links in their mails and do not check the address they get in the address bar after they see the landing page. I think that only after everyone understands the difference between "/" and "|-" (more can be found on http://safetysurfers.com/content/view/20/2/), there will be less successful fraud on the internet.
2

GRC1959,

24/04/2008 22:26:11
Paradoxically, the more phishing e-mails you get, the less likely you are to respond to them... having received invitations to 'update my information' from 'Abbey Bank', 'Nationwide' and 'National Westminster' - NONE of whom I have any accounts with, the likelihood of believing a similarly-worded e-mail which bears the logo of my genuine bank is.... remote, to say the least.

The 'Abbey' said; "We recently upgraded our Online Service to provide a good services for all our Online Banking Users in order not to be experiencing any difficulties when signing to your Online Account. due to this upgrade we sincerely call your attention to follow below link and reconfirm your online account details. Failure to confirm the online banking details will suspend you from accessing your account online.
"

The 'National Westminster' said; "National Westminster Bank has been receiving complaints from our customers for unauthorised use of the Natwest Online accounts. As a result we periodically review Natwest Online Accounts and temporarily restrict access of those accounts which we think are vunerable to the unauthorised use.

This message has been sent to you from National Westminster Bank because we have noticed invalid login attempts into your account, due to this we are temporarily limiting and restricting your account access until we confirm your identity.
"

The 'Nationwide' said "Nationwide Bank Plc announcing the New Security Upgrade.We've upgrade our new SSL servers to serve our Value Customers for better and secure banking services to protect your account against any fraudulent activities.
With the new recent upgrade in our security measure, you are hereby requested to update your online banking account as quickly as possible by clicking the link below

*Important*
These additional information will be asked during your future login security so, please provide all these info completely and correctly otherwise due to security reasons we may have to suspend yo
3

GRC1959,

24/04/2008 22:27:33
OK, msg too long; I was going to say;

They might be believable if they weren't so laughable.

 

Comment on this Story

 

In order to post comments you must Register or Sign In

 
 
 
  

 
 

Features

Featured Advertising



Sister Newspapers:
Press Complaints Commission

This website and its associated newspaper adheres to the Press Complaints Commission’s Code of Practice. If you have a complaint about editorial content which relates to inaccuracy or intrusion, then contact the Editor by clicking here.

If you remain dissatisfied with the response provided then you can contact the PCC by clicking here.