Archive

tag: Fishing

identity

The Japanese Financial Services Agency amends supervisory guidelines. Phishing-resistant authentication methods will become mandatory. It is not biometric authentication as some media say, however! Public comments are open until August 8th.

On the 15th, the Financial Services Agency (FSA) began soliciting public comments on a proposed amendment to the "Comprehensive Supervisory Guidelines for Financial Instruments Business Operators, etc." The deadline for submissions is August 18th (Monday) at 17:00 PM (must be received by this time). This matter concerns unauthorized access and fraudulent transactions (third-party) in internet trading services using customer information (login IDs, passwords, etc.) stolen through phishing sites impersonating securities company websites.

identity

The threat of real-time phishing that cannot be prevented by one-time passwords - The true nature of phishing resistance using passkeys

In recent years, phishing attacks targeting financial institutions and other organizations have become increasingly sophisticated, with a technique known as "real-time phishing" posing a particularly serious threat. This type of attack is known to even disable one-time passwords (OTPs), which were previously considered effective countermeasures against phishing attacks, forcing financial institutions to fundamentally redesign their identity verification systems.