ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Security calamity shakes US banks

Will Knight ZDNet.co.uk

Published: 25 Sep 2000 09:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A UK-based computer expert has reported breaching security at some of the biggest Internet banks in America, gaining control of thousands of personal bank accounts.

In the most serious Internet security incident to hit financial companies yet, Ralph Dressel, a software engineer with the Royal Skandia Investment bank, told the Observer that he was able to transfer funds and alter PIN numbers belonging to whole databases of unknown users.

Dressel says he gained access to these accounts after stumbling across an access log at the Web site belonging to Fiserv, the software firm which provides the banking software for many US banks. Dressel contacted the FBI along with police in Britain and informed the national press in Britain in order to publicise the security incident. Lots of banks worldwide use Fiserv software, including the UK's Abbey National.

Prudential's online bank Egg also uses Friserv banking software although this is not accessible via the public Internet and so was not exposed by this incident. According to Egg's chief technical officer Pete Marsden this dire exposure of bank details demonstrates the importance of auditing not just internal security. "A third party's security has to be as strong as your own. Any online organisation has to make sure of this," he says.

Senior security analyst with Information Risk Management Richard Stagg agrees that this should be standard security procedure. "Quite often you will find companies that want to be secure are let down by outsourcers," he says. "You're only as secure as your weakest link."

Fiserv estimates that its software is used to control 200 million accounts online and $15bn (£9.3bn) of customers' money. This enormous security breach overshadows most other recent security incidents and will undoubtedly confirm fears over Internet banking security sparked by more minor mishaps. Last month, Prudential's Internet bank Egg was last month the target of fraud and Barclays bank accidentally allowed customers to gain access to other users' accounts.

Are Internet banks a security risk? To have your say online click on the TalkBack button and go to the ZDNet News forum.

Let the editors know what you think in the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
24 out of 74 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Technical Consultant, Wholesale Banking Payment, Swift, AIX, Watford

This is an application focussed role & your responsibilities will be to install, configure & set-up these Wholesales Banking Payment systems for my ...

Helpdesk Analyst (Active Directory tools,Reuters,Bloomberg) BANKING

Leading Investment Bank is looking to hire a Senior 1st line Helpdesk Support Analyst to join its vibrant BANKING team.The ideal candidate MUST have ...

Senior Project Manager Global Banking and Markets London

The programme is one of the most high profile initiatives within the bank and will fundamentally re-define the bank process and remain a key part of ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment