ICICI Bank says mobile app malware not a threat to customers

The malware is distributed through a fake flash player app and can ultimately trick the user into sharing his/her login details and password for any of the 232 applications, if they are present on the device.

January 13, 2018 12:11 pm | Updated 12:11 pm IST - Mumbai

 File photo: Chanda Kochhar, Managing Director and CEO, ICICI Bank, at the launch of "Pockets", ICICI's digital bank on mobile phone, in Mumbai on February 10, 2015.

File photo: Chanda Kochhar, Managing Director and CEO, ICICI Bank, at the launch of "Pockets", ICICI's digital bank on mobile phone, in Mumbai on February 10, 2015.

Days after a cyber security firm warned of mobile applications being breached by a malware attack, ICICI Bank on Saturday said that there is no “significant” threat to its customers.

“Whatever we have seen, the malware seems to be not very significant,” bank’s chief technology and digital officer B. Madhivanan told reporters over a conference call.

Quickheal, a Pune-based cyber security firm, had warned lenders of the presence of a malware in the mobile banking apps running on the popular operating system, Android.

“Anyone who wants to sell their anti-malware kind of products, they have the right to continuously test and bring it in,” Madhivanan said, retorting to the warning from the anti-virus maker last week.

According to media reports, Quickheal had spotted a malware that imitates over 200 apps, including some offered by some of the domestic banks.

The malware is distributed through a fake flash player app and can ultimately trick the user into sharing his/her login details and password for any of the 232 applications, if they are present on the device.

The cyber security firm asked users not to download any apps from third-party stores or links provided in SMSes/emails to keep their credentials safe, according to media reports.

“There is always somebody or the other who is trying to attack, and that’s how this entire world of cyber criminals works. But given the multilevel securities that we have put in place, we believe we are extremely capable of defending it within our entire financial structure,” Madhivanan said.

He asserted that in its ten-year history, the bank’s mobile banking, which was the first such application to be launched by any bank, has not “had even one single incident of a technical breach” which harmed customers.

The incidents which have been faced are due to “social re-engineering”, rather than “technical” faults, he claimed.

“Our bigger worry has never been on the technical security part. It’s always been on social engineering fraud, where customers are giving away some of this data where they are cheated by someone masquerading as an Aadhaar person or a telecom person,” he said.

To check and avoid any mishaps, the bank has a strong security architecture which consists of a chief security officer, two network operation centres and a security operation centre, he said.

The bank has 8 million customers using its mobile app, which is growing fast, he said, adding mobile transactions now account for half of its overall digital transactions and will soon be overtaking internet banking.

“Growth of mobile transactions is much faster than the incremental transactions through the internet. We expect mobile transactions to overtake it and become the new standard when it comes to banking transaction,” he said.

In FY17, ICICI handled ₹2.4 trillion worth of transactions through mobile banking, which hit Rs 3.1 trillion by October 2017.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.