Showing posts with label ATM Frauds In India. Show all posts
Showing posts with label ATM Frauds In India. Show all posts

Wednesday, January 4, 2012

Mobile Banking Cyber Security Is Required In India

Mobile banking in India is moving towards an acceptance level. However, till now very few people and institutions are comfortable in using mobile banking in India. Mobile banking in India is still not popular according to RBI. There are certain shortcomings of mobile banking in India that are still left unaddressed.

For instance, mobile governance in India is still not well established. M-governance in India is essential before mobile banking can be successfully implemented in India. We have no regulatory framework for m-governance in India. Even the proposed electronic delivery of services bill 2011 of India has failed to provide a mandatory legal framework for electronic delivery of services in India, including for mobile banking. In short, India is still not ready for m-governance and cloud computing especially in the absence of dedicated e-commerce laws in India.

Mobile banking in India is risky due to absence of mobile cyber security in India. Further, online banking system of India is not secure. In the absence of adequate cyber security safeguards, e-banking in India is not safe. The cyber security trends in India 2011 have also proved that Internet banking cyber security in India is in poor shape and it needs to be strengthened. Even data security, privacy and cyber security in Indian banking industry is not satisfactory.

Online banking risks in India are increasing and this is also shaking the confidence of customers in the same. Even RBI has acknowledged risks of e-banking in India. ATM frauds in India are increasing. In fact, Reserve Bank of India (RBI) has recently released the report of its working group on securing card present transaction that covers ATM security and credit card security issues as well. Internet banking risks in India cannot be effectively tackled till we have dedicated Internet banking laws in India.

Although an integrated banking law of India has been proposed yet it may take some years before it is actually enacted. In an interesting development, the RBI removed limits from mobile banking transactions limits in India. This is good for the development of mobile banking in India but is bad for the interests of mobile banking customers who have almost no safeguards against cyber crimes and technology assisted financial frauds happening in the mobile banking field.

The cyber law in India has prescribed cyber law due diligence for various stakeholders. Cyber due diligence for banks in India is just a part of the same. Cyber due diligence for Indian companies including banks operating in India is very stringent. However, Indian banks are not following the guidelines of RBI prescribing mandatory cyber security requirements for banks of India. Further, banks are also liable

Even on the policy front, mobile banking has received a bad response form Indian government. For instance, absence of effective encryption laws in India and non use of robust encryption in India has made the mobile security very weak in India. Instead of making the encryption requirements redundant and weak, India must concentrate upon further strengthening the same for better and secure mobile communications. Governments of most developed countries allow the usage of strong encryption standards ranging from 128 bits to 256 bits or more to ensure the security of sensitive information exchanged via Internet and other networks. However, India is still clinging to 40 bits encryption standards for the simple reason that intelligence and security agencies of India are not capable enough to break strong encryptions.

A weak mobile banking infrastructure would also affect other projects and schemes as well. For instance, recently the Securities and Exchange Board of India (SEBI) has declared about its intentions to introduce electronic initial public offer (E-IPO) in India. This is a good step but E-IPO cannot succeed in the absence of strong mobile banking and Internet banking infrastructure. Online payments mechanisms in India must also be suitable strengthened to make such proposals workable.

India must give these considerations some serious thoughts if it wishes to encash the benefits of technology. Otherwise, concepts like Internet banking and mobile banking are more nuisance than luxury in India.

Friday, June 3, 2011

ATM Frauds In India And Their Techno Legal Preventive Measures

ATM Frauds in India are increasing at an alarming rate. If we add to it the cases of Credit Card Frauds, Internet Banking Frauds and frauds committed using Phishing techniques, the numbers are really shocking.

It is not the case that Reserve Bank of India (RBI) is not aware of these cases nor is it the case that RBI is not doing anything in this regard. In fact, RBI has recently released the Report of its Working Group on Securing Card Present Transaction that covers ATM Security and Credit Card Security issues as well.

RBI has also recommended Cyber Security Due Diligence for Banks of India. However, despites these pro active steps, ATM Frauds are increasing in India. One chief reason for this growth is that Banks in India are not serious about Cyber Security and they are not following the Recommendations of RBI.

ATM Frauds happen when someone leaves his/her credit card unattended in a vehicle or changing room or allows anyone else to use the card or looses the card that is misused by others or discloses the Personal Identification Number (PIN) to others, etc. These mistakes allow the offender to withdraw money by using the stolen information. Fraudsters are using special devices, skimmers, duplicate ATMs, etc to withdraw money from ATMs. Sometimes such frauds are an insider job with the collusion of the employees of the company issuing those cards. However, misuse of the disclosed PIN for withdrawing money is the most common techniques used for committing ATM Frauds.

ATM Frauds can be prevented if we take some basic level precautions. For instance, never leave your credit card unattended in a vehicle or changing room, never allow anyone else to use your card, always retain sales/charge slips to compare with the amount specified on the billing statement, do not disclose your PIN to anyone, etc.

The Technology can also be used to minimise cases of ATM Frauds in India. The technological mechanisms like Designated time, Microchip technology, Biometric tokens, Enhanced security, ATM Monitoring, Customised softwares, Customer motivation, Alerts, etc can be used to minimise and prevent ATM frauds in India.

Another reason for growth of technology related crimes and ATM Frauds in India is absence of “Deterrent Law” in this regard. The Information Technology Act, 2000 (IT Act 2000) is the sole Cyber Law of India. After the Information Technology Amendment Act, 2008 (IT Act 2008) almost all the Cyber Crimes in India have been made “Bailable” Now Cyber Criminals can commit almost all Cyber Crimes, ATM Frauds, Credit Card Frauds, Internet Banking Frauds in India without any fear. It is high time to repeal the Cyber Law of India as soon as possible and enact Strong and Effective Laws in this regard.

The IT Act, 2000 does not contain any specific provisions regarding ATM Frauds and Credit Card Frauds and the traditional law of IPC, 1860 also cannot be relied solely and independently to tackle this problem. We need a better law for this purpose and Perry4Law and Perry4Law Techno Legal Base (PTLB) have already provided their Suggestions and Recommendations in this regard and other ICT related matters to the Government of India, Department of Information Technology, Department of Science and Technology, Prime Minister’s Office, etc from time to time.

Till we have suitable and apt laws, we must apply existing laws in a purposive and updating manner. However, ATM frauds can be tackled by using Techno Legal Methods alone and neither Legal nor Technical Measures is sufficient in itself.

RBI Recommended Constitution Of Secure Systems To Check Credit Card Frauds

Reserve Bank of India (RBI) has recently released the report of its working group on securing card present transaction. RBI has also prescribed cyber security due diligence standards for banks of India that must be implemented in a phased manner.

Despites these pro active steps, cyber security of banking sector of India is not upto the mark and ATM frauds, credit card frauds, internet banking frauds, etc are increasing in India. This is primarily due to the fact that banks in India are not following the recommendations of RBI.

ATM frauds and credit cards frauds cannot be tackled effectively till we use techno legal measures. Amid rising instances of debit and credit card frauds, an RBI panel has recommended that banks should put in place secure systems to check such cases within a year's time. All acquirers and issuers may put in place adequate fraud risk management systems and processes within 12 months, said the panel in its recommendations for an action plan to implement additional authentication for all card transactions.

For the benefit of debit card holders, it suggested that all transactions through such cards should have a PIN (Personal Identification Number) as an additional factor of authentication at point of sale (POS).

Further, mechanisms like designated time, microchip technology, biometric tokens, enhanced security, ATM monitoring, customised softwares, customer motivation, alerts, etc can be used to minimise and prevent ATM frauds in India. The banks must spread public awareness in this regard among the public so that these frauds can be prevented.

However, preventing ATM frauds is not the sole problem of banks alone. It is a big threat and it requires a coordinated and cooperative action on the part of the bank, customers and the law enforcement machinery. The ATM frauds not only cause financial loss to banks but they also undermine customers’ confidence in the use of ATMs. This would deter a greater use of ATM for monetary transactions. It is, therefore, in the interest of banks to prevent ATM frauds.