Share

Banking app fraud rockets due to phone snatching

accreditation
0:00
play article
Subscribers can listen to this article
(Getty)
(Getty)
  • Bank app fraud due to cell phone snatching has increased significantly, according to a new report by the South African Banking Risk Information Centre.
  • The report points out that there were, however, no reports of the banking app software having been compromised to commit the fraud as the correct credentials were used to access the banking app.
  • These credentials may have been previously compromised through social engineering methods, such as shoulder surfing or phishing.


Cell phone snatching led to a marked rise in banking app fraud, according to a report released by the South African Banking Risk Information Centre (SABRIC) on Wednesday.

But this doesn't mean the problem lies with the apps themselves, the report noted. There were no reports of the banking app software having been compromised to commit the fraud, SABRIC said.

"Although there are various methods and techniques used in the cell phone snatching method of operation, the correct credentials are used to access the app. These credentials may have been previously compromised through social engineering methods, such as shoulder surfing or phishing," the report states.

Rather, criminals are still making use of deception to manipulate consumers to provide confidential or personal information. Phishing and vishing are still the most commonn methods, SABRIC said. 

Phishing makes use of emails to trick the victim into entering their log in credentials by directing them to a "spoofed" website which is designed to look legitimate. 

Vishing, which has significantly increased during 2020, involves criminals making telephone calls to potential victims, purporting to be from a bank and convincing them to compromise their details. In some cases, vishing is used once the criminals have access to the victim's account as an additional step in order to deceive the victim into providing them with the verification token like a one-time-password (OTP) required to complete a transaction.  

In many cases the credentials used to access banking apps were compromised through "vulnerabilities" in the management of such information. For example, the credentials were saved elsewhere on the device or the same username and password were used across multiple apps.

Mobile banking fraud accounted for 59.7% of digital banking crime incidents reported to SABRIC in 2020. It is characterised by a high volume of lower value transactions. SIM swaps were reported in 92.7% (19 537) of mobile banking fraud incidents reported in 2020 and is the most commonly used modus operandi for committing this type of crime.

Another type of mobile banking fraud reported was where an individual known to the victim - such as family member or colleague - was able to access a device and conducted transactions without the victim's knowledge on the mobile banking platform. Examples of fraudulent transactions include the purchase airtime, electricity or the use of instant cash sending facilities.

Although Covid-19 did not directly lead to a significantly higher number of social engineering attacks reported by the banking industry, the content used within these methods shifted drastically towards the virus, associated lockdowns, remote working, personal protective equipment, and vaccinations, the report found.

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
18.62
+0.9%
Rand - Pound
23.32
+0.7%
Rand - Euro
19.95
+0.5%
Rand - Aus dollar
12.14
+0.3%
Rand - Yen
0.12
-1.3%
Platinum
963.20
+1.8%
Palladium
955.50
-0.2%
Gold
2,318.80
+1.4%
Silver
26.67
+1.5%
Brent Crude
86.33
-1.0%
Top 40
69,925
-0.7%
All Share
76,076
-0.5%
Resource 10
61,271
-4.5%
Industrial 25
105,022
+0.4%
Financial 15
16,591
+1.0%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders