Alex Walia
  • Home
  • Finance
  • Gadgets
  • Mobile
  • Recruitment
  • Trading
  • Travel

What are you looking for?

  • Home
  • Finance
  • Gadgets
  • Mobile
  • Recruitment
  • Trading
  • Travel
Alex Walia
  • Home
  • Finance
  • Gadgets
  • Mobile
  • Recruitment
  • Trading
  • Travel

What are you looking for?

  • Home
  • Finance
  • Gadgets
  • Mobile
  • Recruitment
  • Trading
  • Travel
Mobile

Getting ahead of the curve on mitigating mobile fraud

Alex Walia
July 25, 2025
5 Min Read


Table Of Content

  • Lessons to be learned – from mobile to bank accounts
  • Security as a partnership
  • Security assurance even in unsafe environments

Ralitsa Miteva, manager of digital identity and mobile security at OneSpan, discusses how organisations can get ahead of the curve on mitigating mobile fraud threats

In a digital world, we use our mobile devices more often than ever before, especially in communicating with financial services and managing our bank accounts remotely. In the UK, banking customers are becoming more reliant on mobile channels for their financial needs – to put it in perspective, data from Statista shows that in 2008 only 38% of Brits used online and mobile banking – in 2021, this figure sky-rocketed to 80%. Last year, UK Finance reported that the rise in mobile fraud directly corresponds to the shift towards mobile banking. It’s a lucrative channel for cyber criminals, which will not change in 2022.

Recently, researchers observed additional evidence that mobile banking apps are an extremely enticing target for fraudsters. The researchers uncovered that bad actors adapted their techniques to find new ways around Google Play Store restrictions. Seemingly harmless ‘dropper’ apps remained not dangerous for months until they could slowly be updated with malicious code. Due to the slow-burning nature of these attacks, simple anti-virus scans would not identify the threat. Once ready, fraudsters would use the code to download apps without the user’s permission and ultimately download Android banking trojans.

As Google continues to update how it polices apps on its Play Store, financial institutions (FIs) must expect mobile fraud campaigns to continue to evolve and slip through the net despite Google’s good intentions. It’s crucial to understand that security is never a point in time. However, the security hygiene of a user’s device can change over time. In this case, before the dropper app downloaded the malicious payload, it’s possible to assume the device was secure. So, let’s look at exactly how these attacks occurred, what they did, and how banks can get ahead to mitigate similar future attacks on their customers.

The more mobile advertising changes, the more it stays the same

Darren Walsh, head of programmatic demand at InMobi, discusses why in-app advertising continues to be impactful, relevant and resilient, despite the decline of third-party identifiers like IDFA. Read here

Lessons to be learned – from mobile to bank accounts

Mobile applications are created through hundreds, if not thousands, of lines of code, so ultimately, Google Play automates a lot of the scans to detect malicious code for thousands of apps daily. We’re now seeing that these apps being used to infiltrate app stores have some functionality and appear safe by misleading detection scans until cyber criminals deploy the attack.

Once malicious code has been uploaded, attackers can easily trick users by prompting them to download an update to the app from an unknown or third-party source.

The update enables cyber criminals to abuse accessibility settings – designed to simplify phone usage for people with disabilities – to automate mobile device functions for fraud. Some of these malicious applications have allowed fraudsters to abuse these settings to conduct overlay attacks and embed keyloggers so they can steal usernames and passwords or execute lines of code to steal personal data. To get ahead of these threats, it’ll mean different sectors need to be proactive regarding mobile app security.

Security as a partnership

Google and the other app store providers will continuously review their security procedures to make their platforms and devices more secure. But big tech companies like Google have to deal with so many new apps and updates constantly that it’s inevitable that many malicious apps may find their way onto the store.

For a long time, too, there has been a case to educate customers about the threats they face. Banks make noticeable efforts to warn customers about potential threats like clicking suspicious links via SMS or email or not downloading anything to their device from an untrusted source.

But the truth is, inevitably, someone will make a mistake as fraudsters use various techniques to gain a user’s trust. With apps seeming completely harmless, it’s all too easy for precisely this to happen. By the time banks warn their customers about specific threats, the likelihood is that fraudsters are already evolving beyond those techniques, finding new ways to fool their unsuspecting victims.

Even with big tech companies proactively updating security requirements for their app stores and collectively educating customers, advanced security technologies are essential to filling the gap and mitigating potentially fraudulent activity – whether it’s a known or unknown threat.

How financial services companies are gaining value from cloud adoption

Ben Walker, partner and founder at Airwalk Reply, and Matt Mould, partner at Storm Reply, spoke to Information Age about how financial service organisations are gaining value from cloud adoption. Read here

Security assurance even in unsafe environments

Banks and FIs have no control over what their users do on their mobile devices outside their applications. So, the first step to securing mobile banking applications is to assume that apps are continuously operating in unsafe environments. Without this approach, security is implicitly being outsourced to big tech companies. However, customers will still expect their bank to protect the money in their accounts.

To mitigate these types of attacks, banking applications must deploy technology that can identify any malicious activity or interference with a mobile application before funds can be stolen – even when previously unseen threats have targeted customers. App shielding combined with strong customer authentication can mitigate password theft and ensure the integrity of an app’s runtime environment to detect malicious interference with the app and shut it down, even on infected devices.

App shielding ensures strong security against unknown threats on untrusted devices, but the security mechanisms they rely on have little to no impact on the user experience.

When discussing fraudsters’ latest techniques to commit fraud, they’re already planning and innovating for their next campaign. Over the next year, researchers will continue to document new threats and techniques, but mitigating the damage that these future threats can cause means implementing advanced technologies – capable of identifying and preventing new threats as and when they emerge.

Written by Ralitsa Miteva, manager of digital identity and mobile security at OneSpan



Source link

Last Update: July 25, 2025

Please share this article if you like it!

Link Copied!

Other Articles

Previous

Bank fraud reimbursement limit set to be slashed by thousands under new plans | Personal Finance | Finance

Next

5 airport scams as experts are warning travellers

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Find Us on Social

Dribbble
pinterest
Instagram
Youtube

Featured Items

West Midlands financial director jailed after using company credit cards to fund luxury lifestyle and Disney World holiday
August 2, 2025
Norton adds deepfake protection to mobile apps in push to make sure you don’t get caught out by scams
August 2, 2025
Essex Trading Standards issue warning over Basildon scam
August 2, 2025
Man from Mangaluru duped of Rs 22 lakh in online investment scam
August 2, 2025

Technology

Mangaluru man loses over Rs 22 lac in elaborate online trading scam
Alex Walia
2 Min Read
Asisa reports a rise in insurance fraud cases despite reduced losses
Alex Walia
3 Min Read
‘It takes over your life’: Fraud cases up 33 per cent as AI, crypto and social media increase risk for millions of victims
Alex Walia
6 Min Read

Related Posts

Mobile

Telecoms fraud losses over R5bn

3 Min Read
Mobile

Nearly 8% of Ghanaians scammed via mobile phones ended up sending money to fraudsters – World Bank

2 Min Read
Mobile

Thieves ‘shoulder surfing’ victims to steal phones

4 Min Read

Editor's Pick

Woman arrested for railway job scam | Thiruvananthapuram News
July 26, 2025
How well does YOUR bank protect you from mobile and online fraud?
July 26, 2025

Recent Posts

The Ultimate Guide to Review Gadgets in 2025
July 24, 2025
Telecoms fraud losses over R5bn
July 24, 2025

Categories

Finance
Gadgets
Mobile
Recruitment
Trading
Travel
Copyright © 2025
  • Contact
  • Privacy Policy
  • Terms and Conditions