Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

4/4/2011
02:23 PM
50%
50%

75% Of SMB Banking Fraud Occurs Online

Most scams involved online account takeover or theft, according to a study commissioned by security vendor Guardian Analytics and conducted by Ponemon Institute.

Three out of four small and midsize businesses that encountered banking fraud during the past year were victimized online, according to a new study.

Well over half -- 56% -- of those companies experienced some form of banking-related scam during the previous 12 months, according to the report. About 75% of those cases involved online account takeover or other Web-based fraud. Some 61% of SMBs that fell prey to bank fraud were victimized more than once.

The 2011 Business Banking Trust Study, commissioned by security vendor Guardian Analytics and conducted by Ponemon Institute, included 533 businesses with fewer than 200 employees and average annual revenue of $21.6 million. All respondents were owners or senior executives with access to their company's corporate bank accounts. Guardian Analytics CEO Terry Austin noted that the current fraud numbers -- particularly in the online security arena -- showed remarkably little change from the 2010 version, the first year that Guardian sponsored the study. Last year's study found the same rate of Web-based fraud -- 75% of all cases occurred online.

"What we highlighted in 2010 was that the fraud problem was bigger than we expected and having a pretty substantial impact on businesses and the banks that serve them, and it hasn't gotten any better," said Guardian Analytics CEO Terry Austin. "In some cases it has gotten worse, but it certainly hasn't improved over the [last] 12 months."

Small and midsize businesses that manage their money with smaller banks aren't any more likely to run into fraud -- it occurred just as often at midsize or large financial institutions. The study also found that 78% of bank scams involving SMB accounts weren't discovered until after funds were transferred outside of the institution.

"The banks have not stepped up and adopted the techniques and the technology that is available to them in a broad enough fashion to make any material difference," Austin said. He added that some banks are doing a better job combating online crime than others, but the segment overall is losing the fight with fraudsters. "As an industry, the needle hasn't really moved."

Some 31% of the victimized SMBs included in the study said their bank didn't compensate them for fraud-related losses, while another 29% were only partially paid back. Just 8% of those surveyed said their bank fully covered their fraud-related losses.

Austin said the real onus in online banking security lies with the institutions rather than businesses that may not have the resources or expertise to contend with fallout from the Zeus botnet and other threats. While Austin's company recommends SMBs take certain steps to protect their company accounts online, he acknowledges that some of the practices -- such as designating a dedicated PC to be used only for banking -- may not be realistic for the smallest of businesses. He also notes that the technique most commonly used by SMBs in the study -- 78% perform monthly account reconciliations to check for fraud -- correlates closely to the finding that banks are only uncovering scams after the money is stolen.

"Businesses expect their banks to take responsibility for this," Austin said, adding that the banks themselves usually have deeper resources and better technology access than their small business customers. "Expecting [SMBs] to become security experts and adopt a wide array of techniques is pretty unrealistic."

Adding another potential wrinkle in online banking security for SMBs: More than one-third (38%) of respondents said they access their company's accounts on a tablet or smartphone, up from 23% in the 2010 version of the study.

"[Mobile] is a new and pronounced vulnerability, primarily because it's more frequent access and more variability in the endpoint device being used to access the system," Austin said. Mobile adoption further fuels Austin's view that banks need to focus on account protection from a server and back-end perspective, rather than worrying about every potential endpoint. "They need to be examining all of the information about the individual user as they access online banking -- that is the best and most effective way of protecting against fraudulent activity."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
Former CISA Director Chris Krebs Discusses Risk Management & Threat Intel
Kelly Sheridan, Staff Editor, Dark Reading,  2/23/2021
Edge-DRsplash-10-edge-articles
Security + Fraud Protection: Your One-Two Punch Against Cyberattacks
Joshua Goldfarb, Director of Product Management at F5,  2/23/2021
News
Cybercrime Groups More Prolific, Focus on Healthcare in 2020
Robert Lemos, Contributing Writer,  2/22/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Building the SOC of the Future
Building the SOC of the Future
Digital transformation, cloud-focused attacks, and a worldwide pandemic. The past year has changed the way business works and the way security teams operate. There is no going back.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-27132
PUBLISHED: 2021-02-27
SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.
CVE-2021-25284
PUBLISHED: 2021-02-27
An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.
CVE-2021-3144
PUBLISHED: 2021-02-27
In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)
CVE-2021-3148
PUBLISHED: 2021-02-27
An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py.
CVE-2021-3151
PUBLISHED: 2021-02-27
i-doit before 1.16.0 is affected by Stored Cross-Site Scripting (XSS) issues that could allow remote authenticated attackers to inject arbitrary web script or HTML via C__MONITORING__CONFIG__TITLE, SM2__C__MONITORING__CONFIG__TITLE, C__MONITORING__CONFIG__PATH, SM2__C__MONITORING__CONFIG__PATH, C__M...