# Social engineering in the Financial Services : People Are The  Weakest Link in the Security Chain
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2022-06-22
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: Combat Cybercrime with Behavioral Biometrics Solutions
Meta Description: Learn how behavioural biometrics can help detect and prevent authorised push payment fraud and protect your finances from cybercriminals. Stay safe online!
URL: https://financedigest.com/31972social-engineering-in-the-financial-services-people-are-the-weakest-link-in-the-security-chainhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/touch-screen-mobile-phonef-1736815628748-compressed.jpg)

_![](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/iain-swaine-450x671-1736815628730-compressed.jpg)_

_By_ **_Iain Swaine,_** _Head of Cyber Strategy EMEA, BioCatch_

The chance of [becoming a victim of cybercrime increases year](https://www.financedigest.com/scottys-little-soldiers-become-incentive-fm-groups-chosen-charity-in-three-year-partnership.html "Scotty’s Little Soldiers Become Incentive FM Group’s Chosen Charity In Three Year Partnership") after year.  [In the first half of 2021 in the UK](https://www.ukfinance.org.uk/policy-and-guidance/reports-publications/2021-half-year-fraud-report), criminals stole a total of £753.9 million through fraud, an increase of over a quarter (30 per cent) compared to the first half 2020.

With more sophisticated [fraud prevention](https://www.financedigest.com/payroll-fraud-and-how-to-prevent-it.html "Payroll fraud and how to prevent it") measures in place criminals increasingly targeting regular people, customers of banks and other financial institutions.  [Cybercriminals take advantage of the weakest link in the security](https://www.financedigest.com/winning-the-security-race-how-financial-services-can-keep-pace-with-cybercriminals.html "Winning the security race: how financial services can keep pace with cybercriminals") chain – people.

People are error prone and make the same mistake multiple times. The inability of [financial institutions](https://www.financedigest.com/3-ways-financial-institutionscan-leverage-live-engagement-on-social-media.html "3 ways financial institutions can leverage Live Engagement on social media") from preventing us from making mistakes, makes us the weakest link in the chain.  While this form of [fraud has been implemented for years](https://www.financedigest.com/scam-special-how-to-avoid-christmas-shopping-fraud-this-year.html "Scam Special: How to Avoid Christmas Shopping Fraud this Year"), mostly in the form of phishing and vishing (voice phishing), it is growing continually.

Behavioral biometrics-based technology can detect social engineering scam attacks and validate a person’s identification during a banking transaction without the [need for further security](https://www.financedigest.com/why-preparation-for-new-swift-cyber-security-standards-needs-to-start-now.html "‘Why preparation for new SWIFT cyber security standards needs to start now’") layers.

**[Fraud detection](https://www.financedigest.com/the-clues-to-detecting-fraud-are-hidden-in-relationships.html "THE CLUES TO DETECTING FRAUD ARE HIDDEN IN RELATIONSHIPS") in real-time**

Real-time fraud, also known as authorised push payment (APP) fraud, is a form of [social engineering that can cause considerable financial](https://www.financedigest.com/can-financial-services-brands-ever-be-credible-on-social.html "Can financial services brands ever be credible on social? ") harm. To establish the necessary authenticity, cybercriminals utilise their victims’ personal data obtained through data breaches on the dark web or captured from [social media](https://www.financedigest.com/why-no-event-should-be-planned-without-a-social-media-strategy.html "Why No Event Should Be Planned Without a Social Media Strategy") profiles. The more information available to the perpetrators, the more authentic they can appear.

In doing so, they contact their victims via telephone and pretend to be a representative of a government agency, an [employee of the bank](https://www.financedigest.com/73-of-employees-in-the-banking-and-financial-services-industries-are-looking-for-better-physical-and-mental-wellbeing-support-in-the-workplace.html "73% of employees in the banking and financial services industries are looking for better physical and mental wellbeing support in the workplace") or another official organisation. In this way, they can persuade the [person called to transfer a certain amount of money](https://www.financedigest.com/making-money-personal-again-why-money-should-be-about-the-connections-and-possibilities-it-unfolds.html "Making money personal again Why money should be about the connections and possibilities it unfolds") to another account. The banks’ security processes can be bypassed because a [real account](https://www.financedigest.com/its-time-for-real-time-accountancy.html "It’s time for real time accountancy ") holder triggers the transfer. Multi-factor authentication (MFA) thus offers no protection either.

The [fraud is difficult to pinpoint because it is a real user](https://www.financedigest.com/fintechs-how-to-increase-loyalty-through-user-experience-and-fraud-prevention.html "FinTechs: How to increase loyalty through user experience and fraud prevention") who logs in from a legitimate location and completes the authentication procedure with their own end device. This is because the usual checks – for example, identifying the location, the [end device](https://www.financedigest.com/sales-of-vacuum-blood-collection-devices-are-forecast-to-reach-us-4-2-bn-by-the-end-of-2031.html "Sales of Vacuum Blood collection Devices are forecast to reach US$ 4.2 Bn by the end of 2031"), or the IP – are no longer sufficient. Even out-of-band methods such as authentication with a [one-time password](https://www.financedigest.com/breaking-down-the-compliance-limitations-of-sms-one-time-passwords.html "Breaking down the compliance limitations of SMS One-Time Passwords") (OTP) via SMS can be circumvented.

Cybercriminals who carry out such attacks also usually have a sophisticated script and are familiar with a [bank’s security](https://www.financedigest.com/digital-experience-and-security-the-crucial-combination-for-banks.html "Digital experience and security – the crucial combination for banks") practices and procedures. To make matters worse, cyber criminals use [social engineering methods to elicit emotional response](https://www.financedigest.com/corporate-social-responsibility-within-the-festival-industry.html "Corporate Social Responsibility Within The Festival Industry") from their victim. Criminals will try to extract feelings of sympathy, guilt, or companionship from their victims. They will use a sense of urgency, flattery, an aura of authority or trusting dispositions.  These popular methods elicit feelings such as fear, anxiety, or ease, causing victims to behave hastily or without judgement, resulting in the attacker’s desired outcome.

**How can you use Behavioural [Biometrics to detect Authorized Push Payment](https://www.financedigest.com/the-future-of-biometrics-in-payments.html "The Future of Biometrics in Payments") (APP) Fraud?**

APP fraud is gaining traction in the UK – victims have lost an estimated [£479 million](https://www.biocatch.com/blog/app-scams-fraud-director) in total, averaging over £7K per victim. However, technologies based on behavioral biometrics can detect this [type of fraud; it can be used to verify a person’s identity during the entire banking transaction](https://www.financedigest.com/types-of-fraud-in-e-commerce.html "TYPES OF FRAUD IN E-COMMERCE"). BioCatch uses data-based insights to distinguish behaviors of [“real” and manipulated users](https://www.financedigest.com/the-wisdom-of-the-crowd-real-world-users-validate-m-commerce-apps.html "The wisdom of the crowd – ‘real world’ users validate m-commerce apps").  In collaboration with its customers, BioCatch has developed risk models that can be used to identify a variety of threats, as this collaborative effort is deemed essential in empowering clients and [keeping consumers](https://www.financedigest.com/cost-of-living-crisis-consumers-keep-spending-for-now.html "Cost of living crisis? Consumers keep spending for now") safe. In addition, there are clear behavioral patterns that can distinguish “real” from “fraudulent” activity during an online session and reveal manipulation by a cybercriminal:

- **Unusual duration of the session:** the session [lasts considerably longer](https://www.financedigest.com/brand-loyal-brits-have-longer-relationships-with-their-car-than-their-last-lover.html "BRAND-LOYAL-BRITS HAVE LONGER RELATIONSHIPS WITH THEIR CAR THAN THEIR LAST LOVER") than usual, and the account holder shows noticeable behavior patterns, such as aimless mouse movements. This may indicate that the person is nervous or under pressure while waiting for instructions from a criminal.
- **Segmented keystrokes:** If there are interruptions in typing, this may be a [sign that the account](https://www.financedigest.com/twitters-account-of-deal-shows-musk-signing-without-asking-for-more-info.html "Twitter’s account of deal shows Musk signing without asking for more info") number is being read aloud by the perpetrator, preventing routine typing.
- **Hesitation:** The time required to perform simple, intuitive actions such as confirming an entry increases significantly.
- **Unusual handling of the terminal device:** The orientation of the device changes frequently. This may indicate that the logged-in user repeatedly puts down or picks up his smartphone to accept the criminal’s instructions.

Cybercriminals that use social engineering to defraud enterprises are determined and skilled, regardless of how complex a bank’s [systems and controls](https://www.financedigest.com/emission-control-systems-market-to-increase-at-a-cagr-of-5-through-2021-to-2031-persistence-market-research.html "Emission Control Systems Market To Increase At A CAGR Of 5% Through 2021 to 2031: Persistence Market Research") are. After a successful social engineering fraud, there is usually no [way to track down the victim’s money](https://www.financedigest.com/best-ways-to-make-money-online.html "Best ways to make money online"). Therefore, to protect [customers from financial](https://www.financedigest.com/disconnected-customers-are-one-of-the-biggest-problems-facing-financial-companies.html "Disconnected customers are one of the biggest problems facing financial companies") loss, it is imperative to detect fraud the moment it occurs. The use of behavioral biometrics can prevent significant losses, while comprehensively [protect customers and company](https://www.financedigest.com/5-ways-to-protect-your-company-from-cyber-security-threats.html "5 Ways to Protect Your Company From Cyber Security Threats") assets. It [must form the bedrock of any financial](https://www.financedigest.com/the-financial-sector-must-act-to-tackle-internal-data-security.html "THE FINANCIAL SECTOR MUST ACT TO TACKLE INTERNAL DATA SECURITY") institutions anti-fraud protection.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

