Does MAS, IMDA’s phishing scam framework protect small consumers or big corporations?
Making consumers responsible for transactions they did not authorise may erode their trust in the banks
THE Monetary Authority of Singapore (MAS) and the Infocomm Media Development Authority (IMDA) unveiled a much-anticipated shared responsibility framework (SRF) for phishing scams last week.
On the face of it, the SRF protects consumers from a potentially ruinous form of fraud. It sets out specific duties for financial institutions (FIs) and telecommunications companies (telcos) to mitigate the risk of consumers falling prey to phishing scams; and assigns all losses from these scams to FIs and telcos that fail to discharge their respective duties.
The FIs stand first in line to bear these losses, as they are custodians of their customers’ deposits. The telcos are second in line, given their secondary role of facilitating the delivery of SMSes associated with online banking transactions.
The SRF does not completely shield the customers of FIs and telcos, though. “If the FIs and telcos have fulfilled their duties, the SRF will not require payouts to be made to consumers,” MAS and IMDA said last week.
“It is therefore critical for consumers to continue to exercise vigilance at all times and not click on any unsolicited, suspicious links.”
In fact, one could argue that the SRF offers a blueprint of sorts for FIs and telcos to avoid culpability in phishing scams by implementing a handful of clearly defined and backward-looking measures.
The SRF duties for FIs include preventing “high-risk activities” on customer accounts – such as increasing transaction limits or changing contact information – within 12 hours of the activation of digital tokens.
FIs are also required to send notification alerts for the activation of digital tokens and the conduct of high-risk activities; provide ongoing transaction notifications; maintain a 24/7 channel for customers to report scam activities; and provide a “kill switch” that customers can self-activate to freeze their accounts.
The SRF duties for telcos include connecting only to authorised aggregators for delivery of SMSes with a Sender ID; blocking Sender ID SMSes that are not from authorised aggregators; and putting in place anti-scam filters to block SMSes with known phishing links.
Assigning responsibility, losses
To grasp the manner in which the SRF will assign responsibility for – and, consequently, the losses from – phishing scams to people like me, I had a close look at the following case study from the consultation paper:
A scammer manages to deceive a victim into clicking on a phishing link and revealing his bank details and one-time passwords. The scammer uses the information to make three fund transfers from the victim’s account: S$1,000, S$2,000 and S$3,000.
As the victim had previously set his transaction notification threshold to S$1,500, the FI only sends out notifications for the fund transfers of S$2,000 and S$3,000.
Under the SRF, the FI would not have breached any of its duties at this point. While it did not send out a notification for the transfer of S$1,000, this was because the customer had opted to only receive notifications for transfers of S$1,500 or more.
Consequently, the customer would be expected to bear the loss of all three transfers.
What happens if the scam victim were to react to the notification of the S$2,000 transfer by immediately reporting the incident to the FI, or hitting the kill switch, thereby stopping the S$3,000 transfer?
This was not answered in the case study, but my understanding of the SRF principles is that the scam victim would still have to bear the loss of the S$1,000 and S$2,000 transfers – because the FI did not breach its duties.
What if the scam victim was unable to get through to the FI to report the incident and the kill switch did not work?
Based on the SRF principles, the FI would clearly be on the hook for the transfer of S$3,000. The FI might also have to bear the loss for the transfers of S$1,000 and S$2,000 if its failure to enable its customer to quickly report these unauthorised transactions led to the funds not being recoverable.
Upholding trust
For me, one takeaway from this case study is that it is really important to check your phone for notifications in this era of digital banking.
More generally, it seems to me that ordinary consumers will be at a disadvantage versus FIs under the SRF.
While large corporations have the financial and organisational wherewithal to comply with prescribed duties such as maintaining a 24/7 reporting channel for scam victims, most ordinary consumers would be hard-pressed to monitor their phones through a busy workday.
Don’t get me wrong. Everyone should be wary of clicking on suspicious links; and it is important to keep track of e-mail and SMS notifications from your bank.
Yet, most people are comfortable maintaining large bank balances because they trust the banks to keep their funds safe. By making account holders responsible for fund transfers they did not authorise, the SRF may erode this long-held trust.
So, what would it take to prevent phishing scams from undermining confidence in the digital banking and payments system?
This column suggested in July and August last year that FIs should simply be made to bear all the losses from phishing scams. Besides providing reassurance to consumers, it would also incentivise the FIs to invest in the security of their online platforms.
The idea was met with derision from many readers, though. The main concern was that a “moral hazard” problem would emerge, and many consumers might not be incentivised to take the necessary precautions to protect themselves.
Interestingly, Singapore’s major banks are reportedly preparing to introduce a new security feature that will allow their customers to insulate their savings from digital transactions. To gain access to the “locked” funds, their customers would need to show up at a branch in person and prove their identity.
If this security feature proves to be popular, however, it would be an indictment of the level of public confidence in Singapore’s digital banking and payments system.
As for the SRF, perhaps the best way to ensure it succeeds once it is implemented is for MAS and IMDA to provide the public with as much information as possible on the handling of phishing scam claims by the FIs and telcos.
The information could include the types of phishing scams that were perpetrated; the number of customers affected and sums lost; the amount of time it took to process their claims; and the extent to which they were reimbursed under the SRF.
Accountability is usually enhanced under the harsh light of information and transparency.
TRENDING NOW
Grab CEO’s wife Chloe Tong on life with Anthony Tan and finding her purpose
What role can Japan play in Asean’s future?
He built the Vingroup empire. Now South-east Asia’s richest man is handing some key roles to his sons
Asean’s challenge is to become resilient against global geopolitics: former Indonesia trade minister