Why a modern cyber security system is essential for banks and leasing companies
A sigh of relief at Deutsche Leasing: as the Handelsblatt recently reported, the heavyweight of the German leasing industry is able to restart its systems after being the target of a serious hacker attack. In the short term, the work of 2,500 employees was severely impaired in some cases. The hacker attack on Deutsche Leasing is not an isolated incident. Rather, the case is representative of the current trend that financial service providers, such as banks and leasing companies, are increasingly being sought out by hackers as attractive targets.
The increasing threat of cyber attacks undoubtedly represents a significant risk factor of considerable proportions for banks and financial service providers. In recent years, not only the quantity of these attacks has increased significantly, but also their professionalism and sophistication. The worrying range of these attack methods leaves no region untouched and is increasingly attracting cyber criminals operating internationally. The aim of this article is to highlight the growing threat and to show approaches for strengthening cyber security and optimizing protective measures for banks and financial service providers.
1. Financial service providers as a popular target for cyber attacks
In recent years, cyber attacks have intensified enormously and pose a serious problem for banks and financial service providers in particular. Advancing digitalization and the introduction of new technologies have expanded the attack surface and increased the financial incentives for potential attackers.
The current threat situation is extremely worrying, as attackers can gain access to sensitive information through perfidious methods such as phishing, ransomware, DDoS attacks and insider threats. The situation is particularly challenging due to the close integration of the German financial sector with global markets and the need to comply with strict regulatory requirements. This is because compliance with the European General Data Protection Regulation and the IT Security Act requires a high level of personal data protection and a reliable guarantee of IT security, most recently regulated by the Digital Operational Resilience Act (DORA) - with the aim of harmonizing security across the entire EU financial sector.
Cyber criminals use advanced malware, sophisticated phishing techniques and targeted vulnerabilities in network security to infiltrate sensitive systems undetected and cause significant damage. The provision of online banking, mobile payment options and the increasing interconnectedness of financial services open up a multitude of opportunities for attackers to intercept sensitive data and manipulate financial transactions. The stolen data can be used for fraudulent activities such as identity theft or illegal sales on the black market.
2 Spectacular cyber attacks
The following are some significant examples that illustrate the complexity of criminal attacks on the systems of financial service providers and the significant consequences they can have for those affected:
June 2023: Deutsche Leasing AG
The case of the savings bank subsidiary Deutsche Leasing AG described above occurred in June 2023. The incident was so spectacular that more than 2,500 employees were asked not to come into the office while investigations were ongoing. The IT systems were offline, which meant that customers, especially SMEs, were unable to access their data.
April 2023: Deutsche Kreditbank AG (DKB AG)
In April 2023, the bank accounts of customers of Sparkasse and Deutsche Kreditbank AG (DKB AG) were plundered, which is another worrying example.
March 2023: MLF Mercator-Leasing
In 2023, the "installment protection portal" of MLF Mercator-Leasing GmbH & Co. managed by Einhaus-Gruppe GmbH and Finanz-KG in cooperation with JobRad® GmbH suffered a serious cyber attack. As a result, sensitive data was encrypted and copied to the darknet. The portal has not been operational since mid-March 2023. Since the separation from JobRad®, new contracts through Einhaus should be secure.
However, the frequency of attacks in 2023 should not obscure the fact that there have been repeated massive attacks on the IT systems of financial service providers in previous years. In August 2021, for example, the Baden-Württemberg Savings Banks Association was the target of a hacker attack in which a ransom was demanded.
In addition to targeted attacks on individual institutions, there were also widespread attacks on the entire financial sector. In 2020, German banks and energy suppliers were attacked by a hacker group, leading to outages of internet connections, websites and online banking systems.
3 Impact of cyber attacks and outlook for the future
Successful cyber attacks can not only cause significant economic damage, but can also have a lasting impact on the image of financial service providers and undermine customer confidence in the financial sector as a whole. In addition, customers may have doubts about the ability of the affected institutions to adequately protect their sensitive data and financial assets, which can lead to a loss of trust and possibly an exodus of customers.
These incidents illustrate that criminals are succeeding in penetrating banks' security systems and thus jeopardizing the security of sensitive customer data and financial resources. The growing professionalization of attackers, their sophisticated tactics and the use of advanced technologies are making it increasingly difficult to effectively prevent such attacks.
4. Measures and approaches to improve cyber security
The development situation leaves no room for doubt: banks, as well as other financial service providers, leasing companies and factoring companies, are increasingly obliged to address the issue of cyber security. Various approaches and measures exist to improve cyber security in the financial sector, some of the key areas of which are mentioned here:
1) Ensure compliance with high data protection standards and security regulations:
Financial service providers must ensure that their systems and processes comply with the requirements of the General Data Protection Regulation (GDPR) and implement effective mechanisms to detect and defend against attacks.
2) Close cooperation between IT experts and financial service providers:
By sharing information on emerging threats, IT professionals can help financial services providers implement and maintain robust security systems and work together to improve cyber security measures.
3) Invest in modern security technologies:
To counter such threats, it is crucial for financial service providers to continuously adapt and evolve their cyber security measures. The threat landscape and attack methods of cyber criminals are constantly evolving, which is why security measures must be updated accordingly.
4) Employee training and awareness:
Training can minimize the risks of phishing attacks and other social engineering methods.
Are you a financial services provider (e.g. bank, leasing company or factoring company) and want to improve your security standards? Then you've come to the right place! With its solutions for leasing, credit and factoring, NAVAX Software GmbH supports a large number of well-known banks, leasing companies and factoring companies in German-speaking Europe. When introducing our solutions, we place the highest priority on cyber security. So far, no attacks have been recorded in our customer base.
Can we help you? Then we look forward to hearing from you.
Sources:
1 Hofmann, Florian Thomas, "Cyberangriff bei MLF Mercator-Leasing, Jobrad, Einhaus", Bitbasegroup.com, 24.04.2023
2 Menzel, Bettina, "Hackerangriff auf Sparkassen-Tochter - Tausende Mitarbeiter nach Hause geschickt", Merkur.de, 07.06.2023
3 Dr. Schulte am Hülse, Ulrich, "Hackerangriff 2023: Bank accounts of customers of Sparkasse and Deutsche Kreditbank AG (DKB AG) plundered" , Anwalt.de, 28.04.2023
4 Atzler, Elisabeth and Kröner, Andreas, "Number of cyberattacks on Commerzbank and Co. on the rise", Handelsblatt.de, 22.02.2023
5 Atzler, Elisabeth, "Systems at Deutsche Leasing shut down for almost a week", Handelsblatt.de, 09.06.2023
6 "Hacker attack on Baden-Württemberg savings banks association", Swr.de, 12.8.2021
7 "Hacker attack paralyzes online banking: Volksbanken and Sparda banks affected", Rnd.de, 04.06.2021
8 "Hacker: Prominent bank and energy supplier attacked", Hamburger Abendblatt, 17.06.2020