Vietnam debates OTP safety following $22,300 bank account hack

Aug 16th at 10:17
16-08-2016 10:17:01+07:00

Vietnam debates OTP safety following $22,300 bank account hack

A recent incident involving a state-bank cardholder who had VND500 million (US$22,300) in her ATM account withdrawn overnight has become a case study as to whether an OTP, or a one-time password, in Internet banking is really safe.

 

Hoang Thi Na Huong woke up on August 4 to find out someone had managed to transfer that huge amount of money from her account, while she did not receive any notification for the transactions either via SMS or the Vietcombank app on her smartphone.

The hackers had managed to withdraw VND200 million ($8,929) of the stolen money via ATMs in Malaysia, before the Hanoi-based lender took action and froze the remaining VND300 million.

Vietcombank, a major state-run lender, said on Friday last week that Huong had visited a bogus website and provided the card credentials of her ATM account to hackers, who later used them to conduct the ATM theft.

The statement has been perceived as a move to duck responsibility by Vietcombank, with many experts believing that the bank should be held responsible for its Internet banking, whose OTP function proves problematic.

As Huong claimed that she did not receive any OTP, the question remains whether hackers also managed to obtain this one-time password.

While it is clear that hackers can easily log in to the Internet banking page on Vietcombank’s website using the username and password stolen from Huong, they still needed the OTP for each transaction to be completed.

Vietcombank allows users to choose to receive an OTP either via SMS or SmartOTP, a feature on its mobile app.

One of the most plausible hypotheses is that hackers changed the mobile phone number of the victim into theirs, and installed the Vietcombank app on their device using the alternative phone number.

This means the OTPs for the transactions stealing money from Huong would be sent to hackers through the SmartOTP function on their smartphone, instead of Huong’s device.

If this is really the case, experts say Vietcombank is to blame as it allows people to change the phone number for Internet banking on its website, instead of physically coming to a branch office.

Bank cannot duck responsibility

Nguyen Ai Dan, an expert on banking technology, said Vietcombank should not put all the blame on its customer, as the lender already did in last week’s statement on the issue.

“If I were in Vietcombank’s shoes, I could not just say that the customer lost her money through phishing,” he told Tuoi Tre (Youth) newspaper on Sunday.

“That is not enough because the bank plays a part in this too.”

Even if Huong actually lost her account information to a bogus website, Vietcombank should still compensate the victim, Dan asserted.

The expert also suggested that customers avoid putting too much money in one ATM account; limit the number of devices used for online transactions; and not use convenient but high-risk banking services that allow transactions anytime, anywhere.

In the meantime, Vo Van Khang, another banking security expert, said Vietnamese banks should also tighten security on their OTP features.

“What most lenders in Vietnam have yet to do with their Internet banking services is to verify the in-use devices for every transaction,” Khang told Tuoi Tre.

This means banks should track the devices customers use to conduct transactions online, something “Facebook or Yahoo! have done for years,” he said.

For instance, the system should be able to recognize that a user is carrying out a transaction from a smartphone or computer differently from what they used to do, and ask them to confirm if they are really doing the transaction, not a hacker.

Google and Facebook always notify their users whenever there is any new sign-in instance on an unfamiliar device or at an unsual location.

“If banks can do the same, while users are trained to get used to the security of Internet banking, I believe everyone can use the services with ease, as can hundreds of millions of people around the world,” he said.

Ngo Tuan Anh, deputy chairman of Internet security at Bkav, a Hanoi-based security firm, advised Vietnamese ATM cardholders not to boycott Internet banking services following Huong’s case.

“You cannot stop going to the street just because accidents happen every day,” he said. “Boycotting Internet banking services does no good to Vietnam’s development.”

tuoitrenews



NEWS SAME CATEGORY

VAMC can meet debt recovery target this year

The Viet Nam Asset Management Company (VAMC) could meet a target to recover VND30 trillion (US$1.339 billion) of bad debts this year, VAMC Deputy General Director...

SBV reassures people of Maritime Bank's operations

The State Bank of Viet Nam (SBV) confirmed on August 15 that it has the full capacity to support and maintain the normal operation of credit institutions, ensuring...

Businesses hail 3% corporate tax reduction

Entrepreneurs are hailing a national plan to reduce corporate income tax for small- and medium-sized enterprises from 20 per cent to 17 per cent starting next year.

Central Bank projects 7.1% growth in 2H16

The National Bank of Cambodia held a seminar on the state of the economy in the first half of the fiscal year on Saturday, forecasting 7.1 per cent GDP growth for...

More capital from tax havens poured into Vietnam

Foreign businesses have invested in their own companies but have also contributed capital to thousands of Vietnamese companies.

S&P affirms ratings of three Vietnamese banks

Standard & Poor's Global Ratings on Thursday affirmed its ratings of three large Vietnamese banks.

Banks call for customers' caution against cyber attacks

Commercial banks have called for customers to use caution when using telephones and the internet, as hackers may steal from them.

DIV must get larger role: Deputy PM

The Law on Deposit Insurance should be amended to give the Deposit Insurance of Việt Nam (DIV), a non-profit state financial organisation, more independence in...

Vietnam banks' bad debts dip to 2.58 pct of loans in June: cbank

Toxic debts in Vietnamese banks accounted for 2.58 percent of outstanding loans at the end of June, declining from 2.78 percent in the previous month, the central...

Central Bank hints at rate cut

Credit rose 8.54 per cent by July 29 against late last year while mobilised capital surged 9.94 per cent, the State Bank of Viet Nam reported yesterday.

Bank stocks

Insurance stocks


MOST READ


Back To Top