This is how SMS banking fraudsters did it

It was just a matter of time....!
...and the cat & mouse game continues ad infinitum..... new security measures will be introduced and the criminals will find new creative ways around them.
Best is to limit your exposure by keeping a seperate transactional account especially for internet banking and keep your primary account offline. Unfortunately, security always costs, thanks to greed and the criminal society we live in today.
 
Noobs: fail
Banks: fail.
Vodacom: fail.
FICA: fail.

Who is at all surprised?
 
Do we have any more info about the suspect from vodacom? I would like to have a chat with him if is not to far from PE area. (and yes, I have the authority to interrogate most inmates involved in non violent crimes) Mind you, I can track him thru the internal channels too. It will be interesting to hear, first hand, how he come up with the idea :D
 
The idea is nothing new, but I suppose the execution is a little new for us in SA. The situation that played out here is unfortunate, but I still feel that the average criminal won't be able to replicate this. Sure, this was a syndicate, but the problem with syndicates is in the fact that they are well nested, with a foothold right where they want it.

If the banks applied FICA more consistently, they could maybe have made a few more arrests, but recovering the money will always be a longshot.

Things that the article doesn't mention: the customers, who after all the warnings NOT to respond to such mails still do it and also the ease with which email can be faked. If we realistically want to crucify the networks and the banks then we might as well include the ISP's in the witch hunt. This was a crime and a properly planned one. It was detected and for that Vodacom deserves some credit.
 
Why do they call it social engineering? It should be called social manipulation. Is engineering the in-word for this decade?

The short time frame in which the ‘false’ dual-SMS is active means that the legitimate owner of the SIM was typically unaware of the downtime and therefore would not suspect anything untoward.
Transparency fail.
I have often looked at that Vodacom website and wondered why it is that I can see so little.

NOW, let me raise a very important issue here:

YOUR CELL PHONE NUMBER IS NOT THE KIND OF INFORMATION THAT YOU WANT TO HAND OUT.

I have objected to RICA's implementation where they require a cell phone number on this forum many times.
This is just one of the reasons that you'd want to keep your cell phone number private.

And, that big hole in the FICA setup is BLAZINGLY OBVIOUS.
If the freaking ID Book system is failing, how on earth can any system based on the ID Book system work?

Besides that, I can pay somebody R200 to open up a bank account in their name, and then hand all it's details over to me.
Throwing FICA at the security problems just generated a lot of paperwork.

Does anybody here actually really believe that I cannot generate a Telkom account with my little R580 printer?

:(
 
3 years ago I had a long discussion with my ABSA bank manager regarding fraud.

I wanted their systems to send me and SMS and an EMail the moment money left my account to an account number that was not on my own approved list.

I was informed then that at some point the system would be able to send me an SMS every time money left or entered the account.

Now, this is useless to me. I would be getting smses and emails like spam. I wanted to view the exceptions, not the norm.

All my attempts to explain how SPAMMING does not create security because eventually spam is ignored fell onto deaf ears.
 
surely their system should log any changes and or many people should know about it?!
 
yup rica makes this easier to tie the two together(unless the person has a contract)
 
yup rica makes this easier to tie the two together(unless the person has a contract)
You're saying that RICA made it easier for the cell phone number to be associated with the bank account owner?
I doubt that RICA was implemented for that cell number at all.
 
I want one of those ...

Where can I get me a fraudulent back account?

SMS interception and the registration of fraudulent back accounts were part.

Do I have to join the Nigerians or the ANC?
 
This is the problem with security, you always get the one retard that can't behave himself after a few drinks and hands info over to anybody willing to listen.....

But however alot of people are forced by syndicates to do work for them in various means and ways aswell.

Long ago a fraudster committed fraud of over R1Mill just by listening to two bank employees talk on a bus and this all went down in PTA.
 
This doesn't say much for FICA, and for the future of RICA either.

Although, maybe you don't need all the documentation to open a "back" account.

B
 
YOUR CELL PHONE NUMBER IS NOT THE KIND OF INFORMATION THAT YOU WANT TO HAND OUT.

What can you do with my cell number, except to call/SMS me? This was the last step of the process, after they already had coaxed the bank account details and PIN from the victim.

I think you're concerned about the wrong set of numbers.
 
I do my utmost to keep my personal details personal. However, if the DA managed to get hold of my new cellphone number, less than amonth after I changed it, what chance do I have? The *person* that caled me said the number was obtained from the 'national consumer database', which means that somebody, somewhere, in their official capacity, is making money from onselling MY PERSONAL information. The only people that had this number on record at that time, was VOdacom, and ABSA bank. I know for a fact that banks used to sell contact info to marketing companies - don't know if it still is the case.

So in summary, to those that make all these kuk rules to keep us consumers in check, start where it matters: regulate and penalise financial institutions (not just banks, I include retail stores, financiers of every description, municipalities, credit regulators, the lot) for failure to protect their customers' information.

And to all those morons that fall for phising scams, well, good luck.
 
Bring PCI DSS to all
financial institutions (not just banks, I include retail stores, financiers of every description, municipalities, credit regulators, the lot)

I do my utmost to keep my personal details personal. However, if the DA managed to get hold of my new cellphone number, less than amonth after I changed it, what chance do I have? The *person* that caled me said the number was obtained from the 'national consumer database', which means that somebody, somewhere, in their official capacity, is making money from onselling MY PERSONAL information. The only people that had this number on record at that time, was VOdacom, and ABSA bank. I know for a fact that banks used to sell contact info to marketing companies - don't know if it still is the case.

So in summary, to those that make all these kuk rules to keep us consumers in check, start where it matters: regulate and penalise financial institutions (not just banks, I include retail stores, financiers of every description, municipalities, credit regulators, the lot) for failure to protect their customers' information.

And to all those morons that fall for phising scams, well, good luck.
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X