MagicDude4Eva
Banned
Vodacom conveniently does not say that the cellular companies have all the information required to enable internet banking fraud (ie, person's name, address, contact numbers, addresses, ID, banking account details, salary details...) - so no social engineering required ... possibly just a bank contact to provide account balance details and to assist to reset a pin???
It depends. The engineering team would not necessarily have access to all billing details, but people closer to their call-centre and dealerweb applications would have complete insight into billing data, credit scoring information etc. Although we never hear about criminal prosecutions or much detail about the culprits, you can certainly assume that most of them would have had access to privileged information. A great deal of social engineering can be done via the customer portals, retention teams but you would still need to have access to a banking contact to access the accounts with money in it (in most cases you can assume that if customer Varis has a monthly 15K phone bill, he will be loaded and should be a target).
The fraud you don't see at banks are dormant accounts or pre-issued credit-cards (or debit card accounts which did not have the card issued yet). But I think we can safely conclude that both banks and service providers are responsible for SIM swop fraud and neither wants to be accountable for it. Just puzzling that Vodacom goes and says "We have this mechanism to detect a SIM swop, but the banks don't use it" - makes you wonder why.
