Or join a bank that doesn't use SMS authentication...like Capitec.What is needed is a lock down on bank accounts when a sim swop is done that necessitates a branch visit to reactivate.
South Africa’s biggest forum. Discuss, discover, and connect with thousands of members.
Or join a bank that doesn't use SMS authentication...like Capitec.What is needed is a lock down on bank accounts when a sim swop is done that necessitates a branch visit to reactivate.
In one case which Jan is looking at the bank is not willing to provide the details to establish whether this has happened to the client. We asked them for the logs, with the client’s permission, but to date nothing.
From the article: Can you conclusively say that there is no weakness within ABSA (employee or otherwise) which has been providing access to Internet banking accounts to fraudsters (through any means)?
No answer from ABSA
The only really secure way is to have to use a number generator to access your banking site and make payments. AFAIK UBS in Switzerland and Capitec Bank here use this system
Is there any way in which ABSA banking customers can safeguard against large amounts of money being transferred out of their accounts by fraudsters in SIM swap scams?
Move to Capitec
Ok, the Capitec system isn't entirely fool proof, I have figured out a way a hacker can do something.
He would need to have installed a key logger or similar spyware on your PC or you click on the phishing mail, then he would need a script on your PC/his fake webpage interfacing with the Capitec page to run as soon as you authenticate with your dongles generated number to use that number to create beneficiaries and pay into the beneficiary accounts. But he has like 20 or 30 seconds to do it in and then he will be stuck again.
The only really secure way is to have to use a number generator to access your banking site and make payments. AFAIK UBS in Switzerland and Capitec Bank here use this system
Problem with that is that Capitecs android app send the number via 3g or wifi when connected
When you logon on the PC and your Phone is connected via 3G or WiFi then the app gets a push notification and it just prompt you for a pin number. Once pin is entered it sends the confirmation via the app. And your Browser just continues to the next step.
Only Way to bypass capitec's system is to either have the Cyper + Secret or to actually target their mobile apps.
It is the SIM swop procedure that is the exploited loophole.
What I LOVE about Capitec Bank is that they do not rely on RSA ID books ALONE. They fingerprint their customers using a computer scanning device (no ink on fingers). They then use fingerprint identification at branches to assure the identity of customers. In fact, once an account has been opened, Capitec no longer requires a customer to present an RSA ID, but instead simply uses fingerprint identification.
Clearly Capitec is saying that they do not wholly trust the RSA ID book, as most banks do and as ALL mobile networks do.
It seems clear that the exploitation involves counterfeit RSA ID books.
Capitec uses a third party random number generator to create OTP (one time PINs) for use in online banking instead of sending PINs to cell phones.
It seems clear that if all banks and mobile operators adopted the use of fingerprint identification to identify their clients, this would help to secure the process of SIM swaps. Unless your fingerprints match, you can't get a new SIM card.
You are probably correct that Capitec's systems seem to be better than the other banks. But it does not explain how most of the frauds use Capitec accounts to plunder the stolen funds. Their systems can't be that good or perhaps their customers are all fraudsters?
This is a big FAIL for ABSA and MTN.
Who says this isn't an inside job? Remember the Vodavom inside job bank theft a while ago?
FNB phones me, even for R2000 is the transaction looks suspicious to them. It's sometimes annoying since most of the payments to our USA suppliers differ every month due to Rand / Dollar exchange and FNB phones me to verify the transaction every month. But at least I know that our company account is safe. They do with the same with my personal account.
this one kicks off with a phishing message purporting to be from their bank leading them to click on a link
phishing Emails on the web being ABSA ones.
It may be the result of phishing
Wonder what they will do when local thiefs start using Zitmo?
Example:
Source: http://threatpost.com/zitmo-trojan-...-factor-authentication-steal-millions-120612/
Come on ABSA, get your act together and find other means of 2 step authentication. That or start bleeding customers to other banks that do give you piece of mind.


The common trait or explanation for the initiation of these attacks is phishing(even with this "sophisticated" Eurograbber trojan).
From: Absa -Unit [email protected] via cpanel01.safaricombusiness.co.ke
Subject: Customer Service Message
Dear ABSA Client,
Attention! Your online service has been deauthorized.
We suspect someone other than you with IP 117.170.192.235 <-- some random address
making series of incorrect attempts with your card number.
Please confirm your recent activities with us to show
you are not away at this time.
It should be confirmed as soon as possible to
keep it from getting intermitted.
Begin the verification process <-- Google blocks the URL so can not follow it to see where it goes.
Note: This email was sent from a secure server,
please SIGNON to email us as mails sent to this address cannot be answered.
From: Absa. Online <[email protected]> or from ABSA - [email protected] via home.pl
Subject: Important Service Notice or with "Important Service Notification"
Dear ABSA Client,
We noticed a suspicious IP address making series of
incorrect attempts with your card number and we have therefore
temporarily deregistered your online access.
Please confirm your recent access to show
that you are not currently away.
You have to respond with immediate effect to keep
it from getting permanently intermitted.
Initiate the Process <-- Blocked link
Please SIGNON to email us as mails sent to this address wont be delivered.
the payment limit on the account had been increased from R2 000 a day to R500 000, and from R20 000 a month to R500 000
32 payments of between R7 000 and R9 700 were made to the two new beneficiary accounts, which were both held at Capitec.

Oh and for those that wanna know this is how the current ABSA Phising mail looks:
Got about 8 of em in my Gmail SPAM box and do not, and nor did I ever, even bank with ABSA.
Absa Online Banking [email protected] via dedibox.fr