{"id":20628,"date":"2020-04-15T17:21:00","date_gmt":"2020-04-15T11:51:00","guid":{"rendered":"https:\/\/www.kaspersky.co.in\/blog\/?p=20628"},"modified":"2020-04-15T17:36:37","modified_gmt":"2020-04-15T12:06:37","slug":"verification-app-scam","status":"publish","type":"post","link":"https:\/\/www.kaspersky.co.in\/blog\/verification-app-scam\/20628\/","title":{"rendered":"New banking scam tricks"},"content":{"rendered":"<p>Cyber scams have been going on since the dawn of the internet. Victims are scammed for their money and private data usually, via emails, phone calls or messages with links leading to a scam website. The techniques the scammers use are always changing, but the underlying principles remain the same: they pretend to be someone they are not and using this cover they lure you into doing something you won\u2019t normally do.<\/p>\n<p>Here\u2019s a new scam technique that has just surfaced in Malaysia. It relies on several methods such as <a href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/social-engineering\/\" target=\"_blank\" rel=\"noopener\">Social engineering<\/a>, a <a href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/scam\/\" target=\"_blank\" rel=\"noopener\">scam<\/a> website and a mobile app.<\/p>\n<h2>Part 1: Social engineering<\/h2>\n<p>In the past, scammers would call to identify themselves as an officer from a bank or other organization. They would provide their rank and ID if they have that to make them seem more credible. They would go on to request for you to read out your bank account number or even your personal identification number. After which, they would then proceed to ask you some \u201csecurity questions\u201d \u2013 of which when you tell them, you\u2019d be giving away the information they want.<\/p>\n<p>In a new twist, instead of receiving a call from a scammer, victims would receive an SMS or in some cases a WhatsApp message form a \u201cBank\u201d informing them of a privacy breach and that their information has been compromised. In the message they are requested to go to the bank\u2019s website to perform an identity verification.<\/p>\n<p>The link provided leads them to a page that at first glance looks unsuspicious and almost similar in design to the real page \u2013 but it isn\u2019t. It\u2019s a well-designed webpage designed to mimic those of the real website of this bank.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kisa-generic\">\n<h2>Part 2: A New Twist \u2013 Download the app<\/h2>\n<p>It all seems quite like a regular scam, up until now. In the usual scenario, this page would be a phishing page designed to steal your data. But in this case it\u2019s not. This page instructs users to download an app (an Android app \u2013 has already been removed from Google Play) under the pretext of a secure app for details confirmation, The victims are asked to install it, then open it and fill in the details within it.<\/p>\n<div id=\"attachment_20640\" style=\"width: 1195px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-20640\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/36\/2020\/04\/15155201\/combined.jpg\" alt=\"\" width=\"1185\" height=\"528\" class=\"size-full wp-image-20640\"><p id=\"caption-attachment-20640\" class=\"wp-caption-text\">image from Bank Negara Malaysia\u2019s Twitter post<\/p><\/div>\n<p>Now that\u2019s phishing. Once the information is filled in, the scammers would use it to withdraw or transfer all the monies from the bank account \u2013 now that they have all the necessary data to access it. Once that has been done, the scammers would contact the victims via WhatsApp or SMS and request for them to delete the information they have submitted. The communication then ends.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/hashtag\/scamalert?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#scamalert<\/a><\/p>\n<p>BNM does not select random people to beta test our app or system. <\/p>\n<p>Regardless of platform\u2014online, phone call, sms, whatsapp etc\u2014whenever you *have* to give personal info incl banking details &amp; password\/PIN\/TAC number\u2014THAT is a SCAM. <\/p>\n<p>Stop before you lose your money <a href=\"https:\/\/t.co\/ZV9rrblVFV\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/ZV9rrblVFV<\/a><\/p>\n<p>\u2014 Bank Negara Malaysia (@BNM_official) <a href=\"https:\/\/twitter.com\/BNM_official\/status\/1249941088179064832?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">April 14, 2020<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<h2>How to stay safe?<\/h2>\n<p>There\u2019re two things that help against such scams: knowing about them and being very careful. Now that you\u2019ve read the post, you know about the new scam. And here\u2019s how you can be careful to avoid similar scams:<\/p>\n<ul>\n<li>If you receive a call or a message from a source that pretends to be a bank, contact the bank or organization directly. Use the contacts they have on their official website or in the app, but not reply directly to this call or message.<\/li>\n<li>Do not click on links that come in e-mails and messages. Type out the link manually or if you cannot remember it, search for it via your favorite search engine and select the trusted link.<\/li>\n<li>Do not provide sensitive information such as PINs, passwords or even CVV numbers in replies or while on the phone with a bank employee \u2013 banks would never ask for such information.<\/li>\n<li>Install a robust security app such as <a href=\"https:\/\/www.kaspersky.co.in\/mobile-security?icid=in_kdailyplacehold_acq_ona_smm__onl_b2c_kdaily_wpplaceholder_sm-team___kisa____ccbe3384bb4e1385\" target=\"_blank\" rel=\"noopener\">Kaspersky Internet Security for Android<\/a> which is able to warn you of phishing websites or fake apps.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Scammers are becoming innovative when it comes to tricking their victims: now they use mobile apps for phishing.<\/p>\n","protected":false},"author":2428,"featured_media":20634,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,2196],"tags":[500,793,76,701],"class_list":{"0":"post-20628","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-threats","9":"tag-banking","10":"tag-money","11":"tag-phishing","12":"tag-scam"},"hreflang":[{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/verification-app-scam\/20628\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.co.in\/blog\/tag\/scam\/","name":"scam"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/posts\/20628","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/users\/2428"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/comments?post=20628"}],"version-history":[{"count":12,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/posts\/20628\/revisions"}],"predecessor-version":[{"id":20649,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/posts\/20628\/revisions\/20649"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/media\/20634"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/media?parent=20628"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/categories?post=20628"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/tags?post=20628"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}