Internet banking fraud: what can be done?

It is simple. My phone number is linked to the IMEI number on my phone. If this change they must block the transaction. If you get a new phone you need to go into the bank with all the details.
 
It is simple. My phone number is linked to the IMEI number on my phone. If this change they must block the transaction. If you get a new phone you need to go into the bank with all the details.

I totally agree.
Downside it that with the total disregard for human life, thieves will steal the phone and ensure that you cannot report it stolen
 
A good friend of mine in Mobile Security put it quite well.
'when you build a system that uses business rules to limit risk instead of implementing secure processes then it is just a matter of time before it is exploited... '
 
Useless suggestions. Why don't the banks have a 48 hour cooling period for transfers to new beneficiaries over a certain threshold?
 
Why not just something simple like google authenticator that is paired with the software and generates a random number as one time pin. Those are directly linked to accounts and are very simple to set up.
 
Useless suggestions. Why don't the banks have a 48 hour cooling period for transfers to new beneficiaries over a certain threshold?
Standard Bank do (well, 24 hours at least):
That doesn't help with ABSA, it seems one can change the limits within their internet banking system. Other banks require one to go into a branch to do this.

About two years ago I noticed Standard Bank started delaying delaying transactions to any newly-created beneficiaries by 24 hours. Perhaps ABSA should do this too.
 
Capitec has a simple enough system that works.


The big 4 need to step up and do more for clients.
 
In Switzerland one of their banks issued clients with a smartcard reader, so when you doing online banking you have to insert your chip + pin card into the reader, so you need online user name / password and the credit card and it's pin.
 
How about the ISP's conform to the law and prevent their staff from doing illegal sim-swops for a start?

It may only be half of the problem, but its a bloody big half and all I've heard this far is excuses.
 
Capitec has a simple enough system that works.

Exactly, their app is not bound to a cellphone no, rather cellphone itself. But, they do have some of the best IT and security employees of all the banks
 
Opt-in extra level of RVN authentication. Send two different RVN numbers, one to SMS, one to email address. Require both to complete the transaction. A few extra clicks for increased peace of mind, as the criminals would now need to not only sim swap, but gain control of your email account. Changing email address for your account should require visiting a branch with ID.

No extra cost, easy to implement. I'm betting they couldn't be arsed.
 
an automated system that requires a customer to call in and enter a second pin and multiple notifications on two or three sims might also help
 
Opt-in extra level of RVN authentication. Send two different RVN numbers, one to SMS, one to email address. Require both to complete the transaction. A few extra clicks for increased peace of mind, as the criminals would now need to not only sim swap, but gain control of your email account. Changing email address for your account should require visiting a branch with ID.

No extra cost, easy to implement. I'm betting they couldn't be arsed.

Not everyone has access to email on the go. Also, there is sometimes a delay that would cause problems.

Email wouldn't work.

The random number generating dongle + SMS would do the trick.

Plus 24 hour payment delay on new beneficiaries.

Plus 24 hour delay on sim swap, as well as sms notification on application (ie to old sim).

Can't see anyone getting past the above without intervention by the victim.
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X