Archive for May, 2007

Hacking of online banking

Friday, May 4th, 2007

Yesterday I read some interesting story about Russian hackers that developed a Trojan horse for attacking consumers of German banks. This software modifies the source code of bank site in browser so that if the consumer tries to make a transaction, he receives an error. The error message tells that the TAN that consumer just entered is not valid and he must try again.

After that the transaction will be executed without any problems. But the first TAN that was not valid will be transferred to criminal.

This security leak was already closed, but I thought that it’s the right time to change my online banking with TAN-method into mTAN. I entered my mobile phone number and approved it. Than I had 2 possibilities, I could print the order and send it via fax, or I could call a special number and approve my order at this way. I don’t have any fax, that’s why I decided to call the number. At telephone I was prompted to enter my bank account number and PIN and after that I was informed that I could not be validated and the once way that I can activate mTan is to print the order and send it via post.

Is it accident? I hope that the hackers are not able (yet) to trick a service number of the banks :) )