Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Online Merchants and Financial Service Providers are the Two Biggest Sources of Stolen Banking Information
News & Analysis

Online Merchants and Financial Service Providers are the Two Biggest Sources of Stolen Banking Information

ISBuzz TeamBy ISBuzz TeamSeptember 12, 2014Updated:July 3, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
banking_infosec
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

According to a Kaspersky Lab survey of IT professionals, 48 percent of e-commerce/online retail businesses and 41 percent of financial services organisations worldwide have reported losing some type of financial information to cybercriminal activities within the past year.

Kaspersky Lab’s survey also surprisingly found that the e-commerce/online retailer business segment is the least likely to deploy and update specialised anti-fraud measures to protect financial transactions and prevent stolen banking information.

FREE Download: CISO Data Breach Guide

Attitudes Toward Technology

The e-commerce/online retail and financial services business sectors both depend on their abilities to receive, process and store sensitive financial information from customers. Through a combination of targeted attacks, application vulnerabilities and other forms of cyberattacks, almost half of businesses in both sectors will lose some of this information over the course of a year. Such a loss will not only damage the reputations of these businesses, which are highly dependent on trust, but it will also trigger costly legal penalties, removal and clean-up procedures.

But while these two segments share these similarities, their attitudes towards security technology are markedly different.

Only 53 percent of the e-commerce/online retail segment indicated that they “make every effort to keep anti-fraud measures up to date,” which is ten percent lower than the overall global average, and the lowest overall of any business segment. Since the entire business model of online merchants is based on online and electronic payment processing, this reluctance to invest in anti-fraud measures seems highly counter-intuitive.
[wp_ad_camp_4]
The financial services segment takes a more positive and proactive approach towards securing their financial data. When asked if they “make every effort to keep anti-fraud measures up to date,” 64 percent of finacial services providers agreed, a response rate tied for highest across all segments. Additionally, 52 percent of the financial services segment reported a desire to implement new technologies to protect financial transactions, compared to 46 percent of the e-commerce/online retail segment.

Changes After a Breach

Kaspersky Lab’s survey asked businesses that experienced a serious data loss incident about steps taken afterwards to protect their customers. Despite their differing attitudes explained in the segment above, both the e-commerce/online retail and financial services sectors took similar steps to implement additional protections. The most common measure implemented was “providing secure connections for customer transactions,” which was done by 88 percent of financial services organisations and 78 percent of e-commerce/online retailers. Financial service providers are more focused on providing specialised solutions for mobile devices than e-commerce/online retailers (75 percent vs. 56 percent, respectively), which means mobile payment security for online merchants may be a future area of concern.

In general, the least-common step taken by both financial service providers and e-commerce/online retailers following a data breach was to provide free or discounted versions of premium internet security software to their customers. It would appear that both sectors are more willing to invest in securing their own systems rather than investing in securing their customers’ systems.

Lastly, despite the relatively high adoption rates of specialised fraud protection for endpoints following a data breach – 71 percent for financial services and 62 percent for e-commerce/online retailers – the flip-side of those numbers is noteworthy. These numbers show that approximately one-third of companies in both sectors are still not investing in financial security software, even after financial information is stolen from them in a data breach incident.

Recommendations

Security industry research shows that businesses specialising in collecting and processing customer payment information are being actively targeted by cybercriminals, and this Kaspersky Lab survey shows that these businesses are very likely to lose payment data through a data breach. Instead of reacting to the attack, Kaspersky Lab advises businesses to be proactive in securing their IT networks and to secure payment systems with specialised protection.

Kaspersky Endpoint Security for Business helps protect a business network from an onslaught of malware, phishing, and other cyberthreats. Financial institutions need advanced endpoint security across their entire network, including mobile devices, virtual machines, and PCs. Kaspersky Endpoint Security for Business can bring protection for all these endpoints to a single administrator console, giving IT managers superior visibility and policy control over the security of their network.

Kaspersky Fraud Prevention unites a number of technologies to monitor the “back-end” processing of banks for malicious activity; ensures the protection of customer endpoints, including their mobile devices; and provides an SDK for reinforcing the security of mobile banking applications.  This fraud protection platform also uses Kaspersky Lab’s threat intelligence services to increase bank employees’ levels of cyberthreat knowledge and bolster the effectiveness of technologies used to protect financial data.

About Kaspersky Lab

Kaspersky LabKaspersky Lab is the world’s largest privately held vendor of endpoint protection solutions. The company is ranked among the world’s top four vendors of security solutions for endpoint users*. Throughout its more than 17-year history Kaspersky Lab has remained an innovator in IT security and provides effective digital security solutions for large enterprises, SMBs and consumers. Kaspersky Lab, with its holding company registered in the United Kingdom, currently operates in almost 200 countries and territories across the globe, providing protection for over 300 million users worldwide. Learn more at www.kaspersky.com.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}