According to a Sankei Shimbun report1, scams exploiting the fact that biometric authentication cards raise the ATM withdrawal limit by 20 times appear to be increasing rapidly.

The reported scheme appears to have worked as follows.

  • The fraud group called a woman in her 70s at her home in Tokyo in March (3) and asked her to “lend us your name to purchase corporate bonds for a nursing home.” The woman agreed.
  • They then demanded a fee to resolve the problem, telling her that “lending your name is a crime.”
  • Following instructions given over the phone, the woman obtained a biometric authentication cash card from a financial institution. She withdrew a total of approximately ¥6 million in cash from an ATM and was defrauded of the money.

In 6, another woman in her 60s in Tokyo was similarly made to obtain a biometric authentication cash card and was then defrauded of 1,000 myriads of yen.

This seems to indicate that the risk management process is not working properly.

Risk management identifies threats, estimates the corresponding risks, and implements countermeasures against them. This case shows that such an immediately foreseeable threat was not identified, which is evidence that risk management was deficient2. This tends to happen when security is confused with risk management.

I have been pointing out since around 2009 that the same thing could happen with the My Number Card. It is a mistake to invoke the idea that “the greater serves for the lesser” and distribute something with capabilities as powerful as a registered seal for everyday use. If we do that, some people will lose their homes and property. That is why New Zealand decided not to distribute credentials at such a high level to its citizens. This is evidence that its risk management is being conducted properly. Instead, accidents are prevented by always involving a licensed professional. When risk management is considered, it is clear that “the greater does not serve for the lesser.” The appropriate credential must be used for each purpose. And when crossing from one level to another, there must be a clear difference in the user experience. Otherwise, there is a high risk that users will mistake a high-risk procedure for a low-risk one and proceed with it.

Some security vendors apparently propose, “Because the greater serves for the lesser, let us replace everything with high-level credentials and make it possible to do anything with a single card.” I understand why this appeals to procurement-commander-style CIOs who focus only on cost reduction. But this exposes users to risk. I urge such vendors to exercise restraint.

Footnotes

  1. Sankei Shimbun, “Spate of ‘Biometric Authentication Card’ Scams—20 Times the ATM Withdrawal Limit, Metropolitan Police Department” (2015.10.18) http://www.sankei.com/affairs/news/151018/afr1510180004-n1.html
  2. From another perspective, one could say that the company’s management of its own risks was working well. It identified only its own risks and did not identify the risks to users. Taken to an extreme, cases are quite conceivable in which a company transfers its own risks to users and then claims that it has “managed the risks.”

Related posts