More Payment Vulnerability Than You Might Think
One-time passwords (OTP) are a central part of payment security. It is a concern, therefore, to read about hackers hijacking OTPs sent via SMS by Singapore banks to their customers, resulting in fraudulent credit card transaction worth S$500,000, as recently reported by the Monetary Authority of Singapore. To be fair, this happened late 2020 and only affected 75 bank customers.
The hack was possible because criminals gained unauthorised access to the systems of overseas telecommunication companies and modified the location data of the victims’ mobile phones. Armed with the card details, the criminals could make fraudulent online transactions and authenticate them with the diverted OTPs.
Apple Pay vulnerability. A researcher at the University of Birmingham in the UK has demonstrated a vulnerability of Apply Pay to what is known as ‘man-in-the-middle’ attacks. It only applies to a Visa Card within Apple Pay. The attack modifies transactions so that they appear to have been authenticated by the user using Apple biometric or PIN. It exploits the express transit model, launched by Apple in May 2019, which allows payments to be initiated at a transit terminal without unlocking the phone.
Subscriber content
Read the full article
Full access to Cash & Payment News articles, newsletters and archives.