Within the last several months, the FBI has seen a significant increase in fraud involving the exploitation of valid online banking credentials belonging to small and medium businesses, municipal governments, and school districts." (FBI statement, December 2009)
Rude awakening or grassy knoll gunman / tinfoil hat crusade?
Gartner VP Avivah Litan has also been following this banking trojan trend and recently blogged about attending the FDIC's one-day symposium held earlier this year. Her August 2009 warning included this summary:Criminals frequently target business bank accounts that cash managers handle on behalf of small businesses, school districts, county governments and other similar organizations.
Criminals raid these accounts for millions of dollars (no estimates are available for the total amount of money stolen, but Gartner believes it could be very large) by planting trojans on user desktops to steal account credentials and transfer money to criminals' accounts.
Especially problematic aspects of these incidents include:
- Lack of disclosure by banks to shareholders and account holders, who must learn about these incidents from media reports
- Criminals' practice of targeting business accounts, which are typically larger but enjoy less protection under the law than consumer accounts."
