News: 1695188707

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Singapore may split liability for phishing losses between banks and victims

(2023/09/20)


Singapore officials announced on Monday that next month they will deliver a consultation paper detailing a split liability scheme that will mean both consumers and banks are on the hook for financial losses flowing from scams.

It is an answer to a common question these days: in a world of rampant payment and transfer scams, who is responsible?

Countries like Australia have also [1]considered shared loss schemes. Meanwhile, the European Commission has proposed a "refund" to victims of certain types of fraud, including authorized push payment scams.

[2]

Starting next year, the UK will [3]enforce mandatory reimbursement by banks to scam victims up to one million pounds – with the sending and receiving banks sharing the bill.

[4]

[5]

Singapore's minister of state Alvin Tan has a different view.

"There are some views that banks can easily absorb losses arising from individual scam cases. However, full restitution without due consideration of culpability is neither fair nor desirable," he [6]told Parliament on Monday.

[7]

A draft of Singapore's shared responsibility framework was originally intended to be complete in the first half of 2023. Tan admitted on Monday the process had taken longer than the government would like, but a version detailing responses to phishing scams should be completed next month.

[8]South Korea relieved US China chip ban won't bite, as Beijing fumes

[9]Interpol arrests 14 who allegedly scammed $40m from victims in 'cyber surge'

[10]Tech support scammers go analog, ask victims to mail bundles of cash

[11]Singapore monetary authority threatens action on bank over widespread phishing scam

Singaporean authorities first floated a a shared liability strategy in February 2022 after threat actors [12]stole a combined SG$13.7 million ($10.2 million) from around 800 customers of a single bank by spoofing text messages.

At first, Oversea-Chinese Banking Corporation (OCBC) offered "goodwill" payments to a paltry 6.4 percent of victims, but after the Monetary Authority of Singapore (MAS) threatened action, it changed its tune and said it would issue "full goodwill payouts" to all victims.

The sheer magnitude of the required payout left the city-state to [13]rethink its anti-scam measures.

Then-minister of finance – now deputy prime minister – Lawrence Wong said in the future, customers and banks would have a shared responsibility for any losses in order to prevent a "weaken[ed] incentive to be vigilant" on the part of the customer.

[14]

The MAS currently requires banks to secure digital systems, including with multi-factor authentication for online purchase. Banks are also required to send alerts for some transactions and have been given guidance on handling and investigating disputes. Those efforts are supervised by MAS. But all the efforts prove no match for motivated social engineers.

"In scam cases, banks must consider if they have fulfilled their obligations, and whether the victim had acted responsibly. Customers who practised good cyber hygiene and were diligent in preventing their login information and [one-time passwords] from being divulged to third parties, should not have to bear losses," said Tan.

In the current process, unhappy customers can pursue the case in court, while others can agree to the terms and conditions associated with any payout.

The resulting agreements usually mean financial disappointment and a nondisclosure agreement – which many victims do begrudgingly, pointed out parliament member Sylvia Lim.

Lim advocated for a system similar to that of the UK, to give consumers more confidence in their transactions. ®

Get our [15]Tech Resources



[1] https://www.ey.com/en_au/financial-services/who-should-pay-for-the-cost-of-scams-in-australia

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZQrCxLGGH111dap-7RBcVgAAA8I&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.reuters.com/business/finance/uk-banks-told-reimburse-customers-tricked-by-scams-2022-09-28/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZQrCxLGGH111dap-7RBcVgAAA8I&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZQrCxLGGH111dap-7RBcVgAAA8I&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.mas.gov.sg/news/parliamentary-replies/2023/reply-to-adjournment-motion-on-losses-from-scams-and-malware

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZQrCxLGGH111dap-7RBcVgAAA8I&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2022/10/10/china_fumes_over_us_chip_ban/

[9] https://www.theregister.com/2023/08/20/interpol_africa_arrests/

[10] https://www.theregister.com/2023/07/19/tech_support_analog/

[11] https://www.theregister.com/2022/01/18/singapore_monetary_authority_threatens_action/

[12] https://www.theregister.com/2022/01/20/singapores_monetary_authority_requires_banks/

[13] https://www.theregister.com/2022/02/16/singapore_anti_scam_measures/

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZQrCxLGGH111dap-7RBcVgAAA8I&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://whitepapers.theregister.com/



Anonymous Coward

The bank isn't the criminal here (for a change) but it does open up yet another way for them to abuse the system and blame customers for everything.

There's also no incentive for them to improve the security and procedures to help against that sort of scam or make recovery of funds easier.

A couple of simple measures come to mind, including age checking the receiving account then enforced escrow if it's been created in the past x days, weeks etc.

Similarly, escrow if the receiving account is suddenly in receipt of lots of payments from sources that have never paid it before or if it's a new recipient for payments by the victim.

DJO

If the banks allow people to open accounts without proven identification or any way to positively identify the account owner then they should be culpable for any criminal activity from that account.

Who is responsible for rampant payment and transfer scams?

t245t

Ultimatly, the end-user. If someone phones/emails you and persuades you to divulge information or install “TeamViewer Remote then it's down to you. Anything else, it's the banks responsible.

--

Personally I welcome the coming rule from our WEF overlords ;) You shall own nothing, be happy and eat zee bugs /s

Re: Who is responsible for rampant payment and transfer scams?

Headley_Grange

If someone phones my mum to con her out of her money and says they are from her bank and my mum's phone confirms it's the bank's number then the phone company should be responsible either for collusion, an accessory before the fact or some other criminal offence that sees their directors in jail.

who is responsible?

Neil Barnes

The scammers.

Who have spent - in various incarnations - centuries learning how to con people out of their money. If someone falls for it, is it their fault? If a bank has reason to believe that they're giving money to the right person, and they're not, is it their fault?

As it happens, I moved a lot of money from the UK to a foreign account recently. My bank required me to be there in person to approve it, irrespective of the fact that they pay smaller amounts to the same account every month. It was a pain, but I think a worthwhile one.

My late father was scammed years ago - in a complex scam at the time which took account of him calling the bank back and then disabling his phone line so the bank couldn't contact him. The bank refunded him fifty grand or so... (we implemented a new protocol where he would call someone he knew, like me, in future similar events).

RTFA

Diogenes8080

Some commentators appear to have missed one of the points - the Singaporean paper is saying that the banks do not pick up liability if they have not practiced fsckwittery.

That rather limits their scope for communication, since many of the available media are inherently fsckwitted for financial communication. A PSTN that is open to spoofing? SIMs that can be 'jacked by spinning a tale at the local carrier retail outlet? Active collusion by corrupt staff at any point in the over-extended outsourcing chain? Secret Q&A in an era of criminal e-pending? FFS, that's worse that a moderately weak password.

There are secure means of consumer communication. The banks know them and many of us know them. We simply need an ombudsman that knows them, but that might be too big an ask.

Zippy´s Sausage Factory

While I get that this is a good idea, it will encourage banks to close accounts of people who've been scammed - they're a risk, right? And run a list of people who've been scammed so other banks know not to open an account for them (although that's probably illegal, but no doubt will happen behind the scenes). Plus the infernal gazillion checks they already run (that probably catch about 0.005% of all scams) will get worse.

Maybe it's a step in the right direction, but I fear the unintended consequences could be worse than the disease.

(Plus people will probably start to say "who cares if it's a scam, the bank will refund me", which is also bad.)

Where's the "I'm seriously conflicted and while I can see both sides of the argument I'm not sure this is the right answer to the right problem" icon?

Men's skin is different from women's skin. It is usually bigger, and
it has more snakes tattooed on it. Also, if you examine a woman's skin
very closely, inch by inch, starting at her shapely ankles, then gently
tracing the slender curve of her calves, then moving up to her ...

[EDITOR'S NOTE: To make room for news articles about important world events
such as agriculture, we're going to delete the next few square feet of the
woman's skin. Thank you.]

... until finally the two of you are lying there, spent, smoking your
cigarettes, and suddenly it hits you: Human skin is actually made up of
billions of tiny units of protoplasm, called "cells"! And what is even more
interesting, the ones on the outside are all dying! This is a fact. Your
skin is like an aggressive modern corporation, where the older veteran
cells, who have finally worked their way to the top and obtained offices
with nice views, are constantly being shoved out the window head first,
without so much as a pension plan, by younger hotshot cells moving up from
below.
-- Dave Barry, "Saving Face"