
IN AUGUST 2007, my BDO Telebanking account was hacked. P50,000 was illicitly debited from my account. Apart from the shock that my account was breached, the fact that this amount was stolen when only a maximum of P20,000 in a day was allowed to be debited was a further unwelcome surprise.
The account was one which I did not use very often so it was a few days before I realized there was a problem. In retrospect, therefore, I would have expected BDO to have identified the problem before me. After all, there is a daily journal which, if used properly, would have detected that there was an anomaly.
As soon as I realized that my account has been breached, I reported the matter to BDO. Its response was not pleasant, and I realized that BDO’s assumed belief was that there was something wrong with us and not that the issue was with bank.
There is the question of redress. It is necessary, though not sufficient, that the bank refunds the money that was stolen. “What do you want?” enquired the bank. “The truth” I replied.
The truth is always difficult to obtain. In my case, BDO unfortunately was too glib. “We have firewalls,” said a senior manager. “No, you don’t” was my riposte. “If you had proper firewalls, the breach would not have happened. You do not know how or why the breach occurred. If you really understood the cause of the breach, you could prevent it from happening again.”
Sure enough, the problem has re-occurred. Accounts which have been conducted properly, where the access code has not been compromised, are still vulnerable. BDO says it is due to a “sophisticated fraud technique”. Does this mean that BDO still does not know how it was done?
If so, it is not sensible for BSP’s Director of Technology Risk and Innovation Supervision Department, Melchor Plabasan, to assert that banks are “generally safe”. Generally safe means not safe.
Not safe means that banks are subject to an existential threat.
This is unacceptable./PN




