Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Banking Bank Scam on the raise, What are your toughts

views
     
aeiou228
post Jun 15 2022, 09:33 AM

Look at all my stars!!
*******
Senior Member
5,871 posts

Joined: Feb 2006
Astro AEC 8pm yesterday.


Thee are two types of scams. Macau scam and phone hacking.
Macau scam requires scammer calling the potential victim. The recent cases were mostly phone hacking as reported in the above news media.

The following are some of the precautions you can do:
1) Turn off unknown source APK installation.
2) Activate/enable APP Approve or APP Authorize.
3) Set "View only" for account with substantial balance. (Not all online banking support this feature)
4) Go to settings > permission > SMS, check if any unfamiliar apps are allowed to access your SMS. If yes, deny it.
5) Do not side load any unknown APK into your main online banking phone. Instal it on separate phone if you insist.
aeiou228
post Jun 15 2022, 11:17 AM

Look at all my stars!!
*******
Senior Member
5,871 posts

Joined: Feb 2006
QUOTE(KHOdin @ Jun 15 2022, 10:28 AM)
is there any bank still provide hardware token for OTP verification?

more and more banks force us to use app authorization nowadays
*
SMS (OTP/TAC/PAC) security is too venerable to breach, that's why banks up the security level to app authorization. At least until the app authorization can be breached again by the hacker.

As for the physical token, it's not very practical. Prone to malfunction, can't replace battery, hassle to bring along and the biggest problem of all... misplaced it somewhere.
Affin bank however, came out with App version token called Affin Secure. Can carry along wherever you go, never out of battery. Physical token has become obsolete.
aeiou228
post Jun 15 2022, 11:04 PM

Look at all my stars!!
*******
Senior Member
5,871 posts

Joined: Feb 2006
QUOTE(KHOdin @ Jun 15 2022, 04:15 PM)
but it's the same app that you are doing your transaction on, i feel dumb that the 2FA is coming from the same source
*
Affin secure is a dedicated app just for transaction approval only. Can't do other banking transactions.
aeiou228
post Jun 16 2022, 12:43 AM

Look at all my stars!!
*******
Senior Member
5,871 posts

Joined: Feb 2006
QUOTE(MUM @ Jun 15 2022, 11:39 PM)
This Affin secure apps will receives secured information from Affin sent to registered phone numbers..

If the scammer managed to "hijack" the phone number....???
Just like example this recent s'pore ocbc case?

Why some OCBC customers in SMS scams did not get OTPs
https://www.straitstimes.com/tech/tech-news...id-not-get-otps

Why does an SMS appear to be from OCBC when it isn't?
Why do banks use SMS if they are unsecure?
https://www.google.com/url?sa=t&source=web&...K-rrD9W-ZOowkDi
*
Affin Secure is a digital token that only works on an authorized mobile device. You can approve transaction without the SIM being inserted in the phone.
aeiou228
post Jun 16 2022, 10:17 AM

Look at all my stars!!
*******
Senior Member
5,871 posts

Joined: Feb 2006
QUOTE(MUM @ Jun 16 2022, 01:26 AM)
I am not sure how Affin secure works.
But if no need sim in phone,... How Affin knows that the apps in authorised device?
Will it be like the device that downloaded the apps will then act like those physical token that does not need sim?

Also, does one need to carry the non sim inserted device along with the normal sim card inserted device to do online transaction?

Will it be like carry a normal sim card inserted smartphone to do the transaction together with those secure token (individual tac generating device)?
I am currently using the secure token from pbb,... Yes you are correct to mention that it has some inconveniences.
*
1) Similar to Maybank secure2u, you can use Mayban2u App on a registered device with or without SIM slot (non SIM tablet for example)
2) Yes, you need to carry two devices but why wouldn't you register the digital token on your day to day phone ?
3) Yes, it's more convenient than physical token but one downside though, Affin Secure only approve transactions above 10k and the threshold is fixed, you can't adjust the limit in settings. So, given enough time, hacker still can make multiple 10k transactions to steal all your money in the account via OTP/TAC/PAC. I hope Affin can enable adjustable limits in future update.
aeiou228
post Jun 26 2022, 09:42 PM

Look at all my stars!!
*******
Senior Member
5,871 posts

Joined: Feb 2006
https://m.facebook.com/story.php?story_fbid...id=323440711827
Millions of ringgit missing from 40 bank accounts holders. This time, malicious APP is not the culprit, it's insider job instead.

aeiou228
post Aug 20 2022, 10:52 PM

Look at all my stars!!
*******
Senior Member
5,871 posts

Joined: Feb 2006
https://www.facebook.com/294025920750452/po...VdQBl/?sfnsn=mo
Dr also Jean scammed.
aeiou228
post Aug 21 2022, 08:59 AM

Look at all my stars!!
*******
Senior Member
5,871 posts

Joined: Feb 2006
https://m.facebook.com/story.php?story_fbid...823540&sfnsn=mo
Dr's open letter on her FB
aeiou228
post Aug 26 2022, 10:36 PM

Look at all my stars!!
*******
Senior Member
5,871 posts

Joined: Feb 2006
2 more cases reported.

RM7k HLB
user posted image
user posted image

RM82k
https://www.enanyang.my/%E8%A6%81%E9%97%BB/...%84%E5%89%A9800
aeiou228
post Sep 8 2022, 08:52 PM

Look at all my stars!!
*******
Senior Member
5,871 posts

Joined: Feb 2006
PBB 7SEP2022

https://www.facebook.com/groups/10624883604...sn=mo&ref=share
aeiou228
post Sep 27 2022, 10:04 AM

Look at all my stars!!
*******
Senior Member
5,871 posts

Joined: Feb 2006
BNM unveils new measures to strengthen safeguards against financial scams

https://www.thestar.com.my/business/busines...#openShareModal

KUALA LUMPUR: Bank Negara Malaysia (BNM) today announced five additional security measures to be taken by financial institutions in a bid to strengthen safeguards against financial scams, especially online ones.

Governor Tan Sri Nor Shamsiah Mohd Yunus said the modus operandi used by criminals will continue to evolve.
"BNM is therefore continuously intensifying efforts and taking steps to combat scams by introducing additional controls and safeguards from time to time,” she said at the launch of the virtual Financial Cime Exhibition today.


Among the latest measures is requiring financial institutions to migrate from SMS One Time Passwords (OTP) to more secure forms of authentication for online activities or transactions relating to account opening, fund transfers and payments, as well as changes to personal information and account settings.

Nor Shamsiah said financial institutions will also further tighten fraud detection rules and triggers for blocking suspected scam transactions.

"Customers will be immediately alerted when any such activity involving their banking accounts is detected. As an additional measure, financial institutions will block such transactions, and customers will be asked to confirm that such transactions are genuine before they are unblocked,” she said.

Third, a cooling-off period will be observed for the first-time enrolment of online banking services or secure devices, during which no online banking activity is allowed to be conducted.

Moreover, the governor said, customers will be restricted to one mobile or secure device for the authentication of online banking transactions and financial institutions will be required to set up dedicated hotlines for customers to report financial scam incidents.

"Financial institutions have been directed to be more responsive to scam reports lodged by customers. They have also been directed to facilitate efforts to recover and protect stolen funds, including to work with relevant agencies to prevent further losses,” she said.

Nor Shamsiah noted that BNM requires banks in Malaysia to adopt high standards of security, especially for Internet and mobile banking services.

"From time to time, the central bank also issues security advisories to the financial industry highlighting the latest modus operandi of scammers and additional security measures that banks need to implement to protect their customers' savings,” she said.

Nor Shamsiah said the Royal Malaysia Police (PDRM) plays an important role in combating scams, and has implemented various initiatives on this front, including establishing the Commercial Crime Investigation Department (CCID) Scam Response Centre to facilitate the public’s reporting of financial scams.

"BNM will work together with PDRM, the Malaysian Communications and Multimedia Commission (MCMC), and the National Anti-Financial Crime Centre to further elevate the CCID Scam Response Centre as a more systematic information sharing platform that will enable quicker action to prevent further losses,” she said.

According to her, an important aspect in dealing with financial scams is raising public awareness, including of scam tactics used by criminals and the steps that the public can take to avoid becoming victims.

"In this regard, BNM, the financial industry and law enforcement agencies will continue efforts to enhance the effectiveness of awareness programmes and improve on the dissemination of information to the public,” she added.

The virtual Financial Crime Exhibition, organised by the the Museum and Art Gallery of BNM together with PDRM, is aimed at educating the public on financial fraud and can be accessed at https://museum.bnm.gov.my/fce.

It was officiated jointly by Nor Shamsiah and Inspector-General of Police Tan Sri Acryl Sani Abdullah Sani. - Bernama

 

Change to:
| Lo-Fi Version
0.0256sec    1.13    6 queries    GZIP Disabled
Time is now: 23rd December 2025 - 08:59 PM