Combating the invisible bank robber: RMIT expert

By Dr Jonathan Crellin
Tue, June 4, 2024 | 7:32 pm GMT+7

In the past, bank robbers wore masks, but now you cannot see them. In the digital era, second device authentication is the best method of combating the invisible bank robber, wrote Dr Jonathan Crellin, program manager in cybersecurity at RMIT Vietnam.

 Dr Jonathan Crellin, program manager in cybersecurity at RMIT Vietnam. Photo courtesy of RMIT.

Dr Jonathan Crellin, program manager in cybersecurity at RMIT Vietnam. Photo courtesy of RMIT.

Second device authentication (where a code is sent to a second device) is secure, but not invulnerable. For example, a bad actor can create a simulation of a banking login system, and simulate the request for an OTP via text message, or by using a bank app. When the customer enters the OTP into the simulation, the criminal can then use it to log in to the real bank account and take control of the account.

The bad actor may simulate some forms of system failure (“website unavailable please log in later”), so the customer does not immediately realize something has gone wrong. This is one reason why your bank tells you “…never to follow a link sent to you (for example: by email)” as this can contain a very similar URL pointing to a fake, simulated bank site.

From your point of view, always use a legitimate link or web address for your bank. If you use a banking app, download it from a legitimate source, such as the Play Store or Apple’s App Store. If your phone is compromised with malware, it can facilitate a bad actor gaining access to your phone, using apps, seeing received text messages, controlling the phone remotely, running apps, and extracting information.

SIM swapping has been a very popular technique in recent years. This involves a criminal tricking a mobile network company into reissuing a replacement SIM card linked to the same original number. This is often used with high-profile targets. It is an easy attack if the bad actor can obtain personal information about the victim, which may be recoverable from a dark web marketplace. Once the new SIM is reassigned, the original SIM will stop working.

Another technique that was used in the past was SIM cloning. Here, a duplicate SIM is created which has the same IMSI number (the SIM’s network identity number), authentication number (KI), and phone number as the original SIM. This technique became difficult from 3G onward, as the KI is difficult to recover. However, many IMSI KIs can be found for sale on dark websites, so if someone was unlucky, their IMSI might have been listed.

If a bank identifies that their app was used on a different type of device than usual, this suggests that SIM cloning or SIM swapping may have occurred. The bad actor using another phone can set up biometric authentication with the banking app that uses the bad actor’s biometrics. From the app’s point of view, the correct person is using the app since the app relies on the phone’s biometric system to confirm the identity of the user.

In SIM cloning, the bad actor would need some data from the original SIM, then write these to a new programmable SIM card. Then they have a phone with a SIM that pretends to be the victim’s phone. Both phones will work, but only one at once. The bad actor can send a text from another phone, pretending to be the cell network provider, instructing the victim to turn off their phone for a network update. Whilst their phone is off, the bad actor connects to the bank, transfers money, and then turns off the cloned phone. When the victim turns their phone back on, it reconnects to the network without any immediate indication of the attack.

From the bank's point of view, thefts are often due to customer errors, perhaps leaking too much personal information. The bank's systems are usually as robust as they can be (but still usable for most customers). Criminals rely on people’s carelessness, trust and naivety.

The lesson here is treating your phone and SIM as if they have the same value as all the money in your bank accounts. To enhance security, consider using dual SIM card phones and use one SIM only for things like financial transactions, and the other for less important activities. Be careful not to share the secure phone number and detailed personal information you use for financial transactions anywhere other than the bank. Exercise extreme caution when downloading apps, ensuring they come from legitimate sources. Additionally, contemplate the use of an additional phone with a separate SIM if you plan to use riskier applications.

Authentication poses a significant challenge across all internet activities, especially in financial transactions. Over the years, we have seen numerous advancements in authentication, alongside evolving criminal tactics. IT and cybersecurity programs at many universities in Vietnam equip students with the skills and knowledge about the strengths and weaknesses of current authentication systems. These students will be at the forefront of developing and implementing the next generation of technology.

Crime is never going to go away. Every lock we make or system we develop will have some weaknesses, especially if those using them are careless. The motivation to steal money is so strong that there will always be people who work out how to break into systems. But at its best, the digital world does bring many benefits and conveniences, just be careful and aware of what you share and the security of your devices.

From July 1, people in Vietnam transferring money over VND10 million ($393) must authenticate by face and fingerprint.

Comments (0)
  • Read More
Halal market presents major opportunities for Vietnamese businesses

Halal market presents major opportunities for Vietnamese businesses

The global Halal market is projected to reach $5 trillion by 2030, with Malaysia alone expected to hit $113.2 billion, said Shariza binti Abdul Rasheed, Halal product manager at Maybank Malaysia.

Economy - Thu, August 7, 2025 | 9:18 pm GMT+7

Steel major Hoa Phat to pour extra $130 mln into central Vietnam plant

Steel major Hoa Phat to pour extra $130 mln into central Vietnam plant

Vietnam’s leading steelmaker, Hoa Phat Group (HoSE: HPG), will increase investment in its Dung Quat 2 iron and steel production complex by VND3.4 trillion ($129.7 million) as part of an expansion plan.

Industries - Thu, August 7, 2025 | 8:03 pm GMT+7

Vietnam’s army-backed construction firm proposes 14 offshore wind power projects

Vietnam’s army-backed construction firm proposes 14 offshore wind power projects

Lung Lo Construction Corporation (LLC), under the Ministry of National Defense, has submitted investment proposals for 14 offshore wind power projects with a combined capacity of 9,000 MW.

Energy - Thu, August 7, 2025 | 5:07 pm GMT+7

Vietnam's agri major Hoang Anh Gia Lai fined for bond information disclosure failure

Vietnam's agri major Hoang Anh Gia Lai fined for bond information disclosure failure

Vietnam's agri major Hoang Anh Gia Lai JSC has been fined VND92.5 million ($3,528) for failing to disclose bond-related information as required by law.

Companies - Thu, August 7, 2025 | 4:31 pm GMT+7

Northern Vietnam province accelerates $2.2 bln LNG-to-power project

Northern Vietnam province accelerates $2.2 bln LNG-to-power project

Quang Ninh province will hand over 4.9 hectares of reclaimed land to the Quang Ninh LNG-fuelled power plant project before August 11, local authorities stated at a meeting on Wednesday.

Energy - Thu, August 7, 2025 | 4:17 pm GMT+7

Vietnam's seafood firms ride profit wave ahead of US tariff hike

Vietnam's seafood firms ride profit wave ahead of US tariff hike

Vietnam’s seafood companies reported surging profits in Q2/2025, driven by importers ramping up purchases ahead of new U.S. reciprocal tariffs.

Economy - Thu, August 7, 2025 | 2:21 pm GMT+7

Le Anh Tuan appointed new CEO of Dragon Capital Vietfund Management JSC

Le Anh Tuan appointed new CEO of Dragon Capital Vietfund Management JSC

Dragon Capital Group, Vietnam's largest asset manager, has appointed Le Anh Tuan as CEO of its arm Dragon Capital Vietfund Management Joint Stock Company (DCVFM), starting from October 1, 2025.

Companies - Thu, August 7, 2025 | 2:01 pm GMT+7

Indonesia, Malaysia, Thailand expand local currency transaction network

Indonesia, Malaysia, Thailand expand local currency transaction network

Bank Indonesia, Bank Negara Malaysia, and Bank of Thailand have added new Appointed Cross Currency Dealer (ACCD) participating banks to broaden services for bilateral transactions in local currencies across the three nations, Bank Indonesia said in a statement on Tuesday.

Southeast Asia - Thu, August 7, 2025 | 12:48 pm GMT+7

ASEAN to sign MoU on regional power grid implementation

ASEAN to sign MoU on regional power grid implementation

ASEAN member states are set to sign an MoU on the implementation of the ASEAN Power Grid during the bloc’s Energy Ministers’ Meeting this October.

Southeast Asia - Thu, August 7, 2025 | 12:43 pm GMT+7

Vietnam overtakes Thailand to become world's second-largest rice exporter

Vietnam overtakes Thailand to become world's second-largest rice exporter

Vietnam has outranked Thailand as the world’s second-largest rice exporter in the first half of 2025, Thai PBS reported on August 3, citing the Thai Rice Exporters Association.

Companies - Thu, August 7, 2025 | 12:41 pm GMT+7

Vietnam posts trade surplus of $10.18 bln in 7 months

Vietnam posts trade surplus of $10.18 bln in 7 months

Vietnam’s export earnings grew by 14.8% to $262.44 billion in the first seven months of this year, while its import turnover rose by 17.9% to $252.26 billion, resulting in a trade surplus of $10.18 billion.

Economy - Thu, August 7, 2025 | 12:19 pm GMT+7

Malaysia pledges big purchases, investments with US

Malaysia pledges big purchases, investments with US

Malaysia has agreed to buy and invest over $240 billion (MYR1.02 trillion) in the U.S. to help reduce the trade gap between the two countries.

Southeast Asia - Thu, August 7, 2025 | 12:08 pm GMT+7

Vietnam's leading property developer Novaland to issue 152 mln shares to settle $229 mln debt

Vietnam's leading property developer Novaland to issue 152 mln shares to settle $229 mln debt

Novaland, a major real estate developer in Vietnam, plans to issue nearly 152 million new shares to swap more than VND6 trillion ($228.8 million) worth of bond principal.

Companies - Thu, August 7, 2025 | 10:11 am GMT+7

Vietnam's FDI capital disbursement hits five-year record high despite US tariff turmoil

Vietnam's FDI capital disbursement hits five-year record high despite US tariff turmoil

Disbursed foreign direct investment (FDI) capital in Vietnam reached $13.6 billion in Jan-July, up 8.4% year-on-year, despite U.S. tariff concerns.

Economy - Thu, August 7, 2025 | 9:57 am GMT+7

Malaysia steps up efforts to explore nuclear energy potential

Malaysia steps up efforts to explore nuclear energy potential

Malaysia’s Minister of Science, Technology and Innovation Chang Lih Kang on Wednesday reaffirmed his ministry’s commitment to enhancing cooperation with the Ministry of Energy Transition and Water Transformation (PETRA) in exploring the potential of nuclear energy.

Southeast Asia - Thu, August 7, 2025 | 8:10 am GMT+7

Indonesia's economy grows faster than expected

Indonesia's economy grows faster than expected

Indonesia's economy expanded by 5.12% year-on-year in Q2/2025, up from 4.87% in the previous quarter, exceeding the forecasts of many economic organizations, which had previously projected a rate of less than 5%, according to Statistics Indonesia (BPS).

Southeast Asia - Thu, August 7, 2025 | 8:07 am GMT+7