Australian Banks Lag in Email Fraud Protection: Research Shows Vulnerabilities

November 26, 2024 12:00 AM AEDT | By Team Kalkine Media
 Australian Banks Lag in Email Fraud Protection: Research Shows Vulnerabilities
Image source: shutterstock

Highlights 

  • 66% of Australian banks lack the strongest DMARC protection. 
  • Only 34% of Australian banks apply the most secure DMARC setting. 
  • One-quarter of Australian banks have no DMARC record, increasing vulnerability. 

Recent research from cybersecurity firm Proofpoint reveals significant vulnerabilities in the email security practices of Australian banks compared to their US counterparts. The findings highlight that many Australian financial institutions are not using the most effective tools to protect customers from email fraud and phishing attacks, leaving them susceptible to cybercriminal activity. 

Weak DMARC Adoption in Australia 

One of the most concerning findings of the analysis is that 66% of Australian banks have not adopted the most robust form of Domain-based Message Authentication, Reporting, and Conformance (DMARC) protection. DMARC is an essential tool that helps prevent cybercriminals from spoofing legitimate bank emails, a common tactic used in phishing scams. 

While 75% of Australian banks do use some form of DMARC, only 34% enforce the highest level of protection, the "Reject" setting. This setting blocks harmful emails before they can reach customers' inboxes, significantly reducing the risk of scams. The majority of banks in Australia, however, only implement less stringent DMARC policies, failing to provide full protection against phishing attempts. 

Growing Cybersecurity Threats 

The gap in email security practices is compounded by the increasing threat of cybercrime targeting the financial sector. Cybercriminals are becoming more sophisticated, often posing as trusted institutions like banks to deceive individuals into revealing sensitive information. Steve Moros, senior director at Proofpoint, emphasized that Australian banks need to address these security gaps to prevent further exploitation of consumers. 

The research also found that one-quarter of Australian banks do not have any DMARC record in place, making them particularly vulnerable to email-based fraud. Without this foundational security measure, these banks are at heightened risk of becoming targets for impersonation and phishing schemes. 

Comparison with US Banks 

In contrast, US banks are generally better equipped to handle email fraud risks. According to the study, 58% of US banks have implemented the highest level of DMARC protection, significantly reducing the likelihood of email fraud. Furthermore, only 3% of US banks were found to lack any DMARC record, highlighting the stronger security measures in place across the Pacific. 

The Government's New Scam Prevention Framework 

These findings come at a time when the Australian Government is ramping up its efforts to combat scams through a new Scam Prevention Framework. The framework imposes fines of up to $50 million on businesses, including banks, that fail to manage scam risks effectively. This new regulation requires businesses to report scams promptly and provides victims with avenues for compensation, further emphasizing the need for stronger cybersecurity measures within the banking sector. 

Proofpoint's research calls attention to the significant cybersecurity gaps in Australia's banking sector, urging financial institutions to adopt stronger email authentication measures, such as the "Reject" DMARC setting, to safeguard customers. The report also underscores the importance of enhanced vigilance around email authenticity to mitigate the growing risks of phishing and domain impersonation scams. As cybersecurity threats continue to evolve, Australian banks must act quickly to shore up their defenses and protect their customers from the rising tide of email fraud.


Disclaimer

The content, including but not limited to any articles, news, quotes, information, data, text, reports, ratings, opinions, images, photos, graphics, graphs, charts, animations and video (Content) is a service of Kalkine Media Pty Ltd (Kalkine Media, we or us), ACN 629 651 672 and is available for personal and non-commercial use only. The principal purpose of the Content is to educate and inform. The Content does not contain or imply any recommendation or opinion intended to influence your financial decisions and must not be relied upon by you as such. Some of the Content on this website may be sponsored/non-sponsored, as applicable, but is NOT a solicitation or recommendation to buy, sell or hold the stocks of the company(s) or engage in any investment activity under discussion. Kalkine Media is neither licensed nor qualified to provide investment advice through this platform. Users should make their own enquiries about any investments and Kalkine Media strongly suggests the users to seek advice from a financial adviser, stockbroker or other professional (including taxation and legal advice), as necessary. Kalkine Media hereby disclaims any and all the liabilities to any user for any direct, indirect, implied, punitive, special, incidental or other consequential damages arising from any use of the Content on this website, which is provided without warranties. The views expressed in the Content by the guests, if any, are their own and do not necessarily represent the views or opinions of Kalkine Media. Some of the images/music that may be used on this website are copyright to their respective owner(s). Kalkine Media does not claim ownership of any of the pictures displayed/music used on this website unless stated otherwise. The images/music that may be used on this website are taken from various sources on the internet, including paid subscriptions or are believed to be in public domain. We have used reasonable efforts to accredit the source wherever it was indicated as or found to be necessary.


AU_advertise

Advertise your brand on Kalkine Media

Sponsored Articles


Investing Ideas

Previous Next
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.