Home > Financial Services Information Security News > Lawsuit could amplify data protection laws
Financial Services Information Security News:
EMAIL THIS

Lawsuit could amplify data protection laws

By Shawna McAlearney, News Editor
25 Feb 2005 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

More than a few enterprise security managers must have shuddered when they heard about the lawsuit filed against Bank of America by an online banking customer. Such litigation could set precedent for who is responsible for securing a consumer's data -- even on the consumer's own computer.

A Miami man blames Bank of America for more than $90,000 stolen in an unauthorized wire transfer to Latvia. Joe Lopez filed a lawsuit on Feb. 7 claiming that Bank of America had not alerted him to malicious code that could -- and indeed had -- infected his computer. A forensic investigation by the U.S. Secret Service revealed that a Trojan called Coreflood, which acts as a keystroke logger, had compromised one of his PCs.
Should Bank of America be liable?
Share your thoughts in our SoundOff forum.

"A win for Lopez could really rock the already shaky foundations of e-commerce, from Internet banking and trading to online shopping," said Stephen Cobb, a security expert and the author of Privacy for Business. "An unresolved tension has always existed between the responsibility of financial institutions to fully disclose the risks inherent in Internet usage and their desire to get more people to use the Internet."

This is the first known case of a U.S. banking customer suing for a loss that was the result of a hacking incident. Though the cause of the infection hasn't been determined, many experts say the likely culprit was phishing, either through an e-mail or Web site that pretends to come from a legitimate company and solicits the recipient's confidential information.

"Bank of America wants to set precedent that you [the customer] need to have reasonable computer security -- and that's a very reasonable thing to ask for," said Dave Jevans, chairman of the Anti-Phishing Working Group [APWG].

A report released this month by APWG said that 140 brand names have been hijacked to use in online scams since it began examining phishing trends and reporting its findings in November 2003. Included in the number reported for January were eight financial institutions. The group also reported that the number of active phishing sites in January had increased to 2,560 -- an average monthly increase of 28% since July.

Some see user awareness and education as the only way to prevent a continued trend.

"There is growing recognition that things will only get worse unless there is effective and large-scale public education as to Internet risks, security practices and responsible behavior," Cobb said. "I think this is long overdue and needs to be vigorously pursued, particularly in the school system, from kindergarten to college."

More on data breaches

Customer vs. Bank of America: Is the little guy to blame?
Who will win a landmark case on customer data protection?

ChoicePoint CISO on the hot seat, but also firing back
ChoicePoint CISO Rich Baich has his hands full dealing with a data breach, and the ensuing media storm that he says has mislabled this a hack.

Jevans agrees. "People aren't educated about spyware -- a lot has to be done for awareness," he said. "And many still don't use antivirus. I also think you're going to see a much stronger push for two-factor authentication -- it will help prevent these situations from happening."

And two-factor authentication may be just what the doctor ordered. Last week Bank of America announced it will now use VeriSign's Unified Authentication encryption software to make it harder for cybercriminals to steal accounts. "VeriSign Unified Authentication is a complete range of two-factor authentication methods that will integrate with Bank of America's existing technology environment, without costly additions of disparate hardware and software infrastructure," according to a news release. The company said the flexibility in choosing a second form of ID, such as a password, token or smart card, based on open standards was a big selling point.

"Banking regulators are pushing two-factor authentication as a best practice," said Mike Overly, a partner at law firm Foley & Lardner. "We're seeing greater and expanded risks in online banking, but also increased efforts by financial institutions to reduce the incidents of phishing and other similar activities."

However, if banks and other financial institutions aren't willing to take such steps on their own, the government may intercede. "This case will get a lot of scrutiny," Jevans said. "Things may ultimately come down in the form of government regulation."

Tags: Secure user and consumer authentication methodsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Secure user and consumer authentication methods
Gartner's Avivah Litan on the online banking fraud surge
Multifactor authentication options to secure online banking
Survey: Consumers don't trust banks to keep their data secure
Data breach lawsuit puts spotlight on bank's security measures
Credit union launches online banking suite with strong authentication
Winning the war: Personal information protection
BITS releases guide for implementing email authentication protocols
Banks, e-commerce sites use device identification to stop fraud
Evolving authentication methods in the financial industry
Identity management for financial firms in turbulent times

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Financial Security News Topics: Compliance, Management Strategy, Security Technology
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts