Cyber criminals are increasingly circumventing a bank’s security to gain access to sensitive financial data. Getty Images
Cyber criminals are increasingly circumventing a bank’s security to gain access to sensitive financial data. Getty Images
Cyber criminals are increasingly circumventing a bank’s security to gain access to sensitive financial data. Getty Images
Cyber criminals are increasingly circumventing a bank’s security to gain access to sensitive financial data. Getty Images

How banks can strengthen defences against cyber criminals


  • English
  • Arabic

The digital era has opened doors to a wealth of opportunities but also challenges for the banking and finance sector.

While bringing unprecedented speed and convenience to customers, it has also created multiple channels that malicious actors can try to exploit for profit.

According to the Interpol Global Financial Fraud Assessment, widespread technology adoption is fuelling a rise in digital scams.

The use of artificial intelligence, large language models and cryptocurrencies, combined with phishing and ransomware-as-a-service business models, has resulted in a growing number of fraud campaigns without the need for advanced technical skills, and at relatively little cost.

The Global Anti-Scam Alliance has found that scammers stole more than $1 trillion from victims around the world last year. Only 0.05 per cent of these scammers were caught.

What is even more alarming is that these attacks are becoming more sophisticated and co-ordinated, highlighting the increasing intent of cyber criminals to circumvent a bank’s security and gain access to sensitive financial data.

This underscores the importance of continued investment in security measures.

Putting up cyber defences

In this complex cybersecurity landscape, banks are arming themselves against attacks by continuously increasing the awareness of their staff and clients and improving their working processes.

They are also updating their IT infrastructure, implementing advanced threat detection systems, enhancing security protocols and adopting multi-factor authentication to safeguard customer data and transactions.

The Worldwide Security Spending Guide by the International Data Corporation indicates that the financial services and government sectors are poised to emerge as the foremost contributors to security expenditure in the Middle East and Africa this year. Their joint spend is projected to account for nearly a third of the market’s value.

Knowledge is power

Educating customers to help them protect themselves from phishing and smishing (using text messages) attacks and prevent unauthorised access to their accounts plays an important role.

Banks are raising customer awareness through regular communication on cybersecurity risks. For their part, customers can contribute by staying informed and vigilant about their digital footprint.

Customers are naturally concerned about the security of their identity as well as personal and financial data and the confidentiality and integrity of their digital transactions.

Banks should aim to establish a dialogue with their customers on safe digital practices and be alert and aware of phishing and smishing patterns.

Improving communication techniques is key to ensuring their customers are engaging with and acting on these important messages.

The transformative impact of AI

Banks are increasingly using AI for fraud detection and behavioural analytics to prevent unauthorised transactions, while blockchain’s decentralised ledger provides an added layer of security for transaction records and strengthening data integrity.

By analysing various data points in real time, banks can assess customer behavioural patterns and device integrity and apply machine learning to detect irregularities in these patterns to invoke higher security thresholds.

Making security invisible

Historically, security manifested in high levels of customer friction, such as multiple passwords, pin numbers and one-time passwords.

The vision for the future is to make security invisible.

How criminals use technology to defraud victims – in pictures

  • The use of technology in everyday lives has led to growth in scams and fraud. Reem Mohammed / The National
    The use of technology in everyday lives has led to growth in scams and fraud. Reem Mohammed / The National
  • Phishing is one of the most common methods used by fraudsters and it involves sending an unsolicited email that appears to be from a financial institution or online retailer. The National
    Phishing is one of the most common methods used by fraudsters and it involves sending an unsolicited email that appears to be from a financial institution or online retailer. The National
  • Smishing — the SMS equivalent of phishing — is where fraudsters falsify the telephone number so it appears to be a genuine text from a bank or well-known company. Chris Whiteoak / The National
    Smishing — the SMS equivalent of phishing — is where fraudsters falsify the telephone number so it appears to be a genuine text from a bank or well-known company. Chris Whiteoak / The National
  • Vishing is the telephone equivalent of phishing and smishing. Fraudsters may pose as bank staff, police or government officials. Getty Images
    Vishing is the telephone equivalent of phishing and smishing. Fraudsters may pose as bank staff, police or government officials. Getty Images
  • SIM swap involves fraudsters duplicating the SIM of your mobile number without your knowledge or authorisation, allowing them to conduct financial transactions with your bank. AP
    SIM swap involves fraudsters duplicating the SIM of your mobile number without your knowledge or authorisation, allowing them to conduct financial transactions with your bank. AP
  • Identity theft is where someone illegally obtains your confidential information, through various ways such as theft of your wallet, bank and utility bill statements, computer intrusion and social networks. Getty Images
    Identity theft is where someone illegally obtains your confidential information, through various ways such as theft of your wallet, bank and utility bill statements, computer intrusion and social networks. Getty Images
  • Prize scams involve fraudsters claiming to represent well-known organisations. They contact victims to tell them they have won a cash prize and request them to share confidential banking details to transfer the prize money.
    Prize scams involve fraudsters claiming to represent well-known organisations. They contact victims to tell them they have won a cash prize and request them to share confidential banking details to transfer the prize money.
  • Instagram influencer Ramon Abbas, known as Hushpuppi, used a technique known as business email compromise.
    Instagram influencer Ramon Abbas, known as Hushpuppi, used a technique known as business email compromise.
  • The tax authority said some bank customers in the UAE have received phishing emails impersonating financial institutions. EPA
    The tax authority said some bank customers in the UAE have received phishing emails impersonating financial institutions. EPA
  • Jenny Ross, Which? Money editor, says: ‘Scammers are relentless when it comes to wanting our personal information and ultimately our money.’ PA
    Jenny Ross, Which? Money editor, says: ‘Scammers are relentless when it comes to wanting our personal information and ultimately our money.’ PA
  • Netflix's The Tinder Swindler tells the story of three women who say they were conned out of $500. Photo: @simon_leviev_official via Instagram
    Netflix's The Tinder Swindler tells the story of three women who say they were conned out of $500. Photo: @simon_leviev_official via Instagram

Cyber threats transcend borders

Cyber threats are also becoming more transnational in nature. International co-operation is crucial to combat cyber threats.

Sharing threat intelligence and establishing unified cybersecurity standards help create a more secure global banking environment.

Cybersecurity measures adopted by banks for decades have been significantly contributing to industry standards, such as the US National Institute of Standards and Technology Cybersecurity Framework, and regulations like GDPR.

This ensures that customer trust and confidence are upheld through the definition and implementation of best practices.

An example of an emerging best practice is device binding, also known as device registration, which links the customer’s mobile device to the bank’s app, treating the device as a security credential.

This allows customers to securely transact on that device and provides them with peace of mind, knowing that higher-risk transactions can only occur on their registered device.

The future of cyber security

Looking ahead, banks are poised to face an increasingly complex set of cyber challenges, including quantum computing threats to encryption, sophisticated cyber attacks leveraging emerging technologies, such as AI, including generative AI, and the need for adaptive security architecture.

To stay ahead of these challenges, fostering a culture of cyber security is imperative. Banks must invest in next-generation security solutions and continuous education, while customers must improve their knowledge and awareness of cybersecurity threats and vigilance in their digital interactions.

Only this way can we build a robust and secure financial ecosystem that can thwart the hostile intentions of cyber criminals.

Corey Thompson is executive vice president and head of digital for retail banking at Mashreq. Olivier Busolini is executive vice president and head of information security at Mashreq.

Key developments

All times UTC 4

if you go

The flights

Direct flights from the UAE to the Nepalese capital, Kathmandu, are available with Air Arabia, (www.airarabia.com) Fly Dubai (www.flydubai.com) or Etihad (www.etihad.com) from Dh1,200 return including taxes. The trek described here started from Jomson, but there are many other start and end point variations depending on how you tailor your trek. To get to Jomson from Kathmandu you must first fly to the lake-side resort town of Pokhara with either Buddha Air (www.buddhaair.com) or Yeti Airlines (www.yetiairlines.com). Both charge around US$240 (Dh880) return. From Pokhara there are early morning flights to Jomson with Yeti Airlines or Simrik Airlines (www.simrikairlines.com) for around US$220 (Dh800) return. 

The trek

Restricted area permits (US$500 per person) are required for trekking in the Upper Mustang area. The challenging Meso Kanto pass between Tilcho Lake and Jomson should not be attempted by those without a lot of mountain experience and a good support team. An excellent trekking company with good knowledge of Upper Mustang, the Annaurpuna Circuit and Tilcho Lake area and who can help organise a version of the trek described here is the Nepal-UK run Snow Cat Travel (www.snowcattravel.com). Prices vary widely depending on accommodation types and the level of assistance required. 

A%20Little%20to%20the%20Left
%3Cp%3E%3Cstrong%3EDeveloper%3A%20%3C%2Fstrong%3EMax%20Inferno%3Cbr%3E%3Cstrong%3EConsoles%3A%3C%2Fstrong%3E%20PC%2C%20Mac%2C%20Nintendo%20Switch%3Cbr%3E%3Cstrong%3ERating%3A%20%3C%2Fstrong%3E4%2F5%26nbsp%3B%3C%2Fp%3E%0A
How to watch Ireland v Pakistan in UAE

When: The one-off Test starts on Friday, May 11
What time: Each day’s play is scheduled to start at 2pm UAE time.
TV: The match will be broadcast on OSN Sports Cricket HD. Subscribers to the channel can also stream the action live on OSN Play.

The%20specs
%3Cp%3E%3Cstrong%3EPowertrain%3A%20%3C%2Fstrong%3ESingle%20electric%20motor%0D%3Cbr%3E%3Cstrong%3EPower%3A%20%3C%2Fstrong%3E201hp%0D%3Cbr%3E%3Cstrong%3ETorque%3A%20%3C%2Fstrong%3E310Nm%0D%3Cbr%3E%3Cstrong%3ETransmission%3A%20%3C%2Fstrong%3ESingle-speed%20auto%0D%3Cbr%3E%3Cstrong%3EBattery%3A%20%3C%2Fstrong%3E53kWh%20lithium-ion%20battery%20pack%20(GS%20base%20model)%3B%2070kWh%20battery%20pack%20(GF)%0D%3Cbr%3E%3Cstrong%3ETouring%20range%3A%20%3C%2Fstrong%3E350km%20(GS)%3B%20480km%20(GF)%0D%3Cbr%3E%3Cstrong%3EPrice%3A%20%3C%2Fstrong%3EFrom%20Dh129%2C900%20(GS)%3B%20Dh149%2C000%20(GF)%0D%3Cbr%3E%3Cstrong%3EOn%20sale%3A%3C%2Fstrong%3E%20Now%3C%2Fp%3E%0A

GOLF’S RAHMBO

- 5 wins in 22 months as pro
- Three wins in past 10 starts
- 45 pro starts worldwide: 5 wins, 17 top 5s
- Ranked 551th in world on debut, now No 4 (was No 2 earlier this year)
- 5th player in last 30 years to win 3 European Tour and 2 PGA Tour titles before age 24 (Woods, Garcia, McIlroy, Spieth)

Harry%20%26%20Meghan
%3Cp%3E%3Cstrong%3EDirector%3A%20%3C%2Fstrong%3ELiz%20Garbus%26nbsp%3B%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EStars%3A%3C%2Fstrong%3E%20Duke%20and%20Duchess%20of%20Sussex%0D%3Cbr%3E%0D%3Cbr%3E%3Cstrong%3ERating%3A%20%3C%2Fstrong%3E3%2F5%3C%2Fp%3E%0A
Election pledges on migration

CDU: "Now is the time to control the German borders and enforce strict border rejections" 

SPD: "Border closures and blanket rejections at internal borders contradict the spirit of a common area of freedom" 

Classification of skills

A worker is categorised as skilled by the MOHRE based on nine levels given in the International Standard Classification of Occupations (ISCO) issued by the International Labour Organisation. 

A skilled worker would be someone at a professional level (levels 1 – 5) which includes managers, professionals, technicians and associate professionals, clerical support workers, and service and sales workers.

The worker must also have an attested educational certificate higher than secondary or an equivalent certification, and earn a monthly salary of at least Dh4,000. 

While you're here
Gully Boy

Director: Zoya Akhtar
Producer: Excel Entertainment & Tiger Baby
Cast: Ranveer Singh, Alia Bhatt, Kalki Koechlin, Siddhant Chaturvedi​​​​​​​
Rating: 4/5 stars

Company%20profile
%3Cp%3EName%3A%20Tabby%3Cbr%3EFounded%3A%20August%202019%3B%20platform%20went%20live%20in%20February%202020%3Cbr%3EFounder%2FCEO%3A%20Hosam%20Arab%2C%20co-founder%3A%20Daniil%20Barkalov%3Cbr%3EBased%3A%20Dubai%2C%20UAE%3Cbr%3ESector%3A%20Payments%3Cbr%3ESize%3A%2040-50%20employees%3Cbr%3EStage%3A%20Series%20A%3Cbr%3EInvestors%3A%20Arbor%20Ventures%2C%20Mubadala%20Capital%2C%20Wamda%20Capital%2C%20STV%2C%20Raed%20Ventures%2C%20Global%20Founders%20Capital%2C%20JIMCO%2C%20Global%20Ventures%2C%20Venture%20Souq%2C%20Outliers%20VC%2C%20MSA%20Capital%2C%20HOF%20and%20AB%20Accelerator.%3Cbr%3E%3C%2Fp%3E%0A
Story%20behind%20the%20UAE%20flag
%3Cp%3EThe%20UAE%20flag%20was%20first%20unveiled%20on%20December%202%2C%201971%2C%20the%20day%20the%20UAE%20was%20formed.%C2%A0%3C%2Fp%3E%0A%3Cp%3EIt%20was%20designed%20by%20Abdullah%20Mohammed%20Al%20Maainah%2C%2019%2C%20an%20Emirati%20from%20Abu%20Dhabi.%C2%A0%3C%2Fp%3E%0A%3Cp%3EMr%20Al%20Maainah%20said%20in%20an%20interview%20with%20%3Cem%3EThe%20National%3C%2Fem%3E%20in%202011%20he%20chose%20the%20colours%20for%20local%20reasons.%C2%A0%3C%2Fp%3E%0A%3Cp%3EThe%20black%20represents%20the%20oil%20riches%20that%20transformed%20the%20UAE%2C%20green%20stands%20for%20fertility%20and%20the%20red%20and%20white%20colours%20were%20drawn%20from%20those%20found%20in%20existing%20emirate%20flags.%3C%2Fp%3E%0A
Dust and sand storms compared

Sand storm

  • Particle size: Larger, heavier sand grains
  • Visibility: Often dramatic with thick "walls" of sand
  • Duration: Short-lived, typically localised
  • Travel distance: Limited 
  • Source: Open desert areas with strong winds

Dust storm

  • Particle size: Much finer, lightweight particles
  • Visibility: Hazy skies but less intense
  • Duration: Can linger for days
  • Travel distance: Long-range, up to thousands of kilometres
  • Source: Can be carried from distant regions

The Sky Is Pink

Director: Shonali Bose

Cast: Priyanka Chopra Jonas, Farhan Akhtar, Zaira Wasim, Rohit Saraf

Three stars

Indoor cricket World Cup:
Insportz, Dubai, September 16-23

UAE fixtures:
Men

Saturday, September 16 – 1.45pm, v New Zealand
Sunday, September 17 – 10.30am, v Australia; 3.45pm, v South Africa
Monday, September 18 – 2pm, v England; 7.15pm, v India
Tuesday, September 19 – 12.15pm, v Singapore; 5.30pm, v Sri Lanka
Thursday, September 21 – 2pm v Malaysia
Friday, September 22 – 3.30pm, semi-final
Saturday, September 23 – 3pm, grand final

Women
Saturday, September 16 – 5.15pm, v Australia
Sunday, September 17 – 2pm, v South Africa; 7.15pm, v New Zealand
Monday, September 18 – 5.30pm, v England
Tuesday, September 19 – 10.30am, v New Zealand; 3.45pm, v South Africa
Thursday, September 21 – 12.15pm, v Australia
Friday, September 22 – 1.30pm, semi-final
Saturday, September 23 – 1pm, grand final

UAE's final round of matches
  • Sep 1, 2016 Beat Japan 2-1 (away)
  • Sep 6, 2016 Lost to Australia 1-0 (home)
  • Oct 6, 2016 Beat Thailand 3-1 (home)
  • Oct 11, 2016 Lost to Saudi Arabia 3-0 (away)
  • Nov 15, 2016 Beat Iraq 2-0 (home)
  • Mar 23, 2017 Lost to Japan 2-0 (home)
  • Mar 28, 2017 Lost to Australia 2-0 (away)
  • June 13, 2017 Drew 1-1 with Thailand (away)
  • Aug 29, 2017 v Saudi Arabia (home)
  • Sep 5, 2017 v Iraq (away)
if you go

The flights

Air Astana flies direct from Dubai to Almaty from Dh2,440 per person return, and to Astana (via Almaty) from Dh2,930 return, both including taxes. 

The hotels

Rooms at the Ritz-Carlton Almaty cost from Dh1,944 per night including taxes; and in Astana the new Ritz-Carlton Astana (www.marriott) costs from Dh1,325; alternatively, the new St Regis Astana costs from Dh1,458 per night including taxes. 

When to visit

March-May and September-November

Visas

Citizens of many countries, including the UAE do not need a visa to enter Kazakhstan for up to 30 days. Contact the nearest Kazakhstan embassy or consulate.

Profile of Udrive

Date started: March 2016

Founder: Hasib Khan

Based: Dubai

Employees: 40

Amount raised (to date): $3.25m – $750,000 seed funding in 2017 and a Seed round of $2.5m last year. Raised $1.3m from Eureeca investors in January 2021 as part of a Series A round with a $5m target.

The specs

Engine: 1.6-litre 4-cyl turbo

Power: 217hp at 5,750rpm

Torque: 300Nm at 1,900rpm

Transmission: eight-speed auto

Price: from Dh130,000

On sale: now

The Matrix Resurrections

Director: Lana Wachowski

Stars:  Keanu Reeves, Carrie-Anne Moss, Jessica Henwick 

Rating:****

RESULTS
%3Cp%3E%0D%3Cstrong%3E6pm%3A%3C%2Fstrong%3E%20Marfa%20Deira%20%E2%80%93%20Conditions%20(PA)%20Dh80%2C000%20(Dirt)%201%2C200m%0D%3Cbr%3E%3Cstrong%3EWinner%3A%3C%2Fstrong%3E%20Wadheha%2C%20Bernardo%20Pinheiro%20(jockey)%2C%20Majed%20Al%20Jahouri%20(trainer)%0D%3Cbr%3E%3Cstrong%3E6.35pm%3A%20%3C%2Fstrong%3EDubai%20Creek%20%E2%80%93%20Maiden%20(TB)%20Dh82%2C500%20(D)%201%2C400m%0D%3Cbr%3E%3Cstrong%3EWinner%3A%20%3C%2Fstrong%3EBarq%20Al%20Emarat%2C%20Bernardo%20Pinheiro%2C%20Ismail%20Mohammed%0D%3Cbr%3E%3Cstrong%3E7.10pm%3A%20%3C%2Fstrong%3EMina%20Hamriya%20%E2%80%93%20Handicap%20(TB)%20Dh95%2C000%20(D)%201%2C600m%0D%3Cbr%3E%3Cstrong%3EWinner%3A%3C%2Fstrong%3E%20Tahdeed%2C%20Dane%20O%E2%80%99Neill%2C%20Michael%20Costa%0D%3Cbr%3E%3Cstrong%3E7.45pm%3A%3C%2Fstrong%3E%20Mina%20Rashid%20%E2%80%93%20Maiden%20(TB)%20Dh82%2C500%20(D)%201%2C900m%0D%3Cbr%3E%3Cstrong%3EWinner%3A%20%3C%2Fstrong%3ESeyaasi%2C%20Xavier%20Ziani%2C%20Salem%20bin%20Ghadayer%0D%3Cbr%3E%3Cstrong%3E8.20pm%3A%20%3C%2Fstrong%3EAl%20Garhoud%20Sprint%20DP%20World%20%E2%80%93%20Listed%20(TB)%20Dh132%2C500%20(D)%201%2C200m%0D%3Cbr%3E%3Cstrong%3EWinner%3A%3C%2Fstrong%3E%20Mouheeb%2C%20Ray%20Dawson%2C%20Michael%20Costa%0D%3Cbr%3E%3Cstrong%3E8.55pm%3A%3C%2Fstrong%3E%20Mirdiff%20Stakes%20Jebel%20Ali%20Port%20%E2%80%93%20Conditions%20(TB)%20Dh120%2C000%20(D)%201%2C400m%0D%3Cbr%3E%3Cstrong%3EWinner%3A%3C%2Fstrong%3E%20Seyouff%2C%20Antonio%20Fresu%2C%20Michael%20Costa%0D%3Cbr%3E%3Cstrong%3E9.30pm%3A%3C%2Fstrong%3E%20Jebel%20Ali%20Free%20Zone%20%E2%80%93%20Handicap%20(TB)%20Dh95%2C000%20(D)%202%2C000m%0D%3Cbr%3E%3Cstrong%3EWinner%3A%20%3C%2Fstrong%3EAjuste%20Fiscal%2C%20Jose%20da%20Silva%2C%20Julio%20Olascoaga%3C%2Fp%3E%0A
The years Ramadan fell in May

1987

1954

1921

1888

Updated: June 26, 2024, 4:00 AM