Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 Grabpay unauthorized transaction, financial fraud

views
     
TSvexus
post Jan 24 2023, 06:40 PM

Master of Eatery & Sleeping
*******
Senior Member
6,660 posts

Joined: Jan 2003
From: Palace of sexology



QUOTE(emburrar @ Jan 24 2023, 02:13 PM)
Grab banyak problem now
*
Grab customer care is not responding. They are clueless.

Are they going to blame affected user & runaway from this matter?
CyberKewl
post Jan 26 2023, 04:13 PM

Look at all my stars!!
*******
Senior Member
2,900 posts

Joined: Dec 2004


i use a sort of "throwaway" debit card to solve the problem and link to that bank. Recently used a bank called "Rize" - a digital bank where signup takes 5-15 minutes, then u can request for a free debit card and link it with that. In that bank account u just do duitnow transfer every now and then limit to about 300-500 RM (or the amount u willing to lose in case hacker managed to steal the money) so you wont lose everything in case kena hacked. That's one way to do it.

I manually transfer money and its not difficult once u add it to your favorite.
TSvexus
post Jan 26 2023, 04:43 PM

Master of Eatery & Sleeping
*******
Senior Member
6,660 posts

Joined: Jan 2003
From: Palace of sexology



QUOTE(CyberKewl @ Jan 26 2023, 04:13 PM)
i use a sort of "throwaway" debit card to solve the problem and link to that bank. Recently used a bank called "Rize" - a digital bank where signup takes 5-15 minutes, then u can request for a free debit card and link it with that. In that bank account u just do duitnow transfer every now and then limit to about 300-500 RM (or the amount u willing to lose in case hacker managed to steal the money) so you wont lose everything in case kena hacked. That's one way to do it.

I manually transfer money and its not difficult once u add it to your favorite.
*
Same concept like duitnow. Hack can hack rise & disperse your $$$ through a gateway.

If rize has breach in their security, no way you can escape. Some unlucky user will be targeted innocently.
CyberKewl
post Jan 26 2023, 06:10 PM

Look at all my stars!!
*******
Senior Member
2,900 posts

Joined: Dec 2004


QUOTE(vexus @ Jan 26 2023, 04:43 PM)
Same concept like duitnow. Hack can hack rise & disperse your $$$ through a gateway.

If rize has breach in their security, no way you can escape. Some unlucky user will be targeted innocently.
*
that's why i call it a throwaway debit card account. hack also i lose whatever little is in there - i decide. Its not my salary account or main banking account so hack away. Yes i lose money but as I said - only amount I am willing to risk and lose.
SUSCincai lar
post Jan 26 2023, 06:16 PM

Getting Started
**
Junior Member
113 posts

Joined: Apr 2019


i only use grab for transport,.. so never use their wallet on anything else,.. no grab food,.. no grab pay,..
Szzz
post Jan 26 2023, 06:32 PM

Getting Started
**
Junior Member
120 posts

Joined: Dec 2006
QUOTE(silverhawk @ Jan 24 2023, 11:44 AM)
Likely got issue on 2 sides

1) Grab - How could revenue harvest log into user account?

2) Revenue Harvest - This is where likely someone in the company that has access to api keys or customer data logged into the victims account to initiate the transfer.

I'm not surprised if revenue harvest outsourced some of their work to indonesia, which is quite a common practice.
*
I'm not well versed with Grab API but if its similar to payment gateways, I don't see how Revenue Harvest can even get customer payment tokens without them logging into customer's Grab account.
CyberKewl
post Jan 26 2023, 06:56 PM

Look at all my stars!!
*******
Senior Member
2,900 posts

Joined: Dec 2004


One of the guys that kena has gotten his money back through his grabpay wallet and bank account (but unsure if received by bank as he had blocked the account):
https://www.reddit.com/r/malaysia/comments/...allet/?sort=new
YoungMan
post Jan 26 2023, 08:44 PM

Look at all my stars!!
*******
Senior Member
6,808 posts

Joined: Oct 2008
From: Kuala Lumpur



Good luck if got use paylater. Cannot simply remove your CC without getting paylater deactivated through Grab customer service
forgotoldlogin
post Jan 26 2023, 08:57 PM

Getting Started
**
Junior Member
198 posts

Joined: Jan 2022
What is Bank Negara doing? All their so call fintech have security like cap ayam and so easy to bypass. Award so many licenses, security all meh.
TSvexus
post Jan 26 2023, 09:09 PM

Master of Eatery & Sleeping
*******
Senior Member
6,660 posts

Joined: Jan 2003
From: Palace of sexology



top notch western system also being espionage

https://www.pcworld.com/article/1478487/350...l-accounts.html
GymBoi
post Jan 26 2023, 10:43 PM

Regular
******
Senior Member
1,401 posts

Joined: Feb 2006
sohai grab cant even top up without saving cc? I removed all cc .. now need top up .. need add cc and remove again lol .. when this shit gonna be over
TSvexus
post Jan 26 2023, 11:10 PM

Master of Eatery & Sleeping
*******
Senior Member
6,660 posts

Joined: Jan 2003
From: Palace of sexology



QUOTE(GymBoi @ Jan 26 2023, 10:43 PM)
sohai grab cant even top up without saving cc? I removed all cc .. now need top up .. need add cc and remove again lol .. when this shit gonna be over
*
some bank charge for adding card in online apps
PJng
post Jan 26 2023, 11:13 PM

10k Club
********
All Stars
12,041 posts

Joined: Oct 2017


QUOTE(vexus @ Jan 26 2023, 11:10 PM)
some bank charge for adding card in online apps
*
Where got suxh thing
CyberKewl
post Jan 26 2023, 11:21 PM

Look at all my stars!!
*******
Senior Member
2,900 posts

Joined: Dec 2004


QUOTE(vexus @ Jan 26 2023, 11:10 PM)
some bank charge for adding card in online apps
*
charges are at grab/merchant side. Grab charges RM5 if i recall but they refund immediately. TNG charges RM1 but depending on back, might not get back immediately..mine for TNG i didnt get back even my RM1 but not fussed up about it..at least grab refunds immediately when u make card payment - this is to "test" to ensure your card is legit.
leymahn
post Jan 26 2023, 11:25 PM

Getting Started
**
Junior Member
150 posts

Joined: Mar 2008


weh i link my bank account for easy grab topup liao
AdisonMak
post Jan 26 2023, 11:32 PM

Getting Started
**
Junior Member
168 posts

Joined: May 2012
From: On bed blindfolded, with both arms and legs tied.
QUOTE(vexus @ Jan 24 2023, 12:31 PM)
everything is ewallet now. Shop in lazada/shopee also require to save credit card info.

TnG ewallet also require to save your credit card info.

Even your local bank, duitnow, mae? also link in apps. You can't runaway.
*
Not sure about shopee but for lazada unless recent update (haven't update the app yet) change it, it is not mandatory to save cc info.

Recently lots of app UI have arsehole design. It prompt you to save the info but the option to not doing so is hidden away from view. so do scroll around abit.
maxpudding
post Jan 26 2023, 11:33 PM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(PJng @ Jan 26 2023, 11:13 PM)
Where got suxh thing
*
Some banks or platform have one time charge, but will be refunded.
silverhawk
post Jan 27 2023, 10:29 AM

Eyes on Target
Group Icon
Elite
4,956 posts

Joined: Jan 2003


QUOTE(Szzz @ Jan 26 2023, 06:32 PM)
I'm not well versed with Grab API but if its similar to payment gateways, I don't see how Revenue Harvest can even get customer payment tokens without them logging into customer's Grab account.
*
I'm not too sure as well, but the pattern suggests it. Since not everyone's facing the problem, just a handful of people and revenue harvest is the common denominator. My guess would be the token being captured somehow by a POS/Terminal that the customer use grabpay to pay with. Websites "should" redirect to grab's servers so no token exchange in the process.

Would be a huge security flaw to allow tokens to be captured by 3rd party and for it not to be a single-use token. Grab has some accountability here as well.
lawrencek
post Jan 27 2023, 11:31 AM

Getting Started
**
Junior Member
109 posts

Joined: Apr 2009


QUOTE(sadlyfalways @ Jan 24 2023, 07:28 AM)
hello bro, why you care about grab now?? you care about your own money.

grab has made some mistakes and YOU lost your money.

they need to fix it

btw are you an android user? because i see a lot of this no otp cases happening to android users with normal banking apps too
*
Maybe using China Brand andriod phone ?
CyberKewl
post Jan 27 2023, 03:00 PM

Look at all my stars!!
*******
Senior Member
2,900 posts

Joined: Dec 2004


QUOTE(lawrencek @ Jan 27 2023, 11:31 AM)
Maybe using China Brand andriod phone ?
*
one of the guys thar kena is using iphone so its not android or apk related

4 Pages « < 2 3 4Top
 

Change to:
| Lo-Fi Version
0.0196sec    0.67    5 queries    GZIP Disabled
Time is now: 11th December 2025 - 07:16 PM