Trading apps expose investors to cybercriminals, report finds

Trading apps expose investors to cybercriminals, report finds
Some apps store subscribers' passwords or data on trading without encryption.
AUG 10, 2018
By  Bloomberg

Dozens of applications used for online trading by retail investors have cybersecurity vulnerabilities, some of which could lead to hackers siphoning funds from account holders, according to security consultant IOActive Inc. Ten of the 80 applications tested over a one-year period store passwords of their subscribers without encryption, a flaw that could lead to funds being stolen, IOActive reported at the Black Hat cybersecurity conference Thursday in Las Vegas. Those included software by AvaTrade Ltd. and IQ Option, according to the report. Software at ETrade Financial Corp. and TD Ameritrade Holding Corp. stores trading data without encryption, the report found. The largest brokers offer the best security, yet still have weaknesses, said Alejandro Hernandez, a senior security consultant and author of the report. The biggest firms have been responsive to IOActive's findings and are fixing the issues, Mr. Hernandez said. Rebecca Niiya, a TD Ameritrade spokeswoman, said the company investigates any reported vulnerabilities and has "already made progress in addressing the potential issues noted in the IOActive report." Representatives for ETrade, AvaTrade and IQ Option didn't have any comment or didn't respond to emails seeking a response. The analysis looked at desktop, mobile and website-based trading software and found the web platforms to be the most secure. Desktop applications were the least secure. Using the same criteria, banking applications on all platforms are many times more secure than trading apps, Mr. Hernandez said. Retail investors could have a false sense of security because they probably equate their trading applications with their banking software, he said. (More: Market pullback presents robo-advisers with biggest test yet)

Latest News

Social Security trustees see one less year in insolvency countdown, project shortfall to start 2034
Social Security trustees see one less year in insolvency countdown, project shortfall to start 2034

New report shows dimmed outlook for benefits to retirees and disabled Americans, creating further pressure for federal tax hikes or more borrowing.

NY Republican Stefanik presses SEC to probe Harvard bond sale
NY Republican Stefanik presses SEC to probe Harvard bond sale

Open letter to SEC Chair Paul Atkins questions whether the Ivy League university withheld material information prior to its $750 million taxable bond offering.

Ex-LPL leader re-emerges at The Wealth Consulting Group
Ex-LPL leader re-emerges at The Wealth Consulting Group

The Las Vegas-based hybrid RIA overseeing $8.8 billion in assets has named Andy Kalbaugh president to help scale its advisor platform.

Envestnet extends investment offerings with new alts model portfolios
Envestnet extends investment offerings with new alts model portfolios

The wealth tech giant – in collaboration with Fidelity, BlackRock, State Street, and Franklin Templeton – is offering its advisor and wealth firm users more ways to diversify.

Just as wealth industry M&A was picking up, economic uncertainty could kill it again
Just as wealth industry M&A was picking up, economic uncertainty could kill it again

Deal volume increased post-election but now caution has taken over.

SPONSORED RILAs bring stability, growth during volatile markets

Barely a decade old, registered index-linked annuities have quickly surged in popularity, thanks to their unique blend of protection and growth potential—an appealing option for investors looking to chart a steadier course through today's choppy market waters, says Myles Lambert, Brighthouse Financial.

SPONSORED Beyond the dashboard: Making wealth tech human

How intelliflo aims to solve advisors' top tech headaches—without sacrificing the personal touch clients crave