Best Practices For Maintaining Security While Mobile Banking | Bankrate (2024)

Key takeaways

  • It’s important to stay safe when doing mobile banking, in a world where online hacking and identity theft are commonplace.
  • Consumers can help avoid becoming a victim of financial crimes by educating themselves on cyberattacks such as malware and fake banking apps.
  • For additional security, take advantage of safeguards from your bank, including mobile alerts and multi-factor authentication.

For many, mobile banking has become a cornerstone of personal money management. It enables you to do such tasks as check your balance, transfer money and pay bills, with just a few taps. In fact, nearly half (48 percent) of bank customers are using apps on phones or other mobile devices as their top option for managing their bank accounts, the American Bankers Association found.

But is mobile banking truly safe? Bank fraud is popular with identity thieves, who steal personal credentials, usually for financial gain.

Is mobile banking safe?

Cybersecurity experts say mobile banking is safe, but urge consumers to take certain precautions.

“If you download the mobile app from a secure store, that is just as safe as visiting a bank branch,” says Paul Benda, senior vice president for operational risk and cybersecurity at American Bankers Association.

Benda says the safest place to download a mobile banking app is from your bank’s website.

“Banks use extremely secure, high-end encryption technologies,” Benda says. “We like saying that mobile apps are like having a bank branch in your pocket.”

Watch out for these types of cyberattacks

There are myriad ways that fraudsters target consumers. but the FBI cites two forms of cyberattacks in particular:

1. App-based banking Trojans

These are hidden in unrelated apps such as games or tools that are downloaded by unsuspecting bank customers. These “sideload” apps, which are downloaded from unofficial sources, might conceal malware that is dormant until a user launches a legitimate banking app. Then the Trojan creates a pop-up overlay that mimics the bank’s login page. When customers enter their username and password, they are seamlessly directed to the legitimate banking app login page, with no idea that they have been scammed.

“The malware can be downloaded in a variety of ways, such as SMS (short message service, or text) with a malicious hyperlink,” says Teresa Walsh, global head of intelligence at Financial Services Information Sharing and Analysis Center (FS-ISAC), which mitigates cyber threats in financial services. “This type of malware is actually on sale on the criminal underground marketplace.”

2. Fake banking apps

These apps impersonate the real mobile apps of banks and are designed to trick users into entering their login credentials. The FBI say it is “one of the fastest growing sectors of smartphone-based fraud.”

Should you use a mobile banking app?

If you’re worried about using a mobile banking app, be aware that security threats exist everywhere, including inside the bank lobby.

“There is the risk that the bank employee will do something that is illegal, like stealing your banking information; this is known as an insider threat,” says Donald Korinchak of CyberExperts.com.

With a mobile app, “there are potential vulnerabilities related to the security posture of the app itself – vulnerabilities in code, encryption methods, et cetera – and also potential vulnerabilities related to the transmission of information,” he says.

“In both scenarios, the bank invests heavily to ‘bake in’ security,” Korinchak says. Financial institutions monitor their employees’ behavior and also look for vulnerabilities in their app that can be patched before they are exploited by criminals.

There are also precautions you can take to reduce the risk.

How to protect yourself against mobile banking fraud

1. Download a verified banking app from your bank’s website.

Many banks feature links to the app stores from their websites to help you download the right app. “Your bank should have available information on what type of mobile app they use, what features are on it and what you need for access to it,” FS-ISAC’s Walsh says. “Then, use a reliable app store, paying attention to the owner/developer of the app and whether there are other apps with the same name.”

Talk to your bank to make sure, but never download an app found on an open forum.

2. Make sure your bank uses two-factor or multi-factor authentication.

Two-factor or multi-factor authentication requires bank customers to prove their identity when logging in to accounts by providing at least two pieces of authenticating information. This is usually a password or PIN as well as a confirmation code sent via text message to their cellphone.

Two-factor authentication vastly increases security, Korinchak says, but isn’t 100 percent secure. “Someone could gain access to your phone or someone could intercept the SMS traffic to gain access to the code,” he says

3. Use a strong password.

One of the best ways to protect yourself is to use a password that contains random upper and lower case letters, numbers and symbols. Don’t ask your browser to remember it for you either; use a reputable password manager instead.

“Reputable password managers are coded in a way that reduces risk to the user and are highly hardened against potential attackers,” Korinchak says. “Most cyber security experts recommend password manager software.”

4. Avoid using public Wi-Fi.

When you log on to a public Wi-fi hotspot, you often get a warning that you’re not on a secure network, and that others may be able to watch your online actions. That’s a strong reason not to conduct any financial business using a public network. Instead, use your cellular network or your home wi-fi to better protect your personal information.

5. Get smart about phishing and smishing.

Phishing emails often look legitimate, like they really are from your bank or credit card issuer. But ID thieves use them to trick people into divulging personal information, and they may contain malware.

Smishing is the same tactic, but conducted through text messages.

“Users should be familiar with their banking application in the first place to detect abnormal questions or pop-ups that look slightly different than the usual features,” Walsh says.

6. Set up alerts via email, text or the bank’s app.

A quick notification from your bank about transactions on your account can help you detect potential fraudulent activity. You can then address the matter with your bank in a timely manner.

How banks protect customers from cyber threats

Banks, credit unions and investment firms invest heavily to shield themselves against cyberattacks.

“I think it’s safe to say banks spend billions to protect customer accounts,” says ABA’s Benda. “Due to Regulation E, they’re on the hook if there’s an attack.”

Regulation E limits consumer liability to $50 if an unauthorized electronic funds transfer is caught by a customer within two business days, and up to $500 if caught outside the two-day window. Financial institutions are responsible for everything above that amount.

“Banks have very robust controls in place to control fraudulent activity,” says Benda. “A lot depends on consumer behavior, making sure consumers follow safe practices.”

Bottom line

Banks, especially online-only banks, spend a lot of time and money to protect their digital operations (including mobile apps) and their customers from theft and fraud. Customers have to do their part too to best guard against attacks by practicing safe mobile banking habits.

—Bankrate senior writer Karen Bennett contributed to an update of this story.

Best Practices For Maintaining Security While Mobile Banking | Bankrate (2024)

FAQs

Best Practices For Maintaining Security While Mobile Banking | Bankrate? ›

Never leave your mobile phone unattended or stored in an insecure place. Do not use unsecured Wi-Fi networks for banking, purchases or checking your emails. Don't use hotspot in a public place and instead use your 3G or 4G internet connection. Check your device's security settings to ensure maximum protection.

What are 2 best practices for keeping your online banking information secure? ›

What Is the Best Way to Protect Online Banking?
  • Choose strong passwords.
  • Change passwords regularly.
  • Use two-factor authentication.
  • Stay skeptical of scams.
  • Use your financial institution's security offerings.
  • Use a password manager.
  • Check your accounts regularly.
Jul 25, 2023

What type of security precautions do you take when doing mobile banking? ›

Here are some tips for a more secure mobile banking experience:
  • Don't lose your phone. ...
  • Use the official banking app, not the browser. ...
  • Don't just follow any link you see. ...
  • Don't use mobile banking on public Wi-Fi. ...
  • Use strong passwords and 2FA. ...
  • Use antivirus software with malware and phishing protection.
Dec 20, 2023

How to secure mobile banking? ›

Never leave your mobile phone unattended or stored in an insecure place. Do not use unsecured Wi-Fi networks for banking, purchases or checking your emails. Don't use hotspot in a public place and instead use your 3G or 4G internet connection. Check your device's security settings to ensure maximum protection.

How do I ensure security in online banking? ›

Ways to protect your online banking information
  1. Password-protect all banking access. ...
  2. Choose strong and unique passwords. ...
  3. Enable two-factor authentication. ...
  4. Log out when you finish banking. ...
  5. Avoid public Wi-Fi. ...
  6. Don't use a shared computer. ...
  7. Sign up for banking alerts. ...
  8. Guard against phishing scams.
Oct 14, 2023

What are 3 strategies for keeping information secure? ›

In general:
  • Keep high-level Protected Data (e.g., SSN's, credit card information, student records, health information, etc.) ...
  • Securely remove sensitive data files from your system when they are no longer needed.
  • Always use encryption when storing or transmitting sensitive data.

What is the best security for online banking? ›

Create a "strong" password with at least 8 characters that includes a combination of mixed case letters and numbers. Change your password frequently. Never share username and password information with third-party providers. Avoid using an automatic login feature that saves usernames and passwords.

How do you maintain mobile security? ›

  1. Back up your data. This is more about protecting and restoring your information should disaster strike. ...
  2. Keep your operating system and apps updated. ...
  3. Log out of sites after you make a payment. ...
  4. Turn off Wi-Fi and Bluetooth® when not in use. ...
  5. Protect your investment.

What are the best practices that helps in securing your mobile devices? ›

Mobile Device Security Best Practices
  • Enable user authentication.
  • Use a password manager.
  • Always run updates.
  • Avoid public wi-fi.
  • Enable remote lock.
  • Cloud backups.
  • Use MDM/MAM.
Jan 3, 2024

What is the most common security risk of a mobile device? ›

The most common mobile phone security risk is probably malware. Malware is a type of malicious software that can infect mobile devices and steal personal information or damage the device.

What is the risk of mobile banking? ›

The Top 10 Mobile Banking Risks and Vulnerabilities

Manipulated texts and calls claiming to be from your bank. Phishing links in emails and fake fraud alerts. Physical phone theft and hacking. Fake mobile banking apps. “Keylogging” malware that's hidden in other apps.

How to improve mobile banking? ›

Here are 5 ways to improve user experience for mobile banking:-
  1. Make security a top priority. ...
  2. Bankable integration of legacy systems and customer interface. ...
  3. Incorporate emerging technologies to enhance services. ...
  4. Personalized Services to improve satisfaction.

Which is safer, online or mobile banking? ›

Banking apps can be safer than using an online banking portal due to biometric-enabled login options for your phone and the app itself. Your face, your fingerprint and your phone are a lot harder to hack than your username and password.

How is security maintained in e-banking? ›

Online banking security is fortified through multiple layers of protection, designed to safeguard your financial information from unauthorized access. High-End Encryption: SSL/TLS Protocols: Banks predominantly use SSL (Secure Socket Layer) and TLS (Transport Layer Security) protocols.

What are three steps you can take to ensure account security online? ›

Tools and tips to help you stay safe online.
  1. Use strong and unique passwords. Creating a strong, unique password for every account is one of the most critical steps you can take to protect your privacy. ...
  2. Keep track of all your passwords. ...
  3. Check your passwords for security issues.

How can you protect your checking account when using Online & Mobile Banking? ›

How To Increase Your Online Banking Security
  1. Use strong and unique passwords for all of your accounts.
  2. Safely store your online banking details.
  3. Enable two-factor authentication (2FA)
  4. Update your security questions and answers.
  5. Bookmark the bank's website, or use its mobile app.
Feb 21, 2024

Which are two 2 safety tips for online security? ›

Tools and tips to help you stay safe online.
  • Use strong and unique passwords. Creating a strong, unique password for every account is one of the most critical steps you can take to protect your privacy. ...
  • Keep track of all your passwords. ...
  • Check your passwords for security issues.

What are some recommended ways to stay secure online? ›

Top tips for staying secure online
  • Top tips for staying secure online.
  • Use a strong and separate password for your email.
  • Install the latest software and app updates.
  • Turn on 2-step verification (2SV)
  • Password managers: using browsers and apps to safely store your passwords.
  • Backing up your data.
  • Three random words.

How do I keep my financial information safe online? ›

Secure Your Online Financial Information with These 6 Tips
  1. Create Strong Passwords. Did you know that an 8-letter password can be cracked instantly? ...
  2. Use Two-Factor Authentication. ...
  3. Avoid Public WiFi and Access Secure Websites. ...
  4. Be Cautious of Phishing Scams. ...
  5. Secure Your Devices. ...
  6. Resist Saving Passwords in Your Browser.
Aug 31, 2023

How do you keep your safe and secure online? ›

7 Tips for Protecting Yourself Online
  1. Keep your computers and mobile devices up to date. ...
  2. Set strong passwords. ...
  3. Watch out for phishing scams. ...
  4. Keep personal information personal. ...
  5. Secure your internet connection. ...
  6. Shop safely. ...
  7. Read the site's privacy policies.

Top Articles
Latest Posts
Article information

Author: Carmelo Roob

Last Updated:

Views: 6278

Rating: 4.4 / 5 (45 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Carmelo Roob

Birthday: 1995-01-09

Address: Apt. 915 481 Sipes Cliff, New Gonzalobury, CO 80176

Phone: +6773780339780

Job: Sales Executive

Hobby: Gaming, Jogging, Rugby, Video gaming, Handball, Ice skating, Web surfing

Introduction: My name is Carmelo Roob, I am a modern, handsome, delightful, comfortable, attractive, vast, good person who loves writing and wants to share my knowledge and understanding with you.