Fraud & Identity Theft

New York Sues Citibank Over Poor Data Security

New York attorney general is suing Citibank for failing to protect customers against hackers and fraudsters who have stolen millions.

The attorney general of the state of New York has sued Citibank over the financial institution’s alleged failure to protect customers against hackers and fraudsters, as well as its refusal to reimburse victims. 

New York AG Letitia James said individuals in the state have lost millions of dollars as a result of cybercrime schemes that are possible due to Citi’s failure to implement strong data security and anti-breach practices. 

“As a result of Citi’s lax security protocols and procedures, ineffective monitoring systems, and failure to respond in real-time and properly investigate fraud claims, New Yorkers have lost millions to scammers,” the AG’s office said in a press release. “Customers have lost their life savings, their children’s college funds, or even money needed to support their day-to-day lives as a result of Citi’s illegal and deceptive acts and practices.” 

In its complaint, the attorney general has provided several specific examples of New Yorkers who had tens of thousands of dollars stolen from their accounts after being tricked by cybercriminals.

It’s worth pointing out that these incidents do not appear to involve exploitation of any software vulnerabilities or access to Citi systems. Instead, the threat actors rely heavily on social engineering to trick victims into handing over the information needed to access their accounts and conduct unauthorized transfers. 

However, the AG believes Citi should have more efficient systems in place to detect signs of fraud, for instance, based on unrecognized device locations, suspicious password or username changes, and suspicious transfers. 

The bank has also been accused of being slow to respond to fraud reports coming from customers.

In addition, the AG says the bank should reimburse victims of such crimes under the Electronic Fund Transfer Act (EFTA), but Citi is allegedly exploiting a loophole to deny reimbursement claims. 

Advertisement. Scroll to continue reading.

In response to the lawsuit, Citi said it works hard to prevent fraud and assist impacted customers, but noted, “Banks are not required to make customers whole when those customers follow criminals’ instructions and banks can see no indication the customers are being deceived.”

Related: Two More Individuals Charged for DraftKings Hacking

Related: Data of 750 Million Indian Mobile Subscribers Sold on Hacker Forums

Related: 1.5 Million Affected by Data Breach at Insurance Broker Keenan & Associates

Related Content

Fraud & Identity Theft

The open source platform Tazama provides cost-effective monitoring of digital financial transactions to prevent fraud in real time.

Fraud & Identity Theft

Google Play Protect will block the installation of sideloaded applications requesting permissions frequently abused by fraudsters.

Cybercrime

Authorities in 34 countries have cooperated to dismantle cyber-enabled scams as part of a six-month operation.

Endpoint Security

A class action lawsuit has been filed against Intel over its handling of CPU speculative execution vulnerabilities, with a focus on Downfall.

Cybercrime

Silicon Valley fraud detection startup attracts $15 million in new financing from SignalFire, Legion Capital and Rally Ventures.

Cybersecurity Funding

Deduce has raised $9 million in a new funding round led by Freestyle Capital, to launch its AI-generated identity fraud prevention platform.

Data Breaches

A lawsuit filed on behalf of a former student and former employee at the University of Minnesota accuses the university of not doing enough...

Data Breaches

Lawsuits filed against companies that have suffered a data breach are increasingly common, with action being taken even for incidents affecting less than 1,000...

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version