How to Protecting yourself against rising online fraud

How many times have we heard of people losing their deposits to fraudulent schemes or falling prey to hackers who stole the savings from the bank? This is despite constant alerts by regulatory authorities, bankers and the Reserve Bank of India (RBI). Money is erased from your bank account in just minutes to someone sharing a Personal Identification Number (PIN) or One-Time Password (OTP).

A 2020 report 'Crime in India' published by the National Crime Records Bureau (NCRB) has reported 2,160 cases of ATM fraud, 1,194 credit/debit card fraud cases, 4,047 online banking frauds and 1,093 cases of OTP/PIN misuse indicated. Amid the pandemic situation in 2020, NCRB registered 1,194 online fraud cases using credit/debit cards in 2020, an increase of 225 per cent over the previous year. In addition, 60.2 percent of cyber crimes registered in 2020 were committed with the intention of committing fraud.

Here are some common online frauds to be aware of and beware of:

KYC fraud

Banks demanding documents for Know Your Customer (KYC) verification are common. But it was temporarily suspended due to mandatory lockdown in many places during the pandemic coupled with shortage of staff.

However, the fraudsters were quick to take advantage. He posed as a banker, emailed and prompted customers to update their KYC details.

Cash CTO Yashoraj  said, “The modus operandi used by KYC fraudsters starts with sending unsolicited messages through calls/SMS/emails asking them to enter their details such as bank account login, their card, etc. PIN and OTP details etc. They then use this information to commit 'synthetic fraud' by copying the identity of the customer.

Customers often make the mistake of calling the number mentioned in SMS or email and downloading and installing a remote access application in their mobile, which allows full access to the personal information stored in the server. This is the first step in helping the fraudsters to dupe money from bank accounts, even as customers are left helpless to receive messages about the amount being debited from their savings accounts.

 Fraud prevention

Remember, there is no option to verify or update KYC details through the remote access app. Yashoraj said, “People should avoid clicking on any suspicious links. Banks, financial institutions or insurance companies never send any link to the customers to update their KYC. Customers are not required to share their account login details, personal information, a copy of KYC documents, card details, PIN, password and OTP etc. with unknown persons or agencies.

 Sim swap fraud

A mobile SIM card holds the key to a person's personal information- contacts registered on the phone, emails from banks and financial institutions, ATM withdrawal alerts and even by banks through net banking or Immediate Payment Service (IMPS). OTP shared while transferring money.

SIM swap fraud usually occurs by blocking an individual's SIM card or deactivating it by convincing the mobile user to upgrade the services. Recent upgrades pertain to 4G/5G. But remember that fraudsters can also block the SIM, replace it with a fake card, as well as steal data from the blocked card. Know that handing over your SIM leaves you vulnerable to fraud.

Ritesh Bhatia, Cyber ​​Crime Investigator and Founder, V4WEB,  explains how it works. “Fraudsters first get access to financial information like net banking credentials. They then use the victim's KYC documents and get a new SIM issued, even if the old one is inactive. The new card gives the fraudsters access to the net banking details, starts receiving OTP for the transactions being carried out by the fraudsters, and thus clears the funds in the victim's account.

 Avoid the Phishing Email Trap

Note that the domain name of a phishing email is usually misspelled, although the difference is usually minute. E-mails are very poorly written and create a sense of urgency. Phishing emails usually prompt action, such as clicking on a malicious link or asking to download an attachment.

 UPI related fraud

The Unified Payments Interface (UPI) developed by the National Payments Corporation of India  was introduced to simplify the payment mechanism by combining multiple banking features that aid in fund routing and merchant payments under one umbrella. Furthermore, the method caters to a 'peer-to-peer' collection request, which can then be scheduled and paid as per convenience.

Unfortunately, fraudsters now target people on second-hand shopping sites. Ankit Rattan, Co-Founder and CEO,  said, “The most common types of UPI fraud are smashing (SMS phishing) and identity theft. Hackers collect user information from social networking sites like Facebook, LinkedIn, Twitter and make a fake phone call pretending to be a representative of a bank or company. Hackers also use SIM clone to clone any mobile number and get personal information, including OTP. This method also allows them to change the UPI PIN of the user."

play safe

Keep in mind that you are not required to share your OTP or PIN while receiving money in your bank account. Your UPI-PIN should be kept as securely as your ATM PIN.

 Taking care to keep your finances safe

“Better safe than sorry” is a well-known saying that sums up the vigilance required on your part to keep your money safe. Though you can register your complaint with the cyber cell at your nearest police station, but in many cases there is very little you can do after your earnings have been cheated. Mayer Joshi, Director- Indiaforensic.com, suggests the following simple steps that can protect fraudsters from the risk of losing money.

There is no free lunch in this world, so never fall prey to any freebies, even if it is from real looking sites. Such offers on email may contain malicious code that reads information on your device.

PIN, passwords and phrases are the most sensitive information about your presence on the Internet. Avoid sharing them.

Always bookmark the websites of banks, revenue officials and regulators for quick reference. There will be many attempts to lure you away from these authorized websites. Even if you get a message from the Income Tax authorities on your refund process, it is better to access the details through the Income Tax Department website.

 

 

Enjoyed this article? Stay informed by joining our newsletter!

Comments

You must be logged in to post a comment.

About Author