The simple fraud questions MTN and Cell C cannot answer

Vodacom conveniently does not say that the cellular companies have all the information required to enable internet banking fraud (ie, person's name, address, contact numbers, addresses, ID, banking account details, salary details...) - so no social engineering required ... possibly just a bank contact to provide account balance details and to assist to reset a pin???

It depends. The engineering team would not necessarily have access to all billing details, but people closer to their call-centre and dealerweb applications would have complete insight into billing data, credit scoring information etc. Although we never hear about criminal prosecutions or much detail about the culprits, you can certainly assume that most of them would have had access to privileged information. A great deal of social engineering can be done via the customer portals, retention teams but you would still need to have access to a banking contact to access the accounts with money in it (in most cases you can assume that if customer Varis has a monthly 15K phone bill, he will be loaded and should be a target).

The fraud you don't see at banks are dormant accounts or pre-issued credit-cards (or debit card accounts which did not have the card issued yet). But I think we can safely conclude that both banks and service providers are responsible for SIM swop fraud and neither wants to be accountable for it. Just puzzling that Vodacom goes and says "We have this mechanism to detect a SIM swop, but the banks don't use it" - makes you wonder why.
 
It depends. The engineering team would not necessarily have access to all billing details, but people closer to their call-centre and dealerweb applications would have complete insight into billing data, credit scoring information etc. Although we never hear about criminal prosecutions or much detail about the culprits, you can certainly assume that most of them would have had access to privileged information. A great deal of social engineering can be done via the customer portals, retention teams but you would still need to have access to a banking contact to access the accounts with money in it (in most cases you can assume that if customer Varis has a monthly 15K phone bill, he will be loaded and should be a target).

The fraud you don't see at banks are dormant accounts or pre-issued credit-cards (or debit card accounts which did not have the card issued yet). But I think we can safely conclude that both banks and service providers are responsible for SIM swop fraud and neither wants to be accountable for it. Just puzzling that Vodacom goes and says "We have this mechanism to detect a SIM swop, but some of the banks don't use it" - makes you wonder why.

Corrected that for you.

In another thread someone posted of just how that had happened to them after a SIM swap, the bank didn't allow them to immediately create new beneficiaries, because they had seen the SIM was swapped.
 
Corrected that for you.

In another thread someone posted of just how that had happened to them after a SIM swap, the bank didn't allow them to immediately create new beneficiaries, because they had seen the SIM was swapped.

Thanks. Out of interest (more so for the MyBB journalists or any of the SIM Swop victims): Has anyone ever lodged a complaint with OBSSA and possibly PASA? Perhaps I missed this, but I can not recall that for example OBSSA has ruled against the banks being negligent - I guess in most cases banks will just settle to avoid a public precedence with this. I would have also expected that perhaps PASA (or maybe even SARB) would have provided guidelines for banks to authenticate customers for internet banking - it's not like this is an issue unique us and there are more elegant ways to resolve this problem than to rely on a cellular service provider.
 
Corrected that for you.

In another thread someone posted of just how that had happened to them after a SIM swap, the bank didn't allow them to immediately create new beneficiaries, because they had seen the SIM was swapped.

I had the same, ported my sim to Telkom, most bank transactions was blocked for almost two weeks from cellphone banking, couldn't even buy more than just a few rand worth of airtime. Rather annoying at first, but reassuring when I thought about it more.
 
Oh yes, another one, ex-GF ignoring my calls on a contract SIM, that I'm still paying for, for a whole day and I needed some info urgently, doing a SIM swap the next morning so that that SIM got disabled made her quickly get in touch.
Now that's a good reason !!
 
I've been thinking, when we order phones online, you're usually asked to provide copy of ID & proof of residence for RICA, what if they, the scammers, are also working with these drivers to get our info? How safe is it honestly?
 
I've been thinking, when we order phones online, you're usually asked to provide copy of ID & proof of residence for FICA, what if they, the scammers, are also working with these drivers to get our info? How safe is it honestly?

Good point. I signed up for a new FNB account online, they sent their couriers with the card and to collect my FICA documents. FNB never received those documents. They asked me a week later to email / fax them as they hadn't received them. I did that. I eventually still had to go in in person for over an hour to FICA - they couldn't find any of these docs.

One of the many reasons I gave up on FNB.
 
My daughter had a scary interaction with FNB. She relocated to Sydney last year (BTW she used to work for FNB) and they found a lost wallet in a picnic area. She saw that it belonged to a South African from the cards in the wallet. She phoned FNB to try and contact the owner, and they had no problem with providing her with his cell number and e-mail address.
Fortunately she is honest and managed to find the guy, but if she was dishonest she could have used the information.

I found a wallet in the car-park at Kenilworth Centre. It also had an FNB card in it, plus a driving licence. FNB in KC declined to accept it, instead telling me to go the SAPS Claremont. Getting there I was berated for not handing it in at FNB. So I brought it home and found a business card from a car dealer. On calling him, he recognised the name on the FNB card and gave me the phone number. I understand that the SAPS are reluctant to handle this as it requires a bit of work on their part
 
I found a wallet in the car-park at Kenilworth Centre. It also had an FNB card in it, plus a driving licence. FNB in KC declined to accept it, instead telling me to go the SAPS Claremont. Getting there I was berated for not handing it in at FNB. So I brought it home and found a business card from a car dealer. On calling him, he recognised the name on the FNB card and gave me the phone number. I understand that the SAPS are reluctant to handle this as it requires a bit of work on their part

Neither of those two should have given you the runaround. What do the cops think they exist for in the first place. Though to be fair, they are farting into the wind with the resources they have.
 
I found a card at a ATM. Called the relevant bank, provided the details on the card and my contact detail, they called that person, that person then contacted me and had their card returned to them,
 
It's pretty ****ing simple for the Operators to curb this...

On a sim swap request, have the customer supply an alternative number to be contacted on. Customers have Password set up with the operators when they interact with 808. Verify client's details and pin before processing the request...

One would easily then establish if the swaps are done internally without authentication and one can see who viewed the client's profile in the days leading up to the sim swap.

But...

It's too much work. They would rather just receive your money instead of looking after your interests.

Simple to implement... but alas...
 
I don't buy Vodacom's phishing excuse... although it can happen, I think very few people would actually follow through with it these days... and I'm pretty sure if it happened to someone in the IT industry, Vodacom (and other Telco's) would use the same excuse.
 
I've been thinking, when we order phones online, you're usually asked to provide copy of ID & proof of residence for RICA, what if they, the scammers, are also working with these drivers to get our info? How safe is it honestly?

You're only asked to RICA if the phone comes with a sim card. Buying a phone online without a SIM requires no ID or proof of residence whatsoever. RICA only applies to SIM cards, not phones.
 
You're only asked to RICA if the phone comes with a sim card. Buying a phone online without a SIM requires no ID or proof of residence whatsoever. RICA only applies to SIM cards, not phones.

The problem is that most retailers insist that you take a sim with a phone, and you cannot leave without Rica registration.
 
Last edited:
The problem is that most retailers insist that you take a sim with a phone, and you cannot leave with Rica registration.

Yip, I've encountered this before. I just laugh at them and walk out of the store, they obviously don't want my cash. If you want to buy a phone without any hassles just buy it off Takealot. They don't insist that you get a useless sim card with their phones.
 
Even worse with Telkom, they have some undocumented limit on the amount of Sim card you're allow to own, and when you reach that limit it you cannot Rica until a person with more that three baincells know what to do.
 
Top
Sign up to the MyBroadband newsletter
X