Beware of the "switch your cellphone off" scam

It is beyond me as to why anyone would listen to some one telling you to switch off your cellphone.
 
According to the SABRIC, by getting banking customers to turn off their cell phones, customers do not receive any necessary communication or notifications from their banks during the time of the fraudulent transaction.

[highlight]Simultaneously, the perpetrators divert a customer’s landline to a member of their syndicate,[/highlight] who then poses as the targeted customer and authorises the fraudulent transaction.

Presumably this must be credit card fraud (large and uncharacteristic purchases that require a confirmation call from the bank to the bank's credit card customer) and nothing to do with OTPs and online banking?
 
Simultaneously, the perpetrators divert a customer’s landline to a member of their syndicate, who then poses as the targeted customer and authorises the fraudulent transaction.
Huh? So do they have insiders at Telkom or how do they divert the landlines?
 
+1 Yeah, that's what I want to know. How to the scammers get authorization to perform a call divert?

happened at the place my mother works. They all saw a telkom technician fiddling with the exchange, but who ever pays attention to that right. He diverted all incoming calls for half an hour or so. (The oke had a proper telkom bakkie - Apparently they disable the gps unit so that telkom cannot trace which truck it was or who had it.)
Worst thing was who ever pulled it off had fraudulent cheques with official bank numbers. So they had someone inside Telkom as well as inside the bank.
 
happened at the place my mother works. They all saw a telkom technician fiddling with the exchange, but who ever pays attention to that right. He diverted all incoming calls for half an hour or so. (The oke had a proper telkom bakkie - Apparently they disable the gps unit so that telkom cannot trace which truck it was or who had it.)
Worst thing was who ever pulled it off had fraudulent cheques with official bank numbers. So they had someone inside Telkom as well as inside the bank.
I assumed it was just the garden variety clip-on landline fraud method usually used by syndicates to make free international calls at the expense of Telkom customers (although I'm sure there must be many Telkom technicians moonlighting for those same syndicates).
 
Huh? So do they have insiders at Telkom or how do they divert the landlines?

Maybe the article has it wrong... maybe it's just the usual sim swap scam.

When you turn your phone off... then the other sim card becomes active.
 
Maybe the article has it wrong... maybe it's just the usual sim swap scam.

When you turn your phone off... then the other sim card becomes active.

At first I didn't understand what the article was on about, but I re-read it and understood what the criminals are up to.

If this crime is real and if as I suspect is specifically credit card fraud, it would then be committed by a very determined group of criminals who first obtain the cardholder's cellphone and landline numbers, the credit card details (card number, cardholder's name as it appears on the card, expiry date, the CCV number at the back, the billing address, and probably the credit limit as well), the criminals call the cardholder's cellphone and convince the cardholder to switch their cellphone off for several hours, the criminals then make one or more purchases via phone or the Internet such that a physical card is not required (also bypasses POS chip card PIN verification), the cardholder's bank detects suspicious purchases and attempts to contact the cardholder to find out if the cardholder made the purchases, meanwhile the syndicate has dispatched a corrupt Telkom technician to intercept or redirect any calls from the cardholder's bank and possibly pretend to be the cardholder. This last step would require patience and potentially hours of waiting for an incoming call from the bank, so I suspect call forwarding would be more likely than clip-on fraud, and the syndicate would have to have a plausible impersonator standing by to take the bank's call (same gender and able to imitate the cardholder's accent).

It all seems rather implausible, so if it is real, this crime is a lot more sophisticated than the garden variety criminal is able to conceive and execute, and requires loads of patience, which suggests that specific victims would be identified and targetted by a syndicate, perhaps requiring weeks of preparation. Fat cat execs/CEOs with very large credit card limits are probably in the cross-hairs of the syndicates.
 
Last edited:
Sounds awfully complicated... the normal cellphone sim swap syndicates are far more lucrative.

They also use the switch your cellphone off tactic.
 
Sounds awfully complicated... the normal cellphone sim swap syndicates are far more lucrative.

They also use the switch your cellphone off tactic.

Agreed, there would have to be a huge payload for each incident as this scam would require an attention span that most criminals cannot muster.
 
Huh? So do they have insiders at Telkom or how do they divert the landlines?

You don't need insiders, depending on the level on which these okes operate a simple trip to the nearest telkom box on your block should be enough. As far as the scam goes, it really ain't rocket science... I dealt with a company a while back who were looking into this scam and they could not only replicate your sim, they cloned the IMEI number as well. This number is tracked by service providers to determine which device each sim is used in. This means that when you go to the bank they are going to tell you that their fraud department phoned you, to prove them wrong you get a detailed statement of your cellphone bill which states that you took a call on your device. Now imagine explaining all this to a judge with a 3310?

The beauty about everything was the fact that these okes managed to gather all the info they needed quite quickly, this part they wouldn't disclose but from what I gathered it all has to do with some SMS/linking system.
 
At first I didn't understand what the article was on about, but I re-read it and understood what the criminals are up to.

If this crime is real and if as I suspect is specifically credit card fraud, it would then be committed by a very determined group of criminals who first obtain the cardholder's cellphone and landline numbers, the credit card details (card number, cardholder's name as it appears on the card, expiry date, the CCV number at the back, the billing address, and probably the credit limit as well), the criminals call the cardholder's cellphone and convince the cardholder to switch their cellphone off for several hours, the criminals then make one or more purchases via phone or the Internet such that a physical card is not required (also bypasses POS chip card PIN verification), the cardholder's bank detects suspicious purchases and attempts to contact the cardholder to find out if the cardholder made the purchases, meanwhile the syndicate has dispatched a corrupt Telkom technician to intercept or redirect any calls from the cardholder's bank and possibly pretend to be the cardholder. This last step would require patience and potentially hours of waiting for an incoming call from the bank, so I suspect call forwarding would be more likely than clip-on fraud, and the syndicate would have to have a plausible impersonator standing by to take the bank's call (same gender and able to imitate the cardholder's accent).

It all seems rather implausible, so if it is real, this crime is a lot more sophisticated than the garden variety criminal is able to conceive and execute, and requires loads of patience, which suggests that specific victims would be identified and targetted by a syndicate, perhaps requiring weeks of preparation. Fat cat execs/CEOs with very large credit card limits are probably in the cross-hairs of the syndicates.
“The banks are receiving a number of incident reports where customers have been defrauded in this manner, especially where transactions involving stolen cheques are concerned.”
Quite frankly, I don't understand how this scam works, the article is unclear. Who still uses cheques anyway?
 
The beauty about everything was the fact that these okes managed to gather all the info they needed quite quickly, this part they wouldn't disclose but from what I gathered it all has to do with some SMS/linking system.
I can't remember but doesn't the bank also ask some questions to verify the identity of the person answering their call?
 
At first I didn't understand what the article was on about, but I re-read it and understood what the criminals are up to.

If this crime is real and if as I suspect is specifically credit card fraud, it would then be committed by a very determined group of criminals who first obtain the cardholder's cellphone and landline numbers, the credit card details (card number, cardholder's name as it appears on the card, expiry date, the CCV number at the back, the billing address, and probably the credit limit as well), the criminals call the cardholder's cellphone and convince the cardholder to switch their cellphone off for several hours, the criminals then make one or more purchases via phone or the Internet such that a physical card is not required (also bypasses POS chip card PIN verification), the cardholder's bank detects suspicious purchases and attempts to contact the cardholder to find out if the cardholder made the purchases, meanwhile the syndicate has dispatched a corrupt Telkom technician to intercept or redirect any calls from the cardholder's bank and possibly pretend to be the cardholder. This last step would require patience and potentially hours of waiting for an incoming call from the bank, so I suspect call forwarding would be more likely than clip-on fraud, and the syndicate would have to have a plausible impersonator standing by to take the bank's call (same gender and able to imitate the cardholder's accent).

It all seems rather implausible, so if it is real, this crime is a lot more sophisticated than the garden variety criminal is able to conceive and execute, and requires loads of patience, which suggests that specific victims would be identified and targetted by a syndicate, perhaps requiring weeks of preparation. Fat cat execs/CEOs with very large credit card limits are probably in the cross-hairs of the syndicates.
rhey would also need to know the guy's ID number & other such detail the bank would ask...
 
Who still uses cheques anyway?
That is why I assumed it had to be credit card fraud, although I suppose it could be companies that are targetted, in which case how are the cheques stolen in the first place and then the company doesn't bother to have stop payments put on the entire range of stolen cheque numbers?

rhey would also need to know the guy's ID number & other such detail the bank would ask...
I thought about that, if someone phones you and says they are calling from your bank when they could just as easily be phoning from Nigeria, and the person says they need to ask you verification questions, "what is your ID number?", and you give them your ID number. It's phishing over the phone, in fact it is the same technique used in a common form of espionage where an unsuspecting victim is targetted and then unknowingly coerced into giving up information to someone they don't know but believe is legitimate and in a position of authority.
 
Last edited:
I can't remember but doesn't the bank also ask some questions to verify the identity of the person answering their call?

This scam is only the tip of the iceberg, they aren't going to knock people off at random. I think the cloning of your phone will only take place after weeks and weeks of phishing and social engineering to ensure that they have the right answer when the bank phones...

This all just sounds like too much effort though, joe average doesn't have to worry that these okes will be giving him a call any time soon...
 
Most, if not all of your details are available from places like ITC and/or Experian. Full names, addresses present and past, account information, everything is there. That info can be used to pass ID verification checks easily. And it is relatively easy to get. You also don't need to clone or intercept phones - some places will attempt to call you to verify transactions, and will send you an SMS if you can't be reached. These criminals have wide networks of people supplying info. They know which shops checks ID and which don't, and they know the security protocols of the different banks.
 
why not integrate the SIM card number and IMEI into online banking accounts? That way the transfers and/or payments dont go through if the details are different.
 
why not integrate the SIM card number and IMEI into online banking accounts? That way the transfers and/or payments dont go through if the details are different.

Not sure if that is technically possible or feasible to implement, it is a nice idea, but it would not solve the landline redirection problem vaguely described in the article.
 
Top
Sign up to the MyBroadband newsletter
X