BRUNCH

Banking against malware-related scams

Banks are expected to protect their customers from falling prey to malware-related scams. But to what extent should they do this?

Yong Jun Yuan

Yong Jun Yuan

Published Fri, Oct 13, 2023 · 02:00 PM
    • Banks are expected to safeguard their online channels from being compromised, but nuanced approaches are necessary to avoid unnecessarily inconveniencing users.
    • Banks are expected to safeguard their online channels from being compromised, but nuanced approaches are necessary to avoid unnecessarily inconveniencing users. GRAPHIC: SIMON ANG

    BACK in August, Simon Hsu, a customer of OCBC Bank, was trying to access the bank’s mobile app to verify that he had received a PayNow fund transfer, when an error message flashed on the screen.

    The OCBC app on his phone had stopped running because of another app in the phone that had not been downloaded from an official app store, such as Google’s Play Store or Huawei’s AppGallery.

    The app in question was Douyin, the Chinese version of social media app TikTok. He says he favours the app for its self-help content, which he finds relevant.

    Hsu, a 27-year-old IT professional, says he had downloaded the app from Douyin’s website, but that he was confident regarding the security of the apps installed on his phone.

    On OCBC’s move to restrict users with such sideloaded apps on their devices, he says: “I feel it’s too heavy-handed, like parents trying to stop their child from accessing porn.”

    He is not alone in feeling this way. An OCBC Facebook update on Aug 7 about the new security measure garnered 483 “angry” emoji reactions in the following six weeks.

    Some users commented they had issues using the OCBC app because their phones had sideloaded apps that they were required to download for work purposes. Others complained that the bank did not have the right to control what they installed on their phones.

    The Android operating system allows users to install apps with application packages, or APK files. These are similar to how Windows users may install programs with executable “.exe” files.

    Apple users, however, generally do not have the facility to sideload apps unless they jail-break their devices.

    Experts believe that while OCBC’s move to protect users from malicious sideloaded apps was well-intentioned, banks could consider a more nuanced approach when implementing security measures that may inconvenience users.

    To be fair, it is not an easy task to protect customers from scams.

    In its mid-year statistics for scam and cybercrime cases, the Singapore Police Force says there were at least 750 cases of Android users falling prey to malware scams in the first half of 2023. Of these, 11 had unauthorised withdrawals made from their Central Provident Fund savings.

    Lighter touch preferred

    A month after it implemented the new security measure, OCBC says that no losses from malware scams had been reported from users using updated versions of the bank’s app. The lender adds that it also managed to protect the savings of more than 30 customers who had malicious sideloaded apps on their devices.

    National University of Singapore senior lecturer Wang Qiuhong says that while the move was laudable, it unfairly shifted the burden of the threat of malicious apps to consumers.

    Customers would ask why such a drastic measure was not being taken by other international banks, she says. Also, she adds, the complaints did not come from customers who were “ignorant about security”.

    “The other side of the story... is also a very reasonable consideration,” Wang says, adding that OCBC should have focused instead on enhancing the security around its app to prevent it from being compromised.

    The academic, who specialises in the economics of information systems, says she believes that operating system vendors such as Google and Apple may have to work with banks to address the challenges of ringfencing banking apps from malicious apps installed on the same device.

    “In the context of mobile app security and bank account security, all stakeholders should share the costs caused by interdependent security threats,” she says. “Otherwise, we can expect that there could be insufficient incentive for security investments.”

    Shelesh Gupta, managing director of security for South-east Asia at Accenture, suggests that instead of imposing rigid security measures, banks should offer an experience that is personalised to users’ needs and comfort levels, while maintaining app security. “This grants consumers the agency to shape an experience that is both well-informed and aligned with their personal interests, ultimately fostering a favourable perception of these measures.”

    As a rule of thumb, a security measure should not noticeably disrupt user experience, compromise user privacy without justification, or impose unwarranted inconvenience, he adds. For instance, he says a bank in the region, which he did not name, restricted users to one registered device for authentication purposes.

    “While this guarantees secure transactions by authenticating these customers through a single device, it poses challenges for those who rely on multiple devices for their mobile banking needs, resulting in users having to adjust their banking habits to adapt to the change,” he says.

    Accenture’s Shelesh Gupta believes that banks could give users agency to shape their experiences with banking apps, while maintaining app security. PHOTO: ACCENTURE

    On the other hand, Dennis Khoo, managing partner of digital consultancy All Digital Future, suggests that users who subject themselves to higher risks by sideloading apps should still be allowed to use banking apps – if they waive their rights to any recourse if their bank accounts are compromised.

    He likens the act of sideloading apps to raising a person’s risk profile, just as a smoker would have to pay higher premiums for insurance.

    “That seems palatable because you are the one exposing yourself to the risks,” says Khoo, who used to be group head of UOB’s TMRW digital group.

    Appdome mobile app security product lead Jan Sysmans noted that a common way malicious apps attack sensitive apps, such as banking apps, is by requesting for accessibility permissions, and having these activated.

    But such permissions are a double-edged sword: They are meant to help users with disabilities, but they also grant apps the ability to simulate touching the phone’s screen, thus giving access to the contents on the screen.

    Sysmans says that once devices are compromised, hackers automate the process of detecting and finding new credentials to steal from a user. The process does not stop.

    “Whenever an app is updated, whenever anything else happens, (they) continue the attack, regardless of the protections in place,” he says.

    Striking a balance

    With the financial institutions he has worked with, Sysmans says that apps are programmed to track whether a device is performing normally when, for example, a user logs in or makes a transaction.

    “When there is presence of a method or a tool outside of that certain expected thing that should be happening, that is typically a telltale sign of malware,” he says. When this happens, the app may stop working and direct the customer to call the bank and get help to resolve the threat.

    This protects the app from being compromised when it is installed on devices with rooted operating systems, he says. Rooted operating systems, which are those with their deepest and most important code exposed, can give both users and bad actors privileged control over the more sensitive areas of a phone.

    Sysmans notes that customers could buy a second-hand device with a rooted operating system without even knowing it. “(But) a rooted device by itself is not a problem,” he says.

    In September, banks such as Citi, DBS and UOB also introduced anti-malware app features to prevent users from falling prey to scams. These features typically restrict customer access if screen-sharing or screen-mirroring is happening while the mobile apps on these devices are accessed.

    Nilesh Kumar, Citibank Singapore’s head of digital channels and experience, tells The Business Times that when riskier permission settings are enabled, the anti-malware feature is also activated. Some of these permission settings include screen sharing, broadcasting and accessibility services, which he says could make the device more susceptible to malware attacks.

    “Apps that do not attempt to access the Citi Mobile App or activate risky permission settings on the device will not activate the security feature. The security feature also does not monitor or conduct surveillance on customers’ mobile devices.” he says.

    OCBC’s head of anti-fraud, group financial crime compliance, Beaver Chua, tells BT that in lieu of customer feedback, the bank has implemented an option for its customers to retain unverified apps that have been assessed as not malicious and that do not pose a malware risk.

    “The preferred and safer option to combat malware scams is still to uninstall (these apps) and ensure that there are no unverified apps on a mobile device,” he says.

    The Association of Banks in Singapore (ABS) said on Sep 18 that major retail banks will “progressively introduce refinements or new measures to keep pace with changes in the threat landscape”.

    In response to BT’s queries, director of ABS Ong-Ang Ai Boon says that the association is helping its members to learn from each other’s experiences in areas such as the effectiveness of the measures, the handling of false positives and customer communication.

    “This will help banks to calibrate their approach to achieve a right balance between the risk of fraud and inconveniencing legitimate transactions,” she says.

    From November, customers of the three local banks will be able to “lock up” their funds in special accounts, making these funds accessible only through physical channels, such as automated teller machines (ATMs) or personal visits to the bank branches.

    Raising public awareness

    More can also be done to raise the public’s awareness about what they can do to protect themselves.

    OCBC bank customer Hsu says that he once used mobile antivirus apps, but now believes them to be unnecessary, and has since uninstalled them.

    “On the computer, (antivirus apps) are more needed because websites can contain advertisements that have malware. I don’t really use my phone to browse the Internet,” he says.

    Other security policies and measures, such as Google’s Play Protect service on Android phones, are enough, he says. Google Play Protect is a suite of measures that works with the Google Play Store to check for malware and reset app permissions on certain Android versions.

    The Cyber Security Agency of Singapore (CSA) public awareness survey 2022 found that a higher proportion of younger respondents were scammed in cyber incidents than older respondents. Some 37 per cent of respondents aged 15 to 24 reported falling victim to at least one cyber incident, while 31 per cent of respondents aged 40 to 54 reported the same.

    The survey also found that only one in two users have installed cybersecurity software, such as antivirus apps.

    A CSA spokesperson says consumers should remain vigilant and ensure that they download apps only from official app stores.

    “Both Android and iOS users are similarly vulnerable to threats such as phishing links in messages and pop-up ads,” the spokesperson says.

    On Sep 30, CSA released a list of antivirus apps that consumers can install on their Android and iOS devices.

    Associate Professor Edson C Tandoc Jr from Nanyang Technological University’s Centre for Information Integrity and the Internet (IN-cube) says that people who believe that they are susceptible to threats would be more willing to take measures to protect themselves.

    “If they have not been scammed before, they might think they’re not susceptible. Having to submit themselves to such drastic measures can be inconvenient (and) might be too much for them,” he says.

    He notes that in his research, he has found that people who perceive a higher threat of fake news are more likely to undertake fact-checking; conversely, those who are confident about their ability to detect fake news would not.

    Associate Professor Edson C Tandoc Jr says that banks should be more thoughtful about the way anti-scam messages are presented to bank customers. PHOTO: EDSON C TANDOC JR

    Simply sending more anti-scam notifications and messages may not be helpful either. Tandoc suggests that some bank customers may find the repetition of anti-scam messages to be more irritating than helpful.

    In an IN-cube panel survey done in December 2022, 60 per cent of respondents said online anti-scam messages were informative. However, 57 per cent said the messages were repetitive, and 37.4 per cent found them useless. (Respondents could select more than one option.)

    Tandoc says: “I think banks should try and find better ways of nudging people to pay more attention to these things. I think just exposing them every single time they log in might be counterproductive.”

    Similarly, Accenture’s Gupta notes that constant push alerts and continuous location tracking without explanation can cast a negative light on a user’s banking experience.

    “Banks can avoid this by refraining from multiple types of privacy intrusion, such as requesting access to non-relevant data or requiring biometric information for low-risk transactions,” he says. “While these measures enhance security, they can also alienate users, rendering the app unusable and inconvenient.”