Stamp out mobile banking fraud

May 2015 Integrated Solutions, Access Control & Identity Management

Financial services companies should look for solutions that allow them to control the entire mobile transaction lifecycle if they want to beat fraudsters that exploit mobile security gaps to defraud bank account holders.

Zane Renou, chief commercial officer at Cellfind.
Zane Renou, chief commercial officer at Cellfind.

That’s the word from Zane Renou, chief commercial officer at Cellfind, who says that banks should take a proactive approach to securing the vulnerabilities in SIM cards and devices that create opportunities for impostors to defraud customers.

“Internet and mobile banking fraud is on the increase as con artists take advantage of a range of systems and communication channels to pilfer account holders’ information and to access their bank accounts. SIM swapping is still perhaps one of the biggest threats, particularly because it lends itself to social engineering or dishonesty by employees in some cases.

“But other threats are also on the rise, for example, smartphone malware designed to steal customers’ log-in information; and spoofing attacks where hackers produce fake messages or transaction requests so that they can pretend to be someone else.”

Renou outlines the most common forms of mobile banking fraud and theft as follows:

• Eavesdropping: Criminals can eavesdrop on messages since most of these are not encrypted. From these messages, they learn valuable information for use in their intrusions and attacks.

• Smartphones: Because they’re essentially handheld computers, smartphones are vulnerable to malware. Once a hacker has gained control of a smartphone via malware, or by a stolen phone, he or she has access to the account holder’s banking channel.

• SIM swaps: Via identity theft or with the collusion of an employee working for a mobile operator or a service provider, the fraudster could obtain a new SIM card for a user’s cellphone number. This enables the fraudster to receive one-time PIN codes for online transactions or to use the customer’s mobile banking PIN. Of course, the fraudster will need to get the user’s banking details first, which is usually done through a phishing attack.

• Spoofing: Hackers can produce a false USSD request to masquerade as a user, while cross network roaming means that hackers can gain access to a network while masquerading as a user’s mobile phone roaming on another network. Once hackers gain access to the network, they can make and receive any type of communication on behalf of users. This includes voice, SMS and USSD.

• New methods of attack: A recent trend is to combine a SIM swap and network porting. This buys the hackers time as it takes longer to discover the crime and even longer to stop the service across two networks.

“We are extremely concerned about possible future fraud attacks from remote networks. This type of spoofing bypasses the manual processes involved in a SIM swap, so it can be automated.” Renou says. “The old ways of detecting fraud are constrained and only effective against a small number of attack strategies.

“The SIM is perhaps the biggest soft spot for criminals’ attacks on users’ bank accounts,” says Renou. “But there is technology available today, for example ValiPort, that addresses this vulnerability.”

These solutions secure mobile financial transactions by validating the authenticity of the originator, and that the handset and SIM card are who they say they are. Through a series of steps, the mobile banking solution can ensure that the risks surrounding spoofing and SIM swapping are effectively exposed and pro-actively managed.

For mobile-originated traffic, the origin of the request is verified when the session starts. This means that spoofs are no longer possible and compromised SIM swapping is a thing of the past. For mobile-terminating traffic such as a PIN number sent to a subscriber via SMS or USSD push, the destination is similarly verified before the SMS is delivered, effectively reducing the associated risks.

For more information contact [email protected], www.cellfind.co.za





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

A layered approach to safety in schools
Surveillance Integrated Solutions Education (Industry)
Physical security in schools and learning institutions is a hot topic in South Africa, with the Gauteng Department of Education recently announcing plans to use AI-powered cameras and biometric access to strengthen school safety.

Read more...
Balancing secure access control and fire safety
Editor's Choice Access Control & Identity Management Fire & Safety
In modern building management, few topics create as much tension as the intersection between security access control and fire evacuation safety. Nichola Allen of G2 Fire sheds light on this delicate balance.

Read more...
Integrated layers offer dependable security
OPTEX SMART Security Solutions Technews Publishing Perimeter Security, Alarms & Intruder Detection Integrated Solutions
A layered approach to security tightens protection and minimises downtime and operational risk. Moreover, integrating all the parts of a solution and proving they can do the job before spending money are critical.

Read more...
Digital ID and facial recognition for safer learning institutions
Integrated Solutions Education (Industry)
As crime rises, South African schools and tertiary education institutions are locked in an ongoing battle to secure their premises and keep children and students safe. Focusing on advanced digital safeguards could provide enhanced situational awareness and more effective yet unobtrusive protection.

Read more...
Strengthening critical infrastructure security
Integrated Solutions
Security is a top priority for any organisation responsible for safeguarding critical infrastructure. However, recent events have highlighted the fragility of the global energy supply chain and the need for change.

Read more...
Controlling access for people and vehicles
IDEMIA STid Security Technews Publishing Editor's Choice Access Control & Identity Management Asset Management Industrial (Industry) Mining (Industry)
When it comes to access control, the security requirements of mines and the industrial sector are similar, requiring a layered approach that combines physical barriers, digital authentication, and continuous monitoring to protect personnel, assets, and operational continuity.

Read more...
Paxton launches new phone-based security system: Solo
Paxton News & Events Access Control & Identity Management
Paxton has officially unveiled Solo, a phone-based, cloud-hosted access control system. As part of the launch, installers can claim a free Solo starter kit from Paxton, allowing them to trial the system and see how it can work for their business.

Read more...
Impro announces Primo update
News & Events Access Control & Identity Management Integrated Solutions
Impro Technologies recently held a launch event in which it introduced a series of new products, from new readers through to its updated Primo access management software.

Read more...
The security debt hidden in residential estates
Security Services & Risk Management Integrated Solutions Residential Estate (Industry)
Many residential estates undermine their own security not through a lack of technology, but through hidden weaknesses in gate design, fragmented systems, recurring software dependence, weak operational ownership, and insufficient estate management input.

Read more...
Proactive estate security in Cape Town
neaMetrics OneSpace Technologies Technews Publishing SMART Security Solutions Fang Fences & Guards ATG Digital Editor's Choice News & Events Integrated Solutions Infrastructure Residential Estate (Industry)
SMART Security Solutions started the year with our annual SMART Estate Security Conference in Cape Town on 26 February 2026. Held at Anna Beulah Farm, the conference saw a number of delegates enjoying the farm’s excellent cuisine, while listening to outstanding presenters.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.