A bank protects two things at once, every day: its customers' money and their trust. And attackers no longer break into vaults. They trick people.
Banks are attacked because that is where the money is. It is a simple reason, and that is why it never goes away. What has changed in the last few years is that an attacker no longer needs to break into a complex system. More often than not, it is easier to call a frightened customer or a busy employee and politely ask for exactly what they need.
That means a bank's security is no longer just the IT team's job. It is also about how the person at the counter reacts, the customer in the app, and the manager who approves a large payment.
Almost all of today's fraud revolves around a single idea: to get you to do, with your own hand, what the attacker wants.
They all share two things: a rush and a fear. That is why they work. Nobody thinks clearly when told they will lose money in the next five minutes.
It is called social engineering, but in plain terms it simply means tricking the person. The attacker is not looking for a hole in the system. They are looking for someone who has access and can be talked into handing it over.
An example we see often: someone calls support, pretends to be an upset customer, says they have lost access and urgently need a reset. If the employee wants to be helpful and skips a check, the attacker has just walked into the account. No technology catches this if the person has not been taught to recognise the pattern.
A bank has strict, overlapping rules, but the part that matters in a data fraud comes down to a few things.
No single measure solves everything. But a few of them put together block the large majority of fraud.
At INFOSHARE we help banks and financial firms put these in place: from information security and security testing to training the people. And for the personal-data side, everything is visible and provable in one place, in the askGDPR platform.
Most start with phishing (fake emails), vishing (fake calls where someone pretends to be the bank) and smishing (fake text messages). The goal is always the same: to convince a customer or an employee to hand over a password, a code received on the phone, or to approve a payment. Fraud through social engineering, meaning tricking the person, is far more common than technically breaking into the systems.
Because that is where the money is, along with the data that leads to money: accounts, cards, transaction history, identity details. A successful attack turns into profit straight away, so banks are attacked constantly and have to defend themselves every day, not now and then.
Under GDPR, the bank must notify the supervisory authority within 72 hours of becoming aware of the breach and, if the risk to customers is high, notify them too. At the same time it has to stop the leak, gather the evidence and keep a record of the incident.
Yes. It asks for something the person knows (the password) plus something they have (the code on the phone), so a stolen password is no longer enough. It is not perfect, because some attackers trick the customer into handing over the code as well, but it cuts fraud significantly and is one of the cheapest measures for how much it blocks.
We assess the risks, test your people and systems, and put together a defence plan everyone can understand, not just the IT team.