Trading apps expose investors to cybercriminals, report finds

Trading apps expose investors to cybercriminals, report finds
Some apps store subscribers' passwords or data on trading without encryption.
AUG 10, 2018
By  Bloomberg

Dozens of applications used for online trading by retail investors have cybersecurity vulnerabilities, some of which could lead to hackers siphoning funds from account holders, according to security consultant IOActive Inc. Ten of the 80 applications tested over a one-year period store passwords of their subscribers without encryption, a flaw that could lead to funds being stolen, IOActive reported at the Black Hat cybersecurity conference Thursday in Las Vegas. Those included software by AvaTrade Ltd. and IQ Option, according to the report. Software at ETrade Financial Corp. and TD Ameritrade Holding Corp. stores trading data without encryption, the report found. The largest brokers offer the best security, yet still have weaknesses, said Alejandro Hernandez, a senior security consultant and author of the report. The biggest firms have been responsive to IOActive's findings and are fixing the issues, Mr. Hernandez said. Rebecca Niiya, a TD Ameritrade spokeswoman, said the company investigates any reported vulnerabilities and has "already made progress in addressing the potential issues noted in the IOActive report." Representatives for ETrade, AvaTrade and IQ Option didn't have any comment or didn't respond to emails seeking a response. The analysis looked at desktop, mobile and website-based trading software and found the web platforms to be the most secure. Desktop applications were the least secure. Using the same criteria, banking applications on all platforms are many times more secure than trading apps, Mr. Hernandez said. Retail investors could have a false sense of security because they probably equate their trading applications with their banking software, he said. (More: Market pullback presents robo-advisers with biggest test yet)

Latest News

The 2025 InvestmentNews Awards Excellence Awardees revealed
The 2025 InvestmentNews Awards Excellence Awardees revealed

From outstanding individuals to innovative organizations, find out who made the final shortlist for top honors at the IN awards, now in its second year.

Top RIA Cresset warns of 'inevitable' recession amid tariff uncertainty
Top RIA Cresset warns of 'inevitable' recession amid tariff uncertainty

Cresset's Susie Cranston is expecting an economic recession, but says her $65 billion RIA sees "great opportunity" to keep investing in a down market.

Edward Jones joins the crowd to sell more alternative investments
Edward Jones joins the crowd to sell more alternative investments

“There’s a big pull to alternative investments right now because of volatility of the stock market,” Kevin Gannon, CEO of Robert A. Stanger & Co., said.

Record RIA M&A activity marks strong start to 2025
Record RIA M&A activity marks strong start to 2025

Sellers shift focus: It's not about succession anymore.

IB+ Data Hub offers strategic edge for U.S. wealth advisors and RIAs advising business clients
IB+ Data Hub offers strategic edge for U.S. wealth advisors and RIAs advising business clients

Platform being adopted by independent-minded advisors who see insurance as a core pillar of their business.

SPONSORED Compliance in real time: Technology's expanding role in RIA oversight

RIAs face rising regulatory pressure in 2025. Forward-looking firms are responding with embedded technology, not more paperwork.

SPONSORED Advisory firms confront crossroads amid historic wealth transfer

As inheritances are set to reshape client portfolios and next-gen heirs demand digital-first experiences, firms are retooling their wealth tech stacks and succession models in real time.