Trading apps expose investors to cybercriminals, report finds

Trading apps expose investors to cybercriminals, report finds
Some apps store subscribers' passwords or data on trading without encryption.
AUG 10, 2018

Dozens of applications used for online trading by retail investors have cybersecurity vulnerabilities, some of which could lead to hackers siphoning funds from account holders, according to security consultant IOActive Inc. Ten of the 80 applications tested over a one-year period store passwords of their subscribers without encryption, a flaw that could lead to funds being stolen, IOActive reported at the Black Hat cybersecurity conference Thursday in Las Vegas. Those included software by AvaTrade Ltd. and IQ Option, according to the report. Software at ETrade Financial Corp. and TD Ameritrade Holding Corp. stores trading data without encryption, the report found. The largest brokers offer the best security, yet still have weaknesses, said Alejandro Hernandez, a senior security consultant and author of the report. The biggest firms have been responsive to IOActive's findings and are fixing the issues, Mr. Hernandez said. Rebecca Niiya, a TD Ameritrade spokeswoman, said the company investigates any reported vulnerabilities and has "already made progress in addressing the potential issues noted in the IOActive report." Representatives for ETrade, AvaTrade and IQ Option didn't have any comment or didn't respond to emails seeking a response. The analysis looked at desktop, mobile and website-based trading software and found the web platforms to be the most secure. Desktop applications were the least secure. Using the same criteria, banking applications on all platforms are many times more secure than trading apps, Mr. Hernandez said. Retail investors could have a false sense of security because they probably equate their trading applications with their banking software, he said. (More: Market pullback presents robo-advisers with biggest test yet)

Latest News

SEC to lose Hester Peirce, deepening a commissioner crisis
SEC to lose Hester Peirce, deepening a commissioner crisis

The "Crypto Mom" departure would leave the SEC commission with just two members and no Democratic commissioners on the panel.

Florida B-D, RIA owner pitches bold long-term plan to sell to advisors
Florida B-D, RIA owner pitches bold long-term plan to sell to advisors

IFP Securities’ owner, Bill Hamm, has a long-term plan for the firm and its 279 financial advisors.

Fintech bytes: Vanilla, Wealth.com forge new estate planning partnerships
Fintech bytes: Vanilla, Wealth.com forge new estate planning partnerships

Meanwhile, a Osaic and Envestnet ink a new adaptive wealthtech partnership to better support the firm's 10,000-plus advisors, and RIA-focused VastAdvisor unveils native integrations with leading CRMs.

Fiduciary failure: Ex-advisor who sold practice fined after clients lost millions
Fiduciary failure: Ex-advisor who sold practice fined after clients lost millions

A former Alabama investment advisor and ex-Kestra rep has been permanently barred and penalized after clients he promised to protect got caught in a $2.6 million fraud.

Why the evolution of ETFs is changing the due diligence equation
Why the evolution of ETFs is changing the due diligence equation

As more active strategies get packaged into the ETF wrapper, advisors and investors have to look beyond expense ratios as the benchmark for value.

SPONSORED Are hedge funds the missing ingredient?

Wellington explores how multi strategy hedge funds may enhance diversification

SPONSORED Beyond wealth management: Why the future of advice is becoming more human

As technical expertise becomes increasingly commoditized, advisors who can integrate strategy, relationships, and specialized expertise into a cohesive client experience will define the next era of wealth management