
This article first appeared in The Edge Malaysia Weekly on October 10, 2022 - October 16, 2022
BANKS are increasingly exposed to cybercrimes and this makes them susceptible to credit rating downgrades, experts warn, urging for more industry-wide collaboration and cross-border information to strengthen cybersecurity.
Collaboration among industry participants is “extremely helpful” in reducing system-wide risks, says S&P Global Ratings.
“There is a need for collaboration and cross-border information sharing to build cyber resilience. Regulators are key to setting standards for banks and guiding them towards collaboration,” its Sydney-based banking analyst, Nico DeLange, tells The Edge.
Regulators can focus on industry partnerships, pilot projects, sharing of best practices and the like, he says.
DeLange notes that the Covid-19 pandemic in recent years, which resulted in banking moving increasingly online, has pushed up the risks of cyberattacks.
“Attacks on banks are evolving and becoming more sophisticated, frequent and coordinated. Attackers rely on modern technology to target weaknesses,” he says.
His comments follow a recent S&P Global report which notes that while banks in the Asia-Pacific region are “reasonably prepared” to manage such risks, they could be badly damaged in the event of an attack, both monetarily and in terms of reputation.
An attack could also pose risks to the stability of the entire banking system.
“A successful attack may pose systemic risks. The highly concentrated markets of Hong Kong, Singapore and Australia are particularly vulnerable. An incursion that disrupts the operations of one large player in these markets could seriously unsettle the normal business of banks and their customers,” the report, which DeLange co-authors, states.
“In jurisdictions where the entire industry incurs repeated, serious data breaches, or where regulators are particularly lax, we may downgrade our rating scores on all banks,” it adds.
S&P Global says that thus far, it has not downgraded any Asia-Pacific bank as the result of a cyberattack. “However, the hit to individual institutions could be crippling. This could be particularly true for banks that have not invested enough in their cybersecurity,” it warns.
Over in Malaysia, cybercrime has become a hot topic of late given rising incidences of financial scams. Just two weeks ago, Bank Negara Malaysia governor Tan Sri Nor Shamsiah Mohd Yunus revealed that financial institutions had been directed to be more responsive to scam reports lodged by customers.
“Financial institutions have also been directed to facilitate efforts to recover and protect stolen funds, including to work with relevant agencies to prevent further losses,” she said, in announcing a slew of additional measures for banks to take to strengthen safeguards against financial scams.
Among the latest measures is requiring lenders to migrate from SMS one-time passwords (OTPs) to more secure forms of authentication for online activities or transactions relating to account opening, fund transfers and payments, as well as changes to personal information and account settings.
Since announcing those measures, a slew of banks, including Malayan Banking Bhd (Maybank), AmBank Bhd and RHB Bank Bhd, have issued statements highlighting how they have increased their digital security.
In August, iPay88, one of the largest online payment providers in Malaysia, admitted that it had experienced a cybersecurity breach which may have compromised the card data of users. It said an investigation was initiated on May 31 and that the containment process was successfully completed with no further suspicious activity detected since July 20.
Many, including politicians, came out to question why iPay88 only released information on the data breach more than two months after the incident.
Bank Negara had said the breach originated from, and was confined, to iPay88’s payment card systems and did not involve vulnerabilities in the banks’ systems.
Last Friday, the central bank issued an update on the matter, saying that following the completion of the independent forensic investigation, iPay88 has taken the necessary containment and rectification measures to address gaps that had been identified. It also said it had instructed iPay88 to undertake additional measures to ensure similar incidents do not recur in future.
Recently, Maybank and several other banks alerted customers to an advisory by the Malaysia Computer Emergency Response Team (MyCert) about a fraud campaign, known as SMSSpy, in which cybercriminals were using Android malware to steal victims’ online banking credentials in Malaysia.
Even the police have been speaking out more to warn the public about cybercrimes.
Inspector-General of Police Tan Sri Acryl Sani Abdullah Sani recently announced that a total of 12,092 online fraud cases involving losses amounting to RM414.8 million were reported in the country from January to July this year.
He also revealed that, from 2019 to July this year, 33,147 suspects in cyberfraud cases had been arrested, with 22,196 cases charged in court.
“The ability of cybercriminals to exploit technological changes and creatively trap victims with a variety of new modus operandi, paired with the moderate level of public awareness on cybercrime, are among reasons for increasing cases,” he said.
Bank Negara Malaysia, which last week released its financial stability review for the first half of 2022, highlights that cyber resilience will be a high priority for financial institutions.
“Enhancing the financial industry’s capacity to recover from various operational incidents remains our top priority. Some of these efforts include simulated live tests to ensure the practical ability of financial institutions and payment system operators to execute cyber incident response plans effectively,” governor Nor Shamsiah said.
She said the central bank is coordinating efforts with the industry, Royal Malaysia Police and the Malaysian Communications and Multimedia Commission to further improve fraud incident response and recovery efforts, and educate the public on using digital financial services safely.
Save by subscribing to us for your print and/or digital copy.
P/S: The Edge is also available on Apple's App Store and Android's Google Play.