By Ray Birch
DETROIT—It’s no time to get “lax” with multifactor authentication and member transactions, according to one expert, who is warning threat actors just keep getting more cagey and elusive.
The crooks’ latest target—wire transfers.
“We're seeing much more sophisticated fraud schemes today,” said Jad Sheikali, senior associate at Honigman LLP, which works with credit unions on data breach incidents. “The threat actors just keep getting better and better at what they do.”
What is taking place now, explained Sheikali, is crooks are moving away from attacking an organization via “one big event” in favor of a larger number of smaller attacks. He said that is making it much more difficult to detect if a fraudster is inside the system, and then take steps to defend.
“What they are often doing today is getting inside the system, perhaps through phishing, and getting into some employees’ inboxes and then downloading their entire inboxes,” he said.
What the crooks then do with that data is execute more “targeted attacks,” Sheikali said. And, a favorite attack that is growing are wire fraud schemes.
Scouring Inboxes
He said the criminals are scouring inboxes certain information.
“They are running targeted searches to try to find either pending wire transfers or transactions for future wires and then they try to get in the middle of those,” Sheikali said. “In the investigations that we have conducted in the last several months involving wire fraud, we're seeing the threat actors get into the mailboxes and run searches for wire instructions or payment instructions. We're seeing them take sophisticated steps, creating new ‘authorized’ email accounts so that they can themselves authenticate transactions, often impersonating executive level individuals in order to bypass requirements.”
Getting Lax
But at the same time criminal activity has become harder to detect, Sheikali said his firm, in its forensic investigations of attacks on banks and credit unions, has found FIs are becoming a bit “lax” when it comes to consistently requiring multifactor authentication.
“Another thing that we're seeing is somewhat of a breakdown in multi-factor authentication,” said Sheikali. “I think nowadays most entities should at least be aware of the importance of multi-factor authentication, particularly if you're dealing with financial transactions—especially now that the workforce is decentralized, and many are working from home. What we've seen is that there's some financial institutions that may be loosening those requirements to accommodate the convenience and comfort for customers to help get transactions done faster and prevent them from falling by the wayside.”
Meanwhile, all of this is occurring at a time when there is increasing interest from both state and federal regulators in how FIs are responding to data breach incidents, said Sheikali.
“Financial institutions can’t be trading comfort, convenience and speed for less security,” said Sheikali, noting that could lead to even greater scrutiny from regulators. “The regulators are taking a more hands-on approach to their investigations of data breaches, and you don’t want to be in their crosshairs.
Be ‘Transparent’
“Given the nature of these types of follow-ups (from regulators) it's always good to have a counselor with you,” continued Sheikali. “However, it really comes down to just being transparent and forthright with the regulators and being responsive, giving them the information they asked for in a timely manner. It’s about being direct with your answers. I have found that when financial institutions do this, things go smoothly.”
Sheikali pointed out that state data breach laws vary greatly, and that without a unified set of rules at the federal level around breaches it can become confusing for credit unions and banks—which often operate cross state lines—to understand when there is a need to notify regulators and others when a breach is detected.
“Basically, there is a mix of 50 state data breach laws,” Sheikali said. “A lot of them have requirements for notifying state attorney generals, and typically there's a threshold for the number of individuals involved in the breach. In some states only one individual has to be affected, and in others it’s 10,000. That’s quite a bit of disparity.”
AGs Getting Inquisitive
Sheikali said a number of attorneys general offices are now quickly responding to an FI’s notice of a data breach, asking follow-up questions.
“They want to see copies of the data breach notices that went out to consumers, and essentially they want confirmation that individuals who were supposed to be notified were in fact notified,” said Sheikali. “They want to know what's been done in response to the breach, including whether individuals were offered credit monitoring, and, of course, what the company has done in response to the incident.”
