BSP Memoranda BSP Memoranda No. M-2020-090BSP Memoranda No. M-2020-090 2020-12-12T00:00:00.000+08:00

Phishing and Other Similar Social Engineering Attacks

Baxexo SexrnaL No PrLrPrNAs OFFICE OF THE DEPUTY GOVERNOR FINANCIAL SUPERVISION SECTOR MEMORANDUM NO. M-2020-!gq To : ALL CONCERNED BSP-SUPERVISED FINANCIAL INSTITUTIONS (BSFls) Subject : PHISHING AND OTHER SlMltAR SOCIAL ENGINEERING ATTACKS Phishing attacks remain to be one of the top cyber risks in the digitalfinancial services landscape, especially in this time of the COVID-19 pandemic wherein the use of digital payments and financial services has significantly increased. Cybercriminals continue to utilize various platforms and tactics such as phishing emails, SMS phishing {smishing), SMS spoofing and voice phishing (vishing}, including social media channels to gain unauthorized access to financial resources. ln view thereof, BSFIs are enjoined to revisit the recommended controls and measures in previous BSP Memoranda on Guidance on Management of Risks associated with Fraudulent E-mails or Websitesl, SMS-Based Attacks Targeting Customers of Financial Institutions2, and other similar BSP issuances. BSFIs are also reminded to intensify information security awareness and education campaigns as a first line of defense against these phishing and social engineering attacks. Further, BSFIs should minimize risk exposure through employing defense-in-depth security strategies such as calibration of fraud management system rules and parameters, conduct of threat hunting exercises to detect unusual activities and takedown of phishing sites, among others. Likewise, BSFIs should ensure that timely and appropriate consumer protection and redress mechanisms are in place. To preserve the banking public's trust and confidence in digital financial services, BSFIs are strongly advised to implement the following: 1. Consumer assistance helpdesk or hotline available 24 hours a day and 7 days a week (24x7)3; 2. Increased surveillance on online banking systems/activities during holidays or long weekends; 3.Facility to timely block/suspend accounts reported by clients/concerned parties or those tagged as fraudulent or suspicious; and 4. Procedures to resolve disputes arising from the use of the digital financial services within the established turn-around-time (TAT). 1 Memorandum No. M-2015-025 dated 22 June 2OL5 2 Memorandum No. M-2020-066 dated 19 August 2020 3 In accordance with Appendix 11S of the MORB and Appendix Q-70/99/N-12 of the MORNBFI. Note that the operating hours may vary depending on the BSFI's risk management strategies. A l,l:]bin, St, l!41late 1L)O.i Minila Pr]il,ppines . i632i )itl;ili . rvww.bsp.gov.gf[ i:spraiilSbst t]c'.pfr

Lastly, financial fraud resulting from phishing and other types of cyber-related crimes should be promptly reported to the BSP in accordance with Sections 148, 173 and 901 of the Manual of Regulations for Banks (MORB) and Sections L47-Q|L45- S/L42-P/125-N, Section 901-Q, Appendix Q-5/S-3/P-8 /T-4, and Appendix N-1 of the Manual of Regulations for Non-Bank Financial lnstitutions (MORNBFI). For information and guidance. Digitally signed by Chuchi G. 'Fonacier Date:2020.12.12 22:59:04 +08'fi)' CHUCHI G. FONACIER Deputy Governor 12 December 2020

Open the source record ↗

More in BSP Memoranda

Want an analysis of this document?

Ask ASG Legal AI to summarize it, compare it with other rulings, or explain how it applies to your situation — it researches from this same library.