COMMENTARY

Bank on hard token to secure your savings from Internet scammers

Dennis Chan

Dennis Chan

Published Wed, Jul 12, 2023 · 06:44 PM
    • Since 2018, some S$2 billion has been lost to scams in Singapore.
    • Since 2018, some S$2 billion has been lost to scams in Singapore. PHOTO: BT FILE

    THE anecdotes are heartbreaking; the data alarming.

    A 34-year-old woman lost close to S$30,000 after scammers took control of her phone when she downloaded a third-party app. Another lost her life savings of more than S$50,000, also after downloading a third-party app to buy durians online. They were victims of malware that allowed scammers to take control of their Internet banking access.

    Phishing scams continue to thrive despite numerous and sustained measures such as educational campaigns, setting up a special police taskforce to monitor and nab cybercriminals, and heightened internal surveillance by banks.

    Since 2018, some S$2 billion has been lost to scams in Singapore. In 2022, victims lost S$660.7 million. In 2021, it was S$632 million. Incidents of phishing have also shot up. According to a Cyber Security Agency report last month, phishing attempts in 2022 surged to 8,500 reported cases – more than twice the 3,100 cases reported the year before. No prizes for guessing that banks were the top target in spoofing attempts.

    Government services are also a favourite target of scammers, so much so that the Central Provident Fund (CPF) Board is introducing Singpass face verification for vulnerable members – including Android users and those aged 55 and above – logging in to CPF e-services.

    The authorities were alerted to at least eight phishing scams involving CPF savings, with losses totalling S$124,000, between January and June this year. Despite the added inconvenience, I believe face verification is a good tool to prevent scammers from fraudulently accessing a member’s CPF savings.

    That is only half the story, though. Since CPF withdrawals cannot be credited to the banking account of all and sundry, the scammer must not only gain access to the victim’s CPF logins, but also the latter’s verified banking account. No matter what scams they run, the scammers’ objective is almost invariably targeted at the victim’s Internet banking access. This is the focal point of almost every consumer-targeted scam, not just those involving CPF monies.

    The bait may differ – be it spoofed SMS links, QR codes, websites, calls from authorities and so on – but the pattern is the same: befuddle victims into revealing their online banking login name and password. This is why banks have such a major and critical role to play in stemming online fraud.

    To be sure, they have stepped up their game. In the aftermath of an extensive phishing scam involving OCBC customers, which saw about 790 victims lose S$13.7 million between December 2021 and January 2022, the banking industry adopted tighter security measures.

    Clickable links were removed from e-mails or SMSes sent to retail customers. There is now a 12-hour delay before a new soft token can be activated on a mobile device. Banks have introduced a “kill switch” that lets customers freeze their bank accounts if they suspect their accounts have been compromised. For suspicious or high-risk transactions, such as those involving large amounts or high frequency, all banks here require two-factor authentication.

    With all these countermeasures in place, why are there still so many reports of people being conned into revealing their Internet banking details?

    You are not wrong if your answer is human foibles. Fear, insecurity, greed and complacency are what scammers tap to persuade victims to divulge their security codes.

    I would argue, however, that scammers would be far less successful if a physical token – a so-called hard token – is required to authorise suspicious transactions. In a world where anonymous and unidentified bad actors can empty your bank account virtually in minutes, the old-fashioned lock and key is the bulwark to stop, or at least slow, the theft of your money online.

    Requiring a hard token means online scammers would need the active involvement of the victim to steal his money. Taking the trouble to rifle through a drawer and pull out the token may wake up a mesmerised Internet scam victim.

    On the flipside, a hard token is inconvenient to carry around and may be viewed anachronistic in our adoption of digital banking. Yet, that inconvenience is exactly why a physical token is safer than a smartphone-generated one.

    A physical token serves as a formidable barrier against scammers who try to surreptitiously move the victim’s money while he is asleep or otherwise uncontactable for hours.

    Few banks, however, are keen on retaining the physical token. I asked The Association of Banks in Singapore (ABS) about this.

    “Both physical and digital tokens serve as an important second-authentication factor, to ensure that accounts are accessed only by customers issued the token. Banks’ data have thus far shown no difference in the efficacy of either token type to secure online and mobile banking access,” ABS said.

    “Measures are in place to ensure that digital tokens are not easily transferred from a customer’s device without their knowledge or consent – these include 12-hour cooling periods and sending notifications of requests to move the digital token to another device. Rather, scams involving fraudsters taking over customers’ accounts and making unauthorised transactions have involved the compromise of SMS one-time passwords.”

    It also noted that customers generally preferred digital tokens for ease of use and not carrying an additional device aside from their registered smartphone.

    “Nonetheless, those who still prefer physical tokens may inquire with their bank on their availability,” ABS said.

    That sounds reasonable, but the reality is banks that have embraced digital tokens are most reluctant to issue physical tokens. I agree that most customers prefer the convenience of a soft token. Look how quickly Singaporeans jettisoned the physical TraceTogether token once the app-based one came along.

    Still, it must be noted there were no financial stakes in using TraceTogether. Intuitively, I am unconvinced that a hard token does not provide stronger protection – given the major concern of Internet banking is the ease with which you can lose all your money from a momentary lapse of judgment.

    Let me give you an example. Suppose you are in a foreign country and became a victim of a street extortion. Without banking apps on your smartphone, your financial loss at most is all the money in your wallet.

    If you encounter a savvy robber who knows all about app banking, however, he may force you into revealing your banking access. Even a 12-hour cooling period may be no deterrent if the stakes are high.

    Fanciful imagination? Not quite.

    I used to work for the now-defunct Southern Bank in Kuala Lumpur. One day, a colleague came back from lunch and shared that he had been extorted at knifepoint on his way back to the office from Menara Maybank, a mere five-minute walk away, in broad daylight on a working day in the heart of the financial district. Afterwards, he could even joke that he would have been poorer, had the perpetrator waylaid him before he deposited money at Maybank.

    So, what can we do to protect ourselves, short of abandoning digital banking and returning to queuing up at a bank? Here are some suggestions:

    • Diversify by spreading your savings at multiple financial institutions;
    • Ask for a hard token as a second authenticator. Some banks here still provide a hard token as default;
    • Divert the bulk of your cash savings from demand accounts to fixed deposits with automatic renewals, money market funds, Singapore Savings Bonds and T-bills. All are harder for scammers to siphon off quickly, even if they managed to breach your online banking security; and
    • Remove from your phone all your banking apps, except one or two that you intend to use to pay for expenses, when travelling overseas. Leave your physical token at home.