Top News

Banks complain e-crooks using their names to dupe customers
ET Bureau | October 11, 2024 2:40 AM CST

Synopsis

Banks raise alarms over fraudulent entities impersonating them in text messages to dupe customers. They seek intervention from the finance ministry, TRAI, and telecom service providers, and plan to approach the RBI to address compliance challenges with cybersecurity advisories.

Banks have raised concerns with the government over fraudulent entities impersonating them and using their names in text messages to dupe customers.

At a meeting last month, they urged the finance ministry to take up the issue with the telecom regulator and telcos to prevent unauthorised third parties from using the names of lenders in message templates.

They also plan to approach the Reserve Bank of India (RBI) to flag the issue and seek help as they are required to implement the Cyber Security and IT Risk Advisory, said executives aware of the developments.

"We had an internal discussion on the matter, and accordingly we informed the finance ministry and requested them to take up the issue with the Telecom Regulatory Authority of India (Trai) and telecom service providers (TSPs)," said an executive who did not want to be identified.


Another bank executive said, "We have been told by agencies and SMS aggregators that while the headers registered in the banks' names are secure, it is not possible to prevent others from using a bank's name in their templates. This often creates confusion for customers, who then fall for the trap."

The RBI warned banks in a recent advisory against smishing or phishing campaigns to harvest customer data using malicious Android applications. The banking regulator asked them to coordinate with telecom service providers (TSPs) to ensure that SMS headers not registered in their name or in the name of their partners don't contain their names in the text. Smishing is tricking an SMS recipient into downloading malware. Phishing is similar but the attack can be made through email or a website.

"We will raise this issue with the RBI in regards to challenges in compliance with the cyber risks advisory," the second official said.


READ NEXT
Cancel OK