ABSA explains how SIM swap fraud happens

It is currently not clear why ABSA, which uses similar Internet banking security to other banks, is the main target of SIM swap fraud.

ummmmm....
 
That does not explain how they get a hold of the PIN and password.

Do they also ask this during the call, or does a rogue employee with access to the details provide it?
 
99% fraud linked to ABSA, they shood have a good look at themselves.
 
This is both ABSA and MTN trying to cover up a big cock up.
 
You will receive an SMS from your “bank” stating that there is a problem with your account, and a consultant will be in contact with you shortly
A few minutes thereafter you will receive a call, and the consultant will ask you to confirm some details, and ask you for additional information such as your account number, the type of phone you use, and recent dialed numbers.

Did this happen to the people who got robbed? If not, ABSA needs to try again.
 
This is both ABSA and MTN trying to cover up a big cock up.

That's called social engineering.

Something's very fishy here.... Can those people who got [-]robbed[/-]cleaned out confirm that they had a phone call from the "bank" asking them for their banking details before the sim swap fraud occurred?
 
It is currently not clear why ABSA, which uses similar Internet banking security to other banks, is the main target of SIM swap fraud.

Every single case that has been in the news lately involved absa and emty-n. If you ask me this is an inside job
 
They still have to get your pin....usually through phishing and telephone calls.
I asked for a digi tag and i was told it's only for business customers...
 
That does not explain how they get a hold of the PIN and password.

Do they also ask this during the call, or does a rogue employee with access to the details provide it?

Agreed. This is only half of the puzzle and a lot of the other people are claiming to not have responded to any phishing emails so how did the scammers get their account numbers and passwords?
 
they're warning their customers? nobody warned me, or my wife... are they picking & choosing who to 'warn'?
 
2. A few minutes thereafter you will receive a call, and the consultant will ask you to confirm some details, and ask you for additional information such as your account number, the type of phone you use, and recent dialed numbers

Those are pieces of data that would help the criminals perform a fraudulent SIM swap, but the victim's ABSA Internet Banking password is conspicuously absent from that list and it is surprising that ABSA did not blatantly blame that on a phishing email, which of course raises more questions.

I stand by my statement that ABSA employees are an integral part of these syndicates, ABSA can try to prove me wrong on this.
 
I have many times had an argument with someone allegedly from ABSA calling me from an unlisted number, wanting me to confirm some security questions before even wanting to tell me what it is about. When I call them on this, there response was that many people answer the question and don't have a problem with answering the security questions. So ABSA is establishing a culture of phoning and asking questions. Not living by their own advice.
 
It is pretty clear ABSA have the implemented the lowest amount of security among the five banks thats the reason why their clients are being targeted. Their implementation of real time interbank transfers system is probably the biggest weakness. They need to add in 48 hour delays for all new beneficiaries for a mont after they are added. Do that its becomes a lot harder to empty out an account
 
I have many times had an argument with someone allegedly from ABSA calling me from an unlisted number, wanting me to confirm some security questions before even wanting to tell me what it is about. When I call them on this, there response was that many people answer the question and don't have a problem with answering the security questions. So ABSA is establishing a culture of phoning and asking questions. Not living by their own advice.

I recently signed up with an armed response company due to a recently burglary and one thing I liked of their system was that when my alarm is triggered and they call to confirm, they have to provide me with their password that I gave them before I provide them with mine. This ensures that I know it is the armed response people calling.

Your ID, address and telephone numbers are easily and cheaply available on-line if you have any property registered in your name and should not be used to confirm identity over the phone. I recently showed a colleague of mine how much information I could get on him using only his address from an on-line deed and ITC search company. The information I obtained included ID number, number of properties owned, date of property purchase, value of bond taken to purchase property, previous owners of the property and their ID numbers, other properties owned by him, full ITC and Experian reports(The ITC and Experian reports does leave a record of who did the last search). I could have gotten more and all of this cost me less than R100.00.
 
This is why if someone calls me from a bank and ask me to confirm my identity, I just disconnect.

It is 100% the banks fault for getting their customers used to providing confirmation identity when they call you, not vice versa.

Banks must cease this practice immediately - it is being exploited.
 
So basically MTN says it's not us it's you and your bank's fault and ABSA says no no it's not us it's you and your cellular service provider's fault.

I really really really hope this is not an inside job in either ABSA or MTN. Let's say it's not, then ultimately yes the customer is at fault for giving his/her personal banking info. But MTN should also have their internal controls revised if it is possible to perform a SIM Swap without any documentation.
 
Top
Sign up to the MyBroadband newsletter
X