FinAi News

No products in the cart.

Subscribe
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
Log In
No Result
View All Result
  • Banking
  • Lending
  • Payments
  • Risk & Security
  • Strategy
FinAi News
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
BAN PLUS
Log In
No Result
View All Result
FinAi News
No Result
View All Result

Typosquatting Emails Target Bank Employees

Philip RyanbyPhilip Ryan
June 25, 2015
in Risk & Security
Reading Time: 2 mins read
0
Share on Facebook

© Can Stock Photo Inc. / 4774344seanHold on, don’t open that email.

Hackers have known for years that bank employees are the best way to gain access to bank’s system. All a bad guy has to do is send an inviting email and trick the employee into opening it.

A nefarious new approach has come to the attention of security analysts employing “typosquatting,” the practice of picking versions of bank names with typographical errors — for example, bankofamerca.com, which is actually owned by Bank of America — and setting up fake bank sites there. The new wrinkle, according to Carl Leonard, principal analyst for Websense Security Labs, employs phony internal emails. Employees used to receiving dozens of internal emails a day might not look carefully at the sender’s address, and in some cases, the From address can be “spoofed,” or made to appear different than it actually is.

A routine email appearing to include a meeting invite attachment, for example, may actually contain an exploit kit that installs itself on a bank’s system, and wreaks havoc from within the bank’s walls.

“FIs are attacked 300% more than other industries,” Leonard said. “The reason is simple — financial data is more valuable than other kinds of data.”

Websense released a report on security for financial services earlier this week.

A common attack method, Leonard said, is to perform reconnaissance, then send a lure, usually an email. If that lure gets a bite — meaning it’s opened — another is sent, containing an exploit kit. This kit will allow the machine to install malware to harvest data, and potentially attack other machines. In some cases, an email server can be taken over, and fraudulent emails sent from there, either internally to employees, or externally to customers.

Whether this ominous scenario has actually happened to any FIs, Leonard didn’t say.

The next frontier beyond email is text messages. Websense is currently tracking efforts to infect mobile devices of bank employees. FIs need robust “Bring Your Own Device” policies, Leonard said, “to close as many security loopholes as possible.”

Authentication methods employing biometrics are gaining popularity in part because people are over the “creepiness factor,” said Micah Willbrand, director of global AML product marketing at NICE Actimize. Banks are also moving increasingly toward automated processes that lessen the risk of social engineering and human error.

“Sales guys cut corners to make sales,” Willbrand said. “Humans cut corners.” Software doesn’t.

Still, effective software or not, some fraud will always happen. “You set initial controls to scare off the lazy,” Willbrand said. “You push the fraud down the street. You’re trying to create a barrier online, but this can result in customers going to other places where the barriers are lower.” Willbrand was referring to nonbank players who don’t (yet) face the regulatory pressure than banks do.

For FIs though, it’s a delicate balancing act between security and convenience, but there can be few compromises where security is involved.

“Security has to be all-pervasive,” Leonard said. “Malware authors are always adapting.”

Tags: fraudhackershackingmalwarenice actimize
Previous Post

Forget yoga, wearables insurance is the path to a better life!

Next Post

Top 20 Finance Apps of the Week

Related Posts

Two people, who are made of data streams, shake hands
Risk & Security

Implementing AI for AML requires resolute leadership, comprehensive data

July 22, 2026
The OpenAI logo on a laptop computer arranged in the Brooklyn borough of New York, US, on Thursday, Jan. 12, 2023. Microsoft Corp. is in discussions to invest as much as $10 billion in OpenAI, the creator of viral artificial intelligence bot ChatGPT, according to people familiar with its plans. Photographer: Gabby Jones/Bloomberg
Risk & Security

OpenAI models breach Hugging Face, sparking cyber alarms

July 22, 2026
data streams being bottlenecked
Risk & Security

Implementing AI can relieve bottlenecks amid growing AML complexity

July 20, 2026
Next Post

Top 20 Finance Apps of the Week

Please login to join discussion

EMERGING FINTECH DIRECTORY

Emerging Fintech Directory

The Buzz Podcast

SPONSORED

Build an Antifragile Strategy to Outperform the Market

July 14, 2026

How AI and Product Experts Turn Fuzzy Requirements Into Focused Dev-ready Roadmaps

April 19, 2026

Is Your Technology Supplier There for You?

April 1, 2026

  • About Us
  • Help Center
  • Contact Us
  • Privacy Terms
  • ADA Compliance
  • Advertise

 [wt_cli_manage_consent]

Connect

twitter linkedin podcast podcast podcast
© 2026 Royal Media
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Unlock This Article

Create your free FinAi News account to access this article and stay informed on how AI is transforming financial services including banking, lending, payments, and risk.

Yes, I'd like to receive FinAi News updates, breaking news, and exclusive AI insights for financial services leaders.

Continue Reading with FinAi News Premium - Less than $2/Day

Upgrade to FinAi News Premium for unlimited access to news, insights, trends, and intelligence on how AI is transforming financial services including banking, lending, payments, and risk.
Upgrade to FinAi News Premium Subscription
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account