Absa responds to SIM swap scam

Limits are set and configured differently at each bank. Not pointless. Some banks only allow limit changes IN the bank. Different controls, different banks.

This people will have copies of your ID, it doesn't take a master photoshop person to change the ID copy and get it "certified", which the bank will accept.

Ever wonder why most of these stories are about relatively large sums of money? these people are targeted, and by the time they are, these guys have a very good idea of the amount of money they can get out.
 
This people will have copies of your ID, it doesn't take a master photoshop person to change the ID copy and get it "certified", which the bank will accept.

Ever wonder why most of these stories are about relatively large sums of money? these people are targeted, and by the time they are, these guys have a very good idea of the amount of money they can get out.

If that was the case they would go into the branches and have cards issued, apply for loans, target non-Internet banking clients as well. Your over complicating it.

These guys aren't that sophisticated. Social engineering - no photoshop.
 
Fek, I'd classify photoshop as easier than social engineering... but hey.

Its not overcomplicating it, its just the reality. These are not smalltime guys, this stuff is being done by big syndicates who have resources.

Slightly outside the Sim Swap and phishing stuff :
My gf's card was cloned, they managed to draw R2000 before we could cancel the card. The only reason we caught it so quickly was due to us being awake randomly at 1am on a weeknight. They use a random ATM located in an industrial area late at night when they're empty, and they also know the cops aren't really interested so they don't have to hurry. They will have 20 or 30 cards from the days haul at various shops etc, if they only get R2000 from each acount thats R40k+ for an easy days work.
 
Last edited:
So if I as your friend send you an email, will you click on a link in the email?

Sorry, should have spelt it out.....Don't click on links in emails from banks where the link takes you to a website that is not your bank but looks like your bank.

You may click on links from your friends except where your friends are phishers.
Its just as easy to send mail 'from' someone else - it appears to be from that person but isnt. Dont believe that just because the return address says Jannie, its not Ojuku from Nigeria.
 
I'm starting not to believe this phishing business and squarely putting the blame on the service providers...INSIDE JOB??....C'Mon, there's a pattern here.

Yep, always seem to involve MTN and ABSA
 
Insurance does not help


ABSA, together with MTN need to look internally and work out how the fraud is happening.
They assume it's phishing, but with all the information provided to MTN for RICA & credit,
no phishing is required.

ABSA has assumed the OTP via SMS is a secure "two-factor authentication"
We all know that assumption is the mother-of-all-f*ups.
Computer Security 101:For two factor authentication you need to prove two items:
http://www.cs.cornell.edu/courses/cs513/2005fa/nnlauthpeople.html
http://netsecurity.about.com/od/quicktips/qt/twofactor.htm
  • what you know
  • what you have
  • who you are
OTP via SMS fails to prove "what you have" as a SIM swop defeats this check.
They need to confirm "what you have" eg Challenge/Response cards and Cryptographic Calculators or
confirming the SMS delivered to the correct IMEI number.

I blame ABSA for
  • Relying on an insecure system
  • Insurance that does not pay
  • Hiding behind T&C's
MTN for
  • collecting RICA & Credit information
  • Not securing RICA and Credit information
  • Not securing SIM Swops

I'd rate your post +5 Informative, if this was /.
 
WTF!!!! Regarding this story,how is the below(quoted) possible, aren't you supposed to present yourself personally at your bank to change limits.



I used to bank with Standard Bank and when I first registered for internet banking I was asked to set limits and whenever I wanted to change those limits I had to physically got to the bank(And currently with Capitec bank I need to go to the bank).:wtf:



Surely Fraud detection ALARM BELLS should have been ringing here(I assume sim swap not longer than ~24hrs for customer to assume "control")

View attachment 48684

You can change limits online with OTP verification at both ABSA and FNB.
 
BTW now that it's OK for governments to make use of peoples' funds in bank accounts to bail banks out, don't expect your money to be safe, regardless of the scammers. If your bank makes some bad loans, you'll bail them out.
 
I do not blame MTN for anything. besides you do not even need a SIM swap to sidejack SMS's See: Zitmo & Zeus-In-The-Mobile. At least with a sim swap you notice the problem if the attackers used the others you would be none the wiser.

Sorry my blame is 100% on the banks doorstep with this one.

I'm safe. I run a feature phone. No cr@ppy smart phone for me. :)

Also it won't happen on locked down systems like the iPhone/iPad.
 
I'm safe. I run a feature phone. No cr@ppy smart phone for me. :)

It can happen to crappy old Symbian as well... http://www.securelist.com/en/analysis/204792194/

Also it won't happen on locked down systems like the iPhone/iPad.

Do not be so sure about that...

http://www.informationweek.com/security/mobile/iphone-trojan-app-sneaks-past-apple-cens/240003363

Yes I know there are less than Android ones but do not ever think there is 100% security in obscurity.
 
It can happen to crappy old Symbian as well... http://www.securelist.com/en/analysis/204792194/

I don't install anything on my phone and don't surf the web with it. So I'm safe. How can it be infected?

Do not be so sure about that...

http://www.informationweek.com/security/mobile/iphone-trojan-app-sneaks-past-apple-cens/240003363

Yes I know there are less than Android ones but do not ever think there is 100% security in obscurity.

Thankfully I buy only obscure stuff like Japanese music games from Namco Bandai. So I'm safe. ^_^

It's not security through obscurity, but security through lock down and degree of app verification. iOS has hundreds of thousands of apps. In total way more than Android, I bet. If you jailbreak your iPhone, you're on your own.
 
This is so lame! They tell you not to click links, duh, but what about all the spyware and viruses sitting on your computer collecting your banking details?

Invest in a good antivirus before doing online banking! Or instead use a device that is less likely to get a virus, like an iPad.

But still, all of this is pointless if it was an inside job.

The victim's banking pc's should be taken in and checked for spyware etc as part of the investigation for the case.
 
Invest in a good antivirus before doing online banking! Or instead use a device that is less likely to get a virus, like an iPad.

Or simply...

2. Banking

Such is the poor security situation in Windows that experts now commonly discourage users from conducting online banking or other sensitive transactions over a Windows PC. Once again, Linux live media can help you out here.

Use your LiveCD, DVD or USB to boot your computer into Linux when you need to do some banking, and you're effectively removing yourself from the vast ranks of the Windows-based targets most malware seeks. Instead, you can launch a browser and do your banking in comparative safety, away from most malware's prying eyes.

Then, when you're done, you can boot back into Windows again, safe in the knowledge that your money is still in your bank account.

Source:
 
Top
Sign up to the MyBroadband newsletter
X