Something nasty injected login-stealing JavaScript 50K online banking sessions
theregister.com
theregister.com
It would fall in the same category as 'bank believed the customer instructed them to transfer funds when the customer did not make such an instruction'.
The customer in this case is the actual human account holder - not the customers computer system or account.
Notably, this is why lots of tech support scams try to trick the customer into transferring money, even though the scammer already has full access to the victims bank login details and browser. The scammers know that if they just make the transfer themselves, it is the bank they are defrauding, and the bank will typically try far harder to shut them down.
This description suggests that the malware ejects itself after collecting OTP & Credentials, but by the time the miscreants tries to initiate a transfer, I expect the OTP to have expired.
Only issue left is, people not using OTP and/or disabled OTP for online transactions, but that should be not possible in 2023!
https://cybersecurity.att.com/blogs/labs-research/behind-the...