<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MoneyBlogNewz &#124; Financial Education &#38; Gossip &#187; bank fraud</title>
	<atom:link href="http://personalmoneystore.com/moneyblog/tag/bank-fraud/feed/" rel="self" type="application/rss+xml" />
	<link>http://personalmoneystore.com/moneyblog</link>
	<description>Hot Topic News &#38; Financial Education Articles</description>
	<lastBuildDate>Fri, 16 Dec 2011 20:06:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Judge rules bank is not responsible for hacked accounts</title>
		<link>http://personalmoneystore.com/moneyblog/2011/06/08/ocean-bank-online-fraud/</link>
		<comments>http://personalmoneystore.com/moneyblog/2011/06/08/ocean-bank-online-fraud/#comments</comments>
		<pubDate>Wed, 08 Jun 2011 18:52:14 +0000</pubDate>
		<dc:creator>Steve Tarlow</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Law and Order/Legislation]]></category>
		<category><![CDATA[Money Management]]></category>
		<category><![CDATA[ach transfers]]></category>
		<category><![CDATA[automated clearing house]]></category>
		<category><![CDATA[bank account hacked]]></category>
		<category><![CDATA[bank fraud]]></category>
		<category><![CDATA[john rich]]></category>
		<category><![CDATA[ocean bank]]></category>
		<category><![CDATA[online banking]]></category>
		<category><![CDATA[password theft]]></category>
		<category><![CDATA[patco construction]]></category>
		<category><![CDATA[peoples united bank]]></category>

		<guid isPermaLink="false">http://personalmoneystore.com/moneyblog/?p=108343</guid>
		<description><![CDATA[Maine Magistrate Judge John Rich has ruled that despite the fact that a bank allowed online hackers to steal more than $300,000 from a customer&#8217;s account, the bank is not responsible for the lost money. According to BankInfoSecurity, the judge said the plaintiff, a construction company, should have done a better job of protecting its [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_108346" class="wp-caption alignright" style="width: 310px"><a href="http://www.flickr.com/photos/23905174@N00/1594411528/" rel="external nofollow"><img class="size-full wp-image-108346" title="bank_account_hacked" src="http://personalmoneystore.com/wp-content/uploads/2011/06/bank_account_hacked.jpg" alt="A thieving hand reaches from the computer screen to type on the keyboard." width="300" height="236" /></a><p class="wp-caption-text">If your online bank account is hacked, the bank may not be liable for all the money. (Photo Credit: CC BY/Don Hankins/Flickr)</p></div>
<p>Maine Magistrate Judge John Rich has ruled that despite the fact that a bank allowed online hackers to steal more than $300,000 from a customer&#8217;s account, the bank is not responsible for the lost money. According to BankInfoSecurity, the judge said the plaintiff, a construction company, should have done a better job of protecting its bank account details.</p>
<h2>Judge recommends charges against Ocean Bank be dismissed</h2>
<p>Judge Rich recommended that the U.S. District Court in Maine dismiss a complaint filed by Patco Construction Company against Ocean Bank after Patco&#8217;s account was hacked and more than $300,000 was stolen. How much security banks should reasonably be required to provide commercial customers was called into question. If U.S. District Court follows Rich&#8217;s recommendation, legal experts see a precedent being set for liability claims in which online bank theft occurs via password interception. Each year, small- and mid-sized U.S. companies lose hundreds of millions of dollars via fraudulent ACH (Automated Clearing House) transfers, and the District Court ruling on the Ocean Bank case will no doubt be of interest.</p>
<h3>Patco v. People&#8217;s United Bank: The inside story</h3>
<p>Patco Construction Company&#8217;s case against People&#8217;s United Bank (the owner of Ocean Bank) states that in May 2009, it was discovered that <a href="http://personalmoneystore.com/moneyblog/2010/12/08/anonymous-mastercard-down-visa-operation-payback/">hackers were stealing</a> $100,000 per day from the company&#8217;s online Ocean Bank account. Apparently, the company&#8217;s password had been stolen via a malicious email that placed trojan malware onto a Patco employee&#8217;s computer.</p>
<p>Nearly $600,000 was gone before Patco noticed and informed Ocean Bank. The bank was able to block $240,000 in transfers, but told Patco the rest was irretrievable. Patco&#8217;s lawsuit accused the bank of “failing to implement best security practices,&#8221; i.e. requiring customers to use multi-level authentication. Ocean&#8217;s initial defense was that because the online user identification and password matched, it had done its share of maintaining security.</p>
<p>While Judge Rich agreed that Ocean Bank could have done more to maintain security, he concluded that the law does not require banks to use the best security methods available. As Ocean&#8217;s security was similar to other online banks, Rich deemed that Patco was responsible for not securing its log-ins.</p>
<h3>Not the best, just multi-factor</h3>
<p>Patco Construction Company President Mark Patterson argued that Ocean Bank was not in compliance with the Federal Financial Institutions Examination Council&#8217;s authentication processes by only asking for username and password. IT security attorney David Navetta seconded Patterson&#8217;s concern, yet the court was satisfied by Ocean Bank&#8217;s two-step, “multi-factor” process of requiring username and password.</p>
<h3>How to avoid identity theft</h3>
<p><object width="500" height="400"><param name="movie" value="http://www.youtube.com/v/I4yyzZNK6mo?version=3"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/I4yyzZNK6mo?version=3" type="application/x-shockwave-flash" width="500" height="400" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<h3>Sources</h3>
<p><a href="http://www.bankinfosecurity.com/articles.php?art_id=3705&amp;opg=1" rel="external nofollow">BankInfoSecurity</a></p>
<p><a href="http://docs.ismgcorp.com/files/external/authentication_guidance_2005.pdf" rel="external nofollow">Federal Financial Institutions Examination Council</a></p>
<p><a href="http://www.wired.com/threatlevel/2011/06/bank-ach-theft/" rel="external nofollow">Wired</a></p>
]]></content:encoded>
			<wfw:commentRss></wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

