Welcome Guest! To access all forums & features, please register an account or sign-in. → Why register?



Phishing victims' losses are own fault - court


20 replies to this topic - - - - -

#1 +Mephistopheles

    Member N° 1,302

  • 19,384 posts
  • Joined: 18-September 01
  • Location: Frankfurt, DE
  • OS: Windows 7
  • Phone: Nexus 4

Posted 26 April 2012 - 09:14

Phishing victims' losses are own fault - court

Bank customers who give over their account details to "phishers" despite bank warnings against online scams are liable for their own losses, a top German court ruled on Tuesday.

The landmark judgement by the Federal Court of Justice is the first time that Germany’s supreme court has ruled on the question of whether banks or their clients are responsible for online-banking abuse.

It follows a case brought by a pensioner who lost €5,000 from his Sparda Bank account to a Greek account in a transaction he claimed he had not executed himself.

According to the Süddeutsche Zeitung, the transfer occurred three months after he entered ten transaction numbers, or TAN codes, on what turned out to be an illegally manipulated version of his bank’s website. This common internet scam is known as "phishing."

Tuesday’s judgement absolved the bank of any liability for the incident, as it had expressly warned customers of such practices on its website. Instead the judges ruled that the plaintiff’s lack of care in entering his TAN codes amounted to negligence.

TAN codes are sequences of numbers that customers must enter to make online transactions.

The plaintiff argued that the bank had a duty to protect its customers from the abuse of these codes. But the federal court upheld previous judgements by the district and state courts, agreeing with the bank’s argument that the customer should bear responsibility for falling for the con.

The bank said it was widely known that being asked to input several TAN codes was a telltale sign of phishing, and pointed out that a phishing warning appeared on its login page.

The plaintiff had also agreed to keep his TAN codes safe when he signed up to the bank’s online service. The bank argued that as the correct TAN codes were entered, the customer could only have entered them himself or failed to keep them secure.

German authorities were not able to track down the holder of the Greek account, despite enlisting their Greek counterparts.

Sparda Bank is one the few remaining German banks to use the iTAN procedure, and the method is commonly thought to be susceptible to phishing. But a bank spokesman told the Süddeutsche Zeitung, “As far as the court was concerned, the security of the procedure is not in question.”

Most banks favour other procedures that are thought to reduce the chances of fraud, like Mobile-TAN, where the customer receives new codes by text message, or Chip-TAN, where codes are generated by a special machine that the customer keeps at home.

In 2010, the Federal Criminal Police Office of Germany received 5,300 reports of phishing – a rise of 82 percent on the previous year. Last year’s figures are not yet available.

As many as 44 percent of German bank customers do at least some of their banking online, a survey last year found. That amounts to 27 million account holders, according to the Federal Association of German Banks.


Source: Thelocal.de


#2 Vykranth

    Chantez, compagnons, dans la nuit la Liberté nous écoute

  • 2,829 posts
  • Joined: 02-September 04
  • Location: Nancy, France
  • OS: Windows 7 x64

Posted 26 April 2012 - 09:23

Super cynical mode set to 'on'

So, if I were to be a crook who goes from door to door and try to sell bad loans and con money out of people, this is my fault but the customers has his money insurred
But, If I set up my scam on the web, the fault is for my victim.

It is a good thing I know computers!!

#3 DrakeN2k

    Resident Elite

  • 1,007 posts
  • Joined: 04-December 10

Posted 26 April 2012 - 09:23

Good thing i guess , banks cant keep bailing people out due to there stupidity.

#4 TheLegendOfMart

    Neowinian DOMINATING

  • 8,670 posts
  • Joined: 01-October 01
  • Location: England

Posted 26 April 2012 - 09:31

View PostDrakeN2k, on 26 April 2012 - 09:23, said:

Good thing i guess , banks cant keep bailing people out due to there stupidity.
Its easy to say that knowing about computers and the internet, not everyone is so tech savvy. Banks rake in millions and/or billions at the expense of the customer, its up to the bank to make it so fraud isn't possible, if it wasn't possible then phishing wouldn't work.

If this happened in my country I'd move my money elsewhere, see what the banks reaction is once they start losing loads of customers.

#5 Soldiers33

    Neowinian Senior

  • 2,216 posts
  • Joined: 01-September 06
  • Location: London
  • OS: Windows 7 Professional

Posted 26 April 2012 - 09:36

finally someone has some sense. I always take care when it comes to online and money. I have setup mobile security everywhere I could.

#6 Simon-

    Neowinian ULTRAKILL

  • 10,720 posts
  • Joined: 04-November 02

Posted 26 April 2012 - 09:39

View PostDrakeN2k, on 26 April 2012 - 09:23, said:

Good thing i guess , banks cant keep bailing people out due to there stupidity.
No not really, it is not a pure case of stupidity, a pure case of stupidity is where a customer KNOWINGLY gave their details to a 3rd party. What is stupidity is expecting 100% of customers to be computer and scam savvy. Some people have a higher IQ than others and a customer base covers such a broad set of people that is going to range from people with a lower than average IQs and Pensioners whose minds are not as alert as they once were to Ultra genius computer experts such as yourself. This is a very BAD precident because instead of the banks implementing REAL security such as the ones mentioned which are not susceptible to phishing, they can get away with low security with no liability.

REAL Security is more than just SSL, a password and a liability disclaimer. Maybe if the banks didn't implement such crappy security mechanisms that are easily susceptible to human error, they could requiand are it fool proof and we wouldn't have this problem.

I hope this generated a hell of a lot of bad press for the bank and they have a mass exodus of customers as they obviously can't be trusted with their customers interests. It could happen to any of their customers (many could have fallen in the same trap) and they won't help. This also sets the precident when a particularly GOOD phishing attempt comes through where the scammer can actually spell properly and then hundreds of people will fall victim.

#7 +Lovell

    ,l,(-.-),l,

  • 1,517 posts
  • Joined: 14-November 03
  • Location: Great Britain

Posted 26 April 2012 - 09:46

People need to stop opening links from emails, it's not hard to look at the address bar and see what site your on.

#8 DrakeN2k

    Resident Elite

  • 1,007 posts
  • Joined: 04-December 10

Posted 26 April 2012 - 09:55

I understand people argent tech savy like us. but there needs help out there to see the signs

#9 jakem1

    Neowinian Wise One

  • 5,440 posts
  • Joined: 17-November 06

Posted 26 April 2012 - 11:13

View PostDrakeN2k, on 26 April 2012 - 09:55, said:

I understand people argent tech savy like us. but there needs help out there to see the signs

:huh:

After reading that I'm a bit concerned that you might be the sort of person who's vulnerable to phishing scams :p

#10 rippleman

    Neowinian Senior

  • 2,344 posts
  • Joined: 17-June 09
  • Location: Near Calgary, Alberta
  • OS: Windows 7
  • Phone: Upgraded back to 2 year old iPhone 4 from new Galaxy 2Sx

Posted 26 April 2012 - 11:21

banks shouldNOT be responsible for keeping YOUR actions from losing YOUR money. Their actions yes, their security yes, but not yours.

#11 jakem1

    Neowinian Wise One

  • 5,440 posts
  • Joined: 17-November 06

Posted 26 April 2012 - 11:41

View Postrippleman, on 26 April 2012 - 11:21, said:

banks shouldNOT be responsible for keeping YOUR actions from losing YOUR money. Their actions yes, their security yes, but not yours.

I disagree. Banks make more than enough money off our money and there's no reason why a proportion of those profits shouldn't be put towards insuring our savings.

If my debit card is cloned and then money is taken from my account the banks will protect me. If my card is stolen and money is then taken from my account the banks will protect me. I don't see any reason why I shouldn't be offered the same sort of protection if I'm a victim of electronic fraud.

As for this case, I don't see why the banks couldn't have flagged a sudden withdrawal in another country as suspicious. I always tell advise my bank before I travel abroad so they know to expect strange transactions (to stop them blocking my card preemptively). Every time I do they thank me but tell me that their fraud protection systems will block suspicious transactions regardless of whether I warn them in advance or not. It sounds to me as if the bank failed to protect this customer.

#12 firey

    Neowinian Wise One

  • 5,360 posts
  • Joined: 30-October 05
  • Location: Ontario, Canada
  • OS: Windows 7
  • Phone: Android (4.1.2)

Posted 26 April 2012 - 12:04

View Postjakem1, on 26 April 2012 - 11:41, said:

I disagree. Banks make more than enough money off our money and there's no reason why a proportion of those profits shouldn't be put towards insuring our savings.

If my debit card is cloned and then money is taken from my account the banks will protect me. If my card is stolen and money is then taken from my account the banks will protect me. I don't see any reason why I shouldn't be offered the same sort of protection if I'm a victim of electronic fraud.

As for this case, I don't see why the banks couldn't have flagged a sudden withdrawal in another country as suspicious. I always tell advise my bank before I travel abroad so they know to expect strange transactions (to stop them blocking my card preemptively). Every time I do they thank me but tell me that their fraud protection systems will block suspicious transactions regardless of whether I warn them in advance or not. It sounds to me as if the bank failed to protect this customer.

I disagree. The bank had warned about phishing. The bank had strict guidlines on how to use the TAN codes. There was a phishing warning on the login page. The customer did this with all the warning signs, and whistles anyways. That's not the banks fault, that's on the customer.

When you have your card stolen (physically) it's not your fault, you may not have had any warning, same as if there is a card reader when you enter your card. Those are hidden and very hard to notice (if at all). So comparing phising which is in your face, warnings, etc with something that you don't know/have no prior warning of is a bad comparrison.

#13 rippleman

    Neowinian Senior

  • 2,344 posts
  • Joined: 17-June 09
  • Location: Near Calgary, Alberta
  • OS: Windows 7
  • Phone: Upgraded back to 2 year old iPhone 4 from new Galaxy 2Sx

Posted 26 April 2012 - 12:07

View Postjakem1, on 26 April 2012 - 11:41, said:

I disagree. Banks make more than enough money off our money and there's no reason why a proportion of those profits shouldn't be put towards insuring our savings.

If my debit card is cloned and then money is taken from my account the banks will protect me. If my card is stolen and money is then taken from my account the banks will protect me. I don't see any reason why I shouldn't be offered the same sort of protection if I'm a victim of electronic fraud.

As for this case, I don't see why the banks couldn't have flagged a sudden withdrawal in another country as suspicious. I always tell advise my bank before I travel abroad so they know to expect strange transactions (to stop them blocking my card preemptively). Every time I do they thank me but tell me that their fraud protection systems will block suspicious transactions regardless of whether I warn them in advance or not. It sounds to me as if the bank failed to protect this customer.
ok, since you don't mind, how about i send you a phishing email, you type in your credentials, i scam all your money from the account, then when the bank gives you your money back, i will give you back 1/2 of what i scammed out of your account. sound good? we both win right? silly banks make more then enough money anyways, they won't care /s

#14 jakem1

    Neowinian Wise One

  • 5,440 posts
  • Joined: 17-November 06

Posted 26 April 2012 - 12:12

View Postrippleman, on 26 April 2012 - 12:07, said:

ok, since you don't mind, how about i send you a phishing email, you type in your credentials, i scam all your money from the account, then when the bank gives you your money back, i will give you back 1/2 of what i scammed out of your account. sound good? we both win right? silly banks make more then enough money anyways, they won't care /s

What's to stop us from doing that right now? I clone your card, withdraw money, and then we both share the profit when the bank reimburses you.

If it's OK for the bank to protect you against one type of fraud why not another?

#15 jakem1

    Neowinian Wise One

  • 5,440 posts
  • Joined: 17-November 06

Posted 26 April 2012 - 12:14

View Postfirey, on 26 April 2012 - 12:04, said:

I disagree. The bank had warned about phishing. The bank had strict guidlines on how to use the TAN codes. There was a phishing warning on the login page. The customer did this with all the warning signs, and whistles anyways. That's not the banks fault, that's on the customer.

When you have your card stolen (physically) it's not your fault, you may not have had any warning, same as if there is a card reader when you enter your card. Those are hidden and very hard to notice (if at all). So comparing phising which is in your face, warnings, etc with something that you don't know/have no prior warning of is a bad comparrison.

Banks also provide warnings about the risk of card cloning but will still cover victims of that crime. Again, why the double standard? Why should a warning be enough to absolve the banks of responsibility when fraudsters are basically exploiting loopholes in the banks own security?