Documents from the Federal Financial Institutions Examination Council are meant to help financial institutions identify and mitigate cyberattacks.
April 3, 2015
The Federal Financial Institutions Examination Council has published two statements intended to help financial institutions identify and mitigate cyberattacks intended to compromise user credentials or introduce malware to a computer system.
Attacks often involve the theft of credentials used by customers, employees, and third parties to authenticate themselves on business applications and systems. Cybercriminals use these stolen credentials to commit fraud and identity theft, modify and disrupt information systems, and obtain, destroy, or corrupt data.
Additionally, cybercriminals might seek to introduce malware into business systems through e-mail attachments and external devices such as USB drives, or through the use of compromised credentials.
In accordance with FFIEC guidance, institutions should:
Download a PDF file of the FFIEC Statement on Destructive Malware
Download a PDF file of the FFIEC Statement on Compromising Credentials
Additional resources to help raise user awareness about safe online practices: