The criminals who send fake emails and internet links do not have your online banking details, and are hoping you will give them up. (Photo from Kaspersky.com)
Internet banking needs to implement stronger online security to better protect customers who fall prey to web “phishing”, an online expert says.
An inspection of bank websites found only some banks have installed what he calls “anti-web phishing” to double-protect their customers while many do not have this feature on their networks.
A check by the Bangkok Post found that Bangkok Bank and Kasikorn Bank use different measures to deal with phishing. The state-run Krung Thai Bank was not available for comment.
Under the phishing scam, customers who are deceived into clicking on a link in emails claimed to be sent by banks are taken to websites made by online fraudsters. On these pages, which look almost exactly the same as bank websites, if they enter user identities and passwords, the information can easily be collected by criminals.
But with anti-web phishing programmes, customers who are not fully aware of the trick will know immediately whether they come to fake sites. The programme, now being used by CIMB Thai Bank, sends customers “secure words”, or private messages or codes which they earlier gave to the bank, after they type in their user ID. This enables them to check whether they are logging into the right place as only the customers and the bank know the secure words, said Orathip Wongkajorn, first vice-president of the Kuala Lumpur-based bank.
If the customers do not get their correct secure words, Ms Orathip said, they will not go to a next stage to enter their passwords, cutting short the scam to get their information.
“This is a simple but effective measure against the ploy to phish unaware customers,” said the expert.
Yet some banks have not installed it even though the matter is not complex, he said, after his visits to many bank webpages. This makes the intensity of online security measures different from bank to bank, he said.
“Perhaps the banks think it’s not convenient for their customers as they are required to go through additional steps under the anti-web phishing programme to get into their bank accounts,” he said.
But different security standards can lead to legal disputes if customers are exposed to phishing and subsequently money to online criminals. It is currently hard to determine who — banks or customers — should be held responsible for the damages, he said.
He called on the Bank of Thailand to set a stronger minimum security standard to commit all banks to adopting the same online security approach against cyber attackers. If the banks do their best to reinforce their cyber safety, nobody will point a finger at them if customers still fall victim to tricksters.
It does not mean major banks’ current attempts to deal with web phishing are not good, said the expert, whose work involves handling various online fraud cases. These steps, including the launch of warnings against those emails with dangerous links, are helpful. “But how can the banks make sure message receivers understand these warnings?” he said, basing his experience on victims who rarely took the warnings seriously.
The target of phishing gangs is not tech enthusiasts or the so-called millenial generation, those born between 1982 and 2005. It’s people in the classes of “baby boomers” and “generation X”, born between 1945 and 1960, and 1961 and 1981 respectively, the expert said. People of this age often have more money and, as a result, more damage is caused if they are swindled, he said.
The Bangkok Post has found a mix of reactions to banks warnings against online phishing. Senior employee Sujinda Borvorn said such warnings are not enough, and urged banks to install anti-web phishing programmes to help customers, while Techawit Sompetch, a younger office worker in his mid-20s, said the warnings are helpful but he was not confident they can help everyone.
One man who signed up for the much-promoted Prompt Pay scheme, an online money transfer system, became a victim after he received an email last month with the bank logo and what it said was a “message alert” which prompted him to click on a link to check the message. Posting a complaint on Pantip.com, he believed there might have been a problem with his Prompt Pay registration and claimed he had never been warned by the bank.
“About 80% of internet users fall prey to web phishing,” said Technological Crime Suppression Division’s police inspector Patompong Sillapasuk.
They get their email addresses from online shops which bank customers leave their information with and invent a story saying their accounts have been hacked. Alarmed victims easily fail to check whether it is a lie and easily forget banks’ warnings because they are more worried about their money, Pol Maj Patompong said.
Leading financial institutions such as Bangkok Bank and Kasikorn Bank are aware online criminals are exploiting these customers’ weak points as the banks’ online system is intensively guarded. Executives insisted they are helping their customers by working with experts to block access to phishing webpages and shutting them down.
The anti-web phishing programme is only one solution as there are many threats in the cyber world, especially harmful computer viruses which can put customers at risk. Multi-prong measures, including increasing customer awareness are needed to help banks combat cybercrimes, Kasikorn Bank’s first senior vice-president Art Wichiencharoen said.
Web phishing is not an easy issue to deal with as it occurs outside a bank’s security wall, Bangkok Bank executive vice-president Prassanee Ouiyamaphan said. One of the best prevention measures is to educate customers, she said.
