Article 26
Level 2 classification for Level 1 event type External fraud
Institutions shall classify each loss event classified as External fraud in accordance with Article 24 into one of the following Level 2 categories:
|
External fraud Level 2 classification |
Description |
Reference number |
|
Fraud committed by institution’s clients |
Fraudulent acts not relating to data theft or data manipulation that have been committed by a client of the institution, even in collusion with another person. |
2.1 |
|
Fraud not committed by institution’s clients |
Fraudulent acts not relating to data theft or data manipulation that have not been committed by a client of the institution, including by means of the identity of another ignorant person. |
2.2 |
|
Data theft and manipulation |
Data stolen from or maliciously manipulated in bank systems by any means, including cyber-attacks. That covers all types of data, e.g. client data, employee data, and the institution’s proprietary data. |
2.3 |
|
Robbery, burglary and theft of physical assets |
Robbery, burglary and theft of physical assets by an external party. |
2.4 |