COMMENTARY

When scammers can empty your bank accounts of S$8.5m in minutes, where is the sense of security?

Dennis Chan
Published Mon, Jan 17, 2022 · 09:50 PM

    MY first full-time employment was with a bank. On my first day at work, the trainer repeatedly emphasised the importance of integrity. I can still recall his words from 34 years ago: "It's very easy to steal from a bank. But impossible to get away with it."

    Now the reason why there aren't more theft cases in a bank than the average organisation is not that banks are able to hire only upright citizens. It is that their numerous internal checks and balances ensure that the theft will not go unnoticed and the thief will be caught. Never mind integrity, jail time is a major deterrent to any would-be criminal.

    These safeguards extend to customers transacting at branches too. As a customer, not only do you need to be present physically but you also need to produce your identification card, bank book and a matching signature signed in front of the teller to withdraw money.

    I thought Internet banking was just as safe until news broke late December that nearly 470 account holders of OCBC Bank had lost at least S$8.5 million in a phishing scam.

    The stories told by the victims carry a common thread: each had received a fake SMS that seemed real because it was part of a thread containing legitimate communication from OCBC previously. The content of the fake SMS varied, from telling the recipients that their accounts were in danger of being deactivated to seeking confirmation from recipients that an unknown payee had been added to their accounts. The victims were invited to click on a link to remedy the situation. They then unsuspectingly entered their access code and password on the phishing website, enabling the scammers to use the information to siphon the money in the account overseas.

    There were some giveaways, of course. The URL in the fake SMS was in bitly form - a legitimate means to shorten a long address but which also masks the actual address. Upon clicking on the link, the address bar of the displayed webpage did not show the proper OCBC address - a big red flag. But with Internet technology moving so fast and banks constantly updating their online processes, it is not unreasonable that the victims mistook these signs as yet another technological iteration by the bank.

    The sums lost by the victims were mind-boggling: S$250,000 belonging to a 38-year-old software engineer; S$120,000 from a young couple saving to start a family; and S$100,000 by a mother of 7. No doubt there are many more distressing stories that have not been made public.

    It is not good enough for a bank to claim that its security system held firm or that it had issued repeated warnings to customers not to fall prey to phishing expeditions.

    The proof is in the pudding. Has there been any incident in Singapore's history where 470 customers lost their savings to brick-and-mortar banking frauds in a month? I would wager none, not even over the course of a year. This suggests that current online banking practice is riskier than transacting over the counter. For example, if I lose my bank book and my IC to an impersonator, I wouldn't expect him to be able to cash out my entire savings from the teller with no questions asked.

    What does it say about the weight of cash in online banking when it's as effortless to empty an account of S$200,000 as it is of S$200?

    I'm no Luddite and do not propose we turn back time.

    But due to the scale and verisimilitude in the recent scams, the industry and authorities must do a thorough rethink on the processes and underlying assumptions of digital banking.

    For instance, should banks be in such a tearing hurry to do away with the physical or hard token?

    Two-factor authentication was introduced to enhance the security of online banking. But as it turned out, the scammers were able to find a way around it. Did they manage to trick the victims into generating the necessary password from their physical token for higher-order transactions, or did the scammers commandeer the soft token remotely? If it's the latter, banks should consider preserving the use of the physical token. Indeed, OCBC has reversed an earlier decision to phase out the physical token. It should do more - make it compulsory for a customer who wants to switch to a soft token to do so at a branch or speak to a phone banking officer, with a 48-hour activation delay as an added safeguard.

    Realistically, this will need the Monetary Authority of Singapore to make it a part of regulatory requirement. No bank will want to hobble itself to a process that inconveniences its own customers if rival banks are free to disregard it.

    Banks also need to improve their fraud detection algorithms in sussing out unusual transactions and find a way to quickly contact account holders when anomalies are detected. In addition, customers who are alerted must be able to do something about it. Some victims had reported getting genuine pings from OCBC over the unauthorised transactions but were helpless to put a stop to it because they couldn't get through to the bank's fraud reporting hotline.

    It's not just the banking industry that needs to reexamine their processes. The telcos do too, since the trigger for the scams stemmed from the ability of the scammers to use number masking in SMSes to masquerade as OCBC. If nothing is done about it, there may come a time when the short messaging system is seen as a charlatan's epistle.

    It is heartening to note that OCBC has started making goodwill payments to some victims of the scams. Prevention is better than cure, however, not to mention the need to avoid the moral hazard that could surface if customers become lax with security measures if there were to be an automatic bank backstop for phishing scams.

    More work needs to be done to build up society resilience against banking frauds for 2 reasons.

    First, Singapore will soon see the entry of digital-only banks, in which innovations in terms of ease of banking will surely rank high as a factor to differentiate the upstarts from the traditional banks. These new entrants must be mindful to strike the right balance between efficiency/convenience and security.

    Second, Singapore is an ageing society. Studies have shown that the elderly are most vulnerable to tricksters as cognitive ability dulls with age.

    If the elderly did not seem overly represented from among the victims in the December scams, it may be fortuituously due to the fact that many of them are not digital banking users. But today's boomers are. As they become older, they may be exposed to greater risks than the current elderly.

    These days, thieves don't need to climb through windows or break through doors. They don't need to be physically present in Singapore and risking imprisonment if caught. This means there will be more of these scammers, each more brazen than the last.

    Times have changed, and the wisdom of my trainer of yesteryears is only partly right today. Yes, it's still easy to steal from a bank, or at least, from some of its customers. But digital thieving and getting away scot-free has never been easier.

    Personally, I have been thinking about delinking some of my accounts from digital banking once I hit a certain age. Let them break down my door if they want my money.