Looks like fintechs are a going to be a focus for attacks. If you’re working with or for one of these startups, it’s time to invest in secure development practises and security expertise…
The European Union’s Revised Payment Services Directive (PSD2) is designed to give users greater control over their financial data and the option to carry out open banking via a new breed of innovative fintech firms. According to Trend Micro’s research, that increased control could come at a heavy cost.
Vulnerabilities that could be exploited as a result of the EU’s PSD2 include public APIs that allow approved third parties to access users’ banking data and mobile apps that contain transactional data that could make users targets for phishing attacks.
Another concern raised by the report pertained to financial technology (fintech) firms that have no record on data protection and lack the resources of big banks.
In a quick survey of open-banking fintechs, Trend Micro found them to have an average of 20 employees and no dedicated security professionals. The report suggests that such setups make these fintechs ideal targets for attackers and raise concerns over security gaps in their mobile apps, APIs, data-sharing techniques, and security modules that could be incorrectly implemented.