Beware of hackers. And tellers.
That's the message to banks from New York Attorney General Eric Schneiderman, who on Friday warned that tellers and other branch workers have a wealth of client data at their fingertips and managed in a few instances to swipe it. In a letter to nine lenders, he said investigators uncovered identity-theft schemes hatched by tellers at some of the biggest institutions. Hundreds of bank customers have lost millions of dollars, he said.
There are "common security weaknesses in the banking industry that allowed these schemes to go largely undetected," he wrote. They include inadequate employee audits and flawed call-centre data practices, he said.
Read also:
• Insider hacking a big threat for employers
• How NZ banks can fend off cyber fraud
Schneiderman's alert to JPMorgan Chase & Co, Bank of America, Citigroup and other lenders followed his multiyear probe "Operation Pen & Teller," which revealed teller identity-theft plots. He urged banks to improve internal controls and limit employee access to data.