A bank can authenticate the right customer at 9.01am and still lose control of that session by 9.05am, without a single failed login anywhere in between.
Those four minutes, the window right after a customer proves who they are, are where account takeover fraud increasingly plays out now, according to bank and security executives speaking on a recent Fintech News Network webinar.
Banks have spent years tightening the front door with multi-factor authentication, device binding and biometrics. As those defences have improved, fraudsters have started looking for ways around them.
Some account takeover attacks are now targeting customers after they have already passed those checks, according to Goh Ser Yoong, CISO of Ryt Bank.
“The password is now not going to be the top prize,” Ser Yoong explained. “The authenticated session will be.”
Session cookies and other authenticated credentials can let an attacker resume a login without ever entering the customer’s password.
Ser Yoong pointed to infostealer malware and adversary-in-the-middle attacks as the techniques being used to obtain them. A fake login page, for instance, can sit between a customer and the bank during what looks like a normal login.
Once an attacker has what they need to hijack the session, the password has already done its job. Everything about that login can still look legitimate long after control of it has actually changed hands.
Harvinder Singh, RVP APAC for Identity Security at Entrust, connects this shift to a wider change in account takeover fraud.
Stolen passwords and OTPs remain useful, though attackers can now combine compromised identity data with malware, social engineering and deepfakes.
Source link







