Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Banking Bank Scam on the raise, What are your toughts

views
     
CommodoreAmiga
post Aug 21 2022, 10:44 AM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


I am thinking now to buy an old Nokia dedicated for receiving TAC. Will this be workable? But some bank apps use a combination of secureapp and TAC depending on the type of transactions.

Can't hack a dumb phone right?
CommodoreAmiga
post Aug 21 2022, 12:59 PM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


QUOTE(yklooi @ Aug 21 2022, 12:32 PM)
What if you received the TAC in a separate phone,  but revealed it to the scammer?

Never reveal your OTP/TAC to any third party even if the party requesting for such information claims to be from a financial institution, Bank Negara Malaysia or other government agencies.
https://www.rhbgroup.com/others/fraud-aware...ment%20agencies.
*
I think a lot of the cases is not user revealed to scammers, but totally no TAC. This could be phone hacked, SMS redirected after they receive the OTP and delete it by thealware, so user not aware. Once redirected, they can do whatever they want.
CommodoreAmiga
post Aug 21 2022, 01:01 PM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


QUOTE(soul78 @ Jun 17 2022, 12:03 AM)
nothing to do with malicious apk files and all these bull la at this point in time. There are already statements made by those impacted that they did not install or have clicked on any linked in emails etc.

Banks have to investigate if police says this is not in their purview to investigate. If not it's up to BNM to find out what is the issue.

For now.. you do what you need to safeguard your hard earned money. If banks does not strike confidence from their investors is their problem that people would not put more cash in banks moving forward.

Steps I've taken to protect myself.
- Only have less than 5k at one time in bank.
- Keep more in EPF which requires more manual intervention.
- Limit bank footprint. Have only 1-2 banks.
- If possible have overseas bank if you're able.
- Keep some in cryptos. You are your own bank.
- Keep in physical assets. gold/silver.

Other possiblities:
- Joint account which requires 2 person to remove cash.
- Put money in investment platforms that uses more secure 2FA authentication like 30secs codes i.e google authentication type of platform.
- Secure your email with Yubikey as recovery and Remove your phone number from Gmail recovery procedure.
*
Not good idea. You will lose money faster than scammer can scam you


CommodoreAmiga
post Aug 21 2022, 02:51 PM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


QUOTE(yklooi @ Aug 21 2022, 01:37 PM)
🤔🤔Then it is the problem of the "smartphone"  as it allowed downloads of apps that may hv hacking virus...
Not so much of the dumb phone problem...  Thus have the extra dump phone just to receives TAC (as you suggested earlier) may not helps much.
*
Yes. It's a known issue. If you download dodgy app other from Playstore, you sendiri cari pasal. I think dumb phones will help, since it is not capable much of anything, so can't download malware and hack, even if you wanted to. Besides, nobody bother to target those obselete dinosaurs anyway.
CommodoreAmiga
post Aug 21 2022, 05:43 PM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


user posted image

I think I have just received a CIMB fake link by scammer!!

I Certainly don't have any account application in progress!
CommodoreAmiga
post Aug 21 2022, 06:06 PM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


QUOTE(acbc @ Aug 21 2022, 05:50 PM)
1. Use Truecaller to identify and filter out known scammers.

2. On primary phone, u can install the usual social media and messaging apps but no banking related apps.

3. On secondary phone, use a different number solely for data but block all incoming and outgoing calls. U then install all banking related apps like normal. Link TAC number with dumb phone below. No social media or messaging apps here.

3. On spare dumb phone, use a new number solely for receiving TAC and block in incoming and outgoing calls.

For my case, I'm using the A72 as primary phone with everything loaded. For secondary phone, I opt for OnePlus 7 solely for banking related apps. Has a separate number and cannot receive or make calls. All blocked on the phone itself. And finally, an old Nokia 106 solely for receiving TAC and cannot make or receive calls too. Plus, it is small enough to be in the pocket most of the time. Only need recharging every 2 weeks.

As for the monthly cost, it is RM 38 (U Mobile) for primary phone, RM 28 (DiGi) for secondary and finally RM 3 (Yoodo) for SMS.

Simple security tips.
*
What do you mean by link TAC no to dumb phone? You mean all the bank TAC no goes to the dumb phone? Means none of the bank account will send TAC to phone 1 and 2. What about contact? How do bank contact you? By primary phone? Can you set TAC and contact no separately? I can't remember.
CommodoreAmiga
post Aug 21 2022, 09:51 PM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


QUOTE(red streak @ Aug 21 2022, 08:43 PM)
Let me guess, it's from the 63001 number?  hmm.gif
*
No. From 61750. This number was recently used by DHL to sent me some info on my package recently.
CommodoreAmiga
post Aug 21 2022, 10:27 PM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


QUOTE(red streak @ Aug 21 2022, 10:13 PM)
That's the number I just got it from. Might be legit since the url is the same as what cimb uses but I still wouldn't click on it. It might just be a mistake since our local retards banks tend to make a bunch of stupid mistakes like that. Hong Leong did a system wide nonsensical test message the other day via their app and then said sorry later.
*
I receive that test message too from HLB. But the above SMS from CIMB is too suspicious.
CommodoreAmiga
post Sep 20 2022, 07:27 PM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


This is why I have changed my TAc SMS to a Nokia dumb phone with no data line. sweat.gif
CommodoreAmiga
post Sep 27 2022, 10:23 AM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


Another simple method. Allow user to disable midnight transactions. Say between 12am to 7am. A lot of cases happens when you are sleeping. Surely most people don't do shopping midnight (unless got those sales) and anything so urgent meh? Can always wait to transfer in the morning.
CommodoreAmiga
post Sep 27 2022, 04:39 PM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


QUOTE(KHOdin @ Sep 27 2022, 01:23 PM)
seem like great idea but why separating tac phone and bank apps ya?
sad that we need to take all these security precautions on our own hand
*
Because smartphone too smart. One of the common hack is via malware downloaded, once they have your Id and password, they need the TAC to make setting changes and transactions approval. If the TAC is sent to the same phone (usually it is for most people), they will be able to redirect that TAC to them and delete the TAC from your phone, hence a lot of cases users claim didn't receive any TAC. If your TAC is received on the dumb phone, even your smartphone hacked, they can't do anything because they don't have the TAC. It is near impossible to hack dumb phone...no app store to download, don't have USb port, and don't subscribe any data line to it.
CommodoreAmiga
post Sep 28 2022, 07:06 AM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


QUOTE(acbc @ Sep 27 2022, 08:55 PM)
1. Use Truecaller to identify and filter out known scammers. Install on both phones if possible.

2. On primary phone, u can install the usual social media and messaging apps but no banking related or wallet apps.

3. On secondary phone, use a different number solely for data but block all incoming and outgoing calls. U then install all banking related apps like normal. Activate SecureTAC on the bank apps and tie to the secondary phone number only. A dumb phone no longer useful due to the lack of TAC. No social media or messaging apps.

4. Be sure to fill in your contact numbers properly. For the bank to contact u, use the primary number and for SecureTAC, use the secondary number. Some banks may require u to enter the secondary number from the ATM or online.

For my case, I'm using the A72 as primary phone with everything loaded. For secondary phone, I opt for OnePlus 7 solely for banking related apps. Has a separate number with Truecaller installed to monitor which calls coming in. U may set the app to block all calls not in the contact list for extreme security.

As for the monthly cost, it is RM 38 (U Mobile) for primary phone and RM 28 (DiGi) for secondary.

Simple security tips.

** Updated 27/09 to support SecureTAC only **
*
Problem is there are still some banks that use TAC and some mixed. I am not sure which is which, some bank still use TAC when you change your settings like transactions limit etc.
CommodoreAmiga
post Sep 28 2022, 10:10 AM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


QUOTE(acbc @ Sep 28 2022, 07:23 AM)
Starting next month, no more TAC according to BNM.
*
QUOTE(cybpsych @ Sep 28 2022, 08:52 AM)
starting next month?

didnt see BNM set a deadline though. they just put some guidelines and recommendations.
*
Yeah, where can change so fast. This is Malaysia. They will drag another 6 mths or more if no deadline. Malaysia boleh.
CommodoreAmiga
post Sep 29 2022, 06:23 AM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


QUOTE(TY155 @ Sep 28 2022, 02:28 PM)
Actually whenever there is any security update / patch, i will always run and install it. Where some old ppl say do not upgrade it as it slow down your phone. Im like ... ??? What? ~

Reason ambank set not gonna support those device below android 10 below, i guess its because, Android 10 and above has more security restriction.
*
Like some people still insisting on using Windows XP or 7. Lol.
CommodoreAmiga
post Sep 29 2022, 06:25 AM

Look at all my stars!!
*******
Senior Member
3,864 posts

Joined: Jun 2022


QUOTE(CommodoreAmiga @ Sep 28 2022, 10:10 AM)
Yeah, where can change so fast. This is Malaysia. They will drag another 6 mths or more if no deadline. Malaysia boleh.
*
Maybank just announced complete transition sometime middle of 2023, as expected.

 

Change to:
| Lo-Fi Version
0.0278sec    0.70    6 queries    GZIP Disabled
Time is now: 17th December 2025 - 06:34 AM