Economist, June 1, 12013
... and begets the largest fraud in history.

Transparency, checks and balances should never be optional.

It would be quite difficult to compromise security if we each existed entirely in our own hermetically-sealed network like an egg in a carton or a standalone PC on a desk. Each connection with the outside world creates a perforation in the egg shell and creates a security risk in the form of a point of potential compromise. The perforation can be compromised or the "tube" connecting me to the next "egg" can be compromised. Further, the "egg" I'm connecting to can be compromised. Or an "egg" connected to the one I'm connected to can be compromised. As you can imagine, hyperconnectivity increases the number of points of potential compromise exponentially with time.
Our current risk-mitigation approach tries to hermetically seal all the perforations, joints, and pipes by wrapping them in a "fortress firewall." This becomes exponentially more difficult with the increase in points of potential compromise. Attacks are inevitable, as are compromises until and unless our approach to risk mitigation shifts from a "fortress firewall" approach to one in which we can examine, wrap, and filter actual bytes of information as they float around cyberspace.
While I don't know what this approach will look like in practice, I predict it will include a strong focus on data provenance. Imagine an "HTTPS 2.0" in which we not only wrap packets of data in an encrypted security layer, but also give that packet the ability to either reveal its contents or self-destruct based on who/what/where/when/WHY it is accessed.
Until then, data security risk shall continue to increase.
"when P2P file-sharing software is not configured properly, files not intended for sharing may be accessible to anyone on the P2P network. ... we found health-related information, financial records, and drivers’ license and social security numbers--the kind of information that could lead to identity theft."A very small fraction may intentionally use these technologies to steal sensitive or private information about the institution or its clients, but a far larger number are unwittingly exposing this information to the open Internet.
-- FTC Chairman Jon Leibowitz on the FTC's website.
Chinese state television has broadcast footage of what two experts on the Chinese military say appears to be a military institute demonstrating software designed to attack websites in the U.S.DailyTech blog captured screenshots including the image below.
This new Cyber Cold War is the most unconventional and asymmetric war the world has ever seen. Control is extremely decentralized. Weapons are easily acquired. The risk of retaliation is low. Battles are waged remotely. The prosecutors and victims of the war can be anyone or any group of people. Governments, individuals, and businesses are all players, like it or not.
"A vast Chinese cyber-espionage network, codenamed GhostNet, has penetrated 103 countries and infects at least a dozen new computers every week, according to researchers ... [GhostNet] is the latest sign of China's determination to win a future 'information war'... In 2003, the Chinese army announced the creation of 'information warfare units'."Fox News added to the story:
"The Chinese government on Monday denied it was behind GhostNet"Banking has the notion of security at its core. Think of a bank branch and you'll instantly visualize vaults, armed guards and video surveillance. Behind the scenes, banks all have hardened ATMs, teller stick-up procedures, passwords and permissions. In other words, security is tightly integrated with their physical channels.
"Financial Crime (including topics like Money Laundering, Identity Theft, Fraud, Unauthorized Access, and Data Theft) is the next frontier in the evolution of Risk Management." 1/3/2011Halfway through the year, this has been borne out in the headlines. While no institution is immune, headlines this week have given one clear example of what I was talking about:
"Citibank has revealed that it detected a data breach last month that exposed fully 1% of all its North American credit card customers’ account details. Citi has about 21.2 million credit card customers in North America according to its annual report, implying that close to 210,000 accounts may have been hit." Andy Greenberg, Forbes Blog.Only 11 months ago, the remnants of Countrywide Financial settled a class-action lawsuit by setting aside $56.5 million (not including court costs) to cover claims of anyone impacted by an alleged data breach of 2.5m identity records. They, like Citi, were particularly criticized for delaying disclosure. This presumably allowed them time to assess vulnerability, fortify security controls, and perhaps get their legal arguments in order. At the same time, their delay gave identity thieves extra time to use the stolen data to defraud Countrywide's unsuspecting customers.
"The White House’s proposed cybersecurity policy outlined last month would include a mandatory federal breach disclosure law, and another bill proposed by Senator Patrick Leahy would similarly make concealing a data breach a federal crime."These legislative proposals are atop upcoming FDIC regulations and FFIEC standards on authentication which will likely contain provisions addressing:
Let's focus for a moment on the ratio of spending between IT and Ops. Across the industry, FIs spend far less than a third of their Anti-Fraud budget on technology and projects. If you include actual fraud losses in the numbers, that percentage drops well below a tenth of all spend.My dad gave me one dollar billPeople working in anti-fraud live and breathe money: losses, recoveries, write-offs. If it costs $1,000 to investigate and recover $500, we all intuitively know that would be a waste of time. We might as well just write off the $500 and move on. And yet...
'Cause I'm his smartest son,
And I swapped it for two shiny quarters
'Cause two is more than one!
And then I took the quarters
And traded them to Lou
For three dimes -- I guess he don't know
That three is more than two!
...
And then I went and showed my dad,
And he got red in the cheeks
And closed his eyes and shook his head--
Too proud of me to speak!
- Shel Silverstein
Me: “You might not need a new system. Does your existing technology really ensure your team looks at the biggest risks first?”Just like Silverstein's "proud dad" in the poem, this client was a bit red in the face with frustration. His technology and teams clearly had some growing-up to do.Client: “Of course! We do the big transactions first. We have a ‘red’ queue for stuff that requires immediate action.”
Me: “So I imagine if there was a $50k wire, way out of normal for the customer, it would pop into the ‘red’ queue and get looked at right away.”
Client: “Right.”
Me: “And if, at the same time, your systems saw a different account with a series of unusual log-in and balance inquiry events, it would put that in a lower-priority queue?”
Client: “Yeah, unless it was linked to a financial transaction.”
Me: “What if those logins were for the CFO of a very profitable business banking client?”
Client: “Well, the system wouldn’t really know that. We’d see it during investigation.”
Me: “What if the CFO had online access to draw on a $1m revolving line of credit without secondary approval? What if he hadn’t logged in since 2008, but then one day logged in several times, browsed all over your Business Banking portal, and changed wire instructions for an approved beneficiary?”
Client: “Hopefully that would set off alarms! Probably not a ‘red’ alert, but we’d notice for sure. I know we get reports from the wire room every morning. We could call the client and verify the change.”
Me: “What if, at 3:55pm Eastern Time that same day, the CFO logged back in, drew down the line of credit and wired $1m out?”
Client: “NOW there would be a ‘red’ alert!”
Me: “And you'd be on your back foot. How much would you have to spend to drop everything and investigate in order to get the money back?”
Client: “Well it might not be our loss. We can't prevent the client from having a criminal at the CFO spot.”
Me: “How much would you spend to determine if it was really the CFO or an identity thief? No matter what, the client's not going to be happy. Odds are, they're going to close their account. What kind of heat would you get from the banker in charge of the client? Maybe they even drag you to court. What would that cost? ”
Client: “Welcome to my daily nightmare! It's the hassle of a lifetime!”
Me: “Wouldn't it be better if your systems could just prevent the wire in the first place? What if my team could get your existing technology to do that?”
Client: “When can you start?”

First, let me recite some conventional wisdom:
- C-suites, boards, and shareholders are laser-focused on containing cost and building customer relationships
- The cost of acquiring a customer is 5 times the cost of retaining one
- Fraud is a counter-cyclical industry, increasing during economic downturns
Next let me cite a few numbers from recent industry research:
- 25 percent of customers touched by a fraud event leave their financial institution
- 11 million identity theft victims in 2009
- 54 billion dollars lost to identity theft-related fraud in 2009
- 100 percent increase in fraudulent online accounts in 2009
- 12.5 percent of Financial Industry IT budgets are spent on anti-fraud measures
For too many Risk and Fraud-Prevention executives, the real sum of these numbers is most evident in their elevated blood pressure. Without a doubt, this is a challenging time to be on the front lines of fraud prevention.
It is no time to find out you're fighting yesterday's war on fraud. Yet many organizations still rely on a sloppy spaghetti of siloed point-solutions and manual processes, predominantly focused on card or check fraud. Increasingly, fraudsters successfully take advantage of this fact by launching multi-channel, phased schemes.
Don't take my word for it ...
“financial institutions… are all reporting a significant increase in funds transfer fraud involving the exploitation of valid banking credentials belonging to small and medium sized businesses … Web-based commercial EFT origination applications are being targeted by malicious software.” -- FDIC Bulletin, 21 August 2009
“Dwelling House Savings and Loan, which saw most of its capital get wiped out as a result of a large fraud related to electronic fund transfers, was seized by regulators late Friday.” -- TheStreet.com, 14 August 2009
“Criminals have found out they can make victims of more people than ever before … It continues to be a multi-channel crime.” -- James Van Dyke, President of Javelin Strategy & Research, 4 February 2010
Over the coming months, I will use this blog to examine a series of emerging fraud threats and how leading financial institutions are responding.
Combating fraud is a common cause. I encourage readers to share their thoughts, stories, pains, questions, and victories by commenting on this site directly or emailing so I can include your feedback in an upcoming blog.