Absa responds to SIM swap scam

So not their problem and they won't be doing anything more to protect their account holders.

Seems that way ... if anyone can get around their so called 'secure banking' then you are screwed. They may as well just get rid of sms passwords etc, means nothing at the end of the day.
 
Last edited:
At some point we need to accept that crime is everywhere and the only way to prevent online banking related theft is to shut down internet banking.

If I compromise my own account by clicking on a dodgy link, I can hardly expect Absa to take the fall for it. If you want protection, take out insurance.
 
Last edited:
At some point we need to accept that crime is everywhere and the only way to prevent online banking related theft is to shut down internet banking.

If I compromise my own account by clicking on a dodgy link, I can hardly expect Absa to take the fall for it. If you want protection, take out insurance.

No need for insurance. In the case of over R100,000 fraud.. well my bank simply won't allow it. I set a cap. I don't understand how ABSA can allow that amount of money to be transferred without you physically go into the bank and clear the the transfer. (show ID)

I had to do this recently to purchase something over my monthly limit.
 
Last edited:
If you steal the money over more than 24 hours, I'm pretty sure you can get past those R100k restrictions.

If you have all the user information (password, PIN) and his SIM, then you can easily increase those daily limits.

ABSA is probably the most likely target for these scams because of all the phishing Emails on the web being ABSA ones. I haven't seen phising Emails recently for the other banks...

I'd reckon if they build a user profile, like the typical IP address range, OS, browser and amounts drawn, they could also phone up the person if it suddenly changes. Like I know some banks do this with credit cards being used in locations other than the ones used commonly by the person.

ABSA may be able to detect SIM swaps in the near future, but that would require work/collaboration from the mobile service providers.
 
What is needed is a lock down on bank accounts when a sim swop is done that necessitates a branch visit to reactivate.

I am not convinced that all of the frauds are a result of Phishing.
 
What is needed is a lock down on bank accounts when a sim swop is done that necessitates a branch visit to reactivate.

This is a good idea.

But I am kinda siding with ABSA here. The only way a fraudster can get access to your online banking is by knowing your passwords and pins.
And the only way he is going to know those is by some failure on your part.
 
At some point we need to accept that crime is everywhere and the only way to prevent online banking related theft is to shut down internet banking.

If I compromise my own account by clicking on a dodgy link, I can hardly expect Absa to take the fall for it.
If you want protection, take out insurance.
Insurance does not help
She added that, despite having insurance against fraud on her account, ABSA said that the nature of the SIM swap fraud means that the insurance does not cover her.

ABSA, together with MTN need to look internally and work out how the fraud is happening.
They assume it's phishing, but with all the information provided to MTN for RICA & credit,
no phishing is required.

ABSA has assumed the OTP via SMS is a secure "two-factor authentication"
We all know that assumption is the mother-of-all-f*ups.
Computer Security 101:For two factor authentication you need to prove two items:
http://www.cs.cornell.edu/courses/cs513/2005fa/nnlauthpeople.html
http://netsecurity.about.com/od/quicktips/qt/twofactor.htm
  • what you know
  • what you have
  • who you are
OTP via SMS fails to prove "what you have" as a SIM swop defeats this check.
They need to confirm "what you have" eg Challenge/Response cards and Cryptographic Calculators or
confirming the SMS delivered to the correct IMEI number.

I blame ABSA for
  • Relying on an insecure system
  • Insurance that does not pay
  • Hiding behind T&C's
MTN for
  • collecting RICA & Credit information
  • Not securing RICA and Credit information
  • Not securing SIM Swops
 
Last edited:
Wonder what they will do when local thiefs start using Zitmo?

Example:
Online banking customers in Europe are falling victim by the thousands to a new banking Trojan that is infecting Android and BlackBerry devices and is capable of defeating two-factor authentication.

The Trojan, dubbed Eurograbber by researchers at Check Point Software Technologies and Verasafe, is a variant of the Zitmo Trojan. Zitmo, or Zeus-In-The-Mobile, has not moved outside Europe, but could eventually target customers in the United States, for example, as more banks require a second form of authentication for access to their online accounts.

To date, the researchers said, Eurograbber has infected more than 30,000 users and stolen an estimated 36 million Euros. Once the Trojan infects a customer’s PC and mobile device, it is able to transfer funds from a compromised account without the victim’s knowledge in amounts ranging from 500 to 250,000 Euros.

“Eurograbber is an excellent example of a successful targeted, sophisticated and stealthy attack. The threat from custom designed, targeted attacks like Eurograbber is real and is not going away,” wrote Eran Kalige of Verasafe and Darrell Burkey of Check Point in a research report. The victim banks were not identified in the report, but Kalige and Burkey said the financial institutions, as well as law enforcement, have been notified.

Like most targeted attacks, this one kicks off with a phishing message purporting to be from their bank leading them to click on a link which downloads the Trojan onto their PC. The next time the victim logs onto their banking account, the Trojan hijacks the session and injects JavaScript onto the banking page instructing them to proceed through a security upgrade. The message instructs the user to install software that will encrypt transactions from their mobile device, which is used as a second form of authentication via an SMS message sent to the device.

The victim enters their mobile number and device type. In the background, a connection is made to a command and control server where stolen data is stored and further instructions await. The Trojan then sends an SMS to the victim’s mobile that includes a link that will download the Trojan to the phone as well. A device-appropriate version of the malware is sent in the location-appropriate language. A verification code is sent that the victim must enter once the upgrade process is complete.

“Further evidence of the sophistication of the Eurograbber attack, this response informs the attackers when a particular bank customer is now controlled by the Eurograbber attack,” the report said.

The victim then gets a message on their mobile and PC that the security upgrade is complete and they can continue with their banking. In the background, the Trojan is able to hijack the session and start its own transaction in the background, transferring funds to a mule account owned by the attackers.

The key here is the Trojan’s ability to circumvent the second-factor of authentication, or Transaction Authorization Number (TAN) sent via SMS to the user’s mobile. The Trojan gets the SMS and sends the TAN via relay phones and proxy servers to the command and control server’s SQL database. The Trojan uses the TAN to complete its transaction, while the customer sees none of the fraudulent activity.

“In order to avoid detection, the attackers used several different domain names and servers, some of which were proxy servers to further complicate detection,” the report said. “If detected, the attackers could easily and quickly replace their infrastructure thus ensuring the integrity of their attack infrastructure, and ensuring the continuity of their operation and illicit money flow.”

Zitmo traditionally targeted the Android platform, but earlier this year, a version of Zitmo for BlackBerry surfaced. BlackBerry’s use by corporate executives gives the Trojan access to high-value executives, the report said.
Source: http://threatpost.com/zitmo-trojan-...-factor-authentication-steal-millions-120612/

Come on ABSA, get your act together and find other means of 2 step authentication. That or start bleeding customers to other banks that do give you piece of mind.

I Looove this part:

Can you conclusively say that there is no weakness within ABSA (employee or otherwise) which has been providing access to Internet banking accounts to fraudsters (through any means)?

No answer from ABSA

Is there any way in which ABSA banking customers can safeguard against large amounts of money being transferred out of their accounts by fraudsters in SIM swap scams?

No answer from ABSA

in short: Its your fault because we say it is.....
 
Last edited:
10 out of 10 for this, how can they not have an answer for the last question, then they should close the method, it is porous and exposes client to fraud and here they are admitting that.
 
I am not convinced that all of the frauds are a result of Phishing.
It may be the result of phishing, but that just seems to be a convenient way for MTN and ABSA to shift the blame.
But I am kinda siding with ABSA here. The only way a fraudster can get access to your online banking is by knowing your passwords and pins.
And the only way he is going to know those is by some failure on your part.
Not true. Those passwords and pins can be reset by the bank, so it can be done by someone going into the bank with fake identification or by someone working at the bank.
 
MTN for
  • collecting RICA & Credit information
  • Not securing RICA and Credit information
  • Not securing SIM Swops

I do not blame MTN for anything. besides you do not even need a SIM swap to sidejack SMS's See: Zitmo & Zeus-In-The-Mobile. At least with a sim swap you notice the problem if the attackers used the others you would be none the wiser.

Sorry my blame is 100% on the banks doorstep with this one.
 
So not their problem and they won't be doing anything more to protect their account holders.

Yep, I got to the part where they threw their hands up and said 'it's not our problem' and didn't read further. I'm already over ABSA. This debarcle is going to be a HUGE blow to their client base IMO.
 
I do not blame MTN for anything. besides you do not even need a SIM swap to sidejack SMS's See: Zitmo & Zeus-In-The-Mobile. At least with a sim swap you notice the problem if the attackers used the others you would be none the wiser.

Sorry my blame is 100% on the banks doorstep with this one.

MTN are certainly partly to blame, considering 1) the sim swaps take place at their agents and by their staff, 2) they haven't bothered to do anything about it despite NUMEROUS events taking place... if the agents can't control their staff, MTN has no option but to shut them down IMO, but they clearly don't want to do that.

In a nutshell, this kind of fraud needs people from both sides to be involved... right now, the fact that people are involved from sides is just an excuse for either side to blame the other and shirk responsibility.

Has our country become so corrupt that a representative of a company can defraud the companies clients while the company says 'it's not our problem'?
 
Last edited:
Not true. Those passwords and pins can be reset by the bank, so it can be done by someone going into the bank with fake identification or by someone working at the bank.

Then there would be a record of that and the bank would be liable.
 
I just don't understand how absa can't just give a call to the client saying lots of money is being transfered if it you? no then freez the accounts. simple.

Transferring like R195 000 to other bank accounts within a few minutes is supposed to be flag as suspicious end of story.
 
Then there would be a record of that and the bank would be liable.
In one case which Jan is looking at the bank is not willing to provide the details to establish whether this has happened to the client. We asked them for the logs, with the client’s permission, but to date nothing.

From the article: Can you conclusively say that there is no weakness within ABSA (employee or otherwise) which has been providing access to Internet banking accounts to fraudsters (through any means)?

No answer from ABSA
 
Top
Sign up to the MyBroadband newsletter
X