EDITION:GLOBALNORTH AMERICACENTRAL & SOUTH AMERICAUK & IRELANDEUROPEMIDDLE EAST & AFRICAAUSTRALIA & NEW ZEALANDASIA
LANGUAGES:

Welcome
to ContactCenterWorld.com

Raj Wadhwani
President

President of Contact Center World
Wednesday, May 23, 2012
Learn the best practices in the industry from those who 'do the job' every day - click on Top Performers Conferences under conferences and events
OVER 129,000 MEMBERS

The Global Association for Contact Center Best Practices & Networking


Site Map
About this Site
Contact Us


 
 Pulse Survey

Global Benchmarking Study Promo

FEATURED SUPPLIERS
on ContactCenterWorld.com this week:

Global Benchmarking Study of Top Performers







Click on the company name for more details!


View:Folder:
Read:Page:
Order:Asc/Des:
To:CC:
Reply:Forward:
SearchP1:BCC:
Stack:
Error:
Apply Security Online to Protect Yourself Offline

As part of this week’s ‘Get Safe Online’ campaign, Trusteer today issued a warning that fraudulent phone calls are increasing in popularity amongst the criminal community to commit ID theft and that everyone needs to be on their guard to avoid falling victim – on or offline. One possible use for these bogus ‘bank’ calls is to utilise personal identification information stolen using malware to give fraudsters credibility as they collect the missing information required to ‘pull off’ their scams.

"The phenomenon of stealing data using one channel such as the web and using it in a different channel or context such as social engineering attacks is often overlooked", said Amit Klein, CTO of Trusteer. "Trusteer has found that data collected by Man in the Browser attacks can be used for other purposes than automated transaction fraud. Defending against the new wave of hybrid attacks requires both technology to detect MitB malware and vigilance from the users of online services."

Traditional financial malware fraud starts off by identifying the targeted bank and learning how their online banking service functions. Once fraudsters understand the online banking flows and security processes, a fraudulent scheme is designed and the corresponding malware attack is configured. Lastly, bank clients are infected with the malware and fraud starts its execution sequence.

Other forms of financial malware fraud work in reverse – First malware is placed on victims’ machines and malware logs online activity and banking credentials, fraudsters use credential data fished from malware logs to access online banking sites and perpetrate fraud. Trusteer Research has even identified fraudsters selling Zeus malware logs in the open market – the going price is between 1$ to 60cents per 1GB.?

However, the problem with this method is, in many cases, the data collected by the malware is insufficient to commit the actual fraud:

§ The one time password (OTP) authentication credentials originally collected are no longer valid

§ Banks require Transaction Signing to transfer money

§ Additional authentication data is required by the bank when logging in from a new IP address?

‘Professional caller services can be used by fraudsters to obtain the missing data required to complete a successful online fraud. A forum advertisement, discovered by Trusteer, offers a phone service with professional callers, fluent in English and European languages, who can impersonate male and female, as well as old and young voices. As with any business the service states its regular ‘operating hours’ as available during American and European working hours. The price is a rather reasonable 10$ per call. These criminals were offering calls to private customers, banks, shops, post offices and any other organisations according to the customers’ specific requirements. They’ll even prepare the spoof phone numbers to accept calls in case victims should want to call back for any reason. Trusteer’s additional security verification reveals that the group has been operational since 2009.?

Although the actual caller’s scripts are not shared in the forum advertisement we can imagine scripts used to collect the missing data would look something like:?

Step 1: Caller Establishing Credibility

The caller would use data collected by the malware to gain credibility, for example the caller will ask "Are you John Smith, living at their address, with credit card number ending with 2345?"

Step 2: Caller Collect Missing Data?Once the caller has established credibility, they will go on to collect:

a) The SMS OTP - for example "We have just sent you an SMS with an OTP so we can make sure you are John Smith, can you please read it for me?"

b) Collect any other additional authentication information, for example "For verification, can you please give me the last four digits of your SSN?"

c) They can even get the user to generate a transaction signing code with fraudulent payee and amount information, for example "We need to calibrate your transaction signing reader so could you please enter the following details online and then tell us what happens."?

Amit Klein, CTO of Trusteer said, "While everyone’s attention is focused on protecting themselves in the ‘virtual’ world, they’re still very much at risk back here in the ‘real’ world. Fraudsters are turning to phone call services in an endeavour to trick people into disclosing their confidential information, sourcing professional callers to impersonate representatives from financial organisations. The sad truth is that it is actually far easier to perpetrate social engineering over the phone than many realise."?

Klein concludes "It’s rather disturbing how professional the group’s marketing is. It claims to have extensive experience working with bank customers, banks and shops. It even highlights their financial expertise, bragging that in the majority of cases they complete bank transfers and transactions."?

For individuals, Trusteer advises they:

1 make sure to use up-to-date anti-malware solutions, especially any recommended by their bank, to prevent data theft in the first instance;

2 treat all unsolicited phone calls with caution, irrespective of any validation information the caller may offer;

3 use contact numbers provided by the bank, not the caller, to verify the authenticity of the contact.?


Related Groups
Banking / Finance / Credit
Computer Hardware / Software
CRM
Performance
Quality
Security
Technology

Related News
Trusteer Receives Medal at UK IT Industry Award
NEFCU Selects Trusteer to Meet New FFIEC Security Guidelines
First Data Selects Trusteer to Help Financial Institutions Comply with Banking Security
Spyeye Trojan Attacks Airline Website That Accepts Bank Debit Card Payments
Trusteer Rapport Named Best Fraud Prevention Solution
Underground Call-centre for Identity Theft Uncovered

About Trusteer:
Trusteer offers solutions for financial institutions, home users, and businesses. Financial institutions use Trusteer services to secure their customers' browsers from financial malware attacks and fraudulent websites. Trusteer allows financial institutions to proactively protect against attacks that target customers directly. In addition, Trusteer allows financial institutions to receive immediate alerts, and to report whenever a new threat is launched against them or their customers. Using Trusteer, financial institutions can investigate new zero day threats, suspicious computers, and reconnected infected computers.

More Editorial from Trusteer
Trusteer Rapport Named Best Fraud Prevention Solution
Trusteer Receives Medal at UK IT Industry Award
Underground Call-centre for Identity Theft Uncovered
NEFCU Selects Trusteer to Meet New FFIEC Security Guidelines
First SpyEye Attack on Android Mobile Platform is Virtually Undetectable
Trusteer Discovers New Worm-Based Financial Malware

Date Published: Tuesday, November 08, 2011
Printer Friendly Version Printer friendly version
 Recommend to a friend
 Bookmark & Share



Post Message

Post Message






 

 

 





-Back To Top-

| Request Information from CRM & Contact Center Suppliers | About ContactCenterWorld |
| Advertise CRM & Contact Center Solutions | Link to this site |
| Submit CRM and Contact Center Content | Contact Us | Privacy Policy |
| Recommend this site to other CRM & Contact Center Professionals | Disclaimer |

©ContactCenterWorld.com 1999-2011
The Global Support Organization For Contact Center Professionals & the place for information on:
Quality Monitoring, Recruitment, Self Service, Speech Recognition, Telemarketing, Virtual Contact Center, VoIP, Web Chat, Work at Home, Workforce Management