Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
DuitNow
post Dec 17 2018, 04:49 AM

On my way
****
Junior Member
597 posts

Joined: Oct 2018
QUOTE(aku_ker @ Dec 17 2018, 01:32 AM)
The only issue is you can type your password + random numbers and able to login.it takes more than that to transfer money to unknown account.
For Maybank u know right you can withdraw money without ATM card.

Anyway it's a security flaw and cimb should announce and take action.
*
Can explain more on the above? blink.gif

QUOTE(Jibbynomo @ Dec 17 2018, 01:38 AM)
For me i noticed now transfer money also no need any tac for verification. Crazy. So if they masuk someone acc and no need tac verify... Thats it
*
Which bank can do that? blink.gif

QUOTE(hor @ Dec 17 2018, 02:14 AM)
My wild guess:
1) Business: ok guys we need to remove the 8 char pw limitation
2) Tester: wth I used to type the same but now couldn't login
3) Dev: that's easy, we just attempt login with full input and if cant we try again with first 8 char only

*roll out*

4) Customer: wth I can login with extra junk char
5) Dev: (*oh shit)
*
laugh.gif laugh.gif laugh.gif

QUOTE(teehk_tee @ Dec 17 2018, 02:22 AM)
Cant they void all the old passwords and force customers to update new pw upon login? Many brokerages do this.

Not allow 8char + whatever shit to login.
*
Maybank actually do this a couple of months ago, I was force to change my password a couple of times. Probably kena... hmm.gif

QUOTE(leftycall9 @ Dec 17 2018, 03:16 AM)
CIMB didn't send any warning or anything about this through message or announcement. yeah I'm really pissed :/
it happened to mine and my friend's account. not sure about others but I have changed my password
*
What! blink.gif Password : 12345678 can log into your accounts? doh.gif
DuitNow
post Dec 20 2018, 03:38 PM

On my way
****
Junior Member
597 posts

Joined: Oct 2018
QUOTE(heinlein @ Dec 20 2018, 03:28 PM)
suddenly cimb so keen to solve the problem even send me dispute pdf file to sign for blocking the card and investigate. Something happen?
*
Probably more people making police report? hmm.gif
DuitNow
post Dec 20 2018, 04:11 PM

On my way
****
Junior Member
597 posts

Joined: Oct 2018
QUOTE(heinlein @ Dec 20 2018, 04:00 PM)
I did both of them. I was thinking if someone report to bnm cuz cimb fb got someone receive tac send rm4999 to some guy. Tat guy even sms him for tac.
*
Dont understand, who sent who RM4999? blink.gif Any link?

I think the whole mess getting bigger, people lost alot of money.
DuitNow
post Dec 20 2018, 04:27 PM

On my way
****
Junior Member
597 posts

Joined: Oct 2018
QUOTE(heinlein @ Dec 20 2018, 04:14 PM)
https://www.facebook.com/113376605363982/po...999957/?app=fbl

You scroll down and find kc chan's comment

user posted image
user posted image
*
Cant really made out from the picture or in the facebook but is it apparently the hacker asking the owner for the tac code to transfer the owner money into the hacker account? blink.gif

And the hacker even challenge the owner to made a police report? blink.gif
DuitNow
post Dec 21 2018, 02:09 PM

On my way
****
Junior Member
597 posts

Joined: Oct 2018
QUOTE(heinlein @ Dec 21 2018, 02:03 PM)
From what i realized, first it was paypal. Then there is a TAC spam and some unknown stranger hackers act pity ask help to give him tac. Then poof~ money gone. Better transfer away all the money. Though is good to be kind, its not suitable in this society.
*
Who give tac to other people? blink.gif
DuitNow
post Dec 21 2018, 07:43 PM

On my way
****
Junior Member
597 posts

Joined: Oct 2018
QUOTE(heinlein @ Dec 21 2018, 07:36 PM)
user posted image
Now receive this, dun dare fill. Scare another tactics by scammer
*
Topkek. doh.gif
DuitNow
post Dec 21 2018, 10:30 PM

On my way
****
Junior Member
597 posts

Joined: Oct 2018
QUOTE(kopi @ Dec 21 2018, 10:17 PM)
Which debit the kwik or the atm debit. What about going to bank to ask for replacement card? Can fix this issue?
*
Debit card means atm debit card since its directly link to bank accounts, but if want change need pay RM12.
DuitNow
post Dec 22 2018, 12:08 AM

On my way
****
Junior Member
597 posts

Joined: Oct 2018
QUOTE(Volfeed @ Dec 21 2018, 09:02 PM)
Hacker cannot transfer money without TAC, so he just emptied the account by using favourite bill payment which don't use TAC as revenge. So really need to take care to ensure no one can have access to our account.
*
QUOTE(gilabola @ Dec 21 2018, 11:02 PM)
The guy has Astro saved as favourites which doesn't require a TAC. The money isn't lost because you can ask Astro to refund the overpayment or ask CIMB to make good
*
This really is topkek. doh.gif
DuitNow
post Dec 22 2018, 01:02 AM

On my way
****
Junior Member
597 posts

Joined: Oct 2018
QUOTE(Daylight2018 @ Dec 22 2018, 12:52 AM)
Set debit card limit to RM0
What can hackers do about it?
*
Was wondering about this then below answer.

QUOTE(mamamia @ Dec 22 2018, 12:56 AM)
How to set to RM0? I try to set, the default debit card spending limit was RM10k, then the minimum amount is RM1k.. really WTH!!
*
Most banks allow setting to zero, didnt know cimb only accept min 1k setting only. Guess your next option is going to the bank to replace your existing debit card but need pay RM12 fee.
DuitNow
post Dec 22 2018, 01:17 AM

On my way
****
Junior Member
597 posts

Joined: Oct 2018
QUOTE(mamamia @ Dec 22 2018, 01:03 AM)
The only way now is to deactivate oversea spending / withdrawal which will subsequently deactivate all online purchase..
*
The online purchase feature can call cimb bank cs to disable it. I dont have cimb acc but I got other banks accs, I just call up those banks cs to disable all online purchasing feature.
DuitNow
post Dec 26 2018, 07:57 PM

On my way
****
Junior Member
597 posts

Joined: Oct 2018
QUOTE(ozak @ Dec 26 2018, 09:58 AM)
Been quite sometime never touch this acc.

Than tried check with ATM and online. All freeze. Got to go CIMB branch to activate back.

Most pain in the ass is the Online password change. Got to ask the branch official to call for me only able to reset.
*
There's some sort of procedure for lock down if account not active, eg some banks online banking not active for 3 months lock, accounts not active for 6 months or 1 year also lock.
DuitNow
post Dec 27 2018, 04:06 PM

On my way
****
Junior Member
597 posts

Joined: Oct 2018
QUOTE(vinn @ Dec 27 2018, 08:22 AM)
If the regulations never changed. Account will become dormant if no withdrawal within 6 months. Account will be closed automatically after 7 years
*
You are right, its called dormant not lock.
DuitNow
post Dec 31 2018, 10:50 PM

On my way
****
Junior Member
597 posts

Joined: Oct 2018
QUOTE(kona|kona @ Dec 31 2018, 07:44 AM)
so anyone bother changing their debit card ? how long does it takes
*
Probably less than an hour.

This post has been edited by DuitNow: Dec 31 2018, 10:50 PM

 

Change to:
| Lo-Fi Version
0.0565sec    0.66    7 queries    GZIP Disabled
Time is now: 11th December 2025 - 04:06 PM