PROJECT REPORT
ON
INVESTIGATINGS AND REPORTINGS OF DIGITAL FRAUDS
SUBMITTED BY :- VISHWARANJAN KUMAR
SUBMITTED TO :- STATE BANK OF INDIA
COURSE :- [Link] ( banking and finance)
Roll no :- 3230420
Institute : Central university of Jammu
DIGITAL FRAUDS
Digital fraud happens when someone uses a computer or other
device with access to the internet to deceive or abuse web-
enabled assets, usually for financial gain. There are many types of
digital fraud—from click fraud to card cracking to account
takeover fraud—and the most large-scale fraud attacks use some
type of automation to make bots do all the work.
Types of digital frauds
1. Phishing and spoofing: The use of email and online
messaging services to dupe victims into sharing
personal data, login credentials, and financial
details.
2. Data breach: Stealing confidential, protected, or
sensitive data from a secure location and moving it
into an untrusted environment. This includes data
being stolen from users and organizations.
3. Denial of service (DoS): Interrupting access of
traffic to an online service, system, or network to
cause malicious intent.
4. Malware: The use of malicious software to damage
or disable users’ devices or steal personal and
sensitive data.
5. Ransomware: A type of malware that prevents
users from accessing critical data then demanding
payment in the promise of restoring
access. Ransomware is typically delivered via
phishing attacks.
6. Business email compromise (BEC): A sophisticated
form of attack targeting businesses that frequently
make wire payments. It compromises legitimate
email accounts through social engineering
techniques to submit unauthorized payments.
T
INVESTIGATIONS OF BANK FRAUD
A bank fraud investigation is an internal process conducted by the bank
that is designed to determine if a fraudulent claim—or suspicious activity—
is fraudulent or not. The purpose is to identify and understand the fraud
threats the bank is facing, as well as determine strategies for prevention.
How Does a Bank Fraud Investigation Work?
The bank is either alerted of potential fraud from a customer that has been
victimized or from an alert on their fraud detection system. Typically, the bank has a
team of investigators responsible for investigating suspicious activity that comes
up.
At a high-level, it involves detecting instances of potential fraud and escalating
these cases to investigators who can determine whether it was fraud and, ideally,
what type of fraud has occurred and how. Finally, the bank will take action on the
case, by reimbursing the client, charging the merchant, or pursuing the fraudster to
recover losse.
Who Investigates Bank Fraud?
First and foremost, bank fraud investigations are the
responsibility of the bank itself. The bank investigates
fraud claims and suspicious activity and then
determines if the suspicious activity amounts to fraud.
From there, the bank will submit a Suspicious Activity
Report (SAR), which will be escalated to the proper
legal authority.
PROCESS OF REPORTING DIGITAL FRAUDS
• Contact the Federal Trade Commission (FTC) online at [Link] or
call 1-877-438-4338.
• Ask the three major credit reporting agencies to place fraud alerts and a
credit freeze on your accounts.
• Contact the fraud department at your credit card issuers, bank, and other
places where you have accounts.
• Submit an anonymous tip online.
• File a report with the Internet Crime Complaint Center (IC3) as soon as
possible.
• Contact your local FBI field office.
• Contact local police in case of an emergency or for reporting crimes other
than cyber crimes.
Digital Fraud Examples
Digital fraud isn’t disappearing anytime soon. We often see fraudsters cycle
through different attacks and switch up their tactics in response to fraud
detection systems. Some common examples of digital fraud include the
following:
• Account Takeover – Attackers hijack customer accounts to drain bank
accounts, apply for credit, steal personal information, and make
unauthorized purchases.
• Brand Abuse – Fake emails, websites, and messages that trick victims
into sharing login credentials or other personal information with the
attacker.
• Card-Not-Present (CNP) Fraud – Unauthorized purchases made with
credit card information without the cardholder’s knowledge.
• Chargeback Fraud – When a legitimate customer makes a purchase
with the sole intent of issuing a chargeback—keeping their money and
the product.
• Cryptocurrency Fraud – Attackers target exchanges to steal crypto or
create fake projects in order to cashing out user investments before
anyone can make a profit.
• Rogue Mobile Apps – Fake apps that impersonate brands to steal card
or account information from customers.
Ways to Detect & Prevent Fraud in Banking
1. Watch for Internal Fraud
Research published on Clari5 indicating that 70% of banking fraud is
successful because of insiders, it’s more obvious than ever that
monitoring internal fraud should be a top priority.
2. Educate Your Customers
Making customers aware of the risks they face, what to look out for, and safe
transaction tips is a sure way to reduce fraud risks like ATOs. Even more so,
this strategy makes your customers trust your bank more.
3. Monitor Transactions
, transaction monitoring to prevent money laundering and terrorism financing
is a requirement, and includes filing suspicious activity reports when
something is amiss.
keeping an eye on how customers use the website or app of a fintech or
traditional institution can go a long way not just to avoid fines and be
compliant but to detect and investigate potential cases of fraud.
4. Use Real-Time Data Enrichment Tools
As the name should suggest, real-time data enrichment enhances customers’
KYC data with aggregated extra data obtained from various sources such as
open-source databases, digital services, and social networks.
Device Fingerprinting
This module exposes suspicious configuration and activity on the device a customer
used to connect to your site. It helps you answer questions such as:
• Has the user connected with this device before?
• What kind of browser did the customer use?
• Is the user’s device a mobile or desktop?
• What operating system are they using
types of banking frauds in
India customers
1. Frauds using online sales platforms
On online sales platforms, fraudsters pose as purchasers and
express an interest in the seller's product(s). several fraudsters
pose as defence personnel stationed in remote regions to gain
trust.
Instead of paying the seller, they use the Unified Payments
Interface (UPI) app's "request money" option and demand that the
seller authorise the request by entering the UPI PIN. Money is
transferred to the fraudster's account whenever the seller inputs the
PIN.
2. Frauds due to the use of
unknown/unverified mobile apps
According to RBI, fraudsters circulate through SMS, email, social
media, Instant Messenger, etc., certain app links, masked to
appear similar to the existing apps of authorised entities.
Fraudsters trick the customer to click on such links which
results in downloading of unknown / unverified apps on the
customer’s mobile, laptop, desktop, etc.,
3. ATM card skimming
Skimming devices are installed in ATM machines by fraudsters who
take data from the customer's card. According to the RBI release,
“Fraudsters may also install a dummy keypad or a small / pinhole
camera, well-hidden from plain sight to capture ATM PIN. ?
Sometimes, fraudsters pretending to be other customer standing
near-by gain access to the PIN when the customer enters it in an
ATM machine. This data is then used to create a duplicate card and
withdraw money ..
4. Frauds using screen sharing app / Remote
access
RBI warns customers stating the procedure that “Fraudsters
trick the customer to download a screen-sharing app. Using
such an app, the fraudsters can watch/control the customer’s
mobile / laptop and gain access to the financial credentials of
the customer. Fraudsters use this information to carry out
unauthorised transfer of funds or make payments using the
customer’s Internet banking/payment apps.”
THANKS YOU