Уровень 0 · материалов: 4
В кластер входят документы о технических уязвимостях систем онлайн-банкинга, телефонии и кошельков, приводящих к краже данных или средств, но не входят документы об ошибках коммуникации или имитации борьбы со скиммингом.
Общие признаки: технические недостатки защиты банков, риски кражи средств и данных, методы обхода аутентификации, ошибки реализации систем безопасности
Группа выше: Безопасность платёжных данных
Смысл: The main idea is that online banking security is often an illusion because advanced malware can bypass multi-factor authentication and manipulate what the user sees on their screen to steal funds undetected.
Sophisticated banking malware can steal money by intercepting one-time passwords and spoofing account balances to hide theft from the user.
Смысл: The text describes a financial theft from an online wallet, highlighting the vulnerabilities of single-factor authentication and the technical difficulties in tracking attackers who use proxy servers to mask their identities.
A user recounts the theft of 9,500 rubles from their Yandex Money account and the subsequent technical disputes with support regarding IP logging and security.
Смысл: The main idea is that poor security implementation in automated bank phone systems (IVR) allows unauthorized individuals to discover account balances, which significantly empowers social engineering and phishing attacks.
Many banks allow account balance checks via IVR using only basic info, which fraudsters use to impersonate bank staff and scam victims.
Смысл: The text warns that the presence of third-party analytics scripts in a banking personal account allows for potential data theft and password interception, posing a severe security risk to users.
The author demonstrates how third-party trackers in Sberbank Online can be exploited to steal user passwords and personal financial data.