# Five Ways Bad Bots Are Trying To Crack Your Virtual Vaults
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-07-15
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: Protecting Financial Data from Bad Bots: The Virtual Vault Threat
Meta Description: Discover the increasing threat of bad bots to financial institutions and the tactics used by cybercriminals to launch attacks. Stay informed and protect your
URL: https://financedigest.com/five-ways-bad-bots-are-trying-to-crack-your-virtual-vaults-by-erez-hasson-strategist-application-security-at-impervahtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/graphicstock-protect-company-finances-and-tax-optimization-company-investment-represented-by-dollar-symbolsuy7j2vgsg-1-1736838174720-compressed.jpg)

By Erez Hasson, Strategist, Application Security at Imperva

Since the start of the digital era, financial institutions have been at the forefront of the battle over cyber security. The finance industry hold some of the most sensitive data in the world, and hackers have spent decades finding new ways to steal and monetise that data. From customer credit card information to credit and employment status, pricing structure, and more, today’s online banking services and applications are the doorway to [virtual vaults filled with data](https://www.financedigest.com/what-is-a-virtual-data-room-unveil-the-essential-information-here.html "What is a Virtual Data Room? Unveil the Essential Information Here!"), not dollars.

It should come as no surprise, therefore, that these virtual vaults are [increasingly under attack](https://www.financedigest.com/over-half-of-organisations-would-consider-using-cryptocurrencies-for-business-transactions-though-8-in-10-acknowledge-the-increased-risk-of-associated-ddos-attacks.html "Over half of organisations would consider using cryptocurrencies for business transactions, though 8 in 10 acknowledge the increased risk of associated DDoS attacks"). A [key driver behind this is the rise of bad bots that enable cybercriminals to launch successful](https://www.financedigest.com/mvp-for-startups-the-key-to-success.html "MVP for startups: the key to success") widespread attacks with greater efficiency and at lower costs. So, what are these bad bots, and why are they becoming such a big issue for [financial institutions](https://www.financedigest.com/a-cloud-migration-guide-for-financial-institutions.html "A Cloud Migration Guide for Financial Institutions")?

**The threat of bad bots**

[Bots](https://www.imperva.com/learn/application-security/what-are-bots/) are applications that run automated tasks on the internet – some that are helpful; some that are nefarious. Take Googlebot, for example, which builds a searchable index of documents and web pages on the internet, or on [social media](https://www.financedigest.com/ai-and-social-media-are-revolutionizing-personal-finance-in-2023.html "AI and Social Media Are Revolutionizing Personal Finance in 2023") crawlers. This is an example of a good bot. Conversely, bad bots are applications that run automated tasks with malicious intent and are harder to detect and stop. They allow cybercriminals, unprincipled competitors and fraudsters to perform malicious tasks – such as transaction fraud and [financial data](https://www.financedigest.com/how-data-governance-as-a-service-can-transform-the-financial-sector.html "How Data Governance-as-a-Service can transform the financial sector") harvesting – around the clock.

[The 2021 Bad Bad Report from Imperva](https://www.imperva.com/blog/bad-bot-report-2021-the-pandemic-of-the-internet/) found that 40.8% of all internet traffic in 2020 was not human while bad bot traffic – the automated activity that is harder to detect and stop — increased by 6.2%, a new record. Bad bots have been terrorising the internet for the past few years, [growing in sophistication and persistence](https://www.financedigest.com/the-immunooncology-market-is-expected-to-grow-on-a-persistent-note-in-the-future.html "The Immunooncology Market is expected to grow on a persistent note in the future"). In fact, some advanced bad bots can mimic human interactions with web applications in an extraordinarily persuasive way – making this a difficult problem for [financial services](https://www.financedigest.com/devops-the-secret-tool-thats-transforming-financial-services.html "DevOps: The Secret Tool that’s Transforming Financial Services") to manage.

**Cracking the virtual vault**

Throughout 2020, [34% of all](https://www.imperva.com/blog/bad-bot-report-2021-the-pandemic-of-the-internet/) login attempts to private financial accounts originated from malicious bots, determined Imperva, contributing to a 51% increase in account takeover attacks in November-December. With the threat rising, it’s vital that banks get to grips with the threat of bad bots, what it means for their [business and take time to understand the tactics used by bad](https://www.financedigest.com/5-ways-to-grow-your-business-despite-a-bad-credit-score.html "5 Ways to Grow Your Business despite a Bad Credit Score") bot operators. Here are the top five types of [attack banks](https://www.financedigest.com/attacking-banking-and-fintech-fraud-head-on-through-ai-infused-strategies.html "Attacking Banking and Fintech Fraud Head-On Through AI-Infused Strategies ") should look out for:

1. [**Account takeover fraud**:](https://www.financedigest.com/onespan-launches-ai-based-risk-analytics-stop-account-takeover-new-account-fraud.html "OneSpan Launches AI-Based Risk Analytics to Stop Account Takeover and New Account Fraud") These brute force style attacks use lists of compromised user credentials to breach a system. The attack uses bots for automation and scale and assumes that most [users reuse their usernames and passwords](https://www.financedigest.com/ai-is-the-new-password-security-and-ease-for-finance-users.html "AI is the new password: security and ease for finance users ") across various services. The financial services sector is often a key target for attackers, with stolen online banking logins sold for as little as [$40](https://www.privacyaffairs.com/dark-web-price-index-2021/). A successful account takeover attack can result in significant ramifications for organisations: noncompliance with data privacy regulations, loss of personally identifiable information (PII), significant brand damage, customer dissatisfaction, increased fraud and customer [support costs](https://www.financedigest.com/5-ways-to-support-your-employees-during-the-cost-of-living-crisis.html "5 ways to support your employees during the cost of living crisis ") and customer churn.
 [Credit card](https://www.financedigest.com/uk-credit-card-borrowing-rises-by-most-since-2005-boe.html "UK credit card borrowing rises by most since 2005 – BoE") fraud(Card Cracking or Carding): Bad actors apply bots in two different methods. First, bots can be used to authorise stolen credit card information. Second, they’re used to guess missing parts of partial credit card information – often gained through phishing, skimming or data taken from the dark web. Such attacks can result in damage to the fraud score of a business, while also triggering increased customer service costs to process fraudulent chargebacks – not to mention lost revenues from the fraud itself.
Custom content theft(including financial data scraping): Competitors and aggregators often implement bots to scrape proprietary content and rates to stay a step [ahead of rivals and their offerings](https://www.financedigest.com/mfe-offers-to-buy-1-05-stake-in-mediaset-espana-from-vivendi-ahead-of-delisting.html "MFE offers to buy 1.05% stake in Mediaset Espana from Vivendi ahead of delisting"). It’s important to note that unlike screen scraping, which only copies pixels displayed onscreen, some web scraping tools can extract underlying HTML codes and accompanying data that’s stored in a database. The scraper can then replicate entire website content elsewhere to make themselves look more reputable. This leads to revenue and market share loss to competition, or IP infringement.
4. **API attacks**: APIs have become an essential part of the online ecosystem in recent years. Bad bots exploit API endpoints to access to important [data through attacks like API scraping or web](https://www.financedigest.com/investing-in-the-future-with-alternative-web-data.html "Investing in the future with alternative web data") and mobile API hijacking. Many organizations are struggling to manage API security, relying on simple authentication tokens or basic IP rate limiting to [protect these critical attack](https://www.financedigest.com/protecting-against-man-in-the-middle-attacks-with-dynamic-linking.html "Protecting against man in the middle attacks with dynamic linking") vectors.
5. **Denial of [service at the application](https://www.financedigest.com/redline-application-services-scales-up-with-the-bunker.html "Redline Application Services scales up with The Bunker") layer**: Automated application layer attacks are different from a volumetric denial-of-service (DoS) attack. While volumetric attacks are primarily aimed at the lower-level network protocols, bad bot activity targets the application layer. Often attackers don’t intend to focus on the application. Instead, these incidents occur as an indirect consequence of the sheer volume of requests to the web server coming from automated bot traffic, [creating a successful](https://www.financedigest.com/five-critical-tips-to-create-a-successful-start-up.html "Five Critical Tips To Create A Successful Start-up") DoS attack. These attacks slow down web applications, hampering performance and elevating the risk of downtime. This results in loss of revenue due to the website’s unavailability, as well as damage to brand reputation.

[**Developing a bot management strategy**](https://www.financedigest.com/automotive-hmi-system-market-recent-industry-developments-and-growth-strategies-adopted-by-players.html "Automotive HMI System Market: Recent Industry Developments and Growth Strategies Adopted by Players")

[Banks can’t afford to turn](https://www.financedigest.com/governments-and-central-banks-risk-inflation-bank-of-england-has-done-its-bit-now-the-politicians-turn.html "Governments and central banks risk inflation, Bank of England has done its bit, now the politicians’ turn") a blind eye to the potential threats caused by bad bot traffic. They are a real and growing threat, with the potential to cause significant [financial or reputational damage](https://www.financedigest.com/uk-businesses-need-to-embrace-payment-technologies-to-reduce-financial-damage-risk.html "UK businesses need to embrace payment technologies to reduce financial damage risk"). However, you can’t stop bad bots with the flick of a switch. Every [site is targeted for different reasons](https://www.financedigest.com/5-reasons-why-e-commerce-sites-need-a-token-gateway.html "5 reasons why e-commerce sites need a token gateway"), and usually by different methods, so there is no one-size-fits-all bot solution so organisations need to invest in a dedicated bot management solution that can identify and offer control over all traffic so that even sophisticated bad bots can be blocked without disrupting genuine customers.

Bot operators are financially motivated and determined, constantly evolving their methods, which is why [75% of companies](https://services.google.com/fh/files/misc/google_forrester_bot_management_tlp_post_production_final.pdf) are looking to bolster their bot management defences. And given the huge attack surface banks have, it’s essential that they are [securing all access points and have a range of response options to deal](https://www.financedigest.com/incentive-fm-secures-new-deal-with-dollar-uk.html "Incentive FM Secures New Deal with Dollar UK") with incoming bot traffic. Ultimately, without a holistic management solution that is able to work across different team siloes, [banks will end up losing the bot arms](https://www.financedigest.com/hsbc-acquires-british-arm-of-stricken-silicon-valley-bank.html "HSBC acquires British arm of stricken Silicon Valley Bank") race to the criminals.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

