Welcome Guest ( Log In | Register )

6 Pages « < 2 3 4 5 6 >Bottom

Outline · [ Standard ] · Linear+

Banking Bank Scam on the raise, What are your toughts

views
     
SUSyklooi
post Aug 21 2022, 12:32 PM

Look at all my stars!!
*******
Senior Member
8,188 posts

Joined: Apr 2013


What if you received the TAC in a separate phone, but revealed it to the scammer?

Never reveal your OTP/TAC to any third party even if the party requesting for such information claims to be from a financial institution, Bank Negara Malaysia or other government agencies.
https://www.rhbgroup.com/others/fraud-aware...ment%20agencies.
CommodoreAmiga
post Aug 21 2022, 12:59 PM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


QUOTE(yklooi @ Aug 21 2022, 12:32 PM)
What if you received the TAC in a separate phone,  but revealed it to the scammer?

Never reveal your OTP/TAC to any third party even if the party requesting for such information claims to be from a financial institution, Bank Negara Malaysia or other government agencies.
https://www.rhbgroup.com/others/fraud-aware...ment%20agencies.
*
I think a lot of the cases is not user revealed to scammers, but totally no TAC. This could be phone hacked, SMS redirected after they receive the OTP and delete it by thealware, so user not aware. Once redirected, they can do whatever they want.
CommodoreAmiga
post Aug 21 2022, 01:01 PM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


QUOTE(soul78 @ Jun 17 2022, 12:03 AM)
nothing to do with malicious apk files and all these bull la at this point in time. There are already statements made by those impacted that they did not install or have clicked on any linked in emails etc.

Banks have to investigate if police says this is not in their purview to investigate. If not it's up to BNM to find out what is the issue.

For now.. you do what you need to safeguard your hard earned money. If banks does not strike confidence from their investors is their problem that people would not put more cash in banks moving forward.

Steps I've taken to protect myself.
- Only have less than 5k at one time in bank.
- Keep more in EPF which requires more manual intervention.
- Limit bank footprint. Have only 1-2 banks.
- If possible have overseas bank if you're able.
- Keep some in cryptos. You are your own bank.
- Keep in physical assets. gold/silver.

Other possiblities:
- Joint account which requires 2 person to remove cash.
- Put money in investment platforms that uses more secure 2FA authentication like 30secs codes i.e google authentication type of platform.
- Secure your email with Yubikey as recovery and Remove your phone number from Gmail recovery procedure.
*
Not good idea. You will lose money faster than scammer can scam you


SUSyklooi
post Aug 21 2022, 01:37 PM

Look at all my stars!!
*******
Senior Member
8,188 posts

Joined: Apr 2013


QUOTE(CommodoreAmiga @ Aug 21 2022, 12:59 PM)
I think a lot of the cases is not user revealed to scammers, but totally no TAC. This could be phone hacked, SMS redirected after they receive the OTP and delete it by thealware, so user not aware. Once redirected, they can do whatever they want.
*
🤔🤔Then it is the problem of the "smartphone" as it allowed downloads of apps that may hv hacking virus...
Not so much of the dumb phone problem... Thus have the extra dump phone just to receives TAC (as you suggested earlier) may not helps much.
CommodoreAmiga
post Aug 21 2022, 02:51 PM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


QUOTE(yklooi @ Aug 21 2022, 01:37 PM)
🤔🤔Then it is the problem of the "smartphone"  as it allowed downloads of apps that may hv hacking virus...
Not so much of the dumb phone problem...  Thus have the extra dump phone just to receives TAC (as you suggested earlier) may not helps much.
*
Yes. It's a known issue. If you download dodgy app other from Playstore, you sendiri cari pasal. I think dumb phones will help, since it is not capable much of anything, so can't download malware and hack, even if you wanted to. Besides, nobody bother to target those obselete dinosaurs anyway.
jack2
post Aug 21 2022, 03:40 PM

Mr
********
All Stars
15,192 posts

Joined: Oct 2004
phone number spoofing
tadashi987
post Aug 21 2022, 04:55 PM

Look at all my stars!!
*******
Senior Member
2,106 posts

Joined: Jul 2018
BNM is losing its reputation with all these cases
SUSBlackagar Boltagon
post Aug 21 2022, 05:27 PM

Getting Started
**
Junior Member
67 posts

Joined: Aug 2022
Try to avoid saving credit card number in apps. If got, remove them now.

Dont simply download apps.

Try use bigpay as intermediate payments if want to use CC. Use only 1 bigpay card online.
CommodoreAmiga
post Aug 21 2022, 05:43 PM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


user posted image

I think I have just received a CIMB fake link by scammer!!

I Certainly don't have any account application in progress!
acbc
post Aug 21 2022, 05:50 PM

Look at all my stars!!
*******
Senior Member
9,050 posts

Joined: Jan 2003
1. Use Truecaller to identify and filter out known scammers.

2. On primary phone, u can install the usual social media and messaging apps but no banking related apps.

3. On secondary phone, use a different number solely for data but block all incoming and outgoing calls. U then install all banking related apps like normal. Link TAC number with dumb phone below. No social media or messaging apps here.

3. On spare dumb phone, use a new number solely for receiving TAC and block in incoming and outgoing calls.

For my case, I'm using the A72 as primary phone with everything loaded. For secondary phone, I opt for OnePlus 7 solely for banking related apps. Has a separate number and cannot receive or make calls. All blocked on the phone itself. And finally, an old Nokia 106 solely for receiving TAC and cannot make or receive calls too. Plus, it is small enough to be in the pocket most of the time. Only need recharging every 2 weeks.

As for the monthly cost, it is RM 38 (U Mobile) for primary phone, RM 28 (DiGi) for secondary and finally RM 3 (Yoodo) for SMS.

Simple security tips.

This post has been edited by acbc: Aug 21 2022, 05:51 PM
CommodoreAmiga
post Aug 21 2022, 06:06 PM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


QUOTE(acbc @ Aug 21 2022, 05:50 PM)
1. Use Truecaller to identify and filter out known scammers.

2. On primary phone, u can install the usual social media and messaging apps but no banking related apps.

3. On secondary phone, use a different number solely for data but block all incoming and outgoing calls. U then install all banking related apps like normal. Link TAC number with dumb phone below. No social media or messaging apps here.

3. On spare dumb phone, use a new number solely for receiving TAC and block in incoming and outgoing calls.

For my case, I'm using the A72 as primary phone with everything loaded. For secondary phone, I opt for OnePlus 7 solely for banking related apps. Has a separate number and cannot receive or make calls. All blocked on the phone itself. And finally, an old Nokia 106 solely for receiving TAC and cannot make or receive calls too. Plus, it is small enough to be in the pocket most of the time. Only need recharging every 2 weeks.

As for the monthly cost, it is RM 38 (U Mobile) for primary phone, RM 28 (DiGi) for secondary and finally RM 3 (Yoodo) for SMS.

Simple security tips.
*
What do you mean by link TAC no to dumb phone? You mean all the bank TAC no goes to the dumb phone? Means none of the bank account will send TAC to phone 1 and 2. What about contact? How do bank contact you? By primary phone? Can you set TAC and contact no separately? I can't remember.
Mijac
post Aug 21 2022, 08:42 PM

On my way
****
Junior Member
538 posts

Joined: Feb 2018
QUOTE(acbc @ Aug 21 2022, 05:50 PM)
1. Use Truecaller to identify and filter out known scammers.

2. On primary phone, u can install the usual social media and messaging apps but no banking related apps.

3. On secondary phone, use a different number solely for data but block all incoming and outgoing calls. U then install all banking related apps like normal. Link TAC number with dumb phone below. No social media or messaging apps here.

3. On spare dumb phone, use a new number solely for receiving TAC and block in incoming and outgoing calls.

For my case, I'm using the A72 as primary phone with everything loaded. For secondary phone, I opt for OnePlus 7 solely for banking related apps. Has a separate number and cannot receive or make calls. All blocked on the phone itself. And finally, an old Nokia 106 solely for receiving TAC and cannot make or receive calls too. Plus, it is small enough to be in the pocket most of the time. Only need recharging every 2 weeks.

As for the monthly cost, it is RM 38 (U Mobile) for primary phone, RM 28 (DiGi) for secondary and finally RM 3 (Yoodo) for SMS.

Simple security tips.
*
Great detail and info.
Interesting read.

Thanks for sharing your simple security tips.
:thumbsup:
red streak
post Aug 21 2022, 08:43 PM

Doto 2 Pinoy Slayer
******
Senior Member
1,594 posts

Joined: Feb 2006


QUOTE(CommodoreAmiga @ Aug 21 2022, 05:43 PM)
user posted image

I think I have just received a CIMB fake link by scammer!!

I Certainly don't have any account application in progress!
*
Let me guess, it's from the 63001 number? hmm.gif
jack2
post Aug 21 2022, 09:42 PM

Mr
********
All Stars
15,192 posts

Joined: Oct 2004
QUOTE(tadashi987 @ Aug 21 2022, 04:55 PM)
BNM is losing its reputation with all these cases
*
it has been so long until now and yet to come out with the solution
Zuchie
post Aug 21 2022, 09:46 PM

New Member
*
Newbie
22 posts

Joined: May 2017


all this is the fault of the national bank. don't know why not tighten the law.
BNM pukimak!
Actually all banks are vulnerable but what happened to CIMB is the worst.

This post has been edited by Zuchie: Aug 21 2022, 09:50 PM
CommodoreAmiga
post Aug 21 2022, 09:51 PM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


QUOTE(red streak @ Aug 21 2022, 08:43 PM)
Let me guess, it's from the 63001 number?  hmm.gif
*
No. From 61750. This number was recently used by DHL to sent me some info on my package recently.
red streak
post Aug 21 2022, 10:13 PM

Doto 2 Pinoy Slayer
******
Senior Member
1,594 posts

Joined: Feb 2006


QUOTE(CommodoreAmiga @ Aug 21 2022, 09:51 PM)
No. From 61750. This number was recently used by DHL to sent me some info on my package recently.
*
That's the number I just got it from. Might be legit since the url is the same as what cimb uses but I still wouldn't click on it. It might just be a mistake since our local retards banks tend to make a bunch of stupid mistakes like that. Hong Leong did a system wide nonsensical test message the other day via their app and then said sorry later.
CommodoreAmiga
post Aug 21 2022, 10:27 PM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


QUOTE(red streak @ Aug 21 2022, 10:13 PM)
That's the number I just got it from. Might be legit since the url is the same as what cimb uses but I still wouldn't click on it. It might just be a mistake since our local retards banks tend to make a bunch of stupid mistakes like that. Hong Leong did a system wide nonsensical test message the other day via their app and then said sorry later.
*
I receive that test message too from HLB. But the above SMS from CIMB is too suspicious.
ZeneticX
post Aug 21 2022, 10:34 PM

stars for what
********
All Stars
12,413 posts

Joined: Jan 2008
From: KL - Cardiff - Subang - Sydney



Last time when I was in UK for few years, I used to have a UK bank account (under Barclays)

They provide something like a physical RSA key, basically a device to generate random code for 2FA. That device is tied to your name/account only. Any transaction have to enter the code to authenticate. This is much more secure than the OTP/TAC system we are using here

Infact now I think about it, even a simple 2FA method using Google authenticator app also more secure. Wonder why banks dont adopt this method

This post has been edited by ZeneticX: Aug 21 2022, 10:40 PM
jack2
post Aug 21 2022, 10:34 PM

Mr
********
All Stars
15,192 posts

Joined: Oct 2004
Why such fake SMS can't be traced to know the origin source/sender?

6 Pages « < 2 3 4 5 6 >Top
 

Change to:
| Lo-Fi Version
0.0223sec    0.73    5 queries    GZIP Disabled
Time is now: 18th December 2025 - 02:50 AM