When we think of bank robbery the image of armed men comes to mind, but that’s a picture long out of date. The sad fact is that these days it’s a lot easier to rob a bank with a computer than with a gun. Over the last few weeks Internet users in the Kingdom have received numerous e-mails from international financial institutions. Those mails requested that the recipients click to a website to update personal details or confirm user names and passwords. While the e-mails looked authentic and the matching websites were user-friendly, the truth is that those communications were sent by criminals using the Internet to commit acts of fraud globally.
Phishing (pronounced “fishing”) is a method used to steal information. It starts out with a spoof e-mail that directs people to a fake web page, where it is hoped that Internet banking or credit card users will give away their account numbers, user names and passwords. While most people don’t fall for the scam, a recent survey by the UK’s Association for Payment Clearing Services (APACS) found that up to four percent of the people asked would respond to the e-mail.
That’s not good news because phishers operate like typical spammers, sending out millions of e-mails in the hope that a small number of unwary individuals will respond. Even worse, some sophisticated phishers rig their e-mails in ways that simply clicking on the link found in the body of the mail will launch a malicious program in the host computer.
The Kingdom’s banks and IT security firms are well aware of the problem and the Saudi Arabian Monetary Agency has formed a banking security committee to develop methods to enhance banking security and educate Saudi bank customers about the danger of online fraud.
“So far the risk to Internet banking customers in Saudi Arabia is negligible,” said the head of Internet banking at one local bank, who asked to remain anonymous for security reasons. “Right now the risk is mostly confined to high-income expatriates and Saudis who are using the online services of international financial institutions. However, we expect that since several international financial institutions have been given licenses to operate in the Kingdom, there will be increasing risks to greater numbers of Saudi-based individuals, as customers sign up for accounts with those international banks. Internet banking fraud is a global phenomenon and we know it is just matter of time before it becomes a serious issue in the Kingdom. Now is the time to educate our customers to the danger before the targeted online attacks begin.”
The Saudi banks are making an effort at education — some more aggressively than others. For example, the Saudi British Bank (sabb.com.sa) has a clear posting under the title “Security Information” on its home page that reads in part:
“Dear Customer, recently there have been many news reports regarding fraudulent e-mails sent to the Internet customers of major global financial institutions. These e-mails typically try to tempt those institutions’ customers to click an embedded ‘link’ to a fairly realistic looking website, where they are asked to enter their usernames, passwords and/or other personal details ‘for security reasons.’ Unfortunately, the real reasons have nothing to do with security, and everything to do with an attempt to gain unauthorized access to customers’ bank accounts.”
The Saudi British Bank message goes on to advise customers that the bank never sends out e-mails asking customers to give up confidential information online. The bank asks that if customers receive such mails they should not respond to or click on the mails and they should contact the SABB’s Internet Banking Helpline immediately.
SABB has listed quite a bit of online security information at its website. Available resources include tips for secure online banking, details of common types of Internet fraud and even a glossary of terms to help users understand IT and security jargon.
It must be pointed out though that postings at websites about online fraud probably do more to reduce banks’ liabilities that to reach out to customers. More aggressive methods need to be employed to educate the public about this issue as all indications are that sooner rather than later Saudi Arabia’s banking customers will be prime targets for criminals acting online.
“Due to the presence of international financial institutions in their market, the UAE has already had to face the first wave of phishing attacks focused on local Internet banking customers. It will not be long before Saudi Internet banking customers become the focus of criminal gangs online,” said Mirza Asrar Baig, CEO, IT Matrix, a Riyadh-based network security firm. “The efforts that the Saudi banks are currently making to educate their customers about online fraud are fine for a start, but more can be done. Immediately, banks may begin leaving users tips about online security that pop up each time customers log on to their accounts. Banks may sponsor community seminars about Internet banking. They can participate in chamber of commerce events to talk about online fraud with businessmen. I would even encourage them to participate in television and radio call-in shows on this topic.”
There also is currently some debate on whether banks should launch high-tech proactive efforts to reduce online banking fraud. Since many criminals access vital banking information thanks to computers loaded with out of date anti-virus programs, unpatched operating systems or broadband connections unprotected by firewalls, it has been proposed that banks do a quick scan of any computer attempting to log on to an Internet banking service. The scan, which would take under a minute, would look for security holes, installed malicious code and spy ware. Banks could decide either to inform the user about security concerns with the computer or perhaps even deny the machine log-in until the security issues are cleared.
On Oct. 1, APACS launched at new website — www.banksafeonline.org.uk — which is designed to be a one-stop consumer and small and medium-sized (SME) business advice site to help these Internet users protect themselves from online scams and threats. One more victim of online crime is one too many. Click to the APACS site and learn how to protect your assets and join in the international effort to combat online crime.

