Protect yourself from mobile-banking app scams
Security flaws in some mobile-banking apps are being exploited by crooks.
Mobile-banking security is becoming a growing issue as more and more people use banking apps.
Last year the issue gained the public’s attention when a group of thieves started breaking into lockers at gyms across London to steal bank cards and mobile phones while their owners were exercising.
They were then able to use the cards to go on shopping sprees at stores such as Apple and Harrods. Some of the victims reported that their banks were initially unwilling to refund them, saying that the criminals had used their PIN code, so they must have been at fault (eg, by keeping a note of the code with their cards).
Later the banks gave in as it became clear that the problem was not their customers’ carelessness, but weak points in mobile-banking security.
Common bank app scams
There’s no shortage of ways that thieves can try to get into somebody’s account, but many of these involve having some personal information to wriggle around security protocols.
However, what appears to be happening in these cases is simpler. The thief has the cards and the phone. Of course, if they have been able to get a PIN – for example, by watching over the victim’s shoulder as they unlock their phone or use their card – their task is much easier, especially as many people tend to use the same PIN for multiple purposes.
But even if they don’t, they may still be able to get into some bank accounts. The thief installs the mobile banking app for the bank that issues the cards on a new phone and uses the card details to register for it.
Some banks require you to pass detailed identity checks to do this, but a one-time passcode sent to your phone by text message will be enough with others. While the thief can’t get into the original phone, they may be able to read the message in the lock screen if – like many people – the victim has message previews enabled.
Alternatively, they can put the SIM from the stolen phone into another phone. At this point, they can get into the victim’s account via the app, which may allow them to check the PIN for the card or transfer funds to another account, with minimal other security checks.
The apps not vulnerable to scams
Not all apps are so vulnerable: consumer group Which reckons that Lloyds/Halifax, Virgin Money and Barclays are weaker than Chase or Monzo, for example.
But rather than relying on your bank, there are a few steps that can help stop this kind of fraud, beyond obvious ones such as having a hard-to-guess PIN. First, disable message previews so they can’t be seen when your phone is locked.
Second, set a SIM PIN, which stops your SIM being used in a new phone by somebody who doesn’t know the code.
Third, make sure you have Find My iPhone (Apple) or Google’s Find My Device (Android) enabled, so that you can lock and wipe your device remotely if it’s stolen – but note this alone won’t stop a SIM-swap, for example.