BEDFORD, Mass. -
But all is not lost, three credit unions and leading multi-factor authentication provider, RSA Security, told the Credit Union Journal.
"Phishing is not going away, and it's not the only challenge," said Chris Young, vice president, consumer solutions at RSA during an exclusive roundtable last month.
"We see trends toward universal man-in-the-middle kits that make it easier for those with less technical acumen to launch their own attacks, phishing delivered through the voice channel, and Trojans delivered unbeknownst to users to collect keystrokes from PCs or redirect users to fraudulent sites," said Young.
"We're very concerned about these new insidious and invisible attacks," he continued. "At least e-mail phishing is visible and you can take action."
The participating credit unions said they have fought back against e-mail-based phishing in the past two years but had not yet fallen victim to the emerging threats identified by RSA.
"Just hope that you're not the one out in front," said Kevin Dougherty, senior vice president, Information Services at $1.1-billion CFE FCU in Orlando, Fla.
Credit unions are directly in the path of the storm, Dougherty continued.
"More than ever, phishers see us as low-hanging fruit," he asserted. "The constant attacks are putting a strain on credit unions."
Last fall, RSA shut down 24 phishing sites after a "nasty" email-based phishing attack against CFE, Dougherty said.
"It was quite an eye-opener," said Dougherty, who said the CFE battled another, lesser attack just last month.
"Managing phishing is a resource issue," he explained. "It's so burdensome on my network department. I spend 15% of my time responding to security audits. I don't know how smaller credit unions are going to handle the oncoming threats, in addition to the audits, authentication tools and take-down services."
After four direct phishing attacks and one significant false positive in the past two years, Stanford Federal Credit Union in Palo Alto, Calif. is also feeling the strain, said Andrew Voorhies, technology operations manager at the $700-million credit union.
"We're stretched on resources to fight these issues, and there is a need to have more dedicated personnel," he said.
Still, the phishers won't win, Young said.
"Like all fraud, phishing can be managed," he said. "We're very close to not having to worry. Within a year or two we'll really be able to react well to threats."
"It all comes back to education," Dougherty suggested. "Credit unions need to do a better job of educating our members. And the media has to publish education."
Education is tricky, Dougherty said. "There's only so much space, and it's expensive, whether you're using quarterly newsletters or you're face-to-face with members."
RSA recommends marketing security as a benefit to the member.
"Security doesn't have to be a liability," Young said.
CFE will soon hire a dedicated security officer, said Dougherty. And all three credit unions said they expect every employee to join the anti-fraud effort and lighten the load for the technical teams.
"We're spreading the wealth to more than a few employees by training all staff in how to beware of social engineering," added Voorhies.
The Technology Credit Union website boasts an "extensive" security section from which members can use a secure email form to report phishing attempts, offered Victor Smilgys, assistant vice president, eCommerce, at the $1.3-billion credit union in San Jose, Calif.
And soon, the credit union's voice response system will authenticate users, he said.
In addition, the credit unions are thinking twice about what they publish to their websites.
"We used to load every bit of information onto our website," said Dougherty. "We announced our recent credit card upgrade at the site, and phishers used it against us. That made us change our business model about what we put out on the website."
Likewise, upon a recent equipment move, Stanford Federal Credit Union was "very cautious about what we said on our website about downtime and unavailability of phone and online banking," Voorhies explained.
In a move to take advantage of reconnaissance that can be gleaned from friendly, underground moles, RSA will release an intelligence service this summer, Young said.











