<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Frontlines of Fraud</title>
	<atom:link href="http://guardiananalytics.com/blog/index.php/feed/" rel="self" type="application/rss+xml" />
	<link>http://guardiananalytics.com/blog</link>
	<description></description>
	<lastBuildDate>Wed, 11 Apr 2012 21:05:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>Beware the Business Mule: Why Commercial Payees Merit Vigilance</title>
		<link>http://guardiananalytics.com/blog/index.php/2012/04/beware-the-business-mule-why-commercial-payees-merit-vigilance/</link>
		<comments>http://guardiananalytics.com/blog/index.php/2012/04/beware-the-business-mule-why-commercial-payees-merit-vigilance/#comments</comments>
		<pubDate>Wed, 11 Apr 2012 21:05:34 +0000</pubDate>
		<dc:creator>Tiffany Riley</dc:creator>
				<category><![CDATA[Small Business Fraud]]></category>

		<guid isPermaLink="false">http://guardiananalytics.com/blog/?p=248</guid>
		<description><![CDATA[Fraudsters increasingly are targeting the larger account balances of commercial banking customers and hiding behind the more frequent account activity present in business-to-business transactions. The large, frequent fund movements common between organizations are making fraud harder to detect by financial &#8230; <a href="http://guardiananalytics.com/blog/index.php/2012/04/beware-the-business-mule-why-commercial-payees-merit-vigilance/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Fraudsters increasingly are targeting the larger account balances of commercial banking customers and hiding behind the more frequent account activity present in business-to-business transactions. The large, frequent fund movements common between organizations are making fraud harder to detect by financial institutions until the money is gone. As with consumer banking fraud schemes, the crooks rely on money mules to break the final bottleneck – getting the money out. However, because of the complexity of corporate transactions, fraudsters are employing human actors earlier in the process… and closer than ever to the victimized company.</p>
<p>Lately our fraud researchers have noticed a disturbing trend toward “inside jobs” – schemes that rely on money mules recruited from within the legit business’ own employee ranks.  Enlisting them is difficult, so mule handlers offer higher commissions to their traitorous partners. The more common commercial account fraud method is the use of professional mules who set up fictitious companies specifically to receive stolen payouts.</p>
<p>Corporate account credentials command a higher price on the criminal black market. Why? Business-to-business accounts typically transfer higher dollar amounts, more frequently, than retail accounts.  International transfers are easier. Repetitive transactions in a short period of time are easier. These realities all provide more incentive for business mules to complete fraudulent transfers… again and again. Repeat use of business mules is becoming disturbingly common.</p>
<p>These witting mules are hard to detect. The fraudster is relying on a business mule’s seemingly legitimate actions to bypass any security controls. Anti-fraud technology often focuses on business-to-consumer fraud, so B2B transactions receive less scrutiny. The best method of detecting and preventing a mule from emptying your corporate account is to detect account takeover attempts early, before the money is gone. Early fraud setup activity – such as creating a new (fraudulent) payee – can be detected using anomaly detection technology that monitors account activity from login to logout.</p>
<p>My colleague Craig Priess explains business mule scenarios in <a title="Video Fraud Informer #1" href="http://www.youtube.com/watch?v=m95TL-WbLD8" target="_blank">this video explaining their tactics</a>. Check back with this blog for the latest cybercrime tools and techniques from our fraud and threat research teams.</p>
]]></content:encoded>
			<wfw:commentRss>http://guardiananalytics.com/blog/index.php/2012/04/beware-the-business-mule-why-commercial-payees-merit-vigilance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Banking Fraud News Roundup</title>
		<link>http://guardiananalytics.com/blog/index.php/2012/03/online-banking-fraud-news-roundup/</link>
		<comments>http://guardiananalytics.com/blog/index.php/2012/03/online-banking-fraud-news-roundup/#comments</comments>
		<pubDate>Thu, 29 Mar 2012 18:08:21 +0000</pubDate>
		<dc:creator>Tiffany Riley</dc:creator>
				<category><![CDATA[Account Takeover]]></category>
		<category><![CDATA[Consumer Fraud]]></category>
		<category><![CDATA[Small Business Fraud]]></category>

		<guid isPermaLink="false">http://guardiananalytics.com/blog/?p=226</guid>
		<description><![CDATA[2012 started with an explosion of new malware variants. It’s clear already that banking Trojans are propagating at an alarming rate while the ongoing rapid expansion of mobile banking will open a particularly threatening new front in the war on &#8230; <a href="http://guardiananalytics.com/blog/index.php/2012/03/online-banking-fraud-news-roundup/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>2012 started with an explosion of new malware variants. It’s clear already that banking Trojans are propagating at an alarming rate while the ongoing rapid expansion of mobile banking will open a particularly threatening new front in the war on fraud.</p>
<p>Recent industry coverage has only reinforced the continued increase in the overall volume of fraud attacks. In addition, fraudsters are becoming annoyingly adept at covering their tracks with smokescreen methods such as distributed denial-of-service (DDoS) attacks.</p>
<p>What we&#8217;re reminded of repeadedly is that financial institutions must be prepared to defend against a wide range of sophisticated attacks plus new schemes that emerge regularly. Here are a few articles that may be of interest as you develop risk mitigation strategies this year:</p>
<p><strong>New Strains of Malware Emerge…</strong></p>
<p><a href="http://mkto-j0015.com/track?type=click&amp;enid=bWFpbGluZ2lkPWd1YXJkaWFuYW5hbHl0aWNzQmV0YWN1c3QtMTcxNy0yMzA5LTAtMjE3MC1wcm9kLTEzODgmbWVzc2FnZWlkPTAmZGF0YWJhc2VpZD0xMzg4JnNlcmlhbD0xMjYwNjYyMDY2JmVtYWlsaWQ9bWlrZUB0ZWVsaW5nLmNvbSZ1c2VyaWQ9Njg1MTItNTMmZXh0cmE9JiYm&amp;&amp;&amp;http://www.computerworld.com/s/article/9224651/New_Mac_malware_exploits_Java_bugs_steals_passwords?taxonomyId=89&amp;mkt_tok=3RkMMJWWfF9wsRonvK3OZKXonjHpfsX%2B4%2BksW7Hr08Yy0EZ5VunJEUWy2oIGTNQhcOuuEwcWGog8xxlZCOScfY5B9PRRElW7Wyg%3D">New Mac Malware Exploits Java Bugs to Steal Credentials</a><br />
Flashback.G is the first Trojan variant of a well-known family of Mac malware to use an attack vector that doesn&#8217;t require any user interaction. This new version exploits Java vulnerabilities in Mac’s legacy operating system to keylog usernames and passwords for online payment, banking, and credit card websites.</p>
<p><a href="http://mkto-j0015.com/track?type=click&amp;enid=bWFpbGluZ2lkPWd1YXJkaWFuYW5hbHl0aWNzQmV0YWN1c3QtMTcxNy0yMzA5LTAtMjE3MC1wcm9kLTEzODgmbWVzc2FnZWlkPTAmZGF0YWJhc2VpZD0xMzg4JnNlcmlhbD0xMjYwNjYyMDY2JmVtYWlsaWQ9bWlrZUB0ZWVsaW5nLmNvbSZ1c2VyaWQ9Njg1MTItNTMmZXh0cmE9JiYm&amp;&amp;&amp;http://www.networkworld.com/news/2012/020912-citadel-banking-malware-is-evolving-255930.html?mkt_tok=3RkMMJWWfF9wsRonvK3OZKXonjHpfsX%2B4%2BksW7Hr08Yy0EZ5VunJEUWy2oIGTNQhcOuuEwcWGog8xxlZCOScfY5B9PRRElW7Wyg%3D">Citadel Banking Malware Is Evolving and Spreading Rapidly</a><br />
Malware development has gone open source. Citadel, a new ZeuS variant, is evolving and spreading rapidly because its creators adopted a community-based development model. Each version of Citiadel adds new modules and features, some submitted by “customers” themselves.</p>
<p><a href="http://mkto-j0015.com/track?type=click&amp;enid=bWFpbGluZ2lkPWd1YXJkaWFuYW5hbHl0aWNzQmV0YWN1c3QtMTcxNy0yMzA5LTAtMjE3MC1wcm9kLTEzODgmbWVzc2FnZWlkPTAmZGF0YWJhc2VpZD0xMzg4JnNlcmlhbD0xMjYwNjYyMDY2JmVtYWlsaWQ9bWlrZUB0ZWVsaW5nLmNvbSZ1c2VyaWQ9Njg1MTItNTMmZXh0cmE9JiYm&amp;&amp;&amp;http://ffiec.bankinfosecurity.com/articles.php?art_id=4473&amp;mkt_tok=3RkMMJWWfF9wsRonvK3OZKXonjHpfsX%2B4%2BksW7Hr08Yy0EZ5VunJEUWy2oIGTNQhcOuuEwcWGog8xxlZCOScfY5B9PRRElW7Wyg%3D">Banking Malware Finds New Weakness</a><br />
A new ZeuS variant called Ice IX (“ice-9”) automates the process of stealing and changing account holder phone numbers to defeat two-factor authentication. Fraudsters are using it to intercept verification phone calls and pose as the customer to approve their own fraudulent transactions.</p>
<p><strong>….While New Attacks Demonstrate Fraudsters’ Perseverence…</strong></p>
<p><a href="http://mkto-j0015.com/track?type=click&amp;enid=bWFpbGluZ2lkPWd1YXJkaWFuYW5hbHl0aWNzQmV0YWN1c3QtMTcxNy0yMzA5LTAtMjE3MC1wcm9kLTEzODgmbWVzc2FnZWlkPTAmZGF0YWJhc2VpZD0xMzg4JnNlcmlhbD0xMjYwNjYyMDY2JmVtYWlsaWQ9bWlrZUB0ZWVsaW5nLmNvbSZ1c2VyaWQ9Njg1MTItNTMmZXh0cmE9JiYm&amp;&amp;&amp;http://www.theregister.co.uk/2012/02/28/banking_trojan_hijack_live_chat/?mkt_tok=3RkMMJWWfF9wsRonvK3OZKXonjHpfsX%2B4%2BksW7Hr08Yy0EZ5VunJEUWy2oIGTNQhcOuuEwcWGog8xxlZCOScfY5B9PRRElW7Wyg%3D">Banking Trojan Hijacks Live Chat to Run Real-time Fraud</a><br />
A new attack on the Shylock malware platform is hijacking live chat sessions to get business banking customers to hand over their credentials or authorize fraudulent transactions. This Man-In-the-Browser assault interrupts an online session to chat up the victim about a “system check” while the cybercrook simultaneously completes the theft in real-time.</p>
<p><a href="http://mkto-j0015.com/track?type=click&amp;enid=bWFpbGluZ2lkPWd1YXJkaWFuYW5hbHl0aWNzQmV0YWN1c3QtMTcxNy0yMzA5LTAtMjE3MC1wcm9kLTEzODgmbWVzc2FnZWlkPTAmZGF0YWJhc2VpZD0xMzg4JnNlcmlhbD0xMjYwNjYyMDY2JmVtYWlsaWQ9bWlrZUB0ZWVsaW5nLmNvbSZ1c2VyaWQ9Njg1MTItNTMmZXh0cmE9JiYm&amp;&amp;&amp;http://www.infosecurity-magazine.com/view/23953/analysing-the-cyber-scam-that-tried-to-fool-an-infosec-professionals-wife-/?mkt_tok=3RkMMJWWfF9wsRonvK3OZKXonjHpfsX%2B4%2BksW7Hr08Yy0EZ5VunJEUWy2oIGTNQhcOuuEwcWGog8xxlZCOScfY5B9PRRElW7Wyg%3D">New Cyber Scam Is More Polished than Most</a><br />
More professional and elaborate than most social engineering scams, a realistic-looking shopping scam email disguises its executable payload as a harmless PDF where “your recent order can be viewed.” It’s really a nasty Trojan with bot and keylogging capabilities that steals banking credentials.</p>
<p><a href="http://mkto-j0015.com/track?type=click&amp;enid=bWFpbGluZ2lkPWd1YXJkaWFuYW5hbHl0aWNzQmV0YWN1c3QtMTcxNy0yMzA5LTAtMjE3MC1wcm9kLTEzODgmbWVzc2FnZWlkPTAmZGF0YWJhc2VpZD0xMzg4JnNlcmlhbD0xMjYwNjYyMDY2JmVtYWlsaWQ9bWlrZUB0ZWVsaW5nLmNvbSZ1c2VyaWQ9Njg1MTItNTMmZXh0cmE9JiYm&amp;&amp;&amp;http://www.newsfactor.com/news/Malware-Targets-Online-Banking/story.xhtml?story_id=012000E3UEYC&amp;mkt_tok=3RkMMJWWfF9wsRonvK3OZKXonjHpfsX%2B4%2BksW7Hr08Yy0EZ5VunJEUWy2oIGTNQhcOuuEwcWGog8xxlZCOScfY5B9PRRElW7Wyg%3D">New Malware Attacks Target Online Banking</a><br />
A new Man-In-the-Browser attack tricks users who log into a bank’s real site with an offer of training in a new &#8220;upgraded security system.&#8221; After stealing account holder funds it changes on-screen balances to hide its activities, rendering evidence of the theft invisible.</p>
<p><strong>…And the Volume of Attacks Continues to Increase.</strong></p>
<p><a href="http://mkto-j0015.com/track?type=click&amp;enid=bWFpbGluZ2lkPWd1YXJkaWFuYW5hbHl0aWNzQmV0YWN1c3QtMTcxNy0yMzA5LTAtMjE3MC1wcm9kLTEzODgmbWVzc2FnZWlkPTAmZGF0YWJhc2VpZD0xMzg4JnNlcmlhbD0xMjYwNjYyMDY2JmVtYWlsaWQ9bWlrZUB0ZWVsaW5nLmNvbSZ1c2VyaWQ9Njg1MTItNTMmZXh0cmE9JiYm&amp;&amp;&amp;http://www.kaspersky.com/about/news/virus/2012/Number_of_the_week_780_new_malicious_programs?mkt_tok=3RkMMJWWfF9wsRonvK3OZKXonjHpfsX%2B4%2BksW7Hr08Yy0EZ5VunJEUWy2oIGTNQhcOuuEwcWGog8xxlZCOScfY5B9PRRElW7Wyg%3D">780 New Malicious Internet Banking Programs Every Day</a><strong><br />
</strong>Kaspersky Labs reported on the recent explosion of banking malware: 1.1 percent of all malicious programs detected – or 780 new programs EACH day – target financial data. A malicious program of this kind is detected on an average of 2,000 unique users’ computers every day.</p>
<p><a href="http://mkto-j0015.com/track?type=click&amp;enid=bWFpbGluZ2lkPWd1YXJkaWFuYW5hbHl0aWNzQmV0YWN1c3QtMTcxNy0yMzA5LTAtMjE3MC1wcm9kLTEzODgmbWVzc2FnZWlkPTAmZGF0YWJhc2VpZD0xMzg4JnNlcmlhbD0xMjYwNjYyMDY2JmVtYWlsaWQ9bWlrZUB0ZWVsaW5nLmNvbSZ1c2VyaWQ9Njg1MTItNTMmZXh0cmE9JiYm&amp;&amp;&amp;http://allthingsd.com/20120215/for-hackers-attacking-phones-and-tablets-is-the-new-hotness/?refcat=enterprise&amp;mkt_tok=3RkMMJWWfF9wsRonvK3OZKXonjHpfsX%2B4%2BksW7Hr08Yy0EZ5VunJEUWy2oIGTNQhcOuuEwcWGog8xxlZCOScfY5B9PRRElW7Wyg%3D">Mobile Malware Doubled in 2011</a> <strong> <br />
</strong>The 2011 Mobile Threats Report from Juniper Networks found that the amount of malware created for mobile devices across all operating systems more than doubled in 2011. 63 percent of the malware found could collect financial information.</p>
]]></content:encoded>
			<wfw:commentRss>http://guardiananalytics.com/blog/index.php/2012/03/online-banking-fraud-news-roundup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Anomaly Detection Demystified [infographic]</title>
		<link>http://guardiananalytics.com/blog/index.php/2012/02/anomaly-detection-demystified-infographic/</link>
		<comments>http://guardiananalytics.com/blog/index.php/2012/02/anomaly-detection-demystified-infographic/#comments</comments>
		<pubDate>Fri, 17 Feb 2012 01:08:13 +0000</pubDate>
		<dc:creator>Tiffany Riley</dc:creator>
				<category><![CDATA[Account Takeover]]></category>
		<category><![CDATA[Consumer Fraud]]></category>
		<category><![CDATA[Infographic]]></category>
		<category><![CDATA[Small Business Fraud]]></category>

		<guid isPermaLink="false">http://guardiananalytics.com/blog/?p=201</guid>
		<description><![CDATA[In its updated guidance issued June 2011, the FFIEC specifically identified anomaly detection as one of the two minimum components of a layered security program required for any financial institution offering online banking (see page 5!). We recently released an &#8230; <a href="http://guardiananalytics.com/blog/index.php/2012/02/anomaly-detection-demystified-infographic/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>In its <a title="FFIEC Guidance June 2011" href="http://www.ffiec.gov/pdf/Auth-ITS-Final%206-22-11%20(FFIEC%20Formated).pdf" target="_blank">updated guidance issued June 2011</a>, the FFIEC specifically identified anomaly detection as one of the two minimum components of a layered security program required for any financial institution offering online banking (see page 5!). </p>
<p>We recently released an <a href="http://info.guardiananalytics.com/ADToolkit.html">Anomaly Detection Toolkit</a> to help educate financial institutions on the topic.  Here is our infographic on what anomaly detection is, how it works to detect fraud attacks, and how financial institutions can respond to any anomalous, or suspicious, online banking activity. </p>
<p>We here at Guardian Analytics know a little something about anomaly detection. We&#8217;ve pioneered use of this technology to detect online banking fraud, and currently deliver this powerful capability to about 150 banks and credit unions &#8211; day in and day out.</p>
<p>If you want to hear this graphic come to life, <a title="AD Infographic video" href="http://www.guardiananalytics.com/researchandresources/anomaly-detection-infographic-video.php" target="_blank">here’s a video</a> with voiceover that explains the whole process.</p>
<p><em>(click to enlarge the infographic in a new window)</em></p>
<p><a rel="attachment wp-att-203" href="http://guardiananalytics.com/blog/index.php/2012/02/anomaly-detection-demystified-infographic/anomaly-detection-infographic-2/" target="_blank"><img class="alignnone size-full wp-image-203" title="Putting Anomaly Detection into Practics" src="http://guardiananalytics.com/blog/wp-content/uploads/2012/02/Anomaly-Detection-infographic1.jpg" alt="Anomaly Detection infographic" width="481" height="458" /></a><a rel="attachment wp-att-202" href="http://guardiananalytics.com/blog/index.php/2012/02/anomaly-detection-demystified-infographic/anomaly-detection-infographic/"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://guardiananalytics.com/blog/index.php/2012/02/anomaly-detection-demystified-infographic/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mules &amp; Jewels: “Gameover” in 9 Steps</title>
		<link>http://guardiananalytics.com/blog/index.php/2012/02/mules-jewels-%e2%80%9cgameover%e2%80%9d-in-9-steps/</link>
		<comments>http://guardiananalytics.com/blog/index.php/2012/02/mules-jewels-%e2%80%9cgameover%e2%80%9d-in-9-steps/#comments</comments>
		<pubDate>Fri, 17 Feb 2012 00:52:58 +0000</pubDate>
		<dc:creator>Tiffany Riley</dc:creator>
				<category><![CDATA[Account Takeover]]></category>
		<category><![CDATA[Community Banks]]></category>
		<category><![CDATA[Consumer Fraud]]></category>
		<category><![CDATA[Small Business Fraud]]></category>

		<guid isPermaLink="false">http://guardiananalytics.com/blog/?p=198</guid>
		<description><![CDATA[The new “Gameover” malware driving online banking fraud has gotten much attention in the press lately, but I realized that most of it has focused on the distributed denial of service (DDoS) attacks launched by this malware variant to bypass common &#8230; <a href="http://guardiananalytics.com/blog/index.php/2012/02/mules-jewels-%e2%80%9cgameover%e2%80%9d-in-9-steps/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>The new “Gameover” malware driving online banking fraud has gotten much attention in the press lately, but I realized that most of it has focused on the distributed denial of service (DDoS) attacks launched by this malware variant to bypass common controls.  Another important element of the total scheme that I think is worth highlighting is a new twist on how criminals are using money mules to “pick up” and move stolen funds.</p>
<p>Fraudsters are getting creative and employing a new, retail-based approach. Why? To decrease the risk of their mules getting caught. They are using high-end jewelry stores to essentially launder their loot.</p>
<p>Here’s how it works:</p>
<ol>
<li>The fraud victim – typically a business banking customer – gets a phishing email that appears to originate from reputable organizations like the National Automated Clearing House Association (NACHA), the Federal Reserve Bank, or the Federal Deposit Insurance Corporation (FDIC). When this attack was first launched, all emails appeared to originate from NACHA. The email may claim that there is problem with a recent transaction that requires the user’s attention.</li>
<li>When the link in the email is clicked, the victim is sent to a bogus website and inadvertently downloads a new variant of the notorious ZeuS malware called “Gameover”.</li>
<li>Once infecting the victim’s PC, “Gameover” keylogs all online banking activity and sends stolen account credentials to the criminal.</li>
<li>In a new wrinkle, the criminal employs a DDoS attack to cover their tracks. When the attack begins, the victim’s business may be hit with DDoS to prevent Internet access so they don’t notice the attack and can’t reverse the transaction.</li>
<li>In a more sophisticated version of the scheme, the financial institution is included in the DDoS attack, further decreasing the likelihood of the fraudulent transfers being noticed.</li>
<li>The criminal wires money to a high-end jewelry store and then places an order for precious stones or expensive watches.</li>
<li>A mule physically visits the store to pick up the order.  The jeweler checks their account, sees that the funds are there, and delivers the merchandise to the mule.</li>
<li>The mule may then turn the jewelry over to the fraudster or sell it for cash.</li>
<li>When the fraud is discovered, it can be the account holder or the jewelry store itself that’s hit with the loss.</li>
</ol>
<p>It’s definitely “game over” for the victims of this fraud scheme.</p>
<p>This use of the Gameover Trojan was <a title="FBI warning &quot;Gameover&quot;" href="http://www.fbi.gov/news/stories/2012/january/malware_010612" target="_blank">recently written up by the FBI </a>and my colleague Craig Priess explains it nicely in <a title="Video Fraud Informer #1" href="http://www.youtube.com/watch?v=94ikM-Jf62Q&amp;feature=g-all&amp;context=G2644cb4FAAAAAAAAAAA" target="_blank">a video explaining this attack</a>. Our fraud and threat research teams stay up to date on the latest cybercrime tools and techniques and I hope you will use this blog as a resource for combating fraud at your financial institution.</p>
]]></content:encoded>
			<wfw:commentRss>http://guardiananalytics.com/blog/index.php/2012/02/mules-jewels-%e2%80%9cgameover%e2%80%9d-in-9-steps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Tale of Two Banks (A True Story)</title>
		<link>http://guardiananalytics.com/blog/index.php/2011/09/conforming-to-ffiec-guidace-creates-a-good-customer-experience/</link>
		<comments>http://guardiananalytics.com/blog/index.php/2011/09/conforming-to-ffiec-guidace-creates-a-good-customer-experience/#comments</comments>
		<pubDate>Fri, 16 Sep 2011 23:08:27 +0000</pubDate>
		<dc:creator>Tiffany Riley</dc:creator>
				<category><![CDATA[Account Takeover]]></category>
		<category><![CDATA[Compliance/Regulations]]></category>
		<category><![CDATA[Success Stories]]></category>
		<category><![CDATA[account compromise]]></category>
		<category><![CDATA[Account takeover]]></category>
		<category><![CDATA[Authentication Guidance]]></category>
		<category><![CDATA[corporate account takeover]]></category>
		<category><![CDATA[ffiec guidelines]]></category>
		<category><![CDATA[FFIEC Supplement]]></category>
		<category><![CDATA[FraudMAP successes]]></category>
		<category><![CDATA[online banking fraud]]></category>
		<category><![CDATA[security and the customer experience]]></category>

		<guid isPermaLink="false">http://guardiananalytics.com/blog/?p=170</guid>
		<description><![CDATA[We hear often from our bank and credit union clients about the account takeover and fraud they&#8217;ve stopped using our anomaly detection solution, FraudMAP.  Normally the movie plays out roughly the same: fraudster meets bank account, fraudster likes bank account, &#8230; <a href="http://guardiananalytics.com/blog/index.php/2011/09/conforming-to-ffiec-guidace-creates-a-good-customer-experience/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" style="float: right; margin-left: 10px; margin-bottom: 10px;" title="Photo courtesy Steve Snodgrass, Flickr" src="http://farm4.static.flickr.com/3305/3439224738_ab0335a447_m.jpg" alt="" width="240" height="160" />We hear often from our bank and credit union clients about the account takeover and fraud they&#8217;ve stopped using our anomaly detection solution, FraudMAP.  Normally the movie plays out roughly the same: fraudster meets bank account, fraudster likes bank account, FraudMAP detects the fraudster&#8217;s suspicious or anomalous activity, FI looks like a hero to their account holder, fraudster goes home with no money.</p>
<p>Recently we heard a tale from one of our customers with an interesting twist. At Guardian Analytics we are passionate about the concept of great security AND a great account holder experience.  The plot twist in this fraud story highlights how the right protections can create the right customer experience that builds trust and loyalty. And lack of the right protections creates, well, something very different.</p>
<p>The movie begins with one of our customers, Bank A, a mid-sized bank using FraudMAP that proactively detected suspicious activity in an account.  FraudMAP alerted the bank to unusual behavior before any sort of transaction was initiated.</p>
<p>Based on the suspicious behavior, the bank called the account holder to inquire about the activities.  The account holder confirmed that they had not logged in to their account at that time or from that location. He was thrilled that the bank was proactively looking out for his safety and was able to catch this before any money was moved.</p>
<p>Now for the twist: while they were on the phone discussing next steps, the account holder realized that if his account at Bank A had been compromised, it was likely his account at Bank B had been compromised as well.</p>
<p>He logs into his account at Bank B, a much larger national bank, and discovers that a very large wire transfer had been initiated through his account and released by the bank. He had to make &#8220;the call&#8221; that far too many banks receive &#8211; according to a survey done by ISMG &#8211; 76% of FIs find out about fraud from their customers.</p>
<p>One client, two banks. One happy ending, one nightmare.  The FFIEC got it right. In their new Guidance for online banking security, they call for all banks to have anomaly detection as the foundational component of their security strategy.  This account holder&#8217;s money was clearly safer in the bank with sophisticated anomaly detection looking for signs of suspicious activity before money leaves the bank.  Powerful protections and a great customer experience can and do co-exist.</p>
<p>Which movie would you star in? The fairy tale? Or the horror story?</p>
]]></content:encoded>
			<wfw:commentRss>http://guardiananalytics.com/blog/index.php/2011/09/conforming-to-ffiec-guidace-creates-a-good-customer-experience/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>August Fraud Roundup</title>
		<link>http://guardiananalytics.com/blog/index.php/2011/08/august-fraud-roundup/</link>
		<comments>http://guardiananalytics.com/blog/index.php/2011/08/august-fraud-roundup/#comments</comments>
		<pubDate>Mon, 29 Aug 2011 23:09:04 +0000</pubDate>
		<dc:creator>Tiffany Riley</dc:creator>
				<category><![CDATA[Account Takeover]]></category>
		<category><![CDATA[Consumer Fraud]]></category>
		<category><![CDATA[Regulatory Issues]]></category>
		<category><![CDATA[Small Business Fraud]]></category>
		<category><![CDATA[ffiec guidelines]]></category>
		<category><![CDATA[fraud roundup]]></category>
		<category><![CDATA[trends]]></category>

		<guid isPermaLink="false">http://guardiananalytics.com/blog/?p=148</guid>
		<description><![CDATA[For cyber criminals, security researchers, regulators and financial institutions, there’s been no summer break.  The FFIEC announced a Supplement to its 2005 Authentication Guidance, hackers produced significant volumes of new malware, more businesses lost money and another lawsuit was filed. &#8230; <a href="http://guardiananalytics.com/blog/index.php/2011/08/august-fraud-roundup/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" style="float: right; margin-left: 10px; margin-bottom: 10px;" title="Photo courtesy titlap, Flickr" src="http://farm4.static.flickr.com/3428/3901537243_085c10c684.jpg" alt="" width="350" height="233" />For cyber criminals, security researchers, regulators and financial institutions, there’s been no summer break.  The FFIEC announced a Supplement to its 2005 Authentication Guidance, hackers produced significant volumes of new malware, more businesses lost money and another lawsuit was filed.</p>
<p>With so much going on, we thought we’d use the blog to regularly summarize the hot news. Welcome to our first “Fraud Roundup”:</p>
<ul>
<li><strong><a href="http://www.ffiec.gov/pdf/Auth-ITS-Final%206-22-11%20(FFIEC%20Formated).pdf">New FFIEC Supplement and Clarifications from the Agencies</a></strong></li>
</ul>
<p style="padding-left: 30px;"><a href="http://www.ffiec.gov/pdf/Auth-ITS-Final%206-22-11%20(FFIEC%20Formated).pdf"></a>The FFIEC raised the bar on expectations for layered security, risk assessments and customer education. Following the Supplement’s release, there has been a lot of discussion on the topic of the guidance and layered security.</p>
<p style="padding-left: 30px;">In recent presentations by the FDIC, OCC and the Federal Reserve Board, the Agencies make one thing very clear about the Supplement: all institutions are expected to have layered security; layered security at a minimum is defined by the capability to detect and respond to anomalous customer behavior at login and initiation of transaction. The Agencies further clarified this is expected for retail and commercial banking and that business accounts.</p>
<p style="padding-left: 30px;">For more details, resources, and to track what key topics about the Supplement, please visit our <a href="http://www.guardiananalytics.com/ffiec-guidance-supplement-2011/ffiec-guidance-overview.php">FFIEC Resource site</a>.</p>
<ul>
<li><strong><a href="http://www.bankinfosecurity.com/articles.php?art_id=3864">New ACH Fraud Suit Filed</a>, BankInfoSecurity.com </strong></li>
</ul>
<p style="padding-left: 30px;"><strong> </strong>In March 2010, Village View Escrow of California had its online bank account infiltrated by hackers, suffering $465,000 in losses. The company now has filed a lawsuit in the California Superior Court against its bank. This is the latest in a stream of other recent commercial banking fraud lawsuits.</p>
<ul>
<li><strong><a href="http://krebsonsecurity.com/2011/06/fbi-investigating-cyber-theft-of-139000-from-pittsford-ny/">FBI Investigating Online Banking Theft of $139,000 from Pittsford, NY</a></strong><strong>, Krebs on Security</strong></li>
</ul>
<p style="padding-left: 30px;"><strong> </strong>The fraud losses continue. The latest theft is the latest reminder that cybercriminals are effectively bypassing existing controls.</p>
<ul>
<li><strong><a href="http://krebsonsecurity.com/2011/08/ethieves-steal-217k-from-arena-firm/">More Fraud Losses &#8211; eThieves Steal $217k from Arena Firm</a></strong><strong>, Krebs on Security</strong></li>
</ul>
<p style="padding-left: 30px;"><strong> </strong>Cyber thieves stole $217,000 last month from the Metropolitan Entertainment &amp; Convention Authority (MECA), a nonprofit organization responsible for operating the Qwest Center and other gathering places in Omaha, Nebraska.</p>
<ul>
<li><strong><a href="http://www.americanbanker.com/bulletins/Cisco-Study-Finds-Targeted-Email-Attacks-Have-Grown-1039646-1.html">Spam Fraud Down, Targeted Phishing Attacks Up 400%</a>, Bank Technology News</strong></li>
</ul>
<p style="padding-left: 30px;"><strong> </strong>End users aren’t getting any relief. A Cisco study finds that cyber fraud has shifted from mass, generalized attacks to very specific spear phishing hits that harness stolen user information to dupe unwitting consumers (such as bank customers and cardholders) into divulging account information.</p>
<ul>
<li><strong><a href="http://www.usatoday.com/tech/news/story/2011/08/SpyEye-hacker-toolkit-to-lead-to-surge-in-cyberattacks/50080368/1">SpyEye hacker toolkit to lead to surge in cyberattacks</a>, USA Today</strong></li>
</ul>
<p style="padding-left: 30px;"><strong> </strong>Security experts are expecting a surge in SpyEye attacks this year, after the license key to SpyEye, the top rival to the ZeuS banking Trojan, was exposed. Hackers started making versions of SpyEye available for $100 (down from $10,000), making the Trojan kit much more readily available to criminal gangs. More than 2.2M computers are estimated to be infected and under the control of SpyEye botnets.</p>
<ul>
<li><strong><a href="http://www.mcafee.com/us/resources/reports/rp-quarterly-threat-q2-2011.pdf">Mobile Malware on the Rise</a>,</strong> <strong>McAfee</strong></li>
</ul>
<p style="padding-left: 30px;"><strong> </strong>McAfee reports that the Android was the most popular target for malware developers in Q2 2011. Researchers highlight mobile crimeware on the Android that forwards SMS messages, a technique to thwart out of band authentication and verification.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://guardiananalytics.com/blog/index.php/2011/08/august-fraud-roundup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The REST of the Online Banking Fraud Story</title>
		<link>http://guardiananalytics.com/blog/index.php/2011/08/the-rest-of-the-online-banking-fraud-story/</link>
		<comments>http://guardiananalytics.com/blog/index.php/2011/08/the-rest-of-the-online-banking-fraud-story/#comments</comments>
		<pubDate>Fri, 05 Aug 2011 15:57:48 +0000</pubDate>
		<dc:creator>Terry Austin</dc:creator>
				<category><![CDATA[Account Takeover]]></category>
		<category><![CDATA[CEO Insight]]></category>
		<category><![CDATA[Small Business Fraud]]></category>
		<category><![CDATA[Success Stories]]></category>

		<guid isPermaLink="false">http://guardiananalytics.com/blog/?p=129</guid>
		<description><![CDATA[Yesterday, Bloomberg posted a lengthy article &#8211; Hackers Take $1 Billion a Year from Company Accounts Banks Won’t Indemnify &#8211; highlighting the serious problem of online banking fraud attacks against small and medium sized businesses (SMBs). I’m pleased this is &#8230; <a href="http://guardiananalytics.com/blog/index.php/2011/08/the-rest-of-the-online-banking-fraud-story/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Yesterday, Bloomberg posted a lengthy article &#8211; <a href="http://www.bloomberg.com/news/2011-08-04/hackers-take-1-billion-a-year-from-company-accounts-banks-won-t-indemnify.html">Hackers Take $1 Billion a Year from Company Accounts Banks Won’t Indemnify</a> &#8211; highlighting the serious problem of online banking fraud attacks against small and medium sized businesses (SMBs). I’m pleased this is getting more mainstream attention, but anyone reading this blog will know this is not a new problem. In fact, we’re just about at the two-year anniversary of the first alarm bells ringing on the corporate account takeover problem.</p>
<p>The article pretty thoroughly covers the commercial account fraud ecosystem and the devastating results of fraud.  But while it nicely admires the problem, it fails to point out that there are solutions within the reach of every bank and credit union, and that many are equipping themselves to proactively stop these attacks.  And they are doing so successfully and affordably.</p>
<p>A rapidly growing number of national and community banks and credit unions are using <a href="http://www.guardiananalytics.com/products/online-fraud-prevention/index.php">FraudMAP</a>, our anomaly detection and transaction monitoring solution, to identify account takeover and stop the very fraudulent wire and ACH transfers described in this article. These institutions consistently detect and stop fraud, spend less than an FTE to investigate high-risk accounts, and receive high praise from their account holders when they make a call to discuss suspicious activity.  It took many of these institutions less then a week to deploy the solution on a wide variety of online banking platforms, and it costs them less then one average ACH or wire fraud.</p>
<p>As I discussed in my <a href="http://guardiananalytics.com/blog/index.php/2011/06/ffiec-releases-supplemental-guidance-for-internet-banking-security/ ">last blog post</a> the FFIEC recently updated its guidance on Internet Banking security.  They too agree that the threat has grown too great, criminals can defeat existing controls, and this is an issue banks must tackle.  They are now expecting all institutions to have the capability to detect and respond to anomalous behavior.</p>
<p>We had an interesting call from one of our customers today that highlighted the difference between banks that are equipped to solve the problem and those that are not.  Our customer, lets call them Bank A, used FraudMAP to proactively detect an account compromise for one of their accounts. Our solution alerted Bank A to suspicious activity in the account and they quickly notified the account holder. This all happened before a fraudulent money transfer was even attempted.  While discussing the situation, the account holder mentioned that they had also an account at a different institution, Bank B, which is not a user of FraudMAP.  When the account holder checked their account at Bank B, they found an unauthorized wire transfer and a significant amount of $$$ missing from their account.</p>
<p>Bank B now is faced with 1) spending time to attempt claw back the money, 2) trying to explain why they were not able to stop a fraud that Bank A could and 3) a potential customer loss.  Customer churn is a common outcome of these attacks – our <a href="http://info.guardiananalytics.com/2011-Trust-Study.html">2011 Business Banking Trust Study</a> reports that 43 percent of SMBs take their banking business to another institution following a fraud attack. Despite the title of the article, nobody wins when a commercial account is raided.</p>
<p>This real-world scenario shows that with the right protections in place, money can be safe in the bank. And it can be safe at large banks, midsize banks and small banks.  Businesses don’t need to run to the large institutions, they should just work with banks that have the right security.</p>
<p>By this time next year, if institutions meet the updated layered security expectations set forth in the guidance, the story should be very different. Instead of focusing on the villains and victims, we’ll be hearing stories of the heroes who stopped the criminals in their tracks.  We’ll be hearing more stories of  <a href="http://info.guardiananalytics.com/Extraordinary-Fraud-Prevention.html">ordinary institutions providing extraordinary fraud prevention</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://guardiananalytics.com/blog/index.php/2011/08/the-rest-of-the-online-banking-fraud-story/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FFIEC Releases Supplemental Guidance for Internet Banking Security</title>
		<link>http://guardiananalytics.com/blog/index.php/2011/06/ffiec-releases-supplemental-guidance-for-internet-banking-security/</link>
		<comments>http://guardiananalytics.com/blog/index.php/2011/06/ffiec-releases-supplemental-guidance-for-internet-banking-security/#comments</comments>
		<pubDate>Wed, 29 Jun 2011 16:33:26 +0000</pubDate>
		<dc:creator>Terry Austin</dc:creator>
				<category><![CDATA[Account Takeover]]></category>
		<category><![CDATA[CEO Insight]]></category>
		<category><![CDATA[Compliance/Regulations]]></category>
		<category><![CDATA[Regulatory Issues]]></category>
		<category><![CDATA[Account takeover]]></category>
		<category><![CDATA[Authentication Guidance]]></category>
		<category><![CDATA[FFIEC Supplement]]></category>

		<guid isPermaLink="false">http://guardiananalytics.com/blog/?p=119</guid>
		<description><![CDATA[It&#8217;s been 24 hours since the FFIEC released their Supplement to the Authentication in an Internet Banking Environment guidance issued in October 2005 and it has been interesting to watch the industry&#8217;s reaction to this much-anticipated update.  Some think it &#8230; <a href="http://guardiananalytics.com/blog/index.php/2011/06/ffiec-releases-supplemental-guidance-for-internet-banking-security/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been 24 hours since the FFIEC released their Supplement to the Authentication in an Internet Banking Environment guidance issued in October 2005 and it has been interesting to watch the industry&#8217;s reaction to this much-anticipated update.  Some think it is a positive step, some think it is not specific enough in defining responsibilities for banks, and some think it is outright lacking in certain areas.</p>
<p>And while all of these points have some element of truth to them, it is important not to overlook that at its heart and most importantly the guidance acknowledges that today&#8217;s threats are too sophisticated for yesterday&#8217;s controls.  Authentication alone is no longer effective for protecting online accounts and transactions and financial institutions now have new expectations for risk assessments and layered security strategies.</p>
<p>The supplement reinforces the need for a layered security approach, and explicitly states that the agencies <strong>expect</strong> (not suggest or encourage, but <strong>expect</strong>) that an institution&#8217;s layered security program will contain two elements <em>at a minimum</em>: 1) the ability to detect and respond to suspicious activity, and 2) improved control of administrative functions. It defines the first element as processes designed to detect and effectively respond to suspicious or anomalous activity related to initial log-in <em>and</em> electronic transaction requests. That is, check for suspicious activity from log-in to log-out.</p>
<p>There is a reason detecting anomalies and suspicious activity is first &#8211; it works across all customers and across the widest array of threats.  The Guidance even states, &#8220;transaction monitoring and  anomaly detection and response could have prevented many of the frauds  since the ACH/wire transfers being originated by the fraudsters were  anomalous when compared with the customer&#8217;s established patterns of  behavior.&#8221;</p>
<p>Our company was founded on the idea that the best way to prevent online and mobile banking fraud is to do precisely this &#8211; look for anomalous activity at the individual account holder level that is indicative of account takeover, account reconnaissance, and fraudulent transactions. More than 50 financial institutions who we have the privilege of calling customers know this, too, and have day in and day out seen the benefits of proactively stopping criminals in their tracks, before money leaves their institutions.  And now its expected of all institutions.  We think this is a positive step forward and that banks, credit unions, and their account holders will benefit.</p>
<p>There has been a perception perpetuated in the industry that fraud monitoring is difficult to implement and complex to operationalize.  This is just wrong. Our online and mobile banking fraud prevention solution, FraudMAP, is rapidly deployed and customers can be up and running in just a few days with little to no support required from IT.  To learn more about how FraudMAP can help you to meet the first, and most important expectation expressed in the Guidance Supplement, visit our <a href="http://www.guardiananalytics.com" target="_blank">website</a>, or for a more detailed look at how FraudMAP has helped our customers, download our <a href="http://info.guardiananalytics.com/Extraordinary-Fraud-Prevention.html" target="_blank">case study kit</a>.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://guardiananalytics.com/blog/index.php/2011/06/ffiec-releases-supplemental-guidance-for-internet-banking-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Court Recommendation is a Call To Action for the FFIEC on Authentication Guidance</title>
		<link>http://guardiananalytics.com/blog/index.php/2011/06/court-recommendation-is-a-call-to-action-for-the-ffiec-on-authentication-guidance/</link>
		<comments>http://guardiananalytics.com/blog/index.php/2011/06/court-recommendation-is-a-call-to-action-for-the-ffiec-on-authentication-guidance/#comments</comments>
		<pubDate>Tue, 07 Jun 2011 21:38:20 +0000</pubDate>
		<dc:creator>Terry Austin</dc:creator>
				<category><![CDATA[Account Takeover]]></category>
		<category><![CDATA[CEO Insight]]></category>
		<category><![CDATA[Regulatory Issues]]></category>
		<category><![CDATA[Small Business Fraud]]></category>

		<guid isPermaLink="false">http://guardiananalytics.com/blog/?p=106</guid>
		<description><![CDATA[A magistrate has recommended that a U.S. District Court in Maine deny a motion for a jury trial in the case of PATCO Construction suing its former bank, Ocean Bank over a $500,000 fraud loss. According to the order, the &#8230; <a href="http://guardiananalytics.com/blog/index.php/2011/06/court-recommendation-is-a-call-to-action-for-the-ffiec-on-authentication-guidance/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>A magistrate has <a href="http://info.guardiananalytics.com/rs/guardiananalytics/images/DBH_03312010_2-09cv503_PATCO_V_PEOPLES_UNITED_BANK.pdf" target="_blank">recommended</a> that a U.S. District Court in Maine deny a motion for a jury trial in the case of PATCO Construction suing its former bank, Ocean Bank over a $500,000 fraud loss. According to the order, the bank fulfilled its contractual obligations for security and authentication through its requirement for log-in and password credentials.</p>
<p>At issue in the case is whether financial institutions should be held responsible when commercial accounts are drained because of fraudulent ACH and wire transfers approved by the bank. How much security should banks and credit unions reasonably be required to apply to their commercial accounts? The magistrate in this case has closely aligned his recommendation with a literal interpretation of the 2005 FFIEC Guidance that states single factor is not enough.</p>
<p>Now that this water is almost under the bridge, we feel the remaining issue is what the FFIEC can do now to offer leadership to the industry and stem the flood of similar losses and resulting lawsuits.  While the courts may feel that the bank was using reasonable security from a legal standpoint, clearly that security isn’t enough from a practical standpoint and should no longer be the standard.  The court even commented that the bank could have done more and could have prevented the loss.</p>
<p>The case must still be reviewed by the presiding judge, but regardless of how it is ultimately decided, it&#8217;s a hollow victory for the &#8220;winner.&#8221; The only winners in this case were the fraudsters that stole the money.  The bank spent time, treasure and good will defending its contractual obligations and its security framework. And PATCO lost over a quarter of a million dollars plus legal costs and productivity losses.   Worse, this isn’t an isolated incident.   There are many more victims – banks and credit unions, commercial and retail accounts – going through the same thing every day.  And unnecessarily so.</p>
<p>The technology and processes to stop this blight exist in the market today. <strong>They are affordable for any size institution and have been proven over and over again to be effective at stopping online and mobile fraud. </strong> The financial institutions need to adopt them.  The commercial account holders need to insist on them.</p>
<p>But what&#8217;s most important in light of this legal precedent is that the FFIEC step off the sidelines and take action by releasing their long-expected updated guidance with more specificity around risk assessments and control expectations. The FFIEC has the chance to lead the way – but they need to act, and act now.</p>
<p>For a nice summary on the recommendation by the magistrate read Bank Info Security&#8217;s article:<a title="ACH Legal Ruling Favors Bank" href="http://www.bankinfosecurity.com/articles.php?art_id=3705&amp;pg=1" target="_blank"> ACH Legal Ruling Favors Bank</a></p>
]]></content:encoded>
			<wfw:commentRss>http://guardiananalytics.com/blog/index.php/2011/06/court-recommendation-is-a-call-to-action-for-the-ffiec-on-authentication-guidance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Community Bank Perspective on Fraud Prevention</title>
		<link>http://guardiananalytics.com/blog/index.php/2011/05/a-community-bank-perspective-on-fraud-prevention/</link>
		<comments>http://guardiananalytics.com/blog/index.php/2011/05/a-community-bank-perspective-on-fraud-prevention/#comments</comments>
		<pubDate>Thu, 26 May 2011 18:13:02 +0000</pubDate>
		<dc:creator>Tiffany Riley</dc:creator>
				<category><![CDATA[Account Takeover]]></category>
		<category><![CDATA[Community Banks]]></category>
		<category><![CDATA[Success Stories]]></category>

		<guid isPermaLink="false">http://guardiananalytics.com/blog/?p=87</guid>
		<description><![CDATA[I recently spent some time with one of our community bank customers and I was struck by their business and technology approach to securing their account holders. This Illinois-based $2.5B bank strives to offer leading online and mobile products competitive &#8230; <a href="http://guardiananalytics.com/blog/index.php/2011/05/a-community-bank-perspective-on-fraud-prevention/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I recently spent some time with one of our community bank customers and I was struck by their business and technology approach to securing their account holders.</p>
<p>This Illinois-based $2.5B bank strives to offer leading online and mobile products competitive with the big national banks AND deliver community bank style service. Expanding their offerings without increased fraud risk required enhancing their fraud prevention capabilities.  Here are some valuable snippets:</p>
<p style="padding-left: 30px;"><strong><span style="text-decoration: underline;">Security point of view: You can’t depend on account holders, you can’t secure the endpoint:</span></strong> The bank understood that cyber criminals continue to attack account holders directly and designed their fraud prevention strategy with the notion that all end points have been compromised and you can never truly secure the end point.</p>
<p style="padding-left: 30px;">The bank wanted a solution that would transparently provide complete coverage across all account holders and not require account holders to do anything or change their processes. They also wanted a solution that had no dependencies on understanding malware or fraud patterns. As the bank states &#8211; &#8220;You don&#8217;t know what your enemy will do, but you always know what your customers have done.&#8221;</p>
<p style="padding-left: 30px;"><strong><span style="text-decoration: underline;">Business point of view: The risk of fraud is too great to the business not to take action. </span></strong>The bank recognized the strategic value of preventing fraud and that the true cost of fraud goes well beyond any financial losses. Customer churn, reputation issues, and lost staffing time are all risks of a fraud event that the bank was not willing to take.  An executive at the bank explained,  <strong>&#8220;I&#8217;d rather invest a known amount in a proven solution, than risk the unknown costs of a fraud event.&#8221;</strong></p>
<p style="padding-left: 30px;"><span style="text-decoration: underline;"><strong>Benefits beyond fraud losses averted. </strong></span>The bank deployed our solution, FraudMAP, and has experienced a wide range of benefits.  What stands out to me is the impact it has had on their ability to retain current clients and draw in new business. The CISO of the company goes out on sales calls with the account management team,  positioning to their commercial clients that the bank has industry leading security, with FraudMAP as a critical part of their story.</p>
<p style="padding-left: 30px;">Additionally, every call to a customer about suspicious activity has become a relationship building event.  The bank receives wildly positive feedback – “we’re so glad you have our back!”</p>
<p>Our latest<a href="http://www.guardiananalytics.com/customersuccess/case-studies.php"> case study</a> provides more background and details. After implementing FraudMAP, the SVP of Deposit Operations summed up the project quite nicely when he said, &#8220;It&#8217;s the perfect balance of sophistication and affordability.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://guardiananalytics.com/blog/index.php/2011/05/a-community-bank-perspective-on-fraud-prevention/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

