Australia Bankers Association: Australia Safe From NZ Banking Code
Brett Winterford and Liam Tung write on ZDNet Australia:
The Australian Bankers Association says it won't be following New Zealand's lead after its Kiwi peer opted to make users of online banking held liable for Internet fraud.
Earlier this month, The New Zealand Banking Association introduced its 2007 Banking Code of Practice, which leaves customers potentially liable for losses when cheated of their funds by online fraudsters.
If customers of New Zealand banks fail to update their operating system, antivirus, firewall, anti-spyware and anti-spam, or if they fail to follow procedures outlined by the bank, they may find themselves liable if they fall victim to Internet banking fraud.
The changes also allow Kiwi banks to request access to customers' computers to verify standards have been met in cases of fraud. The code states: "If you refuse our request for access then we may refuse your claim."
More
here.
From New Zealand to The UK: Banking Customers On The Hook For Out-of-Date Software
Via OUT-LAW.com.
The banking industry has re-affirmed a policy that makes online banking customers responsible for losses if they have out of date anti-virus or anti-phishing protection. New Banking Codes for consumers and businesses took effect on Monday.
The Banking Code produced by the British Bankers' Association (BBA), and followed by most banks, makes it clear that banks will not be responsible for losses on online bank accounts if consumers do not have up to date anti-virus, anti-spyware and firewall software installed on their machines.
"If you act without reasonable care, and this causes losses, you may be responsible for them," says the Code. "This may apply, for example, if you do not follow section 12.5 or 12.9."
Section 12.9 says: "Keep your PC secure. Use up-to-date anti-virus and spyware software and a personal firewall."
The BBA said that it was not aware that any bank had ever invoked that clause of the Code to avoid covering a consumer's online banking losses. The new Code came into effect at the beginning of this week. The latest edition of the Business Banking Code took effect the same day.
More
here.
Note: Background on the exact same issue in New Zealand
here.
-ferg
Bank of New Zealand Shuts Down Web Site After Phishing Attack
Via Netcraft.
A phishing attack led the Bank of New Zealand to take its online banking web site offline Thursday to prevent scammers from draining customer accounts. The bank said that although there had been no threat to its Internet infrastructure, the site was shut for eight hours to protect customers who shared their banking logins with a spoof web site operated by a phishing crew. The BNZ web site came back online Thursday evening with "restricted functionality," and returned to full service on Friday, bank spokesman told the National Business Review.
Bank of New Zealand said it will continue to closely monitor Internet banking transactions, and has revised daily transaction limits for all customers. The bank also suspended Internet banking access for customers who enteered their details at the fake site.
The bank issued a security advisory describing the email and spoof site and asking customers to contact the bank if they responded to the bogus "bait" email. The bank also restated measures customers can take to protect themselves against phishing attacks.
New Zealand: Consumer Advocates to Fight Banking Online Fraud Liability Code
Brett Winterford writes on ZDNet Australia:
Internet advocacy group InternetNZ and the NZ Consumers' Institute have both come out swinging over the New Zealand Bankers Association's (NZBA) decision to allow victims of Internet banking fraud to be potentially held liable for losses.
Representatives from both institutions have met with the NZBA to voice their concerns about the new Banking Code of Practice, which essentially makes Internet banking users liable for fraud-related losses.
More
here.
Note: Background
here and
here.
New Zealand: Banks Suppress Info About Security of Online Banking
Via Stuff.co.nz.
New Zealand's mainstream banks have suppressed information about the level of concern about the security of online banking.
Polling company Neilsen, which conducts surveys for the Bankers' Association, today published a news release showing the uptake of online banking, but when asked about security questions, spokesman Donald Sheppard said banks didn't want that information released.
"The banks we work with didn't really want that going to press because it's a little bit of a can of worms for them," he told NZPA.
"People are naturally concerned about online banking and that kind of thing and there's been a lot of info in the press about all these scams and phishing and all of that.
"We do monitor it... but our clients are the four main banks and they didn't want that going out into the public arena because they didn't want another song and dance about that," he said.
More
here.
Note: I can't image why people might be
concerned?
-ferg
New Zealand Teen Defrauds Bank Customers
Lane Nichols writes on TheAge.com.au:
A New Zealand teenager who was sent on a computer training course as part of a police rehabilitation program has admitted to hacking into internet banking accounts and stealing nearly $NZ50,000
The 16-year-old from Upper Hutt appeared in court yesterday facing 26 fraud charges over hacking incidents that took place in August and September.
Police say he posted a computer virus on an internet message board and used it to capture details from people's personal computers.
Customers of Westpac, ANZ and ASB were all hit. The biggest transaction involved $US6323, but the banks agreed to reimburse the losses.
More
here.
(
Props, paperghost.)
Shifting Liability: Consumers Fail to Meet Banks' Online Security Demands
Via CBC News.
Many consumers who manage their money through online banking services may be unaware of their financial institution's strict security requirements, thereby jeopardizing their eligibility for fraud reimbursement, according to a study out of Ottawa's Carleton University.
"All the time [the banks] say it's safe, and secure and simple, but consumers should be a little bit cautious about those marketing messages," lead researcher Mohammad Mannan, a computer sciences graduate student, told CBCNews.ca.
"They should check whatever is recommended and required by their bank, and then decide whether they can follow all the advice and recommendations."
Mannan will present the study at the New Security Paradigms workshop in New Hampshire on Tuesday.
More
here.
Note: Interestingly enough, I am seeing exactly what I predicted would eventually (albeit slowly) begin happening several months ago -- a shift to place more online banking and financial fraud liability to the consumer. This study in Canada underscores the same issues that surfaced earlier this year in
New Zealand.
- ferg
Is My Bank The Biggest Scammer Out There?
Liam Tung writes on the ZDNet Australia "Securify This!" Blog:
Under the British Bankers' Association code -- a voluntary code of practice similar to Australia and New Zealand's banking association structure -- the onus is on the bank to prove users have acted fraudulently or without reasonable care before they become liable for the misuse of the card. If it can't, the user isn't liable.
But since the introduction of chip and PIN cards, consumers are increasingly being turned away by banks when making a compensation claim.
That's because chip and PIN technology prevents cards from being cloned through card skimming scams. But so sure are the banks of this bulletproof technology that some are assuming that if a fraudulent transaction occurs where a PIN has been used, it must have been the cardholder's fault.
Bulletproof it's not though. Researchers at Cambridge University recently showed that you don't need to clone a card to compromise it.
More
here.
New Zealand: Online Banking Fraud Liability Issues Still Up In The Air?
Via Stuff.co.nz.
Banker's Association chief executive Alan Yates remains confident that banks will reach a consensus on the terms of a controversial code of practice for the industry that will cover Internet banking, after four months of silence from them on the progress of negotiations.
The association announced in August that banks were considering "clarifying the code", which was issued in June, and had taken media criticism of it on board.
It would then consult with NZ InfoTech and Computerworld, InternetNZ and the Consumers' Institute, which proposed a range of revisions.
The code of practice, issued in June, asserts the right of banks to pass liability for fraud losses on to customers, potentially emptying their accounts, if customers access Internet banking on computers that are not fully protected with up- to-date security software.
More
here.
Background
here.
New Zealand: ASB Bank to Review Net Fraud Liability
Via Stuff.co.nz.
ASB Bank will decide this month whether to back down on its hardline stance over customer liability for Internet banking fraud.
Since July, ASB's 550,000 Internet banking customers have been liable for losses from phishing attacks and other fraud if they use computers without up- to-date anti-virus and firewall software and operating systems.
Spokeswoman Debby Bell says the bank has in the past always reimbursed fraud victims who weren't running up- to-date software, but it won't guarantee it will do this.
ASB will release updated terms and conditions for Internet banking towards the end of this month, she says.
More
here.
Conficker Worm Strikes ANZ Bank
Suzanne Tindal writes on ZDNet.com.au:
Australia and New Zealand Banking Group today confirmed it had become the victim of a computer virus attack, with sources saying it was the much-hyped Conficker worm.
"We have detected a known virus affecting some internal desktop services on the ANZ network," a spokesperson for the bank told ZDNet.com.au today, saying that the virus had been contained and there hadn't been any disruption to its business or implications for information security.
The spokesperson did not specify which virus had infected the bank's desktops, but ZDNet.com.au believes it is a variation of the Conficker worm.
More
here.