Businesses fall prey to cyberthieves' cunning

April 4, 2011 By Steve Johnson

Among the growing ranks of consumers, business owners and others being lured by the convenience of online banking are legions of cybercrooks who have found the technology a convenient way to steal from unsuspecting victims.

More than 72 million households now manage their money online - up from about 12 million a decade ago, according to the financial services firm Fiserv. It's unclear how many of them have been targeted by crooks, but the FBI and a consortium of other government agencies reported in October that "thousands of businesses, small and large, have reportedly fallen victims to this type of fraud" with municipalities and nonprofit organizations increasingly coming under attack. And unlike individuals, they lack legal protections for their losses.

Ann Talbot learned of the danger four years ago when nearly $21,000 was taken from the bank account of her general contracting firm, Golden State Bridge. Then in May last year, cybercrooks struck her Martinez, Calif., company again, making off with about $100,000 from another account.

By then, Golden State had taken out an online-theft insurance policy, which limited its liability to about $10,000, according to Talbot, the company's chief financial officer. Even so, she is wary of the outlaws preying increasingly on those who bank via the Web.

"It's a huge problem," she said, adding that many people "have no idea of the threat out there."

It's just not lay people, either. FBI Director Robert Mueller told the Commonwealth Club of California in 2009 that he stopped online banking after getting an email that appeared to be from his bank, but that he realized was bogus after answering a couple of its questions.

After that, Mueller said, his wife told him, "no more for you."

The cyberthieves aren't fussy about whom they target.

-In September last year, in New York announced against 37 people in a global online scheme that allegedly netted the crooks more than $3 million, including $130,000 from an unidentified hospital's California bank account.

-In October 2009, lawbreakers tried to abscond with $87,000 from a Danville, Calif., church, according to the Washington Post. Luckily, the transfers were blocked by the church's bank. Last August, the Catholic Diocese in Des Moines, Iowa lost several hundred thousand dollars in an online banking breach.

-In April last year, Aleksey Volynskiy was sentenced to 37 months in prison for plotting with hackers in the U.S. and Russia to loot individual Charles Schwab brokerage accounts.

Sarah Bulgatz, a spokeswoman for Charles Schwab, said the accounts were accessed through the victims' computers and not those of her company, adding that Schwab reimburses individuals for such losses. Under the federal Electronic Fund Transfers law, the liability of consumers who report an online bank loss within two days of discovering it is limited to $50 and only after 60 days are they liable for the entire amount.

But the law doesn't protect commercial, governmental or nonprofit enterprises. And the sizable sums those entities often maintain in their financial accounts make them attractive quarry for criminals. Of 504 small and medium-size businesses recently surveyed by Guardian Analytics, which helps banks and credit unions prevent theft, 32 percent said they had experienced an online-banking scam during the previous year.

While some banks have taken steps to prevent such larceny, many others have left themselves easy prey to hackers, who are becoming highly organized and using increasingly sophisticated tactics, said Guardian CEO Terry Austin. With more and more people banking online, he added, "the banking industry in general needs to step up to provide a higher level of security."

Some people - including Talbot of Golden State Bridge - also are urging lawmakers to give commercial ventures the same reimbursements afforded individuals. They have formed an online organization - Cyber Looting Awareness & Security Project - to lobby for the change.

That worries the American Bankers Association. It fears that if a company was shielded from liability the way a consumer is, "the business would be less inclined to take the protection measures necessary to protect their online accounts," which might prompt banks to stop offering online services, said the group's spokesman Doug Johnson.

He added that banks are working with law enforcement authorities to try to limit such crimes but that the problem is increasing because more people are banking online.

Still, many others are reluctant to send their financial information across the Internet. Of the more than 3,000 respondents to a survey by German security software firm Avira in November, 31 percent - nearly one out of three - said they avoid online banking entirely for fear of being ripped off.

Even a security expert can get hoodwinked, said Larry Ponemon of the Ponemon Institute, a data-protection research outfit in Michigan. After recently receiving an email that seemed to be from his bank, "I came really close to doing something silly" that might have compromised his finances, he said. "The bad guys are getting really smart."

One of the crooks' methods is to send a person a "spear phishing" email containing a malicious attachment. Once the person opens it, their computer is infected with malware that snaps up their bank-account login information, allowing the thief to masquerade as the person and steal their money.

Another common scam is to create websites that look just like those of real banks. When people mistakenly give the sites their financial information, criminals use it to make withdrawals.

The increasing numbers of people who bank via their cell phones face another threat, according to a report in November by viaForensics, a Chicago information security firm. It discovered that some phones stored the owner's financial data, making the information vulnerable if the phone is lost. Bogus banking applications for phones also have been designed to steal money from anyone using them.

Although banks are working to fix some of the phone vulnerabilities, "it's still pretty bad out there," said Andrew Hoag, viaForensics' chief investigative officer.

Unfortunately, by the time many people realize their savings have been hijacked, there's little they can do to get it back, said David Johnston, whose Modesto, Calif., electric sign business, Sign Designs, lost about $20,000 two years ago when thieves broke into its online account and transferred the money overseas.

"I was very angry," he said. "Your money should be safe in the bank."

(c) 2011, San Jose Mercury News (San Jose, Calif.).
Distributed by McClatchy-Tribune Information Services.


Rank not rated yet
Relevant PhysicsForums posts

More news stories

SpotterRF debuts Radar Backpack Kit (w/ Video)

(Phys.org) -- SpotterRF has announced a special radar backpack kit designed to enhance situational awareness for soldiers on the ground. The company says its special radar is designed for warfighters as part ...

Technology / Hi Tech & Innovation

created 19 hours ago | popularity 5 / 5 (5) | comments 12 | with audio podcast report

Probability of contamination from severe nuclear reactor accidents is higher than expected: study

Catastrophic nuclear accidents such as the core meltdowns in Chernobyl and Fukushima are more likely to happen than previously assumed. Based on the operating hours of all civil nuclear reactors and the number ...

Technology / Energy & Green Tech

created May 22, 2012 | popularity 3.6 / 5 (21) | comments 55 | with audio podcast

Delphi gasoline-injection engine technique rivals hybrid's edge

(Phys.org) -- Running a diesel like engine on gasoline is something Delphi is doing in notable fashion. They claim they are on to a promising way to enjoy an engine that gives the vehicle owner high efficiency ...

Technology / Energy & Green Tech

created May 21, 2012 | popularity 4.7 / 5 (18) | comments 37 | with audio podcast report

HyperSolar shows dirty water no barrier to power world

(Phys.org) -- The Santa Barbara, California, company, HyperSolar, is set to transparently share the ups and downs of its research experiences toward the company’s ultimate vision, successfully producing ...

Technology / Energy & Green Tech

created May 24, 2012 | popularity 4.8 / 5 (15) | comments 17 | with audio podcast report

Tesla to launch electric sedan in US on June 22

Tesla Motors said Tuesday it would begin deliveries of "the world's first premium electric sedan" on June 22, slightly ahead of schedule.

Technology / Energy & Green Tech

created May 22, 2012 | popularity 4.5 / 5 (11) | comments 18


Scientist: Evolution debate will soon be history

(AP) -- Richard Leakey predicts skepticism over evolution will soon be history. Not that the avowed atheist has any doubts himself.

Dell tablet leak: 10.1-inch display, two-battery choice

(Phys.org) -- Headline after headline talks about vendors’ tablets in the wings as likely number-one contenders for the iPad. Such claims have justifiably been taken with a grain of salt, considering ...

SpaceX capsule has 'new car' smell, astronauts say (Update)

SpaceX's Dragon cargo vessel smells like a new car, said astronauts at the International Space Station after opening the hatches Saturday following the spacecraft's landmark mission to the orbiting lab.

Thousands of shellfish found dead in Peru

Thousands of crustaceans were found dead off the coast of Lima following the mystery mass death of dolphins and pelicans, the Peruvian Navy said Friday.

Astronomers seize last chance in lifetime for Venus Transit

Astronomers are gearing for one the rarest events in the Solar System: an alignment of Earth, Venus and the Sun that will not be seen for another 105 years.

Keep food safety in mind this memorial day weekend

(HealthDay) -- Picnics, parades and cookouts are as much a part of Memorial Day weekend as tributes to the United States' war veterans.