Hong Kong banks have been ordered to step up online security measures after it emerged that thieves had stolen more than 289,000 Hong Kong dollars (37,000 US dollars) in a series of Internet bank raids, officials confirmed Tuesday.
The Hong Kong Monetary Authority (HKMA) said the money was stolen in three separate incidents in which people’s accounts were accessed by thieves who first infected their computers with viruses that stole bank account login details.
Eight banks have been targeted since April, according to a report in the South China Morning Post.
In a statement, the HKMA confirmed it had issued a circular ordering all banks to step up security measures, such as instantly alerting customers by text message or other means every time an online transfer to a third-party is made from their accounts.
According to the authority, thieves are using increasingly sophisticated measures to raid bank accounts.
It said the recent cases involved infecting bank customers’ personal computers with a Trojan horse virus that hijacks user names and passwords.
These details were then used to transfer funds to third-party accounts.
An HKMA spokesman strongly encouraged bank customers to make full use of the text messaging alert system and to notify their bank immediately if they discover any suspected unauthorized transactions.
“We believe that, so long as customers and banks have taken appropriate security precautions, Internet banking services with adoption of two-factor authentication are safe to use.”
Computer security expert Roy Ko, manager of the Hong Kong Computer Emergency Response Team Co-ordination Centre, warned that the onus was now on customers who bank on line to protect their accounts.
“The banks have already adopted security measures like two-factor authentication. The key issue now is whether the customers’ computers are clear [of viruses],” Ko told the South China Morning Post.
“If they’ve been infected, it’s like they are leaving their front doors…