Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

January 11th, 2011, 18:52 GMT · By

Australian Bank Call Center Staff Easy to Socially Engineer

SHARE:

Adjust text size:


Bank call center operators vulnerable to social engineering
Enlarge picture
A study performed by a customer experience research firm revealed that many call center operators from Australian banks can be tricked into helping callers obtain information about other people's accounts.

For their benchmark, the company, called Global Reviews, made twenty calls to the customer service hotlines of eight Australian banks, including the largest ones.

The social engineering tricks used by the callers varied, but they generally posed as people who need to urgently access the account of their friend, partner, spouse or lover.

At first, their requests were declined, but when they insisted and explained the gravity of their supposed situation, many staffers loosened up and agreed to help to various extents.

"The callers would say things like, my girlfriend needs to transfer money today. She's gone to work. I have to do it for her. She'll kill me when I come home tonight," Global Reviews Managing Director Peter Grist told The Sydney Morning Herald.

"Half the time after saying no, the call centre staff would work with the caller to find out ways to do it," he added.

Sometimes this involved guiding them to access the account over the Internet and revealing details such as date of birth or account number.

According to the company, staffers from ANZ Bank, one of Australia's "big four," proved more reluctant to help callers than operators from other banks.

Taking this bank out of the equation, the percentage of call center operators ready to help people access someone else's account is around two thirds. The banks expressed surprise when seeing the results of the study.

"They weren't trying to be fraudulent. They knew the rules. But human beings like to help. And not just in banks. I think it would be the same in any industry," Mr. Grist concluded.

This is very true and can be seen each year during the Social Engineering Contest at the DEF CON hacking conference, where hackers fight over who can obtain more information about large companies by speaking on the phone with their employees.

TELL US WHAT YOU THINK:

1,113 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Owner of Call Service Used by Fraudsters Extradited to US

Vishing Attacks Target Regional Banks and Credit Unions

Many Corrupt Ukrainian Bank Workers Assist Cyber Criminals

Vishing Attacks on the Rise

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM