Home / Information / Research: Croats are changing passwords less frequently

Research: Croats are changing passwords less frequently

On the occasion of the “European Cybersecurity Month,” the Croatian Banking Association presented its regular annual research on the state of internet security.

The survey conducted on a sample of one thousand people from across Croatia aimed to determine the degree of perceived vulnerability and the level of awareness among citizens regarding the need for security protection during the performance of usual activities on the internet, with a particular emphasis on downloading online content via mobile phones.

These activities include using email, communicating via social media, accessing the internet through free, unsecured wireless (Wi-Fi) networks, self-protection when conducting transactions via mobile banking, being cautious about which websites they visit, and whether they download mobile applications only from official stores (App Store, Google Play) or risk unnecessarily elsewhere.

Rarely changing passwords

When it comes to using passwords for communication via email or social media, 59% of respondents change their passwords once a year or less, and 34% only when they forget their old password. Additionally, the number of people who regularly change their passwords has significantly decreased – from 16% in May 2016 to only seven percent in September of this year! Regarding the storage of passwords for accessing mobile banking services, 52% of survey participants claim that only they know this information and that they do not have it stored anywhere, while 29% do not think about it at all.

Statistically significant differences by age were shown in response to this question. Younger people (Generation Z) better protect their mobile banking passwords than older individuals (Baby Boomers). Moreover, older individuals write down these passwords in more places. They do not feel threatened.

Survey participants were asked to assess their own internet security on a scale from one to five – from the stance of not feeling threatened to being a regular target of hacking attacks. More than half (56%) believe they are not threatened, which is an increase of seven percent compared to last year, while as many as 40% do not think about it at all. Four percent of respondents say they are regular targets of hackers.

>>>HUB: Entrepreneurs beware, do not fall for fake emails

In cases where they encounter a message (email, SMS) from an unknown sender that leads them to an enticing offer and contains a link to some online destination – 93 percent of people will ignore such a message and delete it immediately, while the remaining seven percent will take the risk and somehow continue to engage with that message. One-third use free Wi-Fi wherever possible. Regarding free, unsecured wireless internet access (Wi-Fi) – 37% of people use it whenever they can, 31% use Wi-Fi networks occasionally, and 32% do not use free wireless internet access at all.

Wi-Fi as a method of saving

Those who use Wi-Fi mainly do so as a method of saving – reducing the cost of data transmission on the mobile network they use. On these networks, they do what they usually do when they are online: read news, communicate via email, and socialize on social media. The good news is that among those who use Wi-Fi either frequently or only occasionally, only three percent access mobile banking through these unsecured open connections.

The research showed significant differences in the use of wireless, free internet access by age: among those who use open Wi-Fi networks whenever possible, the largest share, 60%, are people from the so-called Generation Z. Wireless, free internet access is least used by members of the so-called Baby Boomers generation. The share of those who use open Wi-Fi networks only occasionally or very rarely is highest in the so-called Generation X group (37%).

Smart people are cautious about where they surf

Participants in the research, although there are still too many casual ones among them, showed considerable caution while surfing – browsing content that interests them on the web. Fifty-five percent do not open websites they are not sure are authentic. However, even 34% of survey participants have not thought about the reliability of the online destinations they visit at all. For most, the most important thing is that the content they are interested in is easily and simply accessible via mobile. Regarding downloading applications, 56% of respondents download applications only through the stores offered by their mobile phones, while 34% do not download any applications to their phones at all.

>>>Research: Mobile internet is everything, but instead of additional gigabytes, we prefer concerts or movies

Applications are most downloaded by members of Generation Z (69%), and the share of those who do not download applications at all is highest in the Baby Boomers age group (65%) and decreases in younger groups. The share of those who download applications from alternative sources is equal and very small across all age groups. How to protect yourself from attacks and safeguard your data.

In Croatia, as well as globally, there is a significant increase in downloading online content via mobile phones. The mobile phone is becoming an increasingly sought-after platform in banking – in Croatia, we record about 600,000 users of mobile banking, emphasized Zdenko Adrović, director of HUB, at a press conference and stressed:

– In the digital age, which we are gradually and undoubtedly entering, secure data and communication protection is becoming increasingly important for citizens and companies, especially for the financial sector, whose business relies on the trust clients have in banks. Therefore, protection and education on cybersecurity will remain a priority for us.

>>>WiFi4EU – EU introduces free public internet at thousands of locations

Commenting on Croatia’s current exposure to threats and cyber attacks, Milan Parat, chairman of the HUB Security Committee, emphasized:

– This year, no significant attacks on banks in Croatia have been recorded, nor on users of internet or mobile banking services. However, alongside the standard attempt at fraud through phishing messages, this year we have recorded an increased number of specific frauds targeting companies. These are frauds through fake business messages in which criminals falsely present themselves as employees of selling companies involved in the purchasing process and then instruct companies to transfer money to a different, new seller’s IBAN, sometimes even in another bank. Defense against this type of attack is relatively simple. If there is a change in the IBAN or the seller’s destination bank just before the completion of the purchasing process, the purchasing companies should verify the accuracy of these new details through other communication channels before executing the payment.

As the number of users of mobile banking services in Croatia increases, Milan Parat suggested additional recommendations for them:

  • do not use mobile banking on rooted or jailbroken devices – devices where access to privileged processes has been enabled by modifying security settings
  • for financial transactions, use only banking applications from the official app store. Do not download applications from unknown sources
  • do not use mobile banking on open Wi-Fi networks

>>>Tele2 first in Croatia to introduce flat internet on mobile devices

  • be cautious if you open links from text messages (SMS) or emails. Your bank will never ask you for confidential information via SMS or email
  • check if new software updates and patches have been released and install them so that the operating system on the device is not exposed to risks
  • if your mobile device supports antivirus software, install it
  • keep the confidentiality of passwords and PINs for mobile devices, do not store passwords on your phone. The security of mobile devices is as important as the security of computers.