· 2 min read

More Payment Vulnerability Than You Might Think

John Winchcombe
John Winchcombe · Editor
More Payment Vulnerability Than You Might Think

One-time passwords (OTP) are a central part of payment security. It is a concern, therefore, to read about hackers hijacking OTPs sent via SMS by Singapore banks to their customers, resulting in fraudulent credit card transaction worth S$500,000, as recently reported by the Monetary Authority of Singapore. To be fair, this happened late 2020 and only affected 75 bank customers.

The hack was possible because criminals gained unauthorised access to the systems of overseas telecommunication companies and modified the location data of the victims’ mobile phones. Armed with the card details, the criminals could make fraudulent online transactions and authenticate them with the diverted OTPs.

Apple Pay vulnerability. A researcher at the University of Birmingham in the UK has demonstrated a vulnerability of Apply Pay to what is known as ‘man-in-the-middle’ attacks. It only applies to a Visa Card within Apple Pay. The attack modifies transactions so that they appear to have been authenticated by the user using Apple biometric or PIN. It exploits the express transit model, launched by Apple in May 2019, which allows payments to be initiated at a transit terminal without unlocking the phone.

Subscriber content

Read the full article

Full access to Cash & Payment News articles, newsletters and archives.

Sign Up to Cash & Payment News Weekly

Receive regular updates on the latest news and articles posted on our website.

Verity

Verity

AI search assistant

Ask me anything from the Cash & Payment News archives.

free questions remaining