The rise of online financial fraud in Malaysia


 CLICK TO ENLARGE
CLICK TO ENLARGE

ONLINE banking fraud is a hot topic of the day. Not only are the case numbers rising, the amount of money being scammed is reaching eye popping levels.

Many Malaysians with online banking facilities are increasingly worried about cybercrime.

In the first seven months of 2022, Malaysians have lost about RM415mil to scammers.

The problem had become so bad that Bank Negara stepped in this week to issue a strict directive to all Malaysian banks to migrate away from the use of SMS-based authentication in online banking services.

The police are getting more vocal about the problem, providing updates on arrests being made and constantly dishing out advice to the public on ways to avoid getting scammed.

The banks, in the past few days, have also issued statements, talking about how they are raising their defences against cybercrime.

But, what went wrong in the first place for the situation to reach this level?

And, will the new steps that banks are taking help stem the problem?

Datuk Khairussaleh Ramli, the group president and chief executive officer of Malaysia’s biggest bank, Malayan Banking Bhd (Maybank) tells StarBizWeek this: “With the rise in eCommerce activity spurred by the Covid-19 pandemic, and as more consumers prefer to transact online, fraudsters are taking the opportunity to find new ways to scam unsuspecting users.

“The increasing risk of cyber attacks and the potential impact on banks and their customers is a top concern. This has been elevated with the rise in more sophisticated scams such as ‘smishing’ (phishing via SMS) and malicious software (malware) scams impersonating banks recently.”

 CLICK TO ENLARGE
CLICK TO ENLARGE

Ho Siew Kei, cyber risk leader of Deloitte Malaysia, reckons that 70% of commercial crime cases now can be categorised as cybercrime cases.

It appears that the problem lies with the usage of SMS in online banking transactions.

Many Malaysian banks have been using SMS one-time passwords or dubbed OTPs for online financial services.

Users need to key-in authentication OTP codes, obtained through SMS, to a browser or a mobile application to carry out their online banking transactions.

However, fraudsters have been able to get control of these codes from the devices of some customers.

It all starts when a user unknowingly downloads malicious applications or clicks on links that eventually leads to the installation of malware.

Such users are enticed to follow such links sometimes due to a promise of receiving a reward or other benefits.

Fraudsters, through the malware, will then be able to intercept sensitive information, including banking credentials and credit card numbers.

It also allows fraudsters to intercept messages being sent to the device such as the OTPs received for online transactions.

Upon obtaining the OTPs, fraudsters may also delete the SMS from the device, which often leaves victims believing they did not receive any SMS.

With this method, fraudsters are able to get control over users’ bank accounts. This can lead to financial scams that often occur without the knowledge of the victims.

According to Sea Chong Seak, chief technology officer of cyber security firm Securemetric Bhd, the problem seems to lie not so much with attacks against banks’ systems or networks but rather due to the weaknesses that exist in the security of end users’ devices.

Users that download suspicious apps or go into questionable links through their mobile devices create an entry point for the fraudsters, owing to the low security control, he says.

“This is why banks need to move away from the usage of SMS OTPs in the authentication processes. The better technology is widely available ranging from the use of QR codes to the use of external dongles,” says Sea.

Sea cites the case of Citibank Malaysia that uses QR codes and biometrics in it authentication processes as an example.

Meanwhile, Maybank points out that it has introduced the usage of Secure2u since April 2017 for an alternative secure authentication method.

“It is a safer and more convenient way for Maybank customers to authorise transactions relating to account opening, fund transfers and payments on its online banking services mobile applications, using one-tap approval and a six-digit transaction authorisation code (TAC) number generated on its applications,” says Khairussaleh.

For better protection against cybercrimes, Khairussaleh says: “Currently, we only allow one Secure2u device per account holder to prevent fraudsters completing financial transactions without authorisation from the registered device.”

However, it should be noted that while more secure authentication technologies have been available to banks, the usage of SMS OTP has been largely used because of the ease of use for customers. This also helped banks migrate its customers into online banking. The usage of dongles or other technologies would have also meant higher costs to the banks.

Ho Siew Kei, cyber risk leader at Deloitte Malaysia, says that while Bank Negara’s decision to nudge financial institutions towards more sophisticated authentication methods is a step in the right direction, there will be challenges due to the widespread use of more traditional devices at this point in time.

“However, as older devices are replaced by devices that are affordable yet are more advanced and able to support the latest technology, we should see adoption of the advanced security features become commonplace,” he says.

In replies to questions from StarBizWeek with regard to the usage of SMS OTP in online financial transactions, Mohd Rashid Mohamad, group managing director and CEO of RHB Bank Bhd, says: “It takes into account the needs of various segments of customer demographics, including those who do not own smartphones or do not have access to data and Internet connections.”

Rashid says RHB Bank views fraudulent activities and financial scams very seriously, and is consistently enhancing its security measures.

However, he believes there is a need for heightened awareness and education about scams and frauds among customers.

“It is equally important that customers are kept informed on the latest scam and fraud trends so that they are aware of potential threats and therefore able to avoid becoming victims,” he says.

RHB Bank uses Secure Plus for its customers’ transaction authorisation process, which uses QR codes and biometrics for authentication.

Rashid notes that RHB Bank plans to fully migrate all transactions into Secure Plus by next year.

Technology firm Marco Kiosk Bhd, which provides SMS-based OTP services to banks, shares a different view. CEO Datuk Kenny Goh, says: “Cyber criminals target individual consumers or financial institutions irrespective of the authentication method or the underlying technology deployed.”

Despite welcoming the central bank’s decision to get financial institutions to move out of the SMS OTPs, Goh says: “There is nothing insecure about using SMS OTPs as experience has shown that often the gaps were in either compromised devices, scammers tricking consumers to download apps or getting unsuspecting users to forward SMS OTPs.”

Goh says that knowledge on scam prevention for the public is more crucial.

“Educating and instilling knowledge of how to prevent cyber-based scams is key rather than discarding a long-standing tool that has been proven effective,” he says.

Goh adds that Bank Negara’s decision to nudge banks to migrate away from SMS OTPs will not have any significant impact on Macro Kiosk’s earnings because of its wide product base and the fact that SMS-based services are only a small portion of its earnings.

Notably, Bank Negara has also directed financial institutions to implement other measures.

These include further strengthening of fraud detection rules and triggers for blocking suspected scam transactions and a cooling-off period to be observed for the first-time enrollment of online banking services or secure devices.

Additionally, the central bank said customers should be restricted to one mobile device or secure device for the authentication of online banking transactions and banks will be required to set up dedicated scam hotlines.

Meanwhile, Securemetric’s Sea refers to Fast Identity Online (FIDO) Authentication, which is a security standard that is increasingly recognised internationally for its capability to replace password-only logins with a more secure and fast login, owing to its multi-factor authentication.

According to Sea, FIDO Authentication is simpler for consumers to use, easier for service providers to deploy and is more secure than passwords and SMS OTPs.

Its multi-factor authentication includes the use of biometrics, QR codes as well as unique PINs.

FIDO Authentication is not new in Malaysia, as the National Cyber Coordination and Command Centre (NC4) was the first to adopt it, Sea points out.

Clarence Chan, partner, digital trust and cybersecurity at PwC Malaysia, adds that FIDO’s passwordless authentication stemmed from the goal of minimising phishing attacks, as passwords are the root cause of most data breaches based on various studies.

Ubaid Mustafa Qadiri, head of technology risk and cyber security for KPMG in Malaysia, says: “FIDO is a more secure approach compared to SMS-based OTPs.”

“With FIDO, customers can be restricted to using only one registered device for authentication and online transactions and as a result, will help in reducing financial frauds and scams while performing online transactions,” he adds.

Deloitte’s Chan adds that FIDO standards are seeing greater adoption in recent years, including Malaysia.

Nevertheless, even something like FIDO will not be able to totally eradicate cybercrime.

“Overall security for online transactions is still heavily dependent on the security of the user’s device. So, no authentication method can guarantee 100% safety,” Chan adds.

Meanwhile, Malaysia’s Inspector-General of Police Tan Sri Acryl Sani Abdullah Sani has been providing constant updates of the online fraud situation.

He said this week that the RM415mil losses from January to July this year is the result of 12,092 online fraud cases.

For the whole of last year, losses accumulated to about RM560.8mil coming from 20,701 cybercrime cases.

For 2019 and 2020, there were a total of 13,703 and 17,227 cybercrime cases with losses of RM539mil and RM511.2mil respectively, according to the IGP.

“From 2019 to July 2022, a total of 33,147 suspects in cyber fraud cases were arrested, with 22,196 cases charged in court,” he said.

It should be noted that online banking fraud is not limited to Malaysia.

Globally, cybercrime is the common type of fraud in most industries, based on a survey by PwC titled “Global Economic Crime and Fraud Survey 2022”. (see table)

PwC also notes that cybercrime poses the biggest threats across organisations of all sizes, followed by customer fraud and asset misappropriation.

Additionally, a recent report by S&P Global, titled “Asia-Pacific Banks’ Digital Opening Raises Cyber Risks”, notes that threats of cyberattacks are soaring in the Asia-Pacific region and globally too.

The report says that for banks, data breaches not only create a direct monetary loss but also damages the reputation of a bank and can hit a bank’s credit profile.

“To prevent attacks, Asia-Pacific regulators will need a dogged determination to understand and manage risks. This points to the need for collaboration, and cross-border information sharing to build cyber resilience across entities to prevent systemic risk,” the report notes.

In a separate report, the global rating agency says data breach appears to be the biggest cyber risk for banks, with association to high losses, for both emerging and developed markets. (see table).

Hence, in all likelihood, cybercrime is likely to remain part of the risks that will always exist, more so as online transactions keep growing.

KPMG’s Ubaid points out that the increasing audacity of cybercriminals will keep this threat on an upward trend.

It is left to be seen if the rising tide of cybercrime in the Malaysian financial landscape will reduce following the wide publicity it is getting and the actions being taken by all concerned.

Get 20% OFF The Star Digital Access

Monthly Plan

RM 13.90/month

RM 11.12/month

Billed as RM 11.12 for the 1st month, RM 13.90 thereafter.

Best Value

Annual Plan

RM 12.33/month

RM 9.87/month

Billed as RM 118.40 for the 1st year, RM 148 thereafter.


Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Next In Business News

Adnex unit secures RM10.96mil interior design contract for Hilti
Cathay Pacific flags stronger first-half profit on travel, cargo demand
South Korean equities jump 6% as memory-chip giants build on gains
FBM KLCI slips amid tech rally revival in regional markets
Japan ready to take decisive currency action as yen hits 40-year low
CPO prices seen between RM4,400-RM4,650 per tonne in August - MPOC
DagangHalal advances Malaysia's halal trade presence at Mega Halal Bangkok 2026
Ringgit opens higher against major currencies, flat vs US$
FBM KLCI slides as banks, plantations shed weight
China's Zhongji Innolight seeks US$7bil Hong Kong listing, Asia's No. 2 in 2026

Others Also Read