Hackers are starting to deploy tactics that bypass stronger authentication schemes. We have seen a Trojan program that did not have to trick victims out of revealing their password, but instead waited for the victim to check their bank balance and the Trojan then silently siphoned money out of the account. We expect this kind of activity to become more prevalent as banks move to stronger forms of authentication, as tactics typically change only when they need to. |
If you click on it, you will download an executable that installs itself into your browser and then just waits until you go to your bank site. |
Most companies think they're OK because their security systems block large-scale attacks. But they may have already been hit by narrow attacks and don't know it. |