MARK TO MARKET

Readers hated my take on bank phishing scams, but here’s what they are missing

Concern about moral hazard in making banks responsible for phishing scam losses might be misplaced

Ben Paul
Published Mon, Aug 1, 2022 · 05:50 AM
    • MAS said on Jul 18 that the development of the framework for equitable sharing of losses from scams is taking longer than expected “in view of the complexity of the issues”
    • MAS said on Jul 18 that the development of the framework for equitable sharing of losses from scams is taking longer than expected “in view of the complexity of the issues” BT FILE

    THIS column received a lot of negative feedback after it said on Jul 11 that Singapore banks ought to bear the losses from phishing scams.

    The notion that depositors should get their money back after giving away their bank credentials to unknown persons did not sit well with many readers.

    It was pointed out to me that the scammers had not hacked into the computer systems of any bank. It was the depositors who had let them in.

    Some readers worried that making the banks reimburse depositors created a “moral hazard”: if depositors know they are shielded from any risk, they might behave even more irresponsibly. This would be unfair to shareholders of the banks.

    Then there were folks who felt that banks are already overburdened by regulation, and cannot be expected to thwart financial crime on their own.

    With the expressed purpose of “broadening” my views, one reader suggested that telecoms companies ought to bear some responsibility for the cyber crimes and fraud their networks facilitate.

    The same reader went on to suggest purveyors of luxury goods, exotic sports cars and trophy homes should be required to look into the sources of their clients’ wealth.

    Some readers wondered if making the banks responsible for ensuring unwary customers are not scammed might result in their online platforms becoming more restrictive. They also feared banks might be deterred from making further investments in technology that would reduce costs and deliver greater convenience.

    In short, many people seem to think that retail bank customers should take responsibility for themselves. If they are tricked into revealing their banking credentials to scammers, that’s just too bad.

    One comment I spotted on social media read: “You can’t legislate against stupid.”

    Negligence narrative

    All the feedback I received was interesting, but none of it has altered my opinion.

    Internet banking has been around for years, but instances of phishing scams have recently grown exponentially.

    The Singapore Police Force said in February that there were 2,237 reported cases of banking-related phishing scams in 2021. This was 897 more than in 2020.

    The victims of these scams lost S$19.4 million, or S$14.1 million more than in 2020. The largest sum lost was S$1 million.

    The surge in these scams is not the result of bank customers suddenly behaving recklessly, but of more customers transacting online and scammers becoming increasingly aggressive in their attacks.

    The well-intentioned reminders from banks and the Monetary Authority of Singapore (MAS) that customers must be “vigilant” and that they have a “responsibility” to take precautions arguably stigmatises the victims of these crimes – supporting the narrative that being scammed is the result of negligence and irresponsibility.

    The reality is that the banks have built their online platforms on networks they do not fully control. As we have seen, web pages and SMS alerts can be faked. And, scammers will doubtless become more creative and cunning over time.

    Is the answer really for banks and the MAS to demand ever greater awareness and vigilance from customers? Or, is it time for the banks to rethink the fundamental workings of their online platforms?

    Back in 2017, the government delinked the work computers of public servants from the Internet in the name of security. This inconvenience was only brought to an end in 2020, after the government was satisfied that advances in remote browsing technology would enable public servants to access the Internet securely.

    To be clear, I am not calling for the banks to take their services offline.

    Yet, the banks have a duty to ensure their technology platforms are not conduits for fund transfers that customers did not authorise.

    Something more than just tinkering with the threshold for fund transfer notifications and giving customers a “kill switch” to freeze their own accounts seems to be in order.

    Promote transparency

    This brings me to the framework for equitable sharing of losses from scams.

    On Jul 18, MAS said the development of this framework is taking longer than expected “in view of the complexity of the issues” and that it will be published for public consultation “in the coming months”.

    This was a surprise. On Feb 4, MAS said the framework would be published within 3 months. And, the conditions under which customers would have to bear the loss arising from a scam seemed clear.

    MAS said customers would be responsible under the framework to take “necessary precautions”. This would include never giving away their banking credentials, never clicking on links contained in an SMS or email, and only transacting through a bank’s official website or app.

    What complexities has MAS encountered? What will it take to resolve them?

    My own view is that making customers liable for losses from phishing scams is fraught with risks. MAS should carefully consider if this will really make them more vigilant, or if the sheer size of the potential losses will erode their confidence in online banking altogether.

    OCBC reportedly made full goodwill payouts to 790 customers who lost S$13.7 million in a spate of phishing scams late last year. This was a drop in the ocean compared to the nearly S$10.6 billion in total income that OCBC reported for 2021. But the average loss per customer of S$17,342 was more than 15 per cent of Singapore’s annualised median household income for 2021.

    MAS should also look into the moral hazard issue from all angles.

    Would customers really behave recklessly if banks underwrote the losses from phishing scams – keeping in mind there would be lengthy investigations before any reimbursement payments are made?

    Would a loss sharing framework result in the banks focusing on how to shift the blame to their customers instead of repelling the scammers?

    MAS should also consider if accountability within the ecosystem would be better fostered by promoting greater transparency.

    For instance, MAS could publish a half-yearly report of all phishing scams suffered by retail banks – including the details of the scams and the vulnerabilities they exposed, the numbers of customers affected and sums lost, and the extent to which the banks chose to reimburse their customers.

    The information would be useful for bank customers to determine the risks they face dealing with each of the banks. It might also incentivise the banks through competition to monitor and head off evolving threats.

    What can bank customers do in the meantime? My only suggestion is that they should spread their cash savings across different retail banks.

    The growing threat of phishing scams and the MAS-led effort to develop a framework to share the losses has arguably increased the risk of dealing with a single bank – especially the largest of the local retail banks, as their customers are most likely to be attacked by scammers.

    Note: Mark To Market will take a break over the next fortnight while the writer clears some leave.