Showing posts with label Business Process. Show all posts
Showing posts with label Business Process. Show all posts

Monday, July 27, 2009

Man in the middle fraud in call centres

Never one to post only on up to the minute stories, the blog was quite interested in the Finextra report a fortnight ago on "man in the middle" fraud in call centres. I just haven't had a chance to write on it until now.

Traditionally, man in the middle fraud has been more associated more with the web channel than the telephone channel (see for example "Man-in-the-middle phishing kits circulating freely on the Web" or "ABN Amro compensates victims of 'man-in-the-middle' phishing attack" from Finextra), so it's interesting to see the attack take place in the telephone channel. It's also interesting that the attack described in Finextra is very low tech compared with the programing knowledge required for the phisihing attacks. The telephone version of man in the middle is described as,

"....where a fraudster calls the victim claiming to work for their bank, warning that their account may have been breached or compromised. The criminal then puts the customer on hold and calls their bank, connecting the two while remaining on the line.

The bank then requests authentication information, such as social security number, passwords and other personal information. Once the personal information is provided, the fraudster quickly ends the conference line and informs the customer that the issue has been resolved.

Meanwhile, with the personal information gathered during the call, the fraudster can take over the customer's phone banking relationship and transfer money out of their accounts."

The interesting thing for me is that for this type of attack to be successful, it highlights how weak the process side of some banks can be. This attack depends on the banks authentication process revealing (a) all of the customer's authentication data each time and (b) not ensuring that customers have multiple levels of authentication. Most banks I've worked with probably wouldn't be caught by this kind of fraud, so I'm interested to see that there are banks out there that still lag so far behind.

It's far less sophisticated than some of the the attack I've seen recently, where fraudsters have built fake IVRs to pretend to be the bank and used VoIP diversion to fool customers into thinking they are calling a local number (see posts like "Contact Centre impersonation arrives in the UK") and probably far less likely to succeed. Similarly, targeted social engineering attacks are also more likely to succeed as these tend to rely on bypassing security procedures rather than attacking them head on.

I would argue that deception based attacks around identity impersonation (such as the one on Barclays discussed in the post "Security, Call Centres and Fraud") seems to be where the real threat remains, but I'm not so sure that the man in the middle approach is where the real threat lies. My suspicion is that combinations of phishing and contact centre impersonation will remain the fastest growing threat for some years to come.

Wednesday, July 01, 2009

Scale and its problems in the contact centre

This week and last week I've been on site at the contact centres of some of the UK's biggest banks. These are also some of the UK's biggest contact centres, so it's been very interesting to see the challenge scale presents.

These organisations tend to have at least 10 million customers, which is a decent number if they all decide to phone you! What makes it even more challenging is that these 10 million customers have they data spread across thirty or more years of legacy systems.

It's interesting for me that the challenge of scale that this presents has been well addressed by telephony but the IT industry still lags behind to a certain extent. This might sound controversial, but if I explain that this is viewed from the perspective of customer service, it should become clearer. Contact Centre telephony (whether Cisco, Avaya, or Genesys) pretty much scales to run a very large customer service operation. It's taken twenty years of ACD development to get here (and the evolution of TDM technology to IP), but the telephony side of things works in terms of getting a call to anywhere that the organisation wants it to go.

By comparison, the availability of data and customer information (especially in real time) is still a real challenge. All the organisations I've been working with run 3270 sessions, or other terminal emulation, as so much of their data is still mainframe based. Processes similarly can be embedded in applications and present real challenges scaling to the wider enterprise. There is recognition that the process and application layer is now one of the choke points for customer service and IT System Integrators are starting to address it (see posts like "System Integrators write interesting things about contact centre for the downturn!"). The problem is that while mainframe was previously a very good answer to many of the scaling problems that organisations experienced, integrating yesterdays good solution into today's customer service requirements is still a struggle.

It's an interesting set of challenges and one I'll blog on further.