Cybercrooks Targeting FIs 300% More Than Any Other Biz Sector

Rajiv Motwani, Websense

AUSTIN, Texas—A new report indicates that cybercrooks are targeting the financial services sector with increasing sophistication—more so than other industries—and that many FIs rely too much on cybercrime insurance to defend the bottom line against growing attacks.

The 2015 Financial Services Drill-Down Report from Websense Security Labs shows that the financial services sector is seeing 300% more security incidents than any other business sector, including healthcare and insurance.

Rajiv Motwani, director of security research for Websense, told CUToday.info that as the increase in attacks on the financial sector grows, so do crooks targeting banks and credit unions with social engineering efforts.

“There is more high-pressure social engineering attacks,” said Motwani. “The level of sophistication is going way up, and we find attackers are disproportionately investing resources in going after banks and credit unions.”

Some of the methods Websense sees crooks relying on more these days are phishing scams and “typo squatting”—also called URL hijacking. With typo squatting, crooks create a domain name that is close to the victims’ URL, but is a character or two off. Thieves then rely on mistakes, such as typographical errors made by Internet users, when inputting a website address into a web browser.

Motwani said with these kinds of attacks, as well as with other areas of cybercrime, employees are the ones opening the doors to crooks—a growing issue among FIs in the cyber line of defense.

“These social engineering attacks against the financial sector are ingenious,” said Motwani. “Crooks register a domain name similar to the victim’s, and then send an e-mail to one or several employees.”

With the URL looking almost identical to the victim’s, and crooks doing a great deal of research on Linked in, Facebook and other resources, the criminals craft a message to employees that appears to come from someone inside the business being attacked.

“The crooks do their homework,” said Motwani, providing an example of thieves trying to fool employees into sending the criminals money.

“They send an e-mail to the finance department that looks like a legitimate message from the CFO,” explained Motwani. “They get the CFO’s title from Linked in, and they find ways to also pick up on the tone and manner of e-mails the company sends to staff. The message may tell the finance department that the company is late paying a bill and that the attached invoice needs to be paid immediately. So the employee, getting the message from the boss that the finance department is late in paying, is fooled into quickly wiring money to the crooks’ account.”

Motwani said that by the study comparing industries, Websense has gained new insight into attack patterns against the financial services sector. Top findings include:

  • Thirty-three percent of all “lure stage attacks” target financial services. “This means that hackers are spending a huge amount of energy targeting financial services companies with a disproportionate amount of reconnaissance and lures being devised in search of the big payload,” said Motwani.
  • Credential-stealing attacks set sights on banking. “The top threats targeting financial services include Asprox, Vawtrack and the Geodo data credential stealing e-mail worm, which is seen 400% more often in the banking industry,” Motwani said.
  • Fraudsters switch-up campaigns frequently to outfox banking security measures. “Patterns in attack campaigns on a month-to-month basis, including huge spikes in malicious redirection and obfuscation detected in March, highlight a whack-a-mole attack methodology designed for campaigns to be harder to detect and analyze,” explained Motwani. 

Finally, Motwani said the study found bank and credit unions are relying too much on cybersecurity insurance—almost as a means of defense—knowing that if the crooks get through, the insurance will protect the institution from large losses.

“The emergence of cybersecurity insurance may only be providing a meager sense of false security,” said Motwani. “Banks with cyber insurance policies aren’t necessarily fixing their security problems. Rather, they’re relying upon their policies as financial liability risk management. But even that assumption is flawed. Cybersecurity insurance is limited in its coverage, and only partially limits the financial impact of a worst-case cyber-attack scenario. I am not saying cybersecurity is not important. What I am saying is don’t let it make you complacent.”

Section: Standard
Word Count: 795
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto.flux5.ccplatform.net/THE-news/Cybercrooks-Targeting-FIs-300-More-Than-Any-Other-Biz-Sector