Banking App + vishing - how did they do it? + Possible PSA

one poster

Well-Known Member
Joined
May 4, 2021
Messages
232
Reaction score
180
Parents (in their 70's) got taken for a decent chunk of money.

MO:
  • phone call from "fraud dept" flagging suspicious transactions.
  • dad being cautious volunteers no information but asks the caller questions that are answered correctly (caller can name exact bank accounts, types of accounts, also lists number of most recent financial transactions - including date, where and amount). -> dad feels is legitimate call and proceeds to complete steps as requested.
  • to "block" transactions he must now open FNB banking app but not log-in to the app.
  • then receives instructions on things to do via the app - unfortunately he can't recall the exact steps but part of it required typing what might be an unfamiliar username (all in lower case, so highly unlikely to be a new password) into a pop-up, receiving an OTP sms that had to be entered and then received what looked like App notifications/push messages confirming that the suspect transactions were blocked.
  • caller made noticeable effort to keep facade of security ("just enter the OTP, do not say it aloud - I must not hear it").
  • total call duration was just under an hour.
  • bit later dad logs into the baking app and notices money gone.
I suspect the call was a process to link a new device (phone or browser) to their online banking profile. The scam would not have worked without confirmation of what he felt was secure/confidential information that led him to believe it is a legitimate call.

The bank account/types info could possibly come from something like the TransUnion breach but being able to list financial transactions, point to either compromised device/s (giving access to email based "inContact" messages for a recent transaction trail) or bank insider involvement? The email address receiving inContact messages is not listed in haveibeenpwned.

So, questions:
  1. what was the lower-case username part about? ("forgotten username" reset requires info that was not shared and should be useless without a banking password that was not shared).
  2. how did dad receive app notifications of blocked transactions? (when dad logged-in later, there were actual blocked transactions in the transaction history for the amounts "flagged" by the "fraud department").
  3. recommendation for checking android devices for malware (though not impossible, neither parent is likely to click links in sms/emails)?
  4. recommendation for someone/company to check their network (their setup was done by their wisp and I am not convinced it is particularly secure ). PM welcome. (please, and thank you).
EDIT: another (possibly unrelated?) element, in this particular case, that increased willingness to comply with instructions to "block" fraudulent transactions, is that a month prior someone opened a MTN cell contract using dad's info/banking details. (#anotherMTNRICAFail)
 
Last edited:
Do they do internet banking on a computer or just their phones?
 
as far a I know they use both, but started defaulting to phone (actually a separate android tablet)
Spyware / Malware more likely to be on their pc's rather than phone unless they downloading dodgy APK's.
 
Spyware / Malware more likely to be on their pc's rather than phone unless they downloading dodgy APK's.
agree, PC probably more likely (they even drove to the local traffic cop shop to confirm a notification of speeding fine sms, rather than interact in any way with the sms - so they are somewhat cautious).
 
I am sorry, but I disagree, there are ****ing bad actors working inside the banks themselves that are contributing to this.

Also nearly got taken once , by someone that knew so much about my bank accounts, recent online transactions, etc. Rather impossible for an outsider to know most of it, unless you actually worked at the bank. And I know my personal online and other security is great due to the fact that I used to also work in the Cybersec field so take every precaution imaginable - heck I even shred receipts and crap.

Thankfully, after 5 minutes, I said I would call the Fraud line to provide some information and that was a good move on my part.

I can say that the call I received even showed a number that looked like it was in the same range as the FNB DID range.
 
there are ****ing bad actors working inside the banks themselves
100%. That is a definite possibility but not one the average client can do much about, so I am trying to get a sense of how this would have been done should it not have involved insider assistance.

Thankfully, after 5 minutes, I said I would call the Fraud line to provide some information and that was a good move on my part.
THIS.

for the PSA part I think the only thing dad (and anyone that receives this kind of call) could have done different was to say to the caller "give me a reference number or something" (NOT a telephone number), hang up and call the fraud dept on the publicly available number.
 
100%. That is a definite possibility but not one the average client can do much about, so I am trying to get a sense of how this would have been done should it not have involved insider assistance.
It can't. An outside fraudster wouldn't be able to get the banking app to push a notification...
 
Top
Sign up to the MyBroadband newsletter
X