Mobile’s Acceleration Drawing Fraudsters’ Attention

SilveiraChris

Chris Silveira, Guardian Analytics

DENVER—By 2017 digital account openings will equal those that take place in the branch, another sign that mobile is growing fast. But this acceleration is drawing the attention of fraudsters, who are stepping up their focus on smartphones.

Chris Silveira, manager of fraud intelligence at Guardian Analytics, made that point clearly at the joint World Council of CU’s World CU Conference and CUNA’s America’s Credit Union Conference here.

“Mobile malware attacks grew 49% from Q4 2014 to Q1 2015,” Silveira said.

Mobile Spyware

With all types of personal information either stored on a smartphone or available via the device’s applications, Silveira said it is no surprise that cyber-thieves are now turning to mobile.

He explained that the personal data on the phone can make the millions of pieces of information stolen from retailer data breaches stored on the criminals’ computers even more useful to crooks.

“Mobile spyware can capture all kinds of user information,” explained Silveira. “Things like website activity, GPS location, social media activity and information. These mobile spyware apps can grab data to make greater use of the stolen data the crooks already possess—create stronger profiles of victims.”

Ingenious Attacks

Silveira shared that crooks are developing ingenious ways to leverage the smartphone, including malware that hijacks apps that control a phone’s video and audio functionality.

“Crooks can monitor voicemail messages, an inbox . . .  use that data to bypass call center verification methods, for example,” Silveira said. “Criminals can capture conversations of victims on their phones and actually make a recording of a person’s voice to be used to get past voice authentication biometrics.”

Silveira also said crooks could gain control of the “gyroscope” device on a phone, which measures rotation and orientation of a mobile phone, measures location, and it is susceptible to vibration. Silveira said that last capability, to measure vibration, can actually be used to simulate a microphone and capture voices in range of the phone, which again could be used to bypass voice authentication security methods.

“What makes the potential of using the gyroscope to simulate a microphone important is that unlike the microphone, apps do not currently need permission to access the gyroscope,” Silveira said.

Smishing attacks are on the rise and evolving, added Silveira, not only increasing their targeting of account holders from smaller FIs, but also finding new ways to bypass phone carrier smishing detection methods.

RDC A Growing Target

And with one of the most popular consumer mobile applications—remote deposit capture— Silveira told attendees to be vigilant here.

“One of the most prevalent attacks on mobile now is with RDC, taking over that capability on the phone, and leading to a new generation of check fraud,” he said.

Section: Standard
Word Count: 568
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-boost/Mobile-s-Acceleration-Drawing-Fraudsters-Attention