News: 1642658468

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Singapore gives banks two-week deadline to fix SMS security

(2022/01/20)


A widespread phishing operation targeting Southeast Asia's second-largest bank – Oversea-Chinese Banking Corporation (OCBC) – has prompted the Monetary Authority of Singapore (MAS) to introduce regulations for internet banking that include use of an SMS Sender ID registry.

Singapore banks have two weeks to remove clickable links in text messages or e-mails sent to retail customers. Furthermore, activation of a soft token on a mobile device will require a 12-hour cooling off period, customers must be notified of any request to change their contact details, and fund transfer threshold will by default be set to SG$100 ($74) or lower.

MAS has also offered a vague directive requiring banks to issue more scam education alerts, and to do so more often.

[1]

Singapore-based banks will also be required to operate dedicated customer assistance teams to deal with potential fraud cases on a priority basis.

[2]

[3]

A dedicated service line could tackle one of the major complaints raised by victims of the [4]OCBC phishing scam : that the bank was not equipped to handle fraud case in progress in real time, and funneled customers into an automated loop while their accounts were being drained.

MAS flagged more regulations will follow.

[5]

“The growing threat of online phishing scams calls for immediate steps to strengthen controls, while longer-term preventive measures are being evaluated for implementation in the coming months," MAS and the Association of Banks in Singapore (ABS) revealed in a [6]joint statement on Wednesday.

The statement said specifically that MAS would continue to work with the Singapore Police Force and the Infocomm Media Development Authority (IMDA) to combat SMS spoofing – including adoption of an SMS Sender ID registry, of which a [7]pilot programme was launched last August. The central banking authority also promised to increase "scrutiny of major financial institutions' fraud surveillance mechanisms" to make sure they can deal the recent influx of new scams.

[8]I own that $4.5bn of digi-dosh so rewrite your blockchain and give it to me, Craig Wright tells Bitcoin SV devs

[9]Foxstuck: Firefox browser bug boots legions of users offline

[10]Tesla driver charged with vehicular manslaughter after deadly Autopilot crash

[11]Microsoft patches the patch that broke VPNs, Hyper-V, and left servers in boot loops

[12]Big shock: Guy who fled political violence and became rich in tech now struggles to care about political violence

The phishing scheme, which first appeared at the start of December 2021, affected at least 469 customers and yielded over SG$8.5 million ($6.3M) by the end of the month alone.

Victims received an unsolicited SMS that asked the account holder to click a link to resolve account issues that redirected them to a fake bank website so the threat actors could collect their logins and passwords. The scammers then transferred the digital token over to their own devices and began the process of draining the accounts.

At first the bank offered "goodwill" payments to a paltry 6.4 per cent of victims. The day after MAS threatened action, OCBC changed its tune and told local media outlet The Straits Times that it would issue "full goodwill payouts" to all victims.

[13]

Emails from the bank to customers [14]revealed the payments came after a full investigation, and the bank promised to contact the victims by January 27. Interestingly, [15]reports have surfaced that the goodwill payout comes with a non-disclosure agreement for the victims.

Overall, MAS warns that the more stringent measures it is implementing will "lengthen the time taken for certain online banking transactions but will provide an additional layer of security to protect customers' funds".

The changes might also have some extra unintended positive effects. As one Singaporean bank account holder put it:

Good, now my bank has to stop sending me links in SMSes suggesting installment plans for my $20 purchases. It's spam, insecure and crowding an avenue which needs fewer but critical messages.

Thereby proving these sort of things can sometimes have silver linings – unless you're a techie at a Singaporean bank and have a very busy fortnight ahead of you. ®

Get our [16]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YelA2VB-GDN1Sp2lvNv5WgAAAMc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YelA2VB-GDN1Sp2lvNv5WgAAAMc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YelA2VB-GDN1Sp2lvNv5WgAAAMc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2022/01/18/singapore_monetary_authority_threatens_action/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YelA2VB-GDN1Sp2lvNv5WgAAAMc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.mas.gov.sg/news/media-releases/2022/mas-and-abs-announce-measures-to-bolster-the-security-of-digital-banking

[7] https://www.straitstimes.com/singapore/imda-urges-more-banks-to-sign-up-with-anti-sms-spoofing-registry-to-combat-scams

[8] https://www.theregister.com/2022/01/19/craig_wright_bitcoin_sv_high_court_sueball/

[9] https://www.theregister.com/2022/01/18/foxstuck_firefox_browser_bug_boots/

[10] https://www.theregister.com/2022/01/19/tesla_manslaughter_autopilot/

[11] https://www.theregister.com/2022/01/18/patching_patch_tuesday/

[12] https://www.theregister.com/2022/01/18/chamath_palihapitiya_uyghur/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YelA2VB-GDN1Sp2lvNv5WgAAAMc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://mothership.sg/2022/01/ocbc-scam-victims-nda/

[15] https://www.straitstimes.com/tech/tech-news/all-affected-ocbc-customers-of-recent-sms-scam-to-get-full-goodwill-payouts

[16] https://whitepapers.theregister.com/



"remove clickable links in text messages or e-mails sent to retail customers"

Pascal Monett

They're still doing that ?

My Luxembourg bank never sends me SMSs, and actually practically never sends me mail to my email address. All communications are held on the banking portal I have access to (ID, password and OTP token), and are held in the Message area, with a little red bell when there's something I haven't read.

On the other hand, my bank does call me when there is an unusual transaction of more than €2,000 to ensure that it was me and that I authorize the movement.

I appreciate that.

anthonyhegedus

I'm glad that the authority involved has put more onus on the banks. The only way these banks will learn to beef up their security as well as educate their customers is if they're forced to refund people their full loss every time someone is scammed. That'll focus their attention on education programmes (for example big posters saying "we never send a text with a link to a website" or "never give your 2FA code to anyone, ever"), and systems to ensure that spoof texts can't be sent. That might mean them paying the mobile networks to do it.

Anonymous Coward

My bank bans giving passwords to third parties, even going so far as to name Payment Express and similar (in a web page you might be able to find behind a disused basement lavatory)

They don't however, simply block these services or otherwise take steps to stop them. If it all goes wrong, they'll just say "we told you not - see, here, behind this disused dunny"

permission denied