Topbar


ITWeb - The Technology News Site
ITWEB JOBS
stick_short.gif (49 bytes)
BRAINSTORM
stick_short.gif (49 bytes)
FREE NEWSLETTERS
stick_short.gif (49 bytes)
ONLINE STORE
stick_short.gif (49 bytes)
RESEARCH
SALES KIT
• Register
• Post your CV
• Find your job
• Subscribe
• Read online
• Get 3 trial issues
• News Daily
• News Weekly
• Other newsletters
• Special editions
• Conference DVDs
• Brainstorm Magazine
• IT Directory
• Salary Survey
• Advertising
• Sponsorships
• Press Office
back to the ITWeb home page Sales info Brought To You By
SEARCH 
INTERNET
Huawei unveils latest wireless modem in SA
SA Tourism gets new face
more in internet...  

advertisement


Loading...
FINANCIAL
Singapore intros SME self-help portal
NetApp reports Q4 results
more in financial...  
COMPUTING
Blatter upbeat on 2010
Countdown to virtual classroom
more in computing...  
BUSINESS
VM6 SME solution released
TeamDynamixHE updates PPM software
more in business...  
ENTERPRISE
Open Text supports standard
SolTech appoints director
more in enterprise...  
NETWORKING
NetApp reports Q4 results
Corporate networks must be secure
more in networking...  
TELECOMS
Genband snaps up Nortel VOIP
MTN spends R500m on network upgrade
more in telecoms...  
CHANNEL
Fujitsu appoints distributor
Perfomanta Technologies on growth path
more in channel...  

advertisement

Back to the Security Home Page 13 June 2006 
Ĺ  Security
Cafés create online banking headache
BY PAUL VECCHIATTO, ITWEB CAPE TOWN CORRESPONDENT
READ IN THIS STORY:
Victim's tale
Low awareness
[Cape Town | ITWeb, 13 June 2006] - A spate of online banking fraud, using key-logger software, has got the commercial banks scratching their heads about how to engage Internet cafés to help improve security, the banks say.

During the past month, several members of various syndicates have been arrested and tried on fraud charges in Gauteng, KwaZulu-Natal and the Western Cape for installing spyware or software that logs keystrokes, and then using people's passwords to clean out their accounts.

"Security is a partnership between a bank and its customers. The real risk comes around when using third-party hardware and something probably needs to be done to raise awareness at places such as Internet cafés," says Christo Vrey, GM of digital channels, Absa.

Vrey says a lot depends on how these parties manage their physical infrastructure, as this could often be the weak link in the security chain.

"We have identified several 'security chokepoints' in the online banking system. For instance, the ability to create new beneficiaries for an account; in such a case one needs an eight-digit code and only then will that beneficiary be paid," he says.

Herman Singh, Standard Bank's director for technology engineering, says the banks are constantly looking at new ways to review the security settings for their online offerings.

"The on-screen pop-up pads - a keypad that constantly moves around the screen - could be compromised by new generations of key-logger software, although we have not come across any cases of that yet. However, there are other security settings that come into play, such as 'mynotification', which is an SMS that alerts one to any transaction taking place," he says.

Victim's tale

ITWeb spoke to one online banking fraud victim in Cape Town, who said her account was compromised earlier this month through key-logging software at a PostNet branch.

According to the victim, she popped in to top up her credit card account and then went to see a film.

"Because I had turned off my cellphone, I did not get the SMS alert that my account had been accessed and about R3 000 was taken out without my authorisation. It all happened in a matter of minutes," she says.

According to the victim, her bank refunded her the full amount within three days and issued her with a 'digitag' - a device that provides randomly generated numbers to use as authorisation codes.

Chris Kotze, CEO of FNB Online, says fraudsters are using a number of devises to get key-logger software onto third-party hardware.

"Sometimes they install a little pipe gadget that plugs between the keyboard and the PC, and other times they just walk into an Internet café and download spyware without the owners knowing," he says.

Low awareness

A senior official at one of the major commercial banks says the financial institutions are wondering how to engage Internet cafés and other public PC providers.

"Something has to be done, especially in the high tourist areas such as Cape Town where Internet banking is really an important tool for travellers," he says.

ITWeb found that security awareness was quite low at several central Cape Town Internet cafés.

At one café, a waiter said: "Online banking security is the bank's problem not ours."

Another café owner said he just told his clients not to do any Internet banking from his premises.

"I really don't know who comes in and out, so I cannot vouch for anyone's privacy and what people are doing," he said.

Related stories:
Scorpions arrest Internet banking scammer
Scorpions probe banking syndicate
SEND TO A FRIEND  | SEND SMS  |  PRINT  |  POST A COMMENT
 ABOUT THE AUTHOR
Paul Vecchiatto is ITWeb's Cape Town correspondent. He can be contacted on (011) 807 3294 or at paul@itweb.co.za.
  MORE INTERNET NEWS
  Obama declines job?
  Obama takes the Web by storm
   MOST POPULAR
  MTN, Neotel boost national capacity
  Neotel network takes a knock
  Fifa careful on Satyam troubles
J:\itweb01\sections\viruswatch\sponsor1.htm

Quick Print
Send to a friend
Send to a cell phone
Personal Archive

Register | Learn more...
Latest Blogs:
TownBoy
TownBoy-“Mobile Mumbles - Part 2”(Weapons of Mobile Destruction
Bullfrog
I am bestowed by the ironies of my life.....
jelo
The OpenSource Hoohah
www.blogit.co.za
Give us feedback
advertisement

ITWeb Events Calendar
2010
> Virtualisation & Cloud Computing
21-22 July | The Forum, Bryanston
This conference is designed for enterprise IT professionals who want to understand how to better manage the virtualised environment and also learn about the various categories of cloud computing and what the implications of moving to the cloud are for their business.
> MobileBiz
28-29 July |  Vodaworld, Midrand
Attend this conference and you will explore the potential of the mobile business platform for B2B and B2C applications, as well as the significant technical and managerial challenges.
> SMEXA
3-4 August | The Forum, Bryanston
SMEXA is the only forum of its kind in SA, bringing you the best ITSM trends and solutions information available, and providing an opportunity to evaluate the various solutions available, in a hands-on environment.



Copyright (c) 1996 - 2010 ITWeb Limited. All rights reserved.
Would you like to see your news here? Contact us for more details at itnews@itweb.co.za
Striata Rackspace Sophos BBG Technologies