Absa responds to SIM swap scam

What is needed is a lock down on bank accounts when a sim swop is done that necessitates a branch visit to reactivate.
Or join a bank that doesn't use SMS authentication...like Capitec.
 
The only really secure way is to have to use a number generator to access your banking site and make payments. AFAIK UBS in Switzerland and Capitec Bank here use this system
 
In one case which Jan is looking at the bank is not willing to provide the details to establish whether this has happened to the client. We asked them for the logs, with the client’s permission, but to date nothing.

From the article: Can you conclusively say that there is no weakness within ABSA (employee or otherwise) which has been providing access to Internet banking accounts to fraudsters (through any means)?

No answer from ABSA

This is worrying. It seems these banks are lean on the PR side... but perhaps they realise that the more they say, the worse for them. I for one vote with my feet in the absence of sound PR from any organisation.

Why are our banks always the last companies to take responsibility... I reckon it boils down to the fact that they feel that they don't have to.
 
Last edited:
The only really secure way is to have to use a number generator to access your banking site and make payments. AFAIK UBS in Switzerland and Capitec Bank here use this system

Why is SMS used (unencrypted) when there's USSD? Nedbank uses USSD for all one time payments and beneficiary additions, as well as the first payment to a beneficiary during a session. So my Q is - why are Absa accounts being targeted and not for example, Nedbank (which doesn't require OTP to log in)? Is there some technical reason perhaps? Is the USSD method more secure that a sim swap won't get around?
 
I agree with the last two posters.

Is there any way in which ABSA banking customers can safeguard against large amounts of money being transferred out of their accounts by fraudsters in SIM swap scams?

Move to Capitec

Fixed it for you ABSA... :D

Ok, the Capitec system isn't entirely fool proof, I have figured out a way a hacker can do something.

He would need to have installed a key logger or similar spyware on your PC or you click on the phishing mail, then he would need a script on your PC/his fake webpage interfacing with the Capitec page to run as soon as you authenticate with your dongles generated number to use that number to create beneficiaries and pay into the beneficiary accounts. But he has like 20 or 30 seconds to do it in and then he will be stuck again.
 
Ok, the Capitec system isn't entirely fool proof, I have figured out a way a hacker can do something.

He would need to have installed a key logger or similar spyware on your PC or you click on the phishing mail, then he would need a script on your PC/his fake webpage interfacing with the Capitec page to run as soon as you authenticate with your dongles generated number to use that number to create beneficiaries and pay into the beneficiary accounts. But he has like 20 or 30 seconds to do it in and then he will be stuck again.

Problem with that is that Capitecs android app send the number via 3g or wifi when connected

When you logon on the PC and your Phone is connected via 3G or WiFi then the app gets a push notification and it just prompt you for a pin number. Once pin is entered it sends the confirmation via the app. And your Browser just continues to the next step.

Only Way to bypass capitec's system is to either have the Cyper + Secret or to actually target their mobile apps.
 
The only really secure way is to have to use a number generator to access your banking site and make payments. AFAIK UBS in Switzerland and Capitec Bank here use this system


And FNB had it and replaced it with the SMS system.
 
Problem with that is that Capitecs android app send the number via 3g or wifi when connected

When you logon on the PC and your Phone is connected via 3G or WiFi then the app gets a push notification and it just prompt you for a pin number. Once pin is entered it sends the confirmation via the app. And your Browser just continues to the next step.

Only Way to bypass capitec's system is to either have the Cyper + Secret or to actually target their mobile apps.

I don't have an app, phone batteries can die. Using the dongle. So don't know how the app does or does not work.
 
It is the SIM swop procedure that is the exploited loophole.

What I LOVE about Capitec Bank is that they do not rely on RSA ID books ALONE. They fingerprint their customers using a computer scanning device (no ink on fingers). They then use fingerprint identification at branches to assure the identity of customers. In fact, once an account has been opened, Capitec no longer requires a customer to present an RSA ID, but instead simply uses fingerprint identification.

Clearly Capitec is saying that they do not wholly trust the RSA ID book, as most banks do and as ALL mobile networks do.

It seems clear that the exploitation involves counterfeit RSA ID books.

Capitec uses a third party random number generator to create OTP (one time PINs) for use in online banking instead of sending PINs to cell phones.

It seems clear that if all banks and mobile operators adopted the use of fingerprint identification to identify their clients, this would help to secure the process of SIM swaps. Unless your fingerprints match, you can't get a new SIM card.
 
I think it's time all banks start to use security tokens like RSA SecurID which have no physical connection to the device being used for banking. Fortunately I don't face the problem of my accounts being plundered because they're pretty much empty the day after pay day. :) Worst case scenario is I lose one month's pay.
 
It is the SIM swop procedure that is the exploited loophole.

What I LOVE about Capitec Bank is that they do not rely on RSA ID books ALONE. They fingerprint their customers using a computer scanning device (no ink on fingers). They then use fingerprint identification at branches to assure the identity of customers. In fact, once an account has been opened, Capitec no longer requires a customer to present an RSA ID, but instead simply uses fingerprint identification.

Clearly Capitec is saying that they do not wholly trust the RSA ID book, as most banks do and as ALL mobile networks do.

It seems clear that the exploitation involves counterfeit RSA ID books.

Capitec uses a third party random number generator to create OTP (one time PINs) for use in online banking instead of sending PINs to cell phones.

It seems clear that if all banks and mobile operators adopted the use of fingerprint identification to identify their clients, this would help to secure the process of SIM swaps. Unless your fingerprints match, you can't get a new SIM card.

You are probably correct that Capitec's systems seem to be better than the other banks. But it does not explain how most of the frauds use Capitec accounts to plunder the stolen funds. Their systems can't be that good or perhaps their customers are all fraudsters?
 
You are probably correct that Capitec's systems seem to be better than the other banks. But it does not explain how most of the frauds use Capitec accounts to plunder the stolen funds. Their systems can't be that good or perhaps their customers are all fraudsters?

Or just maybe they know its a better bank as there systems are safer. Think about it if you knew how easy it is to defraud someone that use bank X would you intrust your money to that bank :)
 
http://www.iol.co.za/business/perso...couple-losing-r280-000-1.1507183#.UX04n50aLYU

Another ABSA + MTN simswap scam victim.

And the recipients were again Capitec account holders.

So here we have all the same culprits again. So now ABSA is to blame for using a insecure SMS system, MTN for allowing fraudulent sim swaps and I suggest now Capitec or at least whomever holds the accounts (Capitec has finger prints, IDs, and facial photos taken at the branch) . If you share the account like that you should be prosecuted (for breaking FICA laws) and profiting from the crime.
 
Last edited:
This is a big FAIL for ABSA and MTN.

Who says this isn't an inside job? Remember the Vodavom inside job bank theft a while ago?

FNB phones me, even for R2000 is the transaction looks suspicious to them. It's sometimes annoying since most of the payments to our USA suppliers differ every month due to Rand / Dollar exchange and FNB phones me to verify the transaction every month. But at least I know that our company account is safe. They do with the same with my personal account.
 
This is a big FAIL for ABSA and MTN.

Who says this isn't an inside job? Remember the Vodavom inside job bank theft a while ago?

FNB phones me, even for R2000 is the transaction looks suspicious to them. It's sometimes annoying since most of the payments to our USA suppliers differ every month due to Rand / Dollar exchange and FNB phones me to verify the transaction every month. But at least I know that our company account is safe. They do with the same with my personal account.

Yes, funny thing that there has been no Vodacom or Cell C and no Standard Bank, Nedbank or FNB scam/simswap news reports with the additional media focus on this issue currently. I'm sure it happens but must be a much rarer event.
 
The common trait or explanation for the initiation of these attacks is phishing(even with this "sophisticated" Eurograbber trojan).

this one kicks off with a phishing message purporting to be from their bank leading them to click on a link

phishing Emails on the web being ABSA ones.

It may be the result of phishing

If people could damn well not click on any thing they have not initiated,like the many sms messages/emails some of my colleagues and friends click on purporting that they've won some large amount of monies.I always ask them "did you voluntarily enter a competition?" and most often the answer is "No".:wtf:They get so shocked when I then start explaining about phishing,trojans and keyloggers etc etc. You'd be surprised at the levels of ignorance some people have about online banking security or even with their email,social network accounts(like the time someone never logged out of their gmail account and as an emergency I wanted to log-in to my gmail account to retrieve some info quickly from their work desktop and voila! it instantly auto logged me into this individuals account:wtf:).
 
The common trait or explanation for the initiation of these attacks is phishing(even with this "sophisticated" Eurograbber trojan).

True, but they use lame ones now cause they work.... wait till they start getting real sly.

For example, Send a Joke mail with a page link to install the a trojan on your PC, while displaying some jokes page.
Next time you log in to bank Trojan kicks off saying you need to install some added security feature to continue using your banking. In doing this you just install the real MIN trojan + Zitmo.

After that bob's your uncle....

Worst part is if they do it now while all this is in the news a crapload of people will fall for the Added security prompt.

Oh and for those that wanna know this is how the current ABSA Phising mail looks:

From: Absa -Unit [email protected] via cpanel01.safaricombusiness.co.ke
Subject: Customer Service Message
Dear ABSA Client,

Attention! Your online service has been deauthorized.
We suspect someone other than you with IP 117.170.192.235 <-- some random address
making series of incorrect attempts with your card number.

Please confirm your recent activities with us to show
you are not away at this time.
It should be confirmed as soon as possible to
keep it from getting intermitted.

Begin the verification process <-- Google blocks the URL so can not follow it to see where it goes.

Note: This email was sent from a secure server,
please SIGNON to email us as mails sent to this address cannot be answered.

or

From: Absa. Online <[email protected]> or from ABSA - [email protected] via home.pl
Subject: Important Service Notice or with "Important Service Notification"

Dear ABSA Client,

We noticed a suspicious IP address making series of
incorrect attempts with your card number and we have therefore
temporarily deregistered your online access.

Please confirm your recent access to show
that you are not currently away.
You have to respond with immediate effect to keep
it from getting permanently intermitted.

Initiate the Process <-- Blocked link

Please SIGNON to email us as mails sent to this address wont be delivered.

Got about 8 of em in my Gmail SPAM box and do not, and nor did I ever, even bank with ABSA.
 
Last edited:

WTF!!!! Regarding this story,how is the below(quoted) possible, aren't you supposed to present yourself personally at your bank to change limits.

the payment limit on the account had been increased from R2 000 a day to R500 000, and from R20 000 a month to R500 000

I used to bank with Standard Bank and when I first registered for internet banking I was asked to set limits and whenever I wanted to change those limits I had to physically got to the bank(And currently with Capitec bank I need to go to the bank).:wtf:

32 payments of between R7 000 and R9 700 were made to the two new beneficiary accounts, which were both held at Capitec.

Surely Fraud detection ALARM BELLS should have been ringing here(I assume sim swap not longer than ~24hrs for customer to assume "control")

aggravated.jpg
 
Oh and for those that wanna know this is how the current ABSA Phising mail looks:
Got about 8 of em in my Gmail SPAM box and do not, and nor did I ever, even bank with ABSA.

:cry: The "From" on it's own is a dead give away that all is not kosher. Never mind people's ignorance isn't it time banks are compelled to educate all new internet banking subscribers on the basics of online fraud and prevention(I understand I'm being drastic here).

Yeah also got a couple from ABSA in my spam,though never banked with them.*sigh*

I mean....The "From" line should tell all.

Absa Online Banking [email protected] via dedibox.fr
 
Top
Sign up to the MyBroadband newsletter
X