Internet banking clients must be alert

“It is possible then to harvest confidential client information such as cellphone numbers and e-mail addresses. Then the cellular service provider, where the client‘s SIM card is swopped for a new one, enables the scamsters to intercept passwords required for sensitive transactions,” Pillay said.

Not sure about the other banks, but with FNB you need to enter the smsed or emailed one time pin [OTP] before you can access/change any of the client contact info.
 
Not sure about the other banks, but with FNB you need to enter the smsed or emailed one time pin [OTP] before you can access/change any of the client contact info.

The ideal would be to have a dongle which generates codes every 2 minutes. This is the way ABN Amro does it. You log in with your user name and password - there is a keyboard and you have to fill in the gaps of the password so you don't ever even send the full password but it may ask for
7 random letters out of 30 of the password. There is also an input box for the code from the dongle. No need for SMS. The dongle and bank server are in sync in terms of time. Each dongle uses a unique seed so that each one generates a different 8 digit number at a different time.

Thief has to know your password and have your dongle to access the account.
 
Not sure about the other banks, but with FNB you need to enter the smsed or emailed one time pin [OTP] before you can access/change any of the client contact info.

The scammer has access to your otp through a swip swap,it doesn't matter when you enter it.

Also if they have used a decent keylogger,they already would have access to your info and balances,backed with screenshots everytime YOU logged in.
 
Last edited:
Ultimately this all boils down to not clicking on emails from your bank with links in them...

But I am confuzzled by the fact that this guy only got R209k of R331k back, because the OTHER banks didn't follow the legislation... since when must this be his problem?... they need to be fined up the wazoo and made to repay this guy every cent.
 
Not sure about the other banks, but with FNB you need to enter the smsed or emailed one time pin [OTP] before you can access/change any of the client contact info.

I think they meant they can harvest information via phishing.

The ideal would be to have a dongle which generates codes every 2 minutes. This is the way ABN Amro does it. You log in with your user name and password - there is a keyboard and you have to fill in the gaps of the password so you don't ever even send the full password but it may ask for
7 random letters out of 30 of the password. There is also an input box for the code from the dongle. No need for SMS. The dongle and bank server are in sync in terms of time. Each dongle uses a unique seed so that each one generates a different 8 digit number at a different time.

Thief has to know your password and have your dongle to access the account.

Capitec Bank's online facility is accompanied by a token device. FNB used to have their Digitag as well. FNB dropped theirs due to low customer pickup (Capitec makes it compulsory to have one). OTPs were born to enable your mobile to become the token device. I don't think anybody thought about SIM swaps.

Ultimately this all boils down to not clicking on emails from your bank with links in them...

But I am confuzzled by the fact that this guy only got R209k of R331k back, because the OTHER banks didn't follow the legislation... since when must this be his problem?... they need to be fined up the wazoo and made to repay this guy every cent.

Customer negligence probably paid a part. He willingly (although unknowingly) gave over his details and access codes to the phishing site. Like the article says, banks always warn customers about this so the customer cannot claim ignorance.
 
Turbo : you're missing the point of my post...

They're only giving him back R209k, because his bank took too long to put a hold on his account, and other banks opened up beneficiary accounts without all the documentation required by law and the money disappeared quickly....

So ultimately the banks are just screwing this oke out of R120k because THEY didn't follow the law.
 
Internet banking clients must be alert

Internet banking clients should just use common sense. To be scammed you really have to be pretty naive. Most people would see the warning sings and back off but too many people are just way too trusting and clueless.

Internet Banking clients should have to go for a video intro session at the bank before their online banking is enabled. That way the bank can give them some basic computer safety tips.
 
Or your new contract tel# has not been deleted by the bank and then they send you an invite to do cell phone banking and ask you to put in a new password. Nearly had 800 k. took me 3 days to get hold of the guy to tell his bank to change his Cell #. Huge hole in the system.
 
It was FNB. SO fone your bank and make sure they have the right cell#
 
Turbo : you're missing the point of my post...

They're only giving him back R209k, because his bank took too long to put a hold on his account, and other banks opened up beneficiary accounts without all the documentation required by law and the money disappeared quickly....

So ultimately the banks are just screwing this oke out of R120k because THEY didn't follow the law.

I agree. The banks who opened the beneficiary accounts should have been pummeled in this case.

However, I don't agree that the customer should have received all their money back. The reasoning behind my post was that the ombudsman could not set a precedent by placing the blame squarely on the banks.

It's a R120k mistake for the customer which would have been a R331k mistake if the banks followed due process.
 
Or your new contract tel# has not been deleted by the bank and then they send you an invite to do cell phone banking and ask you to put in a new password. Nearly had 800 k. took me 3 days to get hold of the guy to tell his bank to change his Cell #. Huge hole in the system.

So you're saying all you need is ownership of the cellphone number to have access to the guys banking profile? Doesn't seem right :confused:
 
The scammer has access to your otp through a swip swap,it doesn't matter when you enter it.

I assume you are referring to sim swops? For that you need the cell number. My point about FNB [which you obviously missed] was that to get to the customer contact details [cell number, email address etc] they would have to enter the OTP. So that means they got the cellphone number from some other means [to do the sim swop] and not from the internet banking site ie. you need the sim to receive the OTP to even view the cellphone number. Hope that makes sense to you.

Also if they have used a decent keylogger,they already would have access to your info and balances,backed with screenshots everytime YOU logged in.

While the above is a danger of internet banking, the article under discussion is about phishing.
 
I assume you are referring to sim swops? For that you need the cell number. My point about FNB [which you obviously missed] was that to get to the customer contact details [cell number, email address etc] they would have to enter the OTP. So that means they got the cellphone number from some other means [to do the sim swop] and not from the internet banking site ie. you need the sim to receive the OTP to even view the cellphone number. Hope that makes sense to you.
Yea thanks,i meant sim swap.Standard also had an onscreen keyboard.It only really protect you in a phishing scam,unless of course you didn't already "update" your details,so why give people a false sense of security.

While the above is a danger of internet banking, the article under discussion is about phishing.
The article is about internet banking safety,they just use one case as an example of phishing.Phishing is a visible thread the user just fall for,keylogging is a stealth method which make it more of a thread.

This is the danger of these articles,an incident happen and suddenly bank officals only highlight that thread.With the classic Absa case,everybody focus on keyloggers and that's when phishing becomes the next big thing.
 
Customer negligence probably paid a part. He willingly (although unknowingly) gave over his details and access codes to the phishing site. Like the article says, banks always warn customers about this so the customer cannot claim ignorance.

Banks also still persist in sending out emails to their customers. That should just go out. FNB sends statements, while Ebucks (FNB) sends emails for ??? reasons, such as a recent "Season's Greetings" thing.

Emails from banks confuse customers. There should simply be NO EMAIL
communication at all between customers and banks. That way the customer never has to worry about when the email is legitimate or not.

If you have an email account you can also logon and view your statement so sending emailed statements is also stupid.
 
I simply delete anything that appears to come from a bank. Legit or otherwise. I do wish I had 300k in my current a/c though.
 
I got an email from "nedbank" requesting me to put in my details, as my account has been locked. Funny thing is, I dont bank with Nedbank. I replied to the email and said I've traced your IP and the police will be there in 5.
 
lol.. If it is a bank I don't use... I go to the Phishing Site (if I can get there... most of them are already blocked) and enter junk data like ...

Name: U R Amoron
Address: 25 Usuck Blvd
City: Bitemeville

.. and other colorful insults.... If anything it must distract them for a few mins.
 
You should try things like DROP DATABASE etc etc...

They may have poor coding skills, and lose everything they've got.
 
The average internet user is SA is quite slow, stupid, naive, etc. Perhaps before registering people for Internet Banking they should make them a web tutorial on internet safety.
 
Top
Sign up to the MyBroadband newsletter
X