Majority Of Internet Users Reuse Online Banking Credentials On Other Websites, Finds Trusteer Report
Published: 03-Feb-2010
Majority of online banking customers reuse their login credentials to access non-financial and much less secure websites, according to a report by Trusteer, the customer protection company for online businesses.
The widespread reuse of online banking credentials is being exploited by criminals who have devised various methods to harvest login credentials from less secure sources, such as webmail and social network websites. Once acquired, these usernames and passwords are tested on financial services sites to commit fraud.
Trusteer found that 73% of bank customers use their online account password to access other websites and that 47% use both their online banking user ID and password to login elsewhere on the internet.
The findings are based on a sample of more than 4 million users of the Rapport browser security service, many of whom are customers of North American and European banks.
Trusteer recommended customers to maintain at least three sets of credentials for financial websites, nonfinancial sensitive websites that hold information about identity and non-sensitive websites that do not maintain confidential information.
Trusteer also recommended financial institutions to identify customers who use their bank login information on nonfinancial websites, educate them to avoid this risk and set risk engine to higher sensitivity for these customers.
Amit Klein, CTO of Trusteer and head of the company’s research organization, said: “Using stolen credentials remains the easiest way for criminals to bypass the security measures implemented by banks to protect their online applications, so we wanted to see how often users repurpose their financial service usernames and passwords. Our findings were very surprising, and reveal that consumers are not aware, or are choosing to ignore, the security implications of reusing their banking credentials on multiple websites.”
Mickey Boodaei, CEO of Trusteer, said: “Being named Innovator of the Year by SC Magazine and having a new category created for our product is an honor and serves as powerful, independent market validation for our approach to securing browser communication and transactions.
“It was gratifying that SC magazine recognized Trusteer for both technical and business innovation. Getting Rapport installed on over three million machines in less than one a year required a creative approach to distribution and almost transparent installation for end-users. It has paid off, Rapport is currently being offered as a free download by more than 50 banks and financial institutions in North America and Europe.”
Trusteer enables online businesses to secure communications with their customers over the internet and protect personally identifiable information (PII) from a user's keyboard into the company's web site.
Rapport from Trusteer is a light weight browser plug-in plus security service that prevents criminals from tampering with a user’s browser and protects against man-in-the-browser, man-in-the-middle, and phishing attacks.
Network Sites

Suppliers To This Sector
Browse A-Z
SecondFloor
Banking and Insurance, Payment Processors and Service Providers ...
Professional Computer Services (PCS)
Banking Software Solutions ...
Prevx
Online Transaction Security and Credential Protection ...
mBlox
The World's Largest Mobile Transaction Network ...
All Media Banking
Solution Development ...
White Papers
Browse A-Z
Use of Voice Biometrics in Smart Card Applications
Many organisations have implemented or are looking into smart card solutions. The objectiv ...
Tower Group Report: Global Exchange Consolidation
This 12-page TowerGroup report analyses the rapidly consolidating exchange market, examine ...
To Protect and Detect: An Evaluation of Compliance System Requirements for the Securities Market
Many financial services firms have been failing to comply with post MiFID Regulations and ...
The Value of Process Management in GRC
In this white paper, the value of Process Management in GRC is discussed. Four main aspect ...
The Value of a Comprehensive Integration Solution
Many enterprises are currently spending more on integration-related projects than they nee ...
The Role of Continuous Controls Monitoring and Auditing in GRC
A business in control is the starting point for most people in business. Without being in ...


Delicious
Digg
LinkedIn
Reddit
Stumble
Viadeo
Mail sent successfully