lausai88 Hypersonic December 1, 2015 Share December 1, 2015 50 smartphone users in Singapore hit by malware targeting mobile banking customers The malware disguised itself as an operating system update or an update for messaging app WhatsApp to trick customers into entering their credit card information, says the Association of Banks in Singapore. for details: http://www.channelnewsasia.com/news/singapore/50-android-users-in/2308976.html ↡ Advertisement 5 Link to post Share on other sites More sharing options...
Kb27 Supersonic December 2, 2015 Share December 2, 2015 Be warned, don't anyhow click a link. http://www.straitstimes.com/tech/mobile-banking-users-lose-thousands-of-dollars-to-hackers Mobile banking users in Singapore have lost thousands of dollars after they fell victim to malicious software targeting Android smartphones. The Association of Banks in Singapore (ABS) yesterday issued a warning against the malicious program, hidden in a pop-up window that prompts users to update their software. Some 50 mobile customers of major retail banks here reported losses of up to "several thousand dollars" after clicking on the dubious link, prompting ABS to issue the warning. "ABS would like to remind mobile banking customers that smartphones are as susceptible to malware as desktop computers or laptops," said Mrs Ong-Ang Ai Boon, director of ABS. "Now, criminals have turned to targeting Android phone users... as banks are pushing out more banking apps for user convenience." The dubious pop-up window is believed to have appeared after mobile phone users visited websites infected with malware. It prompts unsuspecting users to click on an embedded link to update their WhatsApp messaging software or battery management module. People who clicked on the link were asked to enter their credit card details to complete the software upgrade. After doing so, users were greeted with the Android green robot logo with the message: "System update in progress..." It is at this point that cyber criminals take control of the phone, using the credit card details entered and one-time passwords received via SMS for making fraudulent online transactions. Some users have lost several thousand dollars from online transactions which appear to originate in Eastern Europe, according to Mrs Ong-Ang. Items purchased include airline tickets. 3 Link to post Share on other sites More sharing options...
Ktglfc Hypersonic December 2, 2015 Share December 2, 2015 Just go to official bank website to make online banking transactions.... for online shopping, just be cautious ... With advanced tech, the experts are creating even higher tech malware .... sometimes, just wonder if queuing up at banks is still better than click at smart phone .... 8 Link to post Share on other sites More sharing options...
Spring Moderator December 2, 2015 Share December 2, 2015 Just go to official bank website to make online banking transactions.... for online shopping, just be cautious ... With advanced tech, the experts are creating even higher tech malware .... sometimes, just wonder if queuing up at banks is still better than click at smart phone .... My former IT Head doesn't want to have anything to do with internet banking. Queues up at the banks and we laugh at him saying he so old fashioned and being IT saavy some more!! He just laughed it off and said don't come crying when you wake up one morning to find your funds all gone 11 Link to post Share on other sites More sharing options...
1fast1 Supersonic December 2, 2015 Share December 2, 2015 (edited) On a related note, it should be common knowledge that many functions one would use regularly can now be relegated to a simple SMS token rather than having to use the dedicated bank provided token. Only specialised functions require that token still. There are Android apps (and I presume iPhone apps as well) that allow the display of message text on a locked phone. An example is Textra (which is a wonderful SMS app, by the way). So even though my phone has a fingerprint scanner, etc., when the bank sends an OTP through, it can be immediately seen on the locked screen. I always viewed this as a great convenience, but now I'm wondering if it's a liability and whether I should turn off the feature. Granted, if someone does steal my phone (and somehow my other login details), they wouldn't be able to do too much damage. While they can look at my account info and transfer funds to payees already in the system, they can't create any new payee without the token. What do you guys think? Edited December 2, 2015 by Turboflat4 2 Link to post Share on other sites More sharing options...
Kusje Supersonic December 2, 2015 Share December 2, 2015 On a related note, it should be common knowledge that many functions one would use regularly can now be relegated to a simple SMS token rather than having to use the dedicated bank provided token. Only specialised functions require that token still. There are Android apps (and I presume iPhone apps as well) that allow the display of message text on a locked phone. An example is Textra (which is a wonderful SMS app, by the way). So even though my phone has a fingerprint scanner, etc., when the bank sends an OTP through, it can be immediately seen on the locked screen. I always viewed this as a great convenience, but now I'm wondering if it's a liability and whether I should turn off the feature. Granted, if someone does steal my phone (and somehow my other login details), they wouldn't be able to do too much damage. While they can look at my account info and transfer funds to payees already in the system, they can't create any new payee without the token. What do you guys think? What if it is an existing payee who takes your phone? 1 Link to post Share on other sites More sharing options...
Vid Hypersonic December 2, 2015 Share December 2, 2015 On a related note, it should be common knowledge that many functions one would use regularly can now be relegated to a simple SMS token rather than having to use the dedicated bank provided token. Only specialised functions require that token still. There are Android apps (and I presume iPhone apps as well) that allow the display of message text on a locked phone. An example is Textra (which is a wonderful SMS app, by the way). So even though my phone has a fingerprint scanner, etc., when the bank sends an OTP through, it can be immediately seen on the locked screen. I always viewed this as a great convenience, but now I'm wondering if it's a liability and whether I should turn off the feature. Granted, if someone does steal my phone (and somehow my other login details), they wouldn't be able to do too much damage. While they can look at my account info and transfer funds to payees already in the system, they can't create any new payee without the token. What do you guys think? Most of the time banking is secured. The only vulnerability is often the user. That is something nobody can fix. 5 Link to post Share on other sites More sharing options...
1fast1 Supersonic December 2, 2015 Share December 2, 2015 What if it is an existing payee who takes your phone? I considered that. But I prune the payee list regularly for that reason. The only ones on it long term are ones I trust implicitly (generally family). Link to post Share on other sites More sharing options...
1fast1 Supersonic December 2, 2015 Share December 2, 2015 (edited) Most of the time banking is secured. The only vulnerability is often the user. That is something nobody can fix.This is true, but my question was not whether there is a risk with my existing system (I'm aware there is) but whether there is more risk than I'm thinking of (i.e. Stuff I've missed). It's also to bring people awareness of this risk in case they haven't thought of it. I might just disable the feature. It's easy to unlock the phone with a fingerprint anyway. Edited December 2, 2015 by Turboflat4 Link to post Share on other sites More sharing options...
Raychay 6th Gear December 2, 2015 Share December 2, 2015 Be warned, don't anyhow click a link. update their WhatsApp messaging software or battery management module. People who clicked on the link were asked to enter their credit card details to complete the software upgrade. After doing so, users were greeted with the Android green robot logo with the message: "System update in progress..." Update software/firmware don't need to enter credit card details. Smart phone users should be smarter than that. 3 Link to post Share on other sites More sharing options...
Ktglfc Hypersonic December 2, 2015 Share December 2, 2015 Update software/firmware don't need to enter credit card details. Smart phone users should be smarter than that. Precisely its smart phone, that's why we leave all the smartness to the phone .... have seen adults using the calculator in the phone just to add up 2 digits plus 2 digits .... Link to post Share on other sites More sharing options...
Christan Turbocharged December 2, 2015 Share December 2, 2015 Had received similar prompt to update 'Whatsapp' application several times. Had clicked the update option (I think) & countdown timer appeared which requested me to continue if I don't want to lose my data. Nothing happened after reached 0. Have ignore that message henceforth. 2 Link to post Share on other sites More sharing options...
A_korusawa 5th Gear December 2, 2015 Share December 2, 2015 (edited) Internet Banking Security - been in these for years (on compliances) to see the growth of technologies that even the best can be deterred, sabotaged or compromised on its safety features . . . my best advice to everyone here performing transactions via Internet Banking; try to be quick and finish off your executions fast and careful with auto screen shots or notifications archived, then log off straightaway. Avoid keeping your login 'alive' for too long . . . this is especially for those international ones! This also explains why our local ones are shut off by default when not attended/being accesses. and its also recommended NOT to transact on phones app for banking - utmost for verifications only. Cheers! Edited December 2, 2015 by A_korusawa Link to post Share on other sites More sharing options...
Blackyv Turbocharged December 2, 2015 Share December 2, 2015 Update software/firmware don't need to enter credit card details. Smart phone users should be smarter than that. Yup, anything that prompt me to enter such stuff except I'm doing a purchasing transaction will be ignored by me and closed...I'm not buying anything, so no reason to enter those info. Period. Even if I'm buying something online, my first choice of payment is PayPal..not 100% fool prove but better than I key in my cc number unnecessarily.. 2 Link to post Share on other sites More sharing options...
Lala81 Hypersonic December 2, 2015 Share December 2, 2015 On a related note, it should be common knowledge that many functions one would use regularly can now be relegated to a simple SMS token rather than having to use the dedicated bank provided token. Only specialised functions require that token still. There are Android apps (and I presume iPhone apps as well) that allow the display of message text on a locked phone. An example is Textra (which is a wonderful SMS app, by the way). So even though my phone has a fingerprint scanner, etc., when the bank sends an OTP through, it can be immediately seen on the locked screen. I always viewed this as a great convenience, but now I'm wondering if it's a liability and whether I should turn off the feature. Granted, if someone does steal my phone (and somehow my other login details), they wouldn't be able to do too much damage. While they can look at my account info and transfer funds to payees already in the system, they can't create any new payee without the token. What do you guys think? hmm good point. Yeah the msg popup does tend to render locked phones irrelevant. Though i don't even lock my phone lol. 2 Link to post Share on other sites More sharing options...
Yewheng Twincharged December 2, 2015 Share December 2, 2015 (edited) My former IT Head doesn't want to have anything to do with internet banking. Queues up at the banks and we laugh at him saying he so old fashioned and being IT saavy some more!! He just laughed it off and said don't come crying when you wake up one morning to find your funds all gone Coz he work in IT department, surely seen a lot of cases of the IT security loophole until he scared. So go for the traditional way is much safer. Haha Edited December 2, 2015 by Yewheng Link to post Share on other sites More sharing options...
Sabian Turbocharged December 2, 2015 Share December 2, 2015 On a related note, it should be common knowledge that many functions one would use regularly can now be relegated to a simple SMS token rather than having to use the dedicated bank provided token. Only specialised functions require that token still. There are Android apps (and I presume iPhone apps as well) that allow the display of message text on a locked phone. An example is Textra (which is a wonderful SMS app, by the way). So even though my phone has a fingerprint scanner, etc., when the bank sends an OTP through, it can be immediately seen on the locked screen. I always viewed this as a great convenience, but now I'm wondering if it's a liability and whether I should turn off the feature. Granted, if someone does steal my phone (and somehow my other login details), they wouldn't be able to do too much damage. While they can look at my account info and transfer funds to payees already in the system, they can't create any new payee without the token. What do you guys think? I'm using tokens for all my transactions that require OTP. There's also limit to the amount that can be transferred per customer for each bank. The default limit cam be lowered. So all the talk about "all your money disappearing from your account" (even by the savvy IT Head) is just pure BS or too much Hollywood movies. Anyhow, these days, if someone uses his phone for bank OTPs, then they shd treat the phone like a credit card, call your Telco to suspend the phone line as you would if a credit card is misplaced. My disclaimer: I have an OCD with regards to Internet Banking. I log in almost daily to see the available credit on all my credit cards so I have no issue with the banks existing IT security setup for their customers. Just wondering, driving a car may mean ending up dead through no fault of ours in a car accident. So do we insist on riding a horse? 2 Link to post Share on other sites More sharing options...
Lala81 Hypersonic December 2, 2015 Share December 2, 2015 I'm using tokens for all my transactions that require OTP. There's also limit to the amount that can be transferred per customer for each bank. The default limit cam be lowered. So all the talk about "all your money disappearing from your account" (even by the savvy IT Head) is just pure BS or too much Hollywood movies. Anyhow, these days, if someone uses his phone for bank OTPs, then they shd treat the phone like a credit card, call your Telco to suspend the phone line as you would if a credit card is misplaced. My disclaimer: I have an OCD with regards to Internet Banking. I log in almost daily to see the available credit on all my credit cards so I have no issue with the banks existing IT security setup for their customers. Just wondering, driving a car may mean ending up dead through no fault of ours in a car accident. So do we insist on riding a horse my solution is to leave my OTP at my house. I don't use mobile banking apps anyway. I only use my home and work pc to access IB to reduce chance of getting keylogged. ↡ Advertisement 1 Link to post Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In NowRelated Discussions
Related Discussions
Paynow
Paynow
Websites of Singapore public hospitals, polyclinics down due to 'internet access disruption'
Websites of Singapore public hospitals, polyclinics down due to 'internet access disruption'
MyRepublic Vs Whizzcomms
MyRepublic Vs Whizzcomms
OCBC internet banking down?
OCBC internet banking down?
M1 fiber broadband down? 21 Dec 2020
M1 fiber broadband down? 21 Dec 2020
Huge part of internet down
Huge part of internet down
Hyflux RPCS aka Securities
Hyflux RPCS aka Securities
End of Internet Explorer
End of Internet Explorer