Mobile banking apps are holding data insecurely

“Systemic problems” could allow an attacker to manipulate data, take over accounts and commit fraud

mobile banking

Research into a host of mobile banking apps has revealed alarming security fallibilities that could pave the way for cyber criminals to access highly sensitive financial data.

Systemic problems in the financial sector's approach to designing security into mobile banking applications have left glaring holes, spanning from weak encryption standards to data leakage.

Researchers on behalf of Arxan Technologies highlighted 11 types of vulnerability found across 30 Android apps from all flavours of financial institutions across Europe and the US, with a total of 180 critical vulnerabilities discovered.

Advertisement - Article continues below

These, if exploited by an attacker, could lead to identity theft, and account fraud, among other dire consequences.

"When a company fails to implement proper application security technology for its app, it opens up the app to be easily reverse-engineered, potentially leading to account takeovers, data spills, and fraud," said researcher Alissa Valentina Knight.

"As a result, the company could experience significant financial losses and damage to brand, customer loyalty, and shareholder confidence as well as government penalties.

"While the findings in this report are specific to these companies, many of them are systemic across all of the mobile apps tested, and other types of companies should use them as a guide for securing their mobile apps."

Advertisement
Advertisement - Article continues below

The names of the banking apps in which vulnerabilities were detected have were redacted, presumably for fear that these companies will subsequently be targeted by malicious actors.

Retail banking apps were found to harbour the greatest number of critical vulnerabilities, while US-based health savings account (HSA) companies were the least exploitable. Also, to the researcher's surprise, smaller companies had the most secure development hygiene, while larger companies produced the most vulnerable apps.

Advertisement - Article continues below

The most common vulnerability type was a lack of binary protections, with 97% of apps tested being possible to decompile and review the source code. Moreover, all apps tested failed to implement application security to obfuscate the source code.

Meanwhile, 90% of applications tested engaged in unintended data leakage, with data from the mobile banking app inadvertently made available to other apps on a user's device. This, for instance, could lead an attack to harvest financial data through other apps they have control over on a device.

Additionally, 80% of apps implemented weak encryption algorithms or the incorrect implementation of a strong cipher. Adversaries could, by exploiting this, decrypt sensitive data into its original form and either manipulate or sell this on.

The most worrying finding, however, was that 83% of apps tested stored users' sensitive data insecurely in the first place. Financial data was stored outside of a sandbox and in the device's local file system, external storage, or even copied to the clipboard, according to Knight.

To remedy these issues, she recommended that financial companies adopt a comprehensive approach to security, and employ a number of technologies such as app shielding, encryption and threat analytics.

Featured Resources

Top 5 challenges of migrating applications to the cloud

Explore how VMware Cloud on AWS helps to address common cloud migration challenges

Download now

3 reasons why now is the time to rethink your network

Changing requirements call for new solutions

Download now

All-flash buyer’s guide

Tips for evaluating Solid-State Arrays

Download now

Enabling enterprise machine and deep learning with intelligent storage

The power of AI can only be realised through efficient and performant delivery of data

Download now
Advertisement

Recommended

Visit/security/vulnerability/355236/hp-support-assistant-flaws-leave-windows-devices-open-to-attack
vulnerability

HP Support Assistant flaws leave Windows devices open to attack

6 Apr 2020
Visit/security/cyber-security/355234/safari-bug-let-hackers-access-cameras-on-iphones-and-macs
cyber security

Safari bug let hackers access cameras on iPhones and Macs

6 Apr 2020
Visit/software/video-conferencing/355229/zoom-we-moved-too-fast
video conferencing

Zoom CEO admits company "moved too fast" as privacy issues mount

6 Apr 2020
Visit/security/internet-security/355228/mozilla-fixes-two-firefox-zero-days-being-actively-exploited
internet security

Mozilla fixes two Firefox zero-days being actively exploited

6 Apr 2020

Most Popular

Visit/mobile/mobile-phones/355239/microsofts-patent-design-reveals-a-mobile-device-with-a-third-screen
Mobile Phones

Microsoft patents a mobile device with a third screen

6 Apr 2020
Visit/development/application-programming-interface-api/355192/apple-buys-dark-sky-weather-app-and-leaves
application programming interface (API)

Apple buys Dark Sky weather app and leaves Android users in the cold

1 Apr 2020
Visit/software/video-conferencing/355229/zoom-we-moved-too-fast
video conferencing

Zoom CEO admits company "moved too fast" as privacy issues mount

6 Apr 2020