Feeds

BoI to refund phishing victims

Compensation u-turn

Choosing a cloud hosting partner with confidence

Bank of Ireland has agreed to compensate victims of a recent phishing scam, backtracking from its earlier position.

The bank had initially refused to refund victims, who lost about €160,000 to scammers after receiving the fake emails. However, reports in the Irish Independent on Tuesday indicate that the bank has since had a change of heart.

For its part Bank of Ireland has refused to comment on the cases, releasing a general statement on phishing instead.

"Bank of Ireland is aware that there are fraudulent emails being circulated purporting to be from Bank of Ireland 365 online," it said. "Bank of Ireland can not discuss individual cases where a customer has received and responded to such an email."

It seems the banks just can't win. The nine customers who were conned out of the cash had threatened to sue the bank for compensation if their money wasn't returned. But now experts fear that there could be a surge in phishing cases, encouraged by the compensation paid out by Bank of Ireland.

Conor Flynn, technical director of Rits, said the move was essentially a goodwill gesture by the bank. However, he warned that people may feel less threatened by the scams in future as a result.

"It certainly will not help things," he said, speaking with ENN. "People will feel they have a buffer of security."

However, he also pointed out that banks may implement more technologies that will push the responsibility back on to the customers to safeguard their details and prove that they didn't reveal their confidential details to a third party.

"It's not a victimless crime," Flynn pointed out. "Banks still have to record record-profits. If they lose cash through compensating phishing victims, bank customers will pay."

However, despite the high profile coverage, phishing is not a unique problem to Bank of Ireland, something the bank is keen to point out.

"This problem is not unique to Bank of Ireland and similar fraudulent emails purporting to come from other banks, credit card companies, e-retailers etc are also in circulation," Bank of Ireland said in its statement.

Other financial institutions have warned customers of other phishing scams, including AIB and internet bank RaboDirect. eBay is also a popular target for scammers.

Copyright © 2006, ENN

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Why did it take antivirus giants YEARS to drill into super-scary Regin? Symantec responds...
FYI this isn't just going to target Windows, Linux and OS X fans
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
prev story

Whitepapers

Driving business with continuous operational intelligence
Introducing an innovative approach offered by ExtraHop for producing continuous operational intelligence.
Why CIOs should rethink endpoint data protection in the age of mobility
Assessing trends in data protection, specifically with respect to mobile devices, BYOD, and remote employees.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Protecting against web application threats using SSL
SSL encryption can protect server‐to‐server communications, client devices, cloud resources, and other endpoints in order to help prevent the risk of data loss and losing customer trust.