With more people than ever using mobile banking, we are seeing record levels of unauthorised mobile banking fraud. In response to this, Which has compiled a list of the 5 biggest banking security threats and how to avoid them.
In 2023 mobile banking fraud overtook internet banking fraud for the first time and continued to rise in the first half of 2024.
It was expected that fraud levels would rise in line with usage and it is calculated by UK Finance that there are now almost as many people using banking apps (60%) as online banking (62%), according to UK Finance. Which states that, “fraudsters generally view customers as the weakest link, regardless of the banking methods we use”.
So, what are the biggest threats to your bank account and how can you combat them?
1. Account Hacking
When a criminal uses your login details to hijack your account via a banking app downloaded to their device, this is mobile banking fraud.
There is no sign that banking apps are particularly weak regarding fraud, but fraudsters have targeted them more as use has increased.
What are banks doing?
When you log in to your account, banks must make identity checks. Which have noted that: ”These multi-factor authentication (MFA) checks must include at least two components, such as a password or Pin (something only you know), a card reader or registered mobile device (something only you possess) or your digital fingerprint (something unique to you)”.
Which states they want banks to let you view any devices connected to your account so that you can take action if you spot one you don’t recognise. Most now offer this, although some big names – Lloyds banking Group, Santander, and the Co-operative Bank – still don’t do so.
The Co-operative Bank and Santander are reported to have told Which that this feature is in the works, while Lloyds Banking Group have said that all devices are automatically distrusted after 30 days of inactivity, so customers don’t need to be notified of new devices, but this is standard practice for Apple, Google and most email providers.
What can you do?
Which suggests that you do the following: “Set long, random and unique passwords for your accounts and use a password manager so you don’t need to remember them. Use MFA(multi factor authentication) on every website that offers it.
Avoid public wi-fi and never download apps from unofficial sources (use the Amazon, Apple or Google Play app stores instead, as these are vetted). Rogue apps still slip through (many reportedly pose as QR code reader and PDF apps), so read reviews before you download anything.
Keep your device operating system and key applications, such as your web browser, up to date and use reputable antivirus software on all devices, scanning regularly for threats.”
2. Stolen card details
Most card fraud is done remotely, but losses were the lowest reported for nine years in 2023 (£361m). This was due to more stringent verification processes when you shop online.
However, Card ID theft is a growing problem, and Which have reported that in 2024 cases and losses were at the highest level ever recorded.
What are banks doing?
Banks can use artificial intelligence (AI) and machine learning to identify unusual patterns and flag potential fraud in real time.
Which have noted that, “digital banks Monzo and Starling led the way for instant push notifications of incoming and outgoing payments, meaning customers can quickly flag transactions they don’t recognise. Most banks now offer this…”
What can you do?
Which advises that you do the following: “Avoid storing your card details on retailer websites (use wallets such as Apple Pay and Google Pay or PayPal instead).
Review your privacy settings on social media sites and stay vigilant to phishing attempts.
Always check web addresses carefully, particularly if you’ve been directed from adverts or QR codes.
If your card is lost or stolen, most banks let you freeze it via the app (the Co-operative Bank is a notable exception)”.
3. Phone theft
Watch out for people looking over your shoulder when you are using your pin as thieves might be ‘shoulder-surfing’ victims to watch them entering Pins and passwords.
A thief could easily pass security checks, if you’ve used the same or similar passwords for multiple accounts. They will try to use your Sim in their own device, if they can’t crack them.
What are banks doing?
Banks have a number of tools such as transaction monitoring and behavioural biometrics, which detect subtle deviations in the way a device is used. Most also use geolocation data to verify the physical location of customers during transactions and identify unusual activity.
What can you do?
Which suggests that you do the following: “Add a unique Pin to your Sim (under ‘Settings’, look for ‘Sim Pin’ or ‘Lock Sim’) to prevent it being used in another phone. Disable preview notifications (‘Lock screen’ or ‘Notifications’), as these messages can flash up on your phone screen even when your phone is locked, meaning a thief could view text messages or emails sent by your bank.
Register for a tracking app such as Apple’s ‘Find My’ or Google’s ‘Find My Device’, so you can quickly mark your device as stolen and remotely wipe its data if needed. Check if your phone manufacturer offers any tools too, such as Apple Stolen Device Protection and Android Theft Protection.
Finally, avoid keeping your debit and credit cards in your phone case.”
4. Hijacking your phone number
If criminals can get possession of your phone, they can trick your mobile network into transferring your phone number to a Sim card in their possession – a scam known as Sim swapping.
They can then intercept security codes by redirecting calls and texts to a new device. This way they can hijack your bank accounts or payment wallets such as Apple Pay and Google Pay.
What are banks doing?
Most of the responsibility for preventing this scam lies with mobile networks, although many banks use Sim-swap detection (flagging recently swapped Sims as high risk).
What can you do?
Which suggests that you “Ask your network provider about additional security, for example, you may be able to set up a unique Pin or password which must be provided to approve account changes in-store or over the phone.
Call your provider immediately if you receive unsolicited texts or emails about your Sim being ported, a PAC request, or you unexpectedly lose phone service.
Use MFA that doesn’t require SMS where possible – for example, apps such as Microsoft Authenticator are tied to a physical device, not your phone number”.
5. Impersonation scams
Scammers often contact potential victims posing as telecoms providers, law enforcement and banks to trick them into divulging security codes that they can use to authorise payments or even sending money.
What are banks doing?
Banks can block attempts to spoof their phone numbers in calls and texts, by adding them to something called the Do Not Originate (DNO) list (a database of helplines that can only receive calls, never make them).
Detailed fraud warnings and Confirmation of Payee are now the norm, when you send money to new accounts. This helps you to stop you from sending money to a scammer. Your bank will alert you if the name of the account doesn’t match the name of the person or business you intend to pay.
What can you do?
Which suggests that you do the following: “Stay cautious when receiving unsolicited calls, emails and texts. Avoid clicking on links and double-check any ‘urgent’ notifications supposedly from banks or other businesses.
Contact from unknown numbers is a red flag, but even if the number appears legitimate, contact the company using a trusted method such as the phone number on your debit card.
Never share your password, Pin or security codes – anyone asking for these is a scammer – and don’t download screen sharing or remote-access software, as this enables scammers to take full control of your device.
Pay attention to fraud warnings from your bank, as these are designed to protect you. Never lie to your bank about the reason for a payment, as fraudsters are known to coach victims into bypassing security checks.
If the worst happens, report any losses immediately so the banks can freeze accounts and try to recover your money.”

CLICK HERE TO DONATE TO OUR CROWDFUNDER
HELP US BECOME STRONGER SO THAT WE CAN CONTINUE TO DELIVER POWERFUL CITIZEN JOURNALISM!







