The Thief who stole Rs 286 crores from Banks coming to India

Recently all across Europe, the “Euro Grabber” stealthily stole around 36 million euro (Rs 286 crores) from Bank customers. These were all customers who thought that

a) Their money in the Bank was safe.

b) Internet Banking was a great way to do Banking

The Banks thought that they had introduced the “Two Factor Authentication” which was a sophisticated system and made Internet Banking safe.

However, there came a great thief called “Euro Grabber” along with his team of assistants and invaded thousands of  PCs and Mobiles and finally stole money from around 30000 retail and corporate customers of different Banks across different parts of Europe.

“Eurograbber” is a new variant of the Zeus Trojan which steals the credentials of the banking customer both at the desktop and the associated mobile. Hence it easily bypasses the 2 Factor authentication system and is able to execute unauthorized transactions in the customer’s accounts. The trojan is currentlly known to have successfully attack the mobile systems using Android, Blackberry and Symbian operating system which in other words may mean more than 95% of the systems in usage.

The “Eurograbber” is an intelligent trojan which is often dropped through “Drive by Download” method. In otherwords, the infection does not require the user answering a “Phishng Mail”. All those Bankers who are crying from rooftops that “We donot ask for your passwords” and then say “Password can never be compromised unless the customer answers a phishing mail” must realize that  the methodologies used by trojan droppers are above all these routine security warnings. Customers may get infected when they have visited a news paper site or clicked on an unrelated google search result or some times even by visiting the Bank’s own website. (Eg: Bank of India infection in 2007).

Once infected, the Eurograbber, when the customer visits the Bank website, it starts injecting instructions within the running session asking the customer to upgrade security etc. Since these instructions appear during a session initiated by the customer himself he believes that the instructions are from the Bank and proceeds to provide information that compromises his identity including the mobile number. The trojan then sends an SMS message to the mobile with similar instructions ensuring that the customer clicks on a link that infects the mobile also.

With both the desktop and the mobile being infected, the trojan then is able to manipulate both the banking instructions and the OTP password interception and is able to carry out fraudulent transactions.

When such “Unauthorized Transactions” are carried on during a valid session opened by the customer, it creates a huge evidentiary problem for the customers since the time of the transaction coincides with the time of a valid session. Even the IP address of the transaction initiation may tally with the IP address of the customer. Unless the judge hearing the case therefore understands the way these trojans function, it would be near impossible for the hapless customer to convince that the transaction was “Unauthorized”.

Who is to be blamed for placing the Bank Customer in such a situation?

It is clear that Banks are mainly responsible for operating a system of Internet Banking without the adequate  security which places its customers in a compromising position.

To some extent, RBI also should share the blame since it places lot of thrust on the 2 Factor authentication through the mobile.  Users are increasingly being coerced into the use of “Mobile Banking” with false promises. Banks also adopt the policy of  “No Mobile-No account” and mandate the use of mobiles for Internet Banking. 

In this scenario, it will not be long before we will witness a huge Banking fraud emerging in India on the back of the “Eurograbber” trojan.

Naavi

 

Related Article:

Inside Eurograbber: How SMS Was Used to Pilfer Millions

A Case Study on Eurograbber

Posted in Bank, Cyber Law, RBI | Leave a comment

New Banking Licenses in India

The recent decision of RBI to  invite fresh applications for new Banking licenses have evoked response from 26 applicants. The undersigned who joined the Banking industry in 1973 and has been in working in the industry upto 1987 and later around the industry in Marketing of Banking services since 2000, diversified  as a consultant in Information Security for Banks particularly working for “Safe E Banking” environment.

With this background, some of my thoughts on the new licencing aspects have been placed on this website.

Here is a summary of articles so far placed on the website.

1. Should Indian Post be granted Banking license?… Do they need one?

2.Which of the 26 applicants deserve Bank license

3.Banking License aspirants should disclose business plans to public.

4.Will RBI disclose “Santion Mechanism” to enforce sanctity of Banking license conditions?

5. Not all Eligible applicants to get Banking license

6. New Bank Licenses-Make Cyber Crime Insurance Mandatory

7. “Deep Pockets” need not be the sole criteria for Bank licenses

8.Banking Licenses and Public Sector aspirants

9. New Banking License-Let’s remember Gandhian Principles of Banking

Naavi

Posted in Bank, RBI | Tagged , , , , , , , | Leave a comment

Should Indian Post be granted Banking license?..Do they need one?

The decision of Indian Postal Department to seek a Banking license from RBI through the Licensing Scheme meant for private sector has been an object of discussion since the announcement was made.  The application is a source of embarrassment to  RBI which now has the challenge of deciding whether to grant a license to Indian Post or not as a traditional Bank.

There have been many positive reviews by experts indicating why Indian Post deserves a Banking license. However, I am personally not convinced that it is a good idea for Indian Post to become a “Commercial Bank”. In fact Indian Post has a greater future by simply modernizing its traditional services rather than becoming a Bank. By converting itself into a Bank, India will lose a great  digital post service that can be developed by only the department of post and not by any other entity in future.

Let me present some of my preliminary views in this regard so that E&Y instead of advising the Postal department to convert itself into a Bank can work on how to modernize the postal system into a “Digital Postal System”.

To start with, we can recognize that the Postal department is today a department of the Government of India which meets its costs from out of the Consolidated Fund of India. It is stated that  in the fiscal year 2012, it suffered a loss of Rs 6346 crores. Had it not been debited to the consolidated fund of India, perhaps the Postal department would be considered as a “Sick” company and wound up.

Post offices accept Savings Bank accounts, Recurring deposits, Time deposits and also sells long term investment instruments. The deposits in the system  are stated to be in the region of Rs 6 trillion (600,000 crores) . It is therefore the largest Bank in the country as regards deposit mobilization. It has over 150000 offices with nearly 89% of them in rural areas making it the largest institution in financial services across the country.

If the department needs to obtain Banking license then the “Banking Arm” has to be carved out as a “Public Sector Company” and run as a “Profit Center”. It cannot enjoy the benefit of “Money on tap” from the Government and has to earn money out of lending operations. It needs to also maintain SLR and CRR on the deposits.

From the depositor’s angle, the rates of interest paid by the Post office today may go down in the Banking arm. Secondly, the deposits which now have an “Unlimited Deposit Insurance” will come under the limited guarantee scheme of the DICGC. Hence the deposit products of the Indian Postal Bank would be inferior to the current products of the Indian post office.

If this inferior product is offered with the current service levels of the Postal department vis a vis an ICICI Bank or a Kotak Mahindra Bank, it is not possible for the Indian Postal Bank to retain its current customer base of around 23.8 crore customers (Savings Bank).

What will therefore happen is that the postal department will have to continue its operations in the present form while its own sister organization will cannibalize into its present activities. As a result the department will continue to carry the unprofitable part of its operations which has resulted in the loss of Rs 6436 crores in 2012 and will also be burdened with commercial competition from its Banking arm to wean away profitable niche of the current business portfolio.

At the same time, the need to undertake “Lending” as a new activity will create a complete upheaval in the system. At present the manpower in post office is not geared towards any lending activity and hence it has to borrow the entire lending portfolio from outside.

The proposal therefore is neither good for the Postal department nor is rosy for the Banking subsidiary. It would be beneficial for both the Postal department and the Banking industry as well as for the people if Indian Post continues to be “Deposit only Institution” backed for repayment by the Government of India.

The Banking subsidiary of the postal department will essentially be a Government owned Bank much like the REPCO Bank presently owned by the Ministry of Home Affairs (as a Society). This trend of each ministry having a Bank of its own is unhealthy from the point of view of a central regulator like RBI.

Once an Indian Postal Bank comes into existence, its staff mostly drawn from outside will be in a higher remuneration package compared to the existing employees. The existing employees in rural areas will end up doing all the dirty business as agents of their Bank counterparts who will be entrenched in the district head quarters in air conditioned chambers. Sooner or later this will give raise to a huge HR conflict and makes the entire business unviable.

We now have the example of Air India and Public Sector Hotel businesses suffering from the competition fuelled by sell out from within by corrupt politicians. The fate of Indian Postal Bank cannot be different.  We can therefore anticipate that the risk of failure of the Indian Postal Bank is relatively higher than in the case of any other private sector owned Bank.

It must be remembered that “Risk of Failure” is inherent in every financial business and hence it cannot be eliminated in Banking. We can only take precautions so that risks are identified at an early time and mitigated before it becomes unmanageable. From the RBI’s point of view, risk management strategy within the banking system is better administered if the risk can be contained within a “Failed Entity”. If the failure of one Bank can bring down other stable businesses, it would mean bad risk management. In this respect, failure of “Indian Post Bank” has the potential of developing into a major scam that can spread the risk to the consolidated fund of India.

In my opinion it is not logical for RBI to create this new risk.

Further, going by the legal structure in India, it is possible that the prospect of “Indian Post” turning into a “Commercial Venture” either directly or indirectly may be in conflict with the constitutional framework. Hence the Banking license to Indian Post could be challenged.

I would like Dr Subramanya Swamy to provide his views on this aspect.

While therefore giving my firm view that Indian Postal Department should withdraw its application (rather than RBI rejecting the same), I would like to express that the Indian Postal Department can contribute to the “Financial Inclusion” objective without setting up a Bank.

For example, as is already happening, Postal department can continue to be the “Disbursal Agent” for any Government subsidy. By simply linking the E Money order scheme to the disbursement chain, the objectives can be achieved without any additional investment from the side of the postal department.

Postal department can also modernize its IT infrastructure so that the efficiency of operation can be improved. Even today, the Speed Post is actually more efficient than private courier service though many in the public donot realize it. May be we need to introduce 24X7 speed post counters and more customer friendly operators to manage the counters. The back end can be stream lined and just as Premium couriers charge upto Rs 400 for guaranteed next day delivery, Postal authorities may also introduce “Guaranteed Speedpost Delivery” as a premium service.

The postal letter system can also be revolutionized with E-Letters being delivered electronically from one end to another end so that while Telegrams might have gone extinct, all letters would be delivered at the speed faster than the telegrams. The system would require a vending machine where the letter posted would be scanned and delivered to the destination post office where a print out would be delivered to the addressee. This will eliminate the movement of the cards in physical form. This system is similar to the Truncated Cheques or E Cheques conceptualized under the NI Act.

Postal authorities can also develop the “Postal ID” into a biometric based personal ID which can automatically be a “Postal Aadhar”. Then there could be bio-metric-cum face recognition based Assisted Money Vending systems in its rural Post offices which  can be used as universal money disbursal systems for various government disbursements and also support other Banks which donot have such a network.

 Additionally, Postal authority can and should develop a national e-mail exchange backbone with a secured server farm equivalent to the infrastructure of gmail so that all emails from within the country can be handled through this “Indian postal email”. Creating a commercially viable gmail alternative would be a great service that Indian Postal authorities could do to the people of India instead of rushing to become a Bank for which they are ill equipped.

It is regrettable that E &Y has failed to provide the correct guidance to the department for maximizing its service potential by upgrading and extending its present services rather than setting out to be a Banking institution which eventually may turn out to be a bad decision.

Many of the arguments presented above will with some modification apply in principle to the application of LIC Housing Finance also. Hence I donot consider it desirable that neither Indian Post nor LIC Home Finance should be considered for license.

Continuing from our previous discussion  we are now left with 6 applicants only who need to be short listed for the license.

Naavi

Related Articles:

Why India Post should get a banking licence

India Post plans to enter banking businsess

Dept Of Posts To Move Cabinet Note To Apply For Bank License

Post Bank of India?

India Post needs to become a corporate for banking foray

India Post Bank?

Indian Postal Service a Research Report

Posted in Bank, Cyber Law, RBI | Tagged , , , , | Leave a comment

Which of the 26 applicants deserve Bank license?

As the debate on the choice of probable licensees hots up, here is an interesting debate in moneycontrol.com between three experts

See Copy of the Detailed debate here

The three experts who have expressed their views are R Jagannathan, the Editor Firstpost, Haseeb Drabu former chairman J&K Bank and former editor Business Standard and a columnist with Livemint, and B D Narang former chairman of Oriental Bank of Commerce and now director of many companies. The experts have concluded that they would prefer to categorize the applicants into different categories namely NBFCs-pure play, NBFCs backed by Corporates, NBFCs backed by Government,  Brokerage and Real Estate Firms, Corporates in the private sector, Public sector companies and Government owned entities.

All experts are unanimous on rejecting the applications of the brokerage firms and real estate companies. Most also eliminate corporates on the basis of conflict of interest. Pure play NBFCs are being preferred with Shriram and SREI Infrastructure Finance as preferred candidates in this category. In the corporate backed NBFCs, Bajaj FInServe and L&T Finance are preferred. In the Government sector, Postal Department is the preferred applicant with LIC Housing Finance the next preference. One of the experts have preferred both Tatas and Birlas for the license though other two have not shown the inclination.

We thus have six candidates who seem to have passed this short listing exercise and if we add the Tatas and Birlas, it adds upto 8 inthe short list.

I am happy to note that the experts have given weightage to the “Financial Inclusion Capability” as one of the criteria for selection. I cannot but agree with this criteria as the main parity breaker as I have indicated in my earlier post.

Based on the views of the experts the following 18 applicants are considered as not suitable for the award of the license.

1.India Infoline Ltd., Mumbai
2.Religare Enterprises Limited, New Delhi.
3.J M Financial Limited, Mumbai
4.Muthoot Finance Limited, Kochi
5.UAE Exchange & Financial Services Ltd., Kochi
6.INMACS Management Services Limited, Gurgaon.
7.Smart Global Ventures Pvt. Ltd., Noida.
8.Indiabulls Housing Finance Limited, New Delhi
9.Suryamani Financing Company Limited, Kolkata.
10.Janalakshmi Financial Services Pvt. Ltd., Bangalore
11.Magma Fincorp Limited, Kolkata
12.Bandhan Financial Services Pvt. Ltd., Kolkata
13.Edelweiss Financial Services Limited, Mumbai
14.Tourism Finance Corporation of India Limited, New Delhi
15.IFCI Limited, New Delhi
16.IDFC Limited, Mumbai
17.Value Industries Limited, Aurangabad
18.Reliance Capital Limited, Mumbai

This leaves the following 8  candidates in the fray as preferred candidates  namely

1. TATA Sons Limited, Mumbai.
2. Aditya Birla Nuvo Ltd., Mumbai.

3.Bajaj Finserv Ltd., Pune
4. L & T Finance Holdings Limited, Mumbai

5.Shriram Capital Limited, Chennai.
6.SREI Infrastructure Finance Limited, Kolkata

7. Department of Posts, New Delhi.
8. LIC Housing Finance Ltd., Mumbai

I will expand on my comments in my next post.

Naavi

Posted in Bank, RBI | Tagged , , , , | Leave a comment

Beware of any fraudulent email

I am informed that there was an unsuccessful attempt to change password in my yahoo email account. (vijayashankar@yahoo.com). While I have taken some precautions since the report, If this is a malicious attempt and is repeated again with success, I anticipate emails to be sent to my contacts such as ” I am stranded in London, lost my passport and purse, please send me some money immediately..etc”.

Kindly ignore such mails if any.

This post is made as a means of public notice and will also be posted in cyber-notice.com.

Naavi

Posted in Cyber Crime, ITA 2008 | Leave a comment

Banking License Aspirants Should Disclose Business Plans to Public

In India, Reserve Bank of India (RBI) is gearing itself to grant fresh Banking licenses. 26 applications are now under the consideration of RBI. The applicants include a diverse set of groups which includes

a) A department of the Government of India
b) 3 Public sector Companies
c) 4 large private sector groups
d) 11 Private sector NBFCs including a Housing loan company and 2 Infrastructure finance companies
e) 3 Share broking companies
f) A Gold loan company
g) A Currency Exchange company
h) A Mobile handset Company
i) A Management consultancy company

Many of the companies donot even need a second look for rejection.

The list indicates that there might not have been any strict pre application criteria and hence anybody with an intention of getting some free publicity has entered the fray even though they may get rejected in the next 4 months. They will be trading on the false reputation they have gained as “Applicant for Bank License” during the next 4-6 months and extract some benefit out of the same. If nothing else their share prices are likely to remain higher than normal and provide enough financial gain to provide justification for the application.

Continue reading

Posted in Bank, RBI | Tagged , , | Leave a comment