Banco Nacional Ordered
To Pay Restitution To
Customers Victims of
Electronic Fraud
The Banco Nacional (BN)
is the latest state bank
to be found guilty of
not providing sufficient
online security to its
customers.
The Tribunal Contencioso
Administrativo found the
BN guilty after a bank
customer, identified
only by his last name,
Loría, lost ¢1.2 million
colones from his account
from "phishing" or
internet fraud.
The Banco Nacional has
been ordered to pay
Loría his loss,
including interest.
The court found that
Loría's accounts were
broken into on two
separate occasions, on
August 31, 2007 and
September 2, 2006.
José Francisco Araya, a
Banco Nacional official,
said yesterday that the
bank does not share the
opinion of the court and
that the bank had acted
in a responsible manner
to avoid electronic
fraud.
"On our website we spell
out a number of
recommendations for
customers to follow to
ensure security, for
example, not to answer
emails. In addition the
bank was running an
information campaign",
said Araya.
Last month a court found
the Banco de Costa Rica
(BCR) - the other state
bank - of the same guilt
and was ordered to pay
back customers for their
losses. The BCR also did
not agree with the court
decision.
Both state banks have
since last year issued a
number of additional
security controls for
online banking
transactions. For
instance, the BCR last
month announced the
introduction of a "clave
dinámica", a security
measure that requires
customers to have an
additional electronic
key to complete online
financial transactions
to third parties,
including the payment of
utilities.
The electronic key must
be obtained by the
customer personally at
any branch. However, as
of Wednesdays, the bank
did not require the
"clave dinámica" to pay
utilities online,
although bank officials
say that is required.
To minimize being a
victim of "phishing", it
is best not to answer
any email requesting you
to log in to your
account from a link in
the email, usually
telling you that the
request is for security
purposes or that the
account has been
breached.
Only log in using the
financial institutions
secure server noted by
"https" on the URL line
and never, ever, give
out your log in an
password to anyone, send
it by email or write
down where it can be
easily found. In
addition, it is
recommended to
periodically log in an
review movements to your
account.
|