There have been a whopping 187 per cent rise in phishing attacks on various Indian brands in May over the previous month, and interestingly, all of these brands were in the banking sector. That’s what the latest Symantec Intelligence report suggests.
“Significantly, all phishing attacks on Indian brands in May targeted the banking sector – with one in every four using a ‘.in’ domain. And the top cyber threats were created specifically to target your bank balance,” said the latest intelligence report by the Nasdaq-listed global leader in infrastructure software enabling businesses and consumers protect their infrastructure, information, and interactions.
Symantec spokesperson in India told Financial Chronicle that Symantec Intelligence’s latest analysis of the cyber threat landscape had revealed the rise of ‘.in’ URLs in spam. Last year, the India domain (.in) ranked tenth in the distribution list, while it has now jumped to the fifth position. Furthermore, 25 per cent of phishing attacks on Indian brands used the ‘.in’ domain.
While these phishing attacks originated around the world, Hyderabad hosted the second highest number of phishing attacks on Indian brands, according to the report. Hyderabad also tops the list of cities for May that hosted phishing sites in India of non-Indian brands, followed by Nashik, New Delhi and Bangalore on the third, fourth and fifth place, respectively. Hyderabad was at seventh place in April and Thanjavur has featured in this list for the first time, the spokesperson said.
Banking threats are not new; they have been around as far back as 2003. However, even as electronic banking channels have evolved and grown, banking threats have reached a considerable level of sophistication. Particularly in India and emerging nations where banks are encouraging e-transactions as a new stream of revenue, banking threats are widely prevalent. Sality, for instance, the most prevalent malcode in India for the past two years, has the capability of spreading through a variety of means and stealing banking information.
Some of the threats used by cyber attackers to wipe out one’s bank account include ZEUS (infects personal computers, waits for users to log on to a list of targeted banks and financial institutions, and then steals their credentials and sends them to a remote server in real-time), SILENTBANKER (intercepts transactions, silently changes the user-entered destination bank account details to the attacker’s account details instead), TATANARG (enables the attacker to access your computer remotely, intercepts communication between the user and the bank, and effectively controls the infected computer) and INFOSTEALER.BANCOS (it gathers confidential financial information from the user’s computer).
“The good news is that the Reserve Bank of India has proactively directed banks to beef up their information security and risk management posture, outlining 225 checks in seven categories to protect users’ information and money from cyber threats,” Symantec said.
ritwikmukherjee@mydigitalfc.com
