Victim's SIM swop fraud nightmare

bodhi

Executive Member
Joined
Sep 6, 2007
Messages
5,167
Reaction score
635
Location
SA
Internet banking - not for me.

http://www.iol.co.za/index.php?set_id=1&click_id=13&art_id=vn20080112083836189C511499

Derick Lindsay was playing golf in George in the Western Cape when his cellphone number was hijacked almost 1 200km away in Soweto.

Four days later, on Christmas Day, he went online to check his email and discovered a shocking message from his bank confirming a R80 000 payment to an unknown property company.

The transaction had taken place on the day his SIM card was swopped, but, because he was on holiday, Lindsay hadn't switched on his laptop in days.

The transfer was possible as the crooks had received an SMS once-off password from his bank, via Lindsay's hijacked cellphone number - a security measure used by banks to authorise payments to new beneficiaries.

Both Vodacom and Standard Bank - the service providers involved - have washed their hands of the matter, saying victims have been left out of pocket due to their own fault.

Vodacom said that in such cases, personal information has already been compromised before fraudulent SIM swops are done. And Standard Bank said Lindsay unwittingly gave up his online banking details - card number, pin and password - and that they were not responsible.

However, Lindsay and his wife Cheryl are adamant this isn't the case. "I've been Internet banking for years. I've been with Standard Bank for more than 20 years. Why would I do this now?" he asked.

Lindsay's case follows other reported thefts using the same method.

Rhodes University computer science lecturer Barry Irwin said SIM swop frauds weren't random.

"Targets are carefully selected. How exactly remains a mystery, with much in the way of urban legends and conjecture from bank employees, people leaving ATM slips behind and garbage being rifled through." In addition, personal details are kept at all places where accounts are held.

South Africa has world-class electronic banking, but even people who never use public computers and have checks in place are duped into giving away details. Banking details can unknowingly be handed to criminals by users being diverted to false websites. Or key-logging software that logs keystrokes could be secretly recording every detail of the owner's computer activities.

"In general, the Internet is a reflection of the real world, where con artists try to lure the gullible and greedy," said Geoff Rehmet, of Internet Solutions. "As a general rule, you should be just as cautious online as in the physical world."

Standard Bank concluded that Lindsay had been a phishing victim. In an email, with no reference number, the bank says he'd entered secret banking details on a false website purporting to be official.

"Due to the fact that your loss was not facilitated through any fault or negligence of Standard Bank staff or its systems, we regret to advise that Standard Bank will not be able to make payment to you."

The bank was able to recover R435, but would not pay out the remaining R79 565.

No details of the investigation or proof that Lindsay had visited a false website were given to him. Neither are any details of the bank account to which the funds had been transferred. Instead, the number of the banking ombudsman is given for him to lay a complaint if he found the bank's decision unacceptable.

Online behaviour expert Ramon Thomas, of Netucation, said companies offering technological services needed to beef up user awareness. Of the roughly 1,5-million people who banked online, 50 percent checked only statements and balances, and did not do transactions, he pointed out.

"The number one problem we found with the adoption of Internet banking is that people are afraid of their money being stolen and their accounts being hacked."

Phishing had been happening for years, Thomas said. "They knew it was coming. It was just a matter of time. If they took the approach of educational marketing consistently, what would happen is that the client would feel safe and secure. It does not help putting the information on the website - it needs to be done through the traditional channels."

Professor Jan Eloff, head of computer science at the University of Pretoria, said he had witnessed an alarming increase in the volume and complexity of cyber-crimes.

Sim card swop fraud was not new. "It is common knowledge that Internet banking users must always be aware of vulnerabilities, in most cases unknown, and never 'feel' safe," he said. "The dilemma that we as end-users of automated environments such as Internet banking have is that the responsibility for securing your private information is becoming more and more your own responsibility."

Online crime - and in particular sim swop fraud combined with Internet banking theft - was a complex chain of events and involved multiple parties. This made it difficult to find the weak links in the chain, Eloff said.

"The sim swop fraud, as reported in South Africa, is a multifaceted problem and it would be difficult to pinpoint one specific area of vulnerability."

Vulnerabilities needing to be addressed included procedures and technology used by banks; manual and automated procedures for sim card swopping at telecoms providers; technology that linked a phone to a specific sim card; and types of identification documents.

New-media expert Lucien Pierce, of Phukubje Pierce Masithela Attorneys, said banks and cellphone companies would have a clause in contracts stating non-liability, unless they had been grossly negligent. Pierce said cellphone companies had an obligation to do proper and thorough checks before authorising sim swops.

"The victim and the cellphone company would have to share the blame," he said. "Unless the banks have given out that information, you can't really attribute blame to them."

Gross negligence was difficult to prove, but a civil claim was an option, albeit expensive, for victims.

This week, Lindsay, who has sought legal advice, spoke of his shock and anger at the response of both service providers. "It's not a professional way of doing things.

"If I've done something wrong and they can prove it, I'm prepared to suffer the consequences."
 
I use it, I never have problems.
I use FNB and the username and password as well as that one time pin thing.
My password for the FNB web site is so confusing that I have to think about it sometimes and I do NOT use Cellphone banking :)
 
How does "sim card swap" happen? Does someone get a duplicate of your sim card from the service provider?
 
Last edited:
Well, it is not the banks fault. Its halfway the cellphone company and halfway the customers problem.

The customer either user a unsecure public PC or was phished (or somesuch), while the cellphone provider is some way enabled the criminals to get the cellphone code sent by the bank.

I think we need a Cellphone Industry Ombudsman...
 
Cellphone is the common carrier. Its like suing telkom, his ISP, the domain registrar and hosting proivider of the bank etc.

Somehow these clowns cloned or physically got his simcard. They logged on using his details then received his One Time Pin (OTP) and did their evil deed. There is an additional level of protection some banks use - a dongle - it generates a code depending on the time of day and date and that code is then used with the password/username. Other times banks use special graphic keyboards to log on (prevents keylogging)
and/or ask for only certain letters of your password, like insert the 7th, 13th 22nd and 29th letter of your password.

As for keyloggers unless this dude was downloading from local WAREZ sites, I don't think so.
 
Last edited:
Last edited:
Cellphone is the common carrier. Its like suing telkom, his ISP, the domain registrar and hosting proivider of the bank etc.

Somehow these clowns cloned or physically got his simcard. They logged on using his details then received his One Time Pin (OTP) and did their evil deed. There is an additional level of protection some banks use - a dongle - it generates a code depending on the time of day and date and that code is then used with the password/username. Other times banks use special graphic keyboards to log on (prevents keylogging)
and/or ask for only certain letters of your password, like insert the 7th, 13th 22nd and 29th letter of your password.

As for keyloggers unless this dude was downloading from local WAREZ sites, I don't think so.

They don't just choose you randomly.They first log in to see if you have any money.

They don't need to get hold of your simcard.They simply order a new sim for your old number.Old sim got lost or damage or upgrade.Since they already have your info it is quite easy to get verified by the operator.Then they send someone that looks like a company driver/courier to pick it up.They need to transfer the same day cuz your cell won't work anymore with the old card.

Keyloggers don't just keylog,they take screenshots too.So those scrambled keyboards don't help either.What you can't log you can see.
They mostly use custom made keyloggers which is undetectable by av.
 
As an end-user and a consumer, this is rather disconcerting. What measures can you take to prevent this happening to you? I only log into I.B. from work, or home. On either PC, I don't do much surfing, besides certain regular websites that I visit, and sure as heck don't go looking for warez to download.

As for your cellphone, how can you tell if a criminal's done a swap? Use it every day and phone your SP if there's a problem?
 
As an end-user and a consumer, this is rather disconcerting. What measures can you take to prevent this happening to you? I only log into I.B. from work, or home. On either PC, I don't do much surfing, besides certain regular websites that I visit, and sure as heck don't go looking for warez to download.

As for your cellphone, how can you tell if a criminal's done a swap? Use it every day and phone your SP if there's a problem?

First is to make sure you get notified by your bank for logging in.There must be an option somewhere.Once you get the odd sms saying that you're logged in,and you know you ain't,disable your internet banking immediately.Now do the usual,online virus scan first,change passwords,check your cell SP.

Problem is, sometimes it takes ages for that sms to get to you.
 
Can somebody clarify: Did they swop the SIM, clone it or just reprogram a blank SIM to that number?
 
Can somebody clarify: Did they swop the SIM, clone it or just reprogram a blank SIM to that number?

I've that in at least one case, Vodacom/MTN supplied a new SIM card after having one reported as stolen; the perpetrator had ID details or fake ID.
 
They don't just choose you randomly.They first log in to see if you have any money.

They don't need to get hold of your simcard.They simply order a new sim for your old number.Old sim got lost or damage or upgrade.Since they already have your info it is quite easy to get verified by the operator.Then they send someone that looks like a company driver/courier to pick it up.They need to transfer the same day cuz your cell won't work anymore with the old card.

Keyloggers don't just keylog,they take screenshots too.So those scrambled keyboards don't help either.What you can't log you can see.
They mostly use custom made keyloggers which is undetectable by av.

So you're saying those keyloggers take a video of the screen because those keyboards don't show anything - if anything the display shows star characters.
Taking one or a few screen shots won't suffice since you only get 3 chances usually to log on before the password is reset anyway - they'd need to get it right the first time capturing your mouse clicks. And not all keyloggers take screenshots either - many just obtain low level keyboard access and capture keystrokes. Having some sort of firewall or HIPS software should detect this activity : "Application FunnyFreeScreensaver.dll wants to connect to the internet, Deny or Allow?"

What gets me is that to get a keylogger on your machine you'd need to download it first. Unless you surf dodgey local sites or open email attachments you won't get a local keylogger. If you get a foreign keylogger - one which sends info to a non-South African criminal I guess
it won't work unless these guys are connected in some sort of a syndicate.

A keylogger which does its rounds long enough will be picked up by AV software, I would think, unless they custom wrote one although I bet they use the same ones over and over again - whose signatures the AV should pick up.

I guess that's also possible.
 
I've that in at least one case, Vodacom/MTN supplied a new SIM card after having one reported as stolen; the perpetrator had ID details or fake ID.

Well you can't avoid that. If all they request is your address, tel number, date of birth and ID number plus maybe a scan thereof (which could have been obtained from a local video rental shop) - you can't do much against that. In this case the criminals had the login details and the OTP so they really went out of their way to get this guy.
 
So you're saying those keyloggers take a video of the screen because those keyboards don't show anything - if anything the display shows star characters.
Taking one or a few screen shots won't suffice since you only get 3 chances usually to log on before the password is reset anyway - they'd need to get it right the first time capturing your mouse clicks. And not all keyloggers take screenshots either - many just obtain low level keyboard access and capture keystrokes. Having some sort of firewall or HIPS software should detect this activity : "Application FunnyFreeScreensaver.dll wants to connect to the internet, Deny or Allow?"

What gets me is that to get a keylogger on your machine you'd need to download it first. Unless you surf dodgey local sites or open email attachments you won't get a local keylogger. If you get a foreign keylogger - one which sends info to a non-South African criminal I guess
it won't work unless these guys are connected in some sort of a syndicate.

A keylogger which does its rounds long enough will be picked up by AV software, I would think, unless they custom wrote one although I bet they use the same ones over and over again - whose signatures the AV should pick up.

I guess that's also possible.

Sorry but you're assuming a lot of things here.

Don't underestimate your scammer.A scammer that just broke through the highest level of security for online banking will not use a simple commercial keylogger...or using the same old ones over and over.

A good keylogger will be undetectale by AV and firewalls,using some sort of stealth ftp upload feature.The asterisks will be appear on your screen not in the key logs.A good keylogger has mouse click support.Even if not, if your bank has that scrambled keyboard,all the scammer does is set "alert words" or "alert sites",like www.fnb.co.za in his server.Once an alert site or word is detected screenshots will be taken continiously with time stamps,by looking at the pics they have your password.BTW Standard remove that feature.

When they go for the sim swap,they already know EVERYTHING of you and your financial situation.For a real coder an undetectable custom keyloggers is not a challenge.

They don't report your sim as stolen.For that you need a case number.They just upgrade or say sim gets damaged.Your phone will be dead with something like..."please insert correct sim" or "no service".Standard bank guarantee you funds if you use their av and firewall.The only way for them to get out of this mess(not paying the money back) is to say it was phishing...fcukers.

The scary part is:You can get actually away with this.The best way to steal is to get someone to take the fall...fica or not.

BTW this is not new...
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X