Access member only content, take part in discussions with comments on blogs, news and reviews and receive all the latest security industry news directly to your inbox. Join now for free.
A confirmation email has been sent to your email address - SUPPLIED EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @scmagazine.com.au to your white-listed senders.
(Update) The online banking statements of ANZ Bank customers are vulnerable to access via identity thieves, SC Magazine can reveal.
Bank statements viewed online remain stored permanently in browser histories.
Because the statements are not tied to specific browser sessions and do not expire, identity thieves could plunder troves of statements stored in browser histories if using public terminals.
SC informed the bank of the vulnerability more than a week in advance of the publication of this story to allow it time to act on the flaw.
The banks' outsourcer Salmat referred the matter to ANZ.
It said later that it was working with ANZ Bank to resolve the security issue.
"This security issue is not a flaw or breakdown in Salmat systems or processes," a spokesman said."Salmat can confirm that there is no associated security risk for any other bank or creditunion using a Salmat system for bank statements."
A spokesman for the ANZ said the bank was "aware of the issue" and claimed that while the issue was "not specific to ANZ", it was "looking at ways to further improve security".
Customers could mitigate expose to the flaw by wiping browser histories when using shared computer terminals.
Checks on Westpac, Commonwealth Bank, St George, NAB and a number of credit unions and smaller banks found they were not vulnerable to the same flaw.
This method of identity theft would be an order of magnitude more efficient than swiping statements from mail boxes.
Bank statements, when in the wrong hands, provide the account details, name, address and offer an indication of a victim's financial status.
Thieves use this information to con and steal money from individuals and institutions. SC recently detailed how scammers stole $45,000 from one man by leveraging similar information to launch social engineering attacks.
Identity theft is also used to conduct tax return and superannuation fraud.
Copyright © SC Magazine, Australia
To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.