ABSA explains how SIM swap fraud happens

How the hell do they perform a sim swap without a valid ID.
I assume that RICA demands that's you produce one when applying for a SIM.
 
I bet my bottom dolla most of the phishing comes from that 'SARS owes you money' spam mail to obtain account numbers and further details. As for SIM 'illegal' swaps, well it's a joke if it has been going on since 2007. Surely there are many ways to prevent this. (And I can only guess that these illegal SIM swaps happens after hours ? could be wrong though).
 
Last edited:
My advice to any ABSA client using internet banking is to close the account and go elsewhere because it better to be proactive. The amount of discomfort due to theft of your cash will take much more effort to recover than just moving your money. That is if you get the money back.
 
ABSA conveniently omitted to mention that it is their employees who get to check who has a sizeable bank balance and obtain their personal details (including cell number) then pass them on to their friends who then do the sim swaps.
 
It is currently not clear why ABSA, which uses similar Internet banking security to other banks, is the main target of SIM swap fraud.

ummmmm....

Well to me it would indicate that the whole thing is a bit of an inside job. I mean it cannot be pot luck. Same goes for MTN. I do not know what the exact procedure is with sim swaps, but I would imagine they would normally require you to give proof of identity. Why did that one MTN branch come up so many times?

This reeks of collusion.
 
ABSA conveniently omitted to mention that it is their employees who get to check who has a sizeable bank balance and obtain their personal details (including cell number) then pass them on to their friends who then do the sim swaps.

I agree with this, there has to be someone on the inside (most probably in the home loans department since most funds seem to be transferred out of an open bond account) that leaks the clients information but what I still don't get is how they manage to get the pin and password as this information is not available just to any bank employee.

This could also be an internal job from MTN, since it has happened before in vodacom
Big SMS banking scam exposed (2009 article)
 
I agree with this, there has to be someone on the inside (most probably in the home loans department since most funds seem to be transferred out of an open bond account) that leaks the clients information but what I still don't get is how they manage to get the pin and password as this information is not available just to any bank employee.
[/URL]
Some methods they might get username/pin
1. Keyloggers
2. Phishing via email, web or phone calls
3. Someone on the inside could leak/sell the password/pin database or obtained by hacking. It will be encrypted however weak pins and password could be found with dictionary attacks especially if the encrypted data is unsalted.
4. Trojans/Viruses on your pc or smartphone spying on you. Uploading browser passwords etc.
5. People using same passwords on other sites they register on.
6. Possible back door or bug/exploit allowing entry.

These are possibilities I can come up with off the top of my head. I dunno why banks think Phishing is the only possibility. Probably because then they can deny liability and blame the customers.
 
Top
Sign up to the MyBroadband newsletter
X