Corporate Account Takeover & Information Security Awareness

The infor­ma­tion con­tained in this page may con­tain priv­i­leged and con­fi­den­tial infor­ma­tion and is for infor­ma­tion pur­pos­es only. Before act­ing on any ideas pre­sent­ed in this con­tent; secu­ri­ty, legal, tech­ni­cal, and rep­u­ta­tion­al risks should be inde­pen­dent­ly eval­u­at­ed con­sid­er­ing the unique fac­tu­al cir­cum­stances sur­round­ing each insti­tu­tion. No com­put­er sys­tem can pro­vide absolute secu­ri­ty under all con­di­tions. Any views or opin­ions pre­sent­ed do not nec­es­sar­i­ly state or reflect those of Inves­tar or any oth­er entity.

What is Corporate Account Takeover?

A fast grow­ing elec­tron­ic crime where thieves typ­i­cal­ly use some form of mal­ware to obtain login cre­den­tials to Cor­po­rate Online Bank­ing accounts and fraud­u­lent­ly trans­fer funds from the account(s).

  • Short for mali­cious soft­ware, is soft­ware designed to infil­trate a com­put­er sys­tem with­out the owner’s informed consent
  • Mal­ware includes com­put­er virus­es, worms, tro­jan hors­es, spy­ware, dis­hon­est adware, crime­ware, most rootk­its, and oth­er mali­cious and unwant­ed software.
  • Domes­tic and Inter­na­tion­al Wire Trans­fers, Busi­ness-to-Busi­ness ACH pay­ments, Online Bill Pay and elec­tron­ic pay­roll pay­ments have all been used to com­mit this crime
  1. Crim­i­nals tar­get vic­tims by scams
  2. Vic­tim unknow­ing­ly installs soft­ware by click­ing on a link or vis­it­ing an infect­ed Inter­net site
  3. Fraud­sters begin mon­i­tor­ing the accounts
  4. Vic­tim logs on to their Online Banking
  5. Fraud­sters col­lect login credentials
  6. Fraud­sters wait for the right time and then depend­ing on your con­trols — they login after hours or if you are uti­liz­ing a token they wait until you enter your code and then they hijack the ses­sion and send you a mes­sage that Online Bank­ing is tem­porar­i­ly unavailable

STATISTICS

  • Mali­cious web­sites (includ­ing social net­work­ing sites)
  • Email
  • P2P down­loads (e.g. LimeWire)
  • Ads from pop­u­lar websites

Web-borne infec­tions – accord­ing to researchers, 76% of web resources used to spread mali­cious pro­grams were found in 5 coun­tries world­wide – Unit­ed States, Russ­ian Fed­er­a­tion, Nether­lands, Chi­na & Ukraine

  • Form of mal­ware that deceives or mis­leads users into pay­ing for the fake or sim­u­lat­ed removal of malware
  • Has become a grow­ing and seri­ous secu­ri­ty threat in desk­top computing
  • Main­ly relies on social engi­neer­ing in order to defeat the secu­ri­ty software
  • Most have a Tro­jan Horse com­po­nent, which users are mis­led into installing
    • Brows­er plug-in (typ­i­cal­ly toolbar)
    • Image, screen­saver or ZIP file attached to an e‑mail
    • Mul­ti­me­dia codec required to play a video clip
    • Soft­ware shared on peer-to-peer networks
    • A free online mal­ware scan­ning service
  • Crim­i­nal­ly fraud­u­lent process of attempt­ing to acquire sen­si­tive infor­ma­tion (user­names, pass­words, cred­it card details) by mas­querad­ing as a trust­wor­thy enti­ty in an elec­tron­ic communication
  • Com­mon­ly used means:
    • Social web­sites
    • Auc­tion sites
    • Online pay­ment processors
    • IT admin­is­tra­tors
  • What may be relied upon today as an indi­ca­tion that an email is authen­tic may become unre­li­able as elec­tron­ic crimes evolve
  • This is why it is impor­tant to stay abreast of chang­ing secu­ri­ty trends
  • Some experts feel e‑mail is the biggest secu­ri­ty threat of all
  • The fastest, most-effec­tive method of spread­ing mali­cious code to the largest num­ber of users
  • Also a large source of wast­ed tech­nol­o­gy resources
  • Exam­ples of cor­po­rate e‑mail waste:
    • Elec­tron­ic greet­ing cards
    • Chain let­ters
    • Jokes and graphics
    • Spam and junk e‑mail
  • Pro­vide secu­ri­ty aware­ness train­ing for our employ­ees & customers
  • Review our con­tracts – make sure that both par­ties under­stand their roles & responsibilities
  • Make sure our cus­tomers are aware of basic online secu­ri­ty standards
  • Stay informed – attend webinars/​seminars & oth­er user group meetings
  • Devel­op a lay­ered secu­ri­ty approach
  • Mon­i­tor­ing of IP addresses
  • New user con­trols – admin­is­tra­tor can cre­ate a new user. Bank must acti­vate user
  • Cal­en­dar file – fre­quen­cies and limits
  • Dual con­trol pro­cess­ing of files on sep­a­rate devices – recommended
  • Fax or out of band confirmation
  • Secure brows­er key
  • Pat­tern recog­ni­tion software
  • Edu­ca­tion is key – train your employees
  • Secure your com­put­er and networks
  • Lim­it admin­is­tra­tive rights – do not allow employ­ees to install any soft­ware with­out receiv­ing pri­or approval
  • Install and main­tain spam filters
  • Surf the Inter­net carefully
  • Install and main­tain real-time anti-virus and anti-spy­ware, desk­top fire­wall and mal­ware detec­tion and removal soft­ware – use these tools reg­u­lar­ly to scan your com­put­er. Allow for auto­mat­ic updates and sched­uled scans
  • Install routers and fire­walls to pre­vent unau­tho­rized access to your com­put­er or net­work. Change the default pass­words on all net­work devices
  • Install secu­ri­ty updates to oper­at­ing sys­tems and all appli­ca­tions as they become available
  • Block pop-ups
  • Do not open attach­ments from e‑mail – be on the alert for sus­pi­cious emails
  • Do not use pub­lic Inter­net access points
  • Rec­on­cile accounts daily
  • Note any changes in the per­for­mance of your com­put­er — dra­mat­ic loss of speed, com­put­er locks up, unex­pect­ed reboot­ing, unusu­al pop­ups, etc.
  • Make sure that your employ­ees know how and to whom to report sus­pi­cious activ­i­ty to at your com­pa­ny & the bank
  • Con­tact the bank if you:
    • Sus­pect a fraud­u­lent transaction
    • If you are try­ing to process an Online Wire or ACH Batch & you receive a main­te­nance page
    • If you receive an email claim­ing to be from the Bank and it is request­ing personal/​company information