Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 RM2822.16 gone via unauthorized transaction in PBe, Please be extra careful!!!

views
     
TSfelicious
post Oct 11 2008, 05:20 PM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
QUOTE(cherroy @ Oct 11 2008, 02:02 PM)
5. So if hacker got online user name and password, they can do the transfer already because HP is in their hand.

6. So main question and key area is how they obtain those username and password. TS write in the HP or on the stolen stuff?
*
My handphone is not in their hand. My stuffs was lost on January. I canceled my sim card when I lost my sim card already. I don't think there can be 2 active sim cards, right?
I don't write my username and password in handphone or stolen stuff.
TSfelicious
post Oct 12 2008, 09:06 PM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
QUOTE(andrekua @ Oct 12 2008, 12:16 AM)
Are you sure its being done by e-banking?
First of all, I would say its impossible. Even though its just 5digit TAC, how many times he had to tried in order to get the right one. Must be through your atm or something. The chance of guessing the correct tac code is very small leh.. 1/99999.
*
The bank said that it is done by e-banking. And TAC is applied.

QUOTE(Clareen @ Oct 12 2008, 04:06 AM)
I think should be related to the staff in Public bank. Because it's not easy to hack in one account, some more need TAC, that fellow able to get the TAC no as well.
*
We suspected the PBB staff too. All the while my PBB don't have much money. PBB is mainly for PTPTN loan to bank in to me for me to pay college fees. Few days after PTPTN loan banked in to me, the money 'spoof' from my account already.

QUOTE(socratesman @ Oct 12 2008, 05:03 AM)
I join others here who don't understand how the hacker got the TAC.
Two ways I can think of:-

1) Hacker intercepts SMS sent to victim's mobile phone.
2) Hacker uses keylogger to obtain user/pass/PAC and use it while victim is still logged in to e-banking.

For item #2, here's a quote from PBB website.
*
But I didn't log in to PBE on that day.

QUOTE(DotA 5.84C -AR @ Oct 12 2008, 01:03 PM)
felicious:

it has been few weeks already but you still haven't get back your money. i think you should put your concern now on how to get back your money rather than how the hacker hack your money.

the excuse from pbb refuse to return your money is because they claim that the transaction is made by yourself.

things you should do is:

1. you have to ask them for prove, what evidence can shows that the transaction is done by yourself? for example: the TAC should be tie to your phone number, not other ppl's phone number. find out the prove can shows that the transaction is not made by yourself. remember everything done in black and white, don't communicate with them by oral only.

2. if at the end pbb refuse to settle for u, give them some pressure. find their big boss, let them know you are not easily to compromise and going to publish this case on news paper. brand name is very important for a company, if they ignore you then just go ahead. i got some fren working in news paper company smile.gif

3. seek for help from your fren or relative see anyone got know anybody is lawyer, ask advise from lawyer see is there anyway claim back your money trough law
*
I am curious on how my money can be transferred, but my main concern is still to get back my money.

I asked a friend from DiGi customer service and he said that I can't check the transaction on my own. DiGi only deals with police to know my incoming call / SMS.

I meet up their manager of the branch regarding this matter. They don't want to give me the contact of the HQ. The manager just said that he will contact me. We already insist that we want our money back no matter how they investigate this case. We said we will go for hard way if they still don't want to refund.

Sadly, lawyer fees is more expensive than my loss of money.
TSfelicious
post Oct 13 2008, 11:44 PM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
QUOTE(jleecy @ Oct 13 2008, 12:14 AM)
dun go to the branch office...straight go DIGI HQ...show them dat u are really serious in this matter...
*
I have a friend who work in DiGi. He's going to work on Wednesday. I hope he can help me.

QUOTE(jd low @ Oct 13 2008, 12:40 AM)
1.cancel all ur online transaction ,
2.dont use credit card
3.stop giving away ur lil ,lil imformation about ur detail
  for example ,,ur IC,ur atm number card .make sure no one photostat
  ur CREDIT card ,ur atm and ur IC bec they can trasit ur amount out .
by the scammer,,,i heard frm my friend protect ur identity .
*
I canceled my PBE once I know about this matter.
I don't use credit card. Still underage.
I don't give my IC to photostat. If I do, I will make sure they cancel it in front of me. Provided that they photostat my IC without my knowledge.

QUOTE(srm @ Oct 13 2008, 01:03 AM)
Most probably the culprit doesn't need to do as said on previous posts. Once they have access in the mainframe, direct or indirect, partial or full, they can run imagination wild. Not just PBB, all over the world it is well "covered up".

I hope the TS gets her money back. For those who has huge sum of money, >1k a month savings, keep in somewhere not easy to liquid or not exposed to ebanking.

TS.. please share with us what you when through with the bank. http://www.consumer.com.my/ is good database.
*
All the while my bank only have less than RM1k. I am a student and I don't have much money. The money is just banked in from PTPTN few days before the money was transferred out.

QUOTE(MakNok @ Oct 13 2008, 08:43 AM)
excuse me!!

even DIGI HQ won't reveal anything...serious or not serious!

Only Police are allowed to get info from them....

Guess u better hire a lawyer and if u win,bill PB the lawyer fee as well....

if not...go for BN or PKR or DAP for help......it might help!!!!! very very much..
*
I approached DAP earlier on before PBB gave me any answer. But they only can give me advice, asking me to write letter to police office, PBB and go Bank Negara report.

QUOTE(cute_boboi @ Oct 13 2008, 03:32 PM)
No. Both DiGi and PBB (and any other company) will not reveal information to customer. They will only reveal to police, investigation, court order, etc. Unless you have insider help.

Otherwise all companies will be very busy preparing information for every Tom, d*** and Harry.

Even in my previous case, the bank will only report the reasons to BNM. I only get the report/results from the investigation. Not the details though.
*
What case you were having?
What is the result?
TSfelicious
post Oct 14 2008, 12:09 PM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
The content of the letter

QUOTE
We refer to your police report dated 17-09-2008 on the above subject matter and would advise that we are unable to accede to your request for a refund as there was no breach in Bank's Internet Banking Website system security at this or any other time. The identified transaction was conducted using your valid PBeBank.com Internet Banking User ID and password and there were no irregularities to the transaction.

Nevertheless, we shall be lodging a police report on the alleged fraud to facilitate a joint police investigation into your claim



So what is the step I should do?




TSfelicious
post Oct 14 2008, 07:38 PM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
QUOTE(keith_hjinhoh @ Oct 14 2008, 12:59 PM)
Fwd the letter to police officer in charge.

Ask them to investigate the telco side and bank side, which side are at fault?

Give Public Bank a visit and make a talk with their technical department probably?
*
The Public Bank branch had made a police report for me. Do I need to forward to the police in charge some more?

Pay PBB a visit.. which branch? Do they allow me to talk with the technical department?

I haven't done anything since I received the letter.

Where do I need to start first?

This post has been edited by felicious: Oct 14 2008, 07:39 PM
TSfelicious
post Oct 14 2008, 07:54 PM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
QUOTE(OlgaC4 @ Oct 14 2008, 07:44 PM)
I think he forgot to log off when using e-banking. You think a professional hacker want to take RM2000.00 meh when they can target RM2M. Last time i went to CIMB bank and they got some computer for e-banking, some ass also forgot to log off also.


Added on October 14, 2008, 7:52 pm
Report to bank negara. You got plenty of form to fill up there. As for as i know for Credit card bank can claims insurance but for personal acccount i am not to sure..
*
I always log off my e-banking. And I only log on to my PBe with my computer.
I've went to Bank Negara before this letter was sent to me. Should I go again to report?

This post has been edited by felicious: Oct 14 2008, 07:55 PM
TSfelicious
post Oct 17 2008, 04:46 PM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
I haven't done anything because I don't have the latest documents.
I just called Public Bank, the person in charge of this matter. He said that this transaction is done using valid ID and password. Also, TAC number is applied to my registered phone number to be used for the transaction. Thus, Public Bank said that they could not refund the money, as it has nothing to do with their PBe security.
TSfelicious
post Oct 18 2008, 10:30 AM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
QUOTE(mIssfROGY @ Oct 17 2008, 09:39 PM)
hMm...issit an PBB insider job?? Hmmm.....then they will have all pwd, username and tac also rite? ahha.....
weird lor....the least digi shd tell u where did they deliver the TAC to ma. It didnt appear in your HP rite? Then it must have went sumwer...else like i asid, didnt go anywer at all. Insider job :/

Or did u check wif any of your family members if they took out money from your acc? Coz last time when i was working in a bank, the mother reported that her credit card got fraud. Later after all investigations, we found out rupanya the daughter "stole" her card and used a great deal out of it :/
*
My username n password is used to log in to my PBe. TAC is applied to my phone number.
Nobody in my family can access to my PBe. Impossible my family members took out the money. If so, they will let me know before I make the report.

QUOTE(keith_hjinhoh @ Oct 17 2008, 11:45 PM)
Then ask them to freeze the other person account, ask him for testimony. I believe with police report, you can request for relevant documents and information about the other person account, ask police to summon him out.
*
I asked for the 3rd party account details, but they refuse to give me. I thought I am the victim and I am suppose to know the details? Public Bank can't give me any answer. And the money was actually taken out already. PBB said then it is the police's job.

QUOTE(zenquix @ Oct 18 2008, 08:16 AM)
TS is not the only victim. I know a guy who lost rm1k over the last weekend. PBB account as well.

Maybe TS might want to pay Michael Chong (MCA) a visit.

On intercepting SMS, it is not so easy especially if TS's phone is always on. If really the TAC was requested may I suggest TS to check the phone number configured or request a TAC now and see whether she receives it.

The TAC generation I believe is via

[Bank database] -> [TAC Server] -> [Telco] -> [User Phone]

Thus possible points of failure are

1) Bank Database -> phone number for TAC changed
                          -> Another option that can be considered is maybe PBB system has a bug and the transaction has erronously been credited from her account. Ie. Login, Password, TAC all correct, only account number wrong.

2) TAC server -> Make to generate TAC to a different number (dummy message sent to server etc.)

3) Telco -> Tapping into physical systems
             
4) Phone -> lost
*
How's your friend's case? Can I have your friend's phone number? I wanna know more details about his case.

My phone is always on. The transaction was done on 12.16pm. At that time, I was at home preparing to go college, as my class started at 12.30pm. Or, I might be already at college for class. My handphone 95% is always by my side.

QUOTE(wankongyew @ Oct 18 2008, 08:23 AM)
Have you checked that the registered phone number on file is still your actual number? The TAC part is the most puzzling to me because it's effectively a one-use temporary password, so it should be impossible to steal. If PB's security protocols are working, then it should be impossible for even any of its staff to do this because they won't have access to plaintext versions of any customers' passwords. The likeliest explanation is still the simplest, in my opinion. Someone close to you got a hold of your phone during the time the transaction happened and transferred the money. Your problem is that there was such a huge gap in time between when you discovered the theft and when the transaction actually happened. If possible, try to remember what you did during the day of the transaction and whether or not you left your phone with someone.
*
Yes, the bank told me it is my number.
TSfelicious
post Oct 19 2008, 12:50 AM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
QUOTE(deitel73 @ Oct 18 2008, 12:38 PM)
After you log out from PB, did u perform clear cache and clear temp internet files ?
*
Unfortunately, No sad.gif

QUOTE(cherroy @ Oct 18 2008, 02:12 PM)
The third part is not robbing or stealing from TS account. So police can't do it. It is just a E-transfer.
TS must prove it is a fraud case which until now TS has no strong position except no TAC being received. TS needs to prove those transaction is carried withouts TAC or TAC never obtained.
That's why we need to investigate how this fraud case being carried out also.

You must think from the other side, from police (enforcer) perspective, what if TS is telling lie or TS transferred the money but claim not doing after that and claim compensation from banks or TS actually transferred but regretted and try to make amend by telling lie? or whatever other reason.
Although I knew TS is not falling into these category, but from a police (as an enforcer), you must think from neutral point. No offence to TS or anyone.
Just like someone had mentioned about credit card fraud as earlier post, it is not a fraud after all.
*
TAC was applied to my registered phone number.
I need to do something to prove that this transaction is not done by me. But, how?
TSfelicious
post Oct 19 2008, 04:34 PM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
QUOTE(ibnuasad @ Oct 19 2008, 02:23 AM)
Are you sure that you did not received the TAC message? Try going to MCMC and ask them to check whether the TAC message sent by PB server was received successfully to the registered phone number.

Every mobile telco should keep a record of all sent and received messages. If the telco says the message was successfully sent to your mobile number, it could be that someone has cloned your sim card.

These days, sim card cloning is highly unlikely but there is always a possibility.


Added on October 19, 2008, 2:25 amBtw, what phone are you using? Is it a Symbian or JAD/JAR enabled phone? There's a possibility that your phone might be hijacked.
*
Can MCMC know about this? I thought only my Telco company know that whether TAC is sent to my phone number or not. Too bad, Telco company will not allow me to know it. Only police have the right to know. My friend told me that it is quite easy to clone sim card now. I am using Symbian phone.
If my phone is hijacked, my PC also hacked by someone?


QUOTE(mIssfROGY @ Oct 19 2008, 03:47 AM)
Maybe can prove by the telco co that msg didnt send to your HP?
If its a police case already, i think they will help kua?

But honestly i dun understand y dun the bank check with the 3rd party acc where the funds had transferred to, Wouldnt hurt to clarify one ma rite. Last time my mom's PBB acc also got sudden funds masuk. She gotto scream her lungs out at the officer to check on the case....else they wont care. Ya...she gotto scream eventho the funds was given to her FREE (BIG AMT...hahaha...many zeros is all i can say) and ya its also PBB...too bad mom is not here anymore, else i could have asked her about it for u. Btw, this happened 20 years back.....no ebanking then. Maybe you can use the harsh way and insist that they check it out for u, your rights what since its your money they have lost. If me I will proly make a big newspaper case out of it...2k is small, but this is a big matter aint it, millions could have been transferred instead! Go MCa or something....
*
Yea, I hope this will be brought to press, but I don't have any contacts in newspapers. I went to DAP and DAP advice me to write letter to PBB and Police Station. I also don't understand why bank don't want to check with 3rd party account. When I wanna go to HQ, he say that I go HQ also useless, ask me to contact him.
TSfelicious
post Oct 19 2008, 10:53 PM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
QUOTE(mIssfROGY @ Oct 19 2008, 08:36 PM)
Oh...btw i told one of my fren about your case, he told me that after you make the police report, please report to BNM (BANK Negara) They will definately take action. So please do....go report the case to BNM. And u can also inform PBB that u r reporting to BNM, usually these banks are "scared" when matters go to BNM, they might speed up their work. Update us yar!!
*
I reported to Bank Negara before they make this decision.
TSfelicious
post Oct 19 2008, 11:34 PM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
QUOTE(keith_hjinhoh @ Oct 19 2008, 11:22 PM)
You should called up BNM to updates, check with police station as well, we're as concern as you do, because we're internet banking users too.
*
I ll call them tomorrow. I received their letter that they need 14 days to give me an answer. As for police station, I already send them a letter, but there is still no reply from them. And the Bank Manager had lodged another report about my case. I should send the letter regarding the new report again?
TSfelicious
post Oct 20 2008, 06:26 PM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
QUOTE(keith_hjinhoh @ Oct 20 2008, 01:08 AM)
No need. Perhaps a call to enquire about their investigation status would be relatively faster compare to the snail mail?
*
I got advice that I need to send letter to prove that I am doing my job for keep chasing them. Black and white will be useful.
By the way, I just called Bank Negara, and they said that bank already investigate and their decision is not to refund me. Bank Negara also ask me to refer to regarding my case.

I gonna send a letter to Public Bank and the content will be :
-asking them to prove to me that the transaction is done by valid username and password.
-ask them to check on the 3rd party and the money had gone to where
-ask them to prove to me that TAC is applied to my phone.

Is there anymore I should enquire?

This post has been edited by felicious: Oct 20 2008, 06:27 PM
TSfelicious
post Oct 20 2008, 09:49 PM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
QUOTE(alex_cyw1985 @ Oct 20 2008, 06:44 PM)
IP that requested the TAC?
*
You mean the IP address that requested the TAC number?

Can they check the location of the person who logged in to my account?
TSfelicious
post Nov 4 2008, 09:50 PM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
I've sent letter to Public Bank, police station and FMB. I am waiting for their reply now. By the way, I had read online that Nigeria is having e-banking problem. I am wondering is the person a Nigerian.
TSfelicious
post Nov 5 2008, 11:47 PM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
QUOTE(stupid @ Nov 5 2008, 09:01 AM)
how about ebroking?
i juz want t o apply 1 pbb ebroking a/c
*
ebroking? shocking.gif

QUOTE(speed7791 @ Nov 5 2008, 11:29 PM)
nigerians.... erm sorry i mean if u have any sort of enquiry whatsoever from nigeria for online biz be super duper careful. they r super famous for online fraud. just google them up to see what i mean.

they'll pose as so many different ppl with different names n use various methods to draw your attention. if u receive a deal o offer that sounds too good to be true, it probably is. they may not say they r from nigeria in the beginning. but if u entertain their emails n later all seems to head that direction. pull the brakes minus ABS....

point..... have nothing to do with anything o anyone from there.
*
I've read an article online on Nigerians' online fraud.
And usually, I ignore emails from those unknown people.

FMB just called me and said that they received my letter already. They will follow up the case.

Again, my same wish for this year is to hope that I can get back my money.
TSfelicious
post Nov 6 2008, 11:19 PM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
QUOTE(bai1101 @ Nov 6 2008, 01:11 PM)
hmm w/o tarc? how abt the money transfer to wat acc also not show?
*
The money is transferred to someone with name ends with Charles. Should I post his name here? hmm.gif

By the way, what do you mean by w/o tarc?
TSfelicious
post Nov 10 2008, 10:03 PM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
QUOTE(ibnuasad @ Nov 7 2008, 02:38 PM)
MCMC have authority over the Telco company. You might want to give a call to MCMC.

If your phone was hijacked, most probably your PC was also hijacked by a Trojan or Keylogger. Keep in mind that custom made or custom programmed keylogger and trojans can be undetectable. If someone hijacked your phone and PC the person is probably a close friend or relative that has knowledge in the IT Industry and has direct access to your PC and Phone.

Btw, you might want to take a look at CyberSecurity Malaysia. They may be able to help with the investigation.
*
This CyberSecurity may help in investigation? This means that I need to liaise with police on this?

QUOTE(clawhammer @ Nov 7 2008, 03:12 PM)
Did you logon your account from Cyber cafes, etc? PC's and places that are not safe might potentially be risky.
*
As I mentioned before, I don't log on e-banking at CC.

QUOTE(Cubex01 @ Nov 8 2008, 09:59 AM)
Btw will the bank give u back the money? I meant insurance. There is no way the hacker can receive the TAC. Maybe he infiltrate to database server. I had been told that Maybank also got hacked by African hacker. Not sure where did this black men got the hacking skill or our banking security is low.
*
I've never heard of M2u fraud, but I've heard 2 cases of PBE before mine happened.

QUOTE(kumarr @ Nov 9 2008, 05:40 AM)
How they proceed the case now and how well the progress? Did they manage to find out ur acc been hacked?
*
I've sent letter to FMB, police station and PBB. I still don't receive any letter from them. Guess I should call the manager again.

QUOTE(Vv.SoViEt.vV @ Nov 10 2008, 05:54 PM)
wait wait.. I read a few pages back, I dont know how your login is being hacked. You give us insufficient information and we cannot give your proper assumption. How do you think you get hacked? u used online banking at cc or starbucks using wireless connection?


Added on November 10, 2008, 6:30 pm
I come to the conclusion that the person who stole her money is close-acquaintances if, it's not the work of insider. Think of it, the hacker can penetrate double security layer.
*
What else information you would like to know? I am not sure how my account is hacked too. I don't know how my username and password is revealed out. And I don't know how TAC is applied to my handphone WITHOUT me receiving it. Nobody knows my username and password. And my handphone is always by my side.
TSfelicious
post Nov 11 2008, 05:15 PM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
QUOTE(ibnuasad @ Nov 10 2008, 11:14 PM)
Yes. Contact CyberSecurity at +603-89926888 for more info.
Also, you have to keep calling the Police at least once every 2 days. To you, RM 2K+ is a priority but to the Police, it is just a small & low priority case. Keep calling them...it's better to speak to the same officer/inspector that is leading your case so you don't have to explain everything all over again to a 'clerk/desk' police officer who gives the same reply every time.
*
Thanks for your information. I'd call them, but it seems like they can't help much in this. However, they ask me to send an email to them to report.

As for police side, today is too late to call them. They close at 5pm. So, I ll call them again tomorrow morning.

QUOTE(Vv.SoViEt.vV @ Nov 11 2008, 10:11 AM)
where was the last time you used e-banking and you found out that your is being hacked?

maybe you should check with your celco provider if you actually received the TAC.
*
The last time I used e-banking was few weeks before my account is hacked. When I confirmed my bank is hacked, I logged on to PBE again.

TSfelicious
post Nov 14 2008, 05:57 PM

Regular
Group Icon
VIP
1,438 posts

Joined: Aug 2007
QUOTE(benghooi @ Nov 14 2008, 12:46 PM)
Received email phishing for Maybank2u password.

I have attached the images of the phishing email at my blog:

Phishing


Added on November 14, 2008, 12:54 pmAs far as I can remember, Maybank did not request email from customers. So how can customers receive email from them?
*
I know about the phishing website, but IINM, I never log on to that website.

QUOTE(normeck @ Nov 14 2008, 01:37 PM)
after reading all 14 pages...how come they get your TAC number?....and u dont even do online banking on that day isn't?....pening aleady...

last hope was asking Digi telco to comfirm that day u got the TAc or not ...
*
My house don't have internet connection at that period. I forgot when was the last time I logged on to my e-banking. I logged on to PBB once at night, but failed because DiGi EDGE is very slow that day. But, I am not sure whether is it 25th or not. The transaction was done on 25th noon. If he manage to get my TAC, it is already expired.

By the way, I am meeting an inspector this Sunday. Will update you guys after meeting him.

3 Pages < 1 2 3 >Top
 

Change to:
| Lo-Fi Version
0.0325sec    0.86    6 queries    GZIP Disabled
Time is now: 7th December 2025 - 12:36 AM