Advertisement
Sections
Keeping digital wallets safe: Staying vigilant is key as cyber theft risks rise
If 2018 was the year of mobile malware, 2019 is the year of everywhere malware.

Innovations in India’s fintech landscape are changing the way its population manages their finances. Post demonetization, the economy has seen a rapid increase in the number of digital transactions with almost 11.8 billion such transactions being conducted by Q2FY19, as per latest data from the Reserve Bank of India (RBI) and National Payments Corporation of India (NPCI).This high adoption rate is fuelled by the ease and convenience of digital payment solutions, availability of cheaper internet schemes and the ever-expanding smartphone market. While digital payment solutions are making pockets lighter, literally, there is an increased burden to safeguard users from malicious actors in cyberspace. As India moves towards a cashless economy, there is a heightened need to secure one’s digital wallets and mobile banking applications.[caption id="attachment_6900471" align="alignnone" width="1024"]
As India moves towards a cashless economy, there's a greater need to secure digital wallets.[/caption]Digital payments and peer-to-peer lending apps have revolutionised the way we move money, making it simpler, easier and faster than ever! While on the surface, digital money transfers may seem convenient, they are vulnerable to multiple cybersecurity risks. A digital wallet requires the user to link their bank account details to the app to transfer money based on user’s needs, which means sensitive information is now floating in the worldwide web.Mobile phone theft is basic and perhaps the easiest way to steal someone’s personal data. Once in the hands of a cybercrook, the unsecured device becomes the pathway to carry out online financial frauds or steal someone’s identity. It is therefore advisable to secure your phone with a complex password and installing a device security software with a phone finder feature. Using the phone finder feature, not only can you trace the handset but remotely erase the data on the phone by resetting the device to factory settings.[caption id="attachment_5423901" align="alignnone" width="1280"]
Digital payments and peer-to-peer lending apps have revolutionised the way we move money. Image: bhimupi.org.in[/caption]With companies and government encouraging consumers to route their payments via mobile wallets, users are increasingly connecting their phones to unsecured public WiFi networks, to access multiple utility apps, including their digital wallets. Many of us download apps from reference links sent by other users of the apps. These links can be manipulated by the attacker and be used to perpetrate phishing attacks to gain access to the user’s bank details and other personal information linked to the account.A phishing attack is easily identifiable – the cybercriminal could move a letter or two around in the URL and create a bogus link almost identical to the genuine one. Once clicked, it results in the installation of a malware which then runs in the app’s background. Such attacks can be easily dodged by keeping a vigilant eye on the links or attachments sent to the user. Do not click or open them if you suspect malicious activities; what good is a 100-rupee cashback if it puts your bank balance in jeopardy![caption id="attachment_6900481" align="alignnone" width="1280"]
Cybercriminals are finding new ways to bypass Google security.[/caption]As per a recent report, a 77 percent increase in banking Trojans were noted and it was also predicted that this type of exploitation would continue to grow. Unfortunately, that prediction has come true. Cybercriminals are finding new ways to bypass Google security. Their success in getting onto mobile devices means they will also explore adding additional forms of revenue like ransomware, ad click fraud, and acting as a download conduit for other types of malware. Beware of fake apps on app stores; many times, cybercriminals leverage the laxity in the hosting policies of the app store and publish bogus apps which look like the actual apps. These apps are used to harvest bank details of the user by installing malware that will monitor keystrokes or exfiltrate data using command-and-control connection signal from the attacker.While one could say the onus lies on the financial service providers to protect customer data, safeguarding confidential information online is equally the responsibility of the user. Luckily, some simple steps can go a long way in protecting your financial information from getting breached online.
As India moves towards a cashless economy, there's a greater need to secure digital wallets.[/caption]Digital payments and peer-to-peer lending apps have revolutionised the way we move money, making it simpler, easier and faster than ever! While on the surface, digital money transfers may seem convenient, they are vulnerable to multiple cybersecurity risks. A digital wallet requires the user to link their bank account details to the app to transfer money based on user’s needs, which means sensitive information is now floating in the worldwide web.Mobile phone theft is basic and perhaps the easiest way to steal someone’s personal data. Once in the hands of a cybercrook, the unsecured device becomes the pathway to carry out online financial frauds or steal someone’s identity. It is therefore advisable to secure your phone with a complex password and installing a device security software with a phone finder feature. Using the phone finder feature, not only can you trace the handset but remotely erase the data on the phone by resetting the device to factory settings.[caption id="attachment_5423901" align="alignnone" width="1280"]
Digital payments and peer-to-peer lending apps have revolutionised the way we move money. Image: bhimupi.org.in[/caption]With companies and government encouraging consumers to route their payments via mobile wallets, users are increasingly connecting their phones to unsecured public WiFi networks, to access multiple utility apps, including their digital wallets. Many of us download apps from reference links sent by other users of the apps. These links can be manipulated by the attacker and be used to perpetrate phishing attacks to gain access to the user’s bank details and other personal information linked to the account.A phishing attack is easily identifiable – the cybercriminal could move a letter or two around in the URL and create a bogus link almost identical to the genuine one. Once clicked, it results in the installation of a malware which then runs in the app’s background. Such attacks can be easily dodged by keeping a vigilant eye on the links or attachments sent to the user. Do not click or open them if you suspect malicious activities; what good is a 100-rupee cashback if it puts your bank balance in jeopardy![caption id="attachment_6900481" align="alignnone" width="1280"]
Cybercriminals are finding new ways to bypass Google security.[/caption]As per a recent report, a 77 percent increase in banking Trojans were noted and it was also predicted that this type of exploitation would continue to grow. Unfortunately, that prediction has come true. Cybercriminals are finding new ways to bypass Google security. Their success in getting onto mobile devices means they will also explore adding additional forms of revenue like ransomware, ad click fraud, and acting as a download conduit for other types of malware. Beware of fake apps on app stores; many times, cybercriminals leverage the laxity in the hosting policies of the app store and publish bogus apps which look like the actual apps. These apps are used to harvest bank details of the user by installing malware that will monitor keystrokes or exfiltrate data using command-and-control connection signal from the attacker.While one could say the onus lies on the financial service providers to protect customer data, safeguarding confidential information online is equally the responsibility of the user. Luckily, some simple steps can go a long way in protecting your financial information from getting breached online.- Be sure to go through your monthly credit reports for any suspicious transactions. Often the cybercrooks steal money in multiple small transactions and the user notices it only when his bank balance reduces drastically over time.
- Use two-factor authentication for all your online accounts and sign up to receive SMS alerts or email notifications to detect any unusual activity on your account. Many companies offer this service free of cost.
- While registering for any financial service or apps, make it a point to read the customer reviews to gauge the authenticity and look for policies around customer data safety.
- Most importantly Stop, Think and Connect – Do not blindly click on e-mails or links.
- Ensure you have the appropriate security software on your devices to help you stay safe.
- It’s a combination of common sense and using the right tools that can give you a safe experience online.
First Published:Jun 28, 2019, 21:04:55 IST
Advertisement
Advertisement

Why AI notetakers are raising serious privacy and security concerns
AI notetakers promise effortless meeting summaries, but experts warn they could expose confidential conversations, corporate secrets and personal voiceprints. As businesses increasingly adopt AI-powered meeting assistants, questions over data storage, privacy, consent and legal risks are becoming impossible to ignore
5 min read
China's low-cost AI models are changing the global AI race. Here's why Silicon Valley is worried
As Chinese firms continue to improve performance while keeping prices low, the AI race is no longer just about building the smartest model—it is increasingly becoming a battle over who can deliver the best value
2 min read
China's Kimi K3 challenges US AI leaders with frontier-level performance at lower cost
Chinese artificial intelligence startup Moonshot AI has unveiled its latest open-weight AI model, Kimi K3, with early results suggesting it could compete with some of the world's most advanced AI systems developed by leading US companies
2 min read
How did Instagram run ads promoting child abuse in India?
India has issued a notice to Meta after an investigation alleged that Instagram displayed paid advertisements promoting child sexual abuse material. MeitY ordered Meta to remove such Instagram ads and explain within seven days how they were approved
8 min read
Why has India halted WhatsApp’s username feature before launch?
India has halted WhatsApp’s planned username feature, citing concerns about cybercrime, impersonation, and law enforcement challenges. As Meta races to address security concerns, here’s why MeitY has paused the rollout, what the feature does, and how it could influence privacy and online safety in India
3 min read
Advertisement
Advertisement
