
CIMB has issued a statement with regards to the security concerns raised by a number of its users alleging that the bank’s online banking portal and app have security flaws.
The statement:
CIMB Bank Berhad (“CIMB” or “the Bank”) would like to address recent social media news on the alleged insecurity of its online banking portal, CIMBClicks.
Please take note that our CIMBClicks system remains secure and all customers’ transactions continue to be protected.
The bank would like to inform that it had, over the weekend, introduced a few additional measures to enhance the security of its CIMBClicks transactions.
Apart from ensuring that the system is now able to accommodate passwords longer than eight (8) characters and up to 20 characters, we have also added the reCaptcha security measure on CIMBClicks to
ensure the user is not a bot.If you any queries, please call +60 3 6204 7788
RECAP:
Several CIMB Clicks users have reported unauthorised transactions from their bank accounts over the weekend.
Most of the unauthorised transactions involved repeated transactions via Paypal and debit card transactions.
While it isn’t clear if this is a security breach, CIMB had suddenly implemented Google’s reCAPTCHA service on their online banking portal’s login page. This raised user concerns over whether the CIMB Clicks page is genuine.
Users also alleged that their passwords were opened for hacking.



