Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Banking > Two weak links cyber attackers are exploring to breach banks
    Banking

    Two weak links cyber attackers are exploring to breach banks

    Two weak links cyber attackers are exploring to breach banks

    Published by linker 5

    Posted on February 24, 2021

    Featured image for article about Banking

    By Rui Ribeiro, CEO at Jscrambler

    The coronavirus pandemic has brought on a lot of changes into modern society, specifically when it comes to digital transformation. If we were already headed into the digital direction pre-pandemic, these unprecedented circumstances have only further accelerated the process. From education to banking, all sectors are going through this digital transformation, providing much-needed safer alternatives to in-person interactions. But how does this new paradigm impact the cybersecurity posture of organisations? How are financial institutions adapting and what do they need to improve?

    When it comes to the banking sector, the digital component has become instrumental in the economy. On this note, it was found in a recent survey that 84% of consumers expect banks to actively transform their processes and offer digital services to keep them safe. We have seen large-scale closure of physical banks, and the use of electronic payments is increasing as people make the shift from cash to digital. Due to the circumstances, there has also been a general increase in e-commerce transactions, for example, there was an 81% increase in Italy according to Mckinsey & Co. All these factors are making traditional banks shift to digital banking faster than ever.

    Incumbents are embracing the democratization of financial services and launching customer-centric platforms, for example, Santander launching openBank or RBS launching Bó. Not only are we seeing traditional banks shift their processes, but we are also seeing an increase in neobanks. These banks operate exclusively online without traditional physical branch networks as is the case with Revolut, N26, Nubank, and many more. But what does all this rapid growth mean for banks in terms of security?

    With all the upsides digital banking brings, also come new challenges, specifically in terms of keeping user’s data safe. The core logic of modern web banking apps and hybrid mobile banking apps is written in JavaScript, a programming language that allows development teams to shorten product release cycles. However, JavaScript requires special attention in terms of security, as it can be easily retrieved or tampered with by attackers, who can target the JavaScript source code to plan or automate data exfiltration attacks.

    The majority of digital banking providers also rely on an agile product development process to be able to keep up with market demand and they often sacrifice security because of it. This race also increases the possibility of web supply chain attacks since development teams are relying extensively on third-party code. For example, we saw this issue in November of 2018 when an attacker was able to gain control of the event-stream JavaScript library, which was a third-party code dependency of Copay, a cryptocurrency wallet. This allowed the attacker to inject malicious code which harvested the credentials and private keys of Copay users. The company’s development team did not detect the malicious code immediately and released several builds of the infected application.

    The Copay example is only one in many incidents that have happened over the years. These cybersecurity incidents are sadly not uncommon, especially when technology advances as fast as it has in the past few years. With this rapid mutation of digital banking solutions, we see malicious strategies also improving fast to try and keep up with the market. Companies need to be aware of this double-edged sword so that they can also focus on improving their security. Having visibility and control over their products is crucial when it comes to ensuring that their web and mobile applications are not being leveraged by attackers to siphon user data.

    In conclusion, although the shift to digital transformation is bringing a lot of needed safety for users when it comes to avoiding in-person interactions, users also need protection in the digital space. Because of this, banks are required to consider the possibility of the various online threats and find solutions to keep their users’ data safe. Developing an application fast enough to keep up with other digital banking applications is not enough to provide a good user experience. The key takeaway here is that banks need to take action now and mature their client-side security to prevent breaches and be compliant with regulations. If they are able to successfully manage their client-side security, they can outpace attackers and keep their users safe.

    Related Posts
    CIBC wins two Global Banking and Finance Awards for student banking
    CIBC wins two Global Banking and Finance Awards for student banking
    DeFi and banking are converging. Here’s what banks can do.
    DeFi and banking are converging. Here’s what banks can do.
    Are Neo Banks Offering Better Metal Debit Cards Than Traditional Banks?
    Are Neo Banks Offering Better Metal Debit Cards Than Traditional Banks?
    Banking at the Intersection: From Nashville to Cannes, A Strategic Call to Action
    Banking at the Intersection: From Nashville to Cannes, A Strategic Call to Action
    Driving Efficiency and Profit Through Customer-Centric Banking
    Driving Efficiency and Profit Through Customer-Centric Banking
    How Ecosystem Partnerships Are Redefining Deposit Products
    How Ecosystem Partnerships Are Redefining Deposit Products
    CIBC Private Banking wins four 2025 Global Banking & Finance Awards
    CIBC Private Banking wins four 2025 Global Banking & Finance Awards
    How Banks Can Put AI to Work Now and Prove ROI in 90 Days
    How Banks Can Put AI to Work Now and Prove ROI in 90 Days
    Top 5 AI quality assurance framework providers for Banks and Financial Services firms.
    Top 5 AI quality assurance framework providers for Banks and Financial Services firms.
    The Unbanked Paradox: How Banking Access Creates Economic Resilience
    The Unbanked Paradox: How Banking Access Creates Economic Resilience
    Hyper-Personalised Banking - Shaping the Future of Finance
    Hyper-Personalised Banking - Shaping the Future of Finance
    The End of Voice Trust: How AI Deepfakes Are Forcing Banks to Rethink Authentication
    The End of Voice Trust: How AI Deepfakes Are Forcing Banks to Rethink Authentication

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Previous Banking PostAs We Get Back to the Future of Work, Banks Must Embrace WhatsApp
    Next Banking PostWhat banks need to know about observability

    More from Banking

    Explore more articles in the Banking category

    Predicting and Preventing Customer Churn in Retail Banking

    Predicting and Preventing Customer Churn in Retail Banking

    Growth and Impact: Banreservas Leads Dominican Republic Economic Expansion

    Growth and Impact: Banreservas Leads Dominican Republic Economic Expansion

    Turning Insight into Impact: Making AI and Analytics Work in Retail Banking

    Turning Insight into Impact: Making AI and Analytics Work in Retail Banking

    KeyBank Embraces Next-Generation AI Platform to Transform Fraud and Financial Crime Prevention

    KeyBank Embraces Next-Generation AI Platform to Transform Fraud and Financial Crime Prevention

    Understanding Association Banking: Financial Solutions for Community Success

    Understanding Association Banking: Financial Solutions for Community Success

    Applying Symbiosis for advantage in APAC banking

    Applying Symbiosis for advantage in APAC banking

    AmBank Islamic Berhad Earns Triple Recognition for Excellence in Islamic Banking

    AmBank Islamic Berhad Earns Triple Recognition for Excellence in Islamic Banking

    FinTok Strategy: How Banks Are Reaching Gen Z Through Social Media

    FinTok Strategy: How Banks Are Reaching Gen Z Through Social Media

    Rethinking Retail Banking Sustainability: Why the ATM is an Asset in the Sustainable Transition

    Rethinking Retail Banking Sustainability: Why the ATM is an Asset in the Sustainable Transition

    How private banks can survive the neo-broker revolution

    How private banks can survive the neo-broker revolution

    Next-Gen Bank Branches: The Evolution from Transaction Hubs to Experience Centers

    Next-Gen Bank Branches: The Evolution from Transaction Hubs to Experience Centers

    The Banking Talent Crunch: How Financial Institutions Are Competing for Digital-Native Skills

    The Banking Talent Crunch: How Financial Institutions Are Competing for Digital-Native Skills

    View All Banking Posts