{"id":537493,"date":"2024-05-20T19:07:44","date_gmt":"2024-05-20T17:07:44","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=537493"},"modified":"2024-05-20T19:17:27","modified_gmt":"2024-05-20T17:17:27","slug":"fnb-virtual-cards-safety-warning","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/537493-fnb-virtual-cards-safety-warning.html","title":{"rendered":"FNB Virtual Cards safety warning"},"content":{"rendered":"<p>While FNB\u2019s virtual cards provide great safety features, like a regularly rotating CVV, they are not a silver bullet for card fraud.<\/p>\n<p>Frontend engineer Herman Stander recently <strong><a href=\"https:\/\/mybroadband.co.za\/news\/security\/537453-hacker-shows-how-to-steal-someones-payment-card-details-and-buy-a-tank-of-petrol.html\">fell victim to a phishing attack<\/a><\/strong> in which cybercriminals linked his virtual card to a tap-to-pay digital wallet and cleaned out his bank account.<\/p>\n<p>Unfortunately, the virtual card was linked to his debit card, and his salary had just been paid into his account. They stole it all.<\/p>\n<p>He didn\u2019t receive notifications or SMS messages warning him that transactions were going off against his account.<\/p>\n<p>FNB\u2019s fraud department also didn\u2019t flag that twelve relatively large transactions went off right after one another, many for just under R5,000.<\/p>\n<p>FNB has been promoting its Virtual Card product as a feature that enhances security and prevents card fraud.<\/p>\n<p>It also heavily incentivises clients to use virtual cards by linking them to eBucks rewards.<\/p>\n<p>When FNB told Stander that the loss was his fault for getting phished and it wouldn\u2019t refund him, he set about reverse engineering the attack to understand how it works.<\/p>\n<p>He also developed a <strong><a href=\"https:\/\/www.youtube.com\/watch?v=P4_vq-vqvIc\" target=\"_blank\" rel=\"noopener\">proof-of-concept attack<\/a>,<\/strong> which he tested against his wife\u2019s FNB account to confirm his findings.<\/p>\n<p><a  data-lightbox=\"post-image\" href=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/05\/FNB-Virtual-Card-promise.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-537459\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/05\/FNB-Virtual-Card-promise.jpg\" alt=\"\" width=\"1274\" height=\"800\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/05\/FNB-Virtual-Card-promise.jpg 1274w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/05\/FNB-Virtual-Card-promise-600x377.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/05\/FNB-Virtual-Card-promise-800x502.jpg 800w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/05\/FNB-Virtual-Card-promise-768x482.jpg 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/05\/FNB-Virtual-Card-promise-1200x754.jpg 1200w\" sizes=\"(max-width: 1274px) 100vw, 1274px\" \/><\/a><\/p>\n<p>Stander\u2019s tests showed that when linking a virtual card to a digital wallet like Google Pay, the CVV is only required when initially registering the card on the platform.<\/p>\n<p>The rotating CVV of FNB\u2019s Virtual Card only helps with online shopping-type payments, also known as card-not-present transactions.<\/p>\n<p>After it is linked to a supported digital wallet, the card\u2019s CVV is bypassed.<\/p>\n<p>FNB confirmed this when MyBroadband asked for comment about Stander\u2019s case and attack demo.<\/p>\n<p>\u201cA CVV is not required for card present transactions,\u201d FNB corporate affairs executive Jacqui O\u2019Sullivan said.<\/p>\n<p>\u201cCVV and OTP is required at the time that the digital wallet is registered on a device to transact, in this case, this was done when the customer\u2019s card details were phished and compromised.\u201d<\/p>\n<p>Fortunately, the CVV is not the only thing preventing attackers from registering a card on platforms like Google Pay.<\/p>\n<p>The trick to this attack is for cybercriminals to convince you to send them a one-time PIN that is SMSed to your phone when registering.<\/p>\n<p>They try to do this in many ways, most of which direct you to a fake website designed to look just like the real thing.<\/p>\n<p>In Stander\u2019s case, an SMS directed him to a website that looked like the SA Post Office to pay customs on a parcel he was expecting.<\/p>\n<p>The attackers probably didn\u2019t know their victim was expecting a package. They simply blast out emails and SMSes to databases containing millions of people\u2019s contact details and hope to catch someone.<\/p>\n<p>Attackers also don\u2019t exclusively use the Post Office as an angle of attack. They\u2019ll claim to be from DHL, FedEx, a bank, or a medical aid \u2014 all in the hopes of guessing right once and hooking a victim.<\/p>\n<div id=\"attachment_537463\" style=\"width: 2170px\" class=\"wp-caption aligncenter\"><a  data-lightbox=\"post-image\" href=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/05\/Herman-Standard-POC-FNB-Virtual-Card-attack-phishing-SMS-SAPO-attack-site-Google-Pay.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-537463\" class=\"size-full wp-image-537463\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/05\/Herman-Standard-POC-FNB-Virtual-Card-attack-phishing-SMS-SAPO-attack-site-Google-Pay.jpg\" alt=\"\" width=\"2160\" height=\"1280\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/05\/Herman-Standard-POC-FNB-Virtual-Card-attack-phishing-SMS-SAPO-attack-site-Google-Pay.jpg 2160w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/05\/Herman-Standard-POC-FNB-Virtual-Card-attack-phishing-SMS-SAPO-attack-site-Google-Pay-600x356.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/05\/Herman-Standard-POC-FNB-Virtual-Card-attack-phishing-SMS-SAPO-attack-site-Google-Pay-800x474.jpg 800w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/05\/Herman-Standard-POC-FNB-Virtual-Card-attack-phishing-SMS-SAPO-attack-site-Google-Pay-768x455.jpg 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/05\/Herman-Standard-POC-FNB-Virtual-Card-attack-phishing-SMS-SAPO-attack-site-Google-Pay-1536x910.jpg 1536w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/05\/Herman-Standard-POC-FNB-Virtual-Card-attack-phishing-SMS-SAPO-attack-site-Google-Pay-2048x1214.jpg 2048w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/05\/Herman-Standard-POC-FNB-Virtual-Card-attack-phishing-SMS-SAPO-attack-site-Google-Pay-1200x711.jpg 1200w\" sizes=\"(max-width: 2160px) 100vw, 2160px\" \/><\/a><p id=\"caption-attachment-537463\" class=\"wp-caption-text\">Screenshots from Stander\u2019s proof-of-concept attack: Example phishing SMS (left), attack site (middle), and card details loaded into Google Wallet (right)<\/p><\/div>\n<p>For an attack like this, the fake site will ask you to enter your credit card information as usual for \u201ccustoms clearance\u201d or some other reason.<\/p>\n<p>Once they have your credit card information, they will try to convince you to send the OTP you receive to verify or confirm the payment.<\/p>\n<p>This is a red flag, although even the most vigilant and knowledgeable users might miss it if they are in a rush or otherwise distracted.<\/p>\n<p>However, this would\u2019ve also been one in a series of red flags to watch out for, which is why attackers often try to cloud your judgement with urgency.<\/p>\n<p>Stander\u2019s case highlights several warning signs and security issues to be aware of when making online payments.<\/p>\n<ul>\n<li>Virtual cards are not a silver bullet against card fraud.<\/li>\n<li>If you can manage your credit and have access to a credit card, avoid using debit cards for payments. Banks generally fix credit card fraud much faster.<\/li>\n<li>Be wary when following links from emails, SMSes, WhatsApps, and other messages.<\/li>\n<li>Always check a page\u2019s URL. Don\u2019t just check for a lock icon \u2014 that doesn\u2019t mean the page is safe.<\/li>\n<li>Watch out for typos, spelling mistakes, and similar telltale signs of scams.<\/li>\n<li>You will never be asked to provide a banking OTP to a merchant when making a payment. Ensure transaction verification requests match what you are used to seeing with your bank. This is generally via apps nowadays, not OTPs.<\/li>\n<\/ul>\n<p>\u201cWith cybercriminals becoming more sophisticated, customers are encouraged to remain vigilant and take proactive measures to protect themselves at all times,\u201d O\u2019Sullivan stated.<\/p>\n<p>\u201cWe encourage customers to immediately report any events that may result in fraud on their bank accounts and to use our FNB App to stop or cancel their cards.\u201d<\/p>\n<p>MyBroadband asked FNB for feedback on why Stander didn\u2019t receive transaction notifications when the criminals cleaned out his account using the hijacked virtual card. It did not provide an answer by publication.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Frontend engineer Herman Stander developed a proof-of-concept hack to illustrate concerns regarding the safety of FNB&#8217;s virtual cards.<\/p>\n","protected":false},"author":15,"featured_media":416832,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[10106,27],"tags":[39368,18390,72916,35,94759,27981,417,76422],"class_list":["post-537493","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-banking","category-security","tag-contactless-payments","tag-first-national-bank-fnb","tag-fnb-virtual-card","tag-headline","tag-herman-stander","tag-jacqui-osullivan","tag-phishing","tag-tap-to-pay"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/537493"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=537493"}],"version-history":[{"count":2,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/537493\/revisions"}],"predecessor-version":[{"id":537745,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/537493\/revisions\/537745"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/416832"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=537493"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=537493"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=537493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}