Vigilance urged over banking scams
Phishing, vishing and smishing are methods of deceitfully obtaining personal information such as passwords, ID numbers and bank card details by tricking clients into believing that they are from trusted sources.
The South African Banking Risk Information Centre is urging bank customers to avoid becoming victims of phishing, vishing and smishing scams.
According to the police, phishing is when an email requests the user to click on a link, which then directs them to a ‘spoofed’ website designed to fool users into thinking that it is a legitimate attempt to obtain, verify or update contact details or other sensitive financial information.
The spoofed website will look almost exactly like that of a legitimate or a well-known financial institution, saying that phishing emails, which are a form of spam emails, are typically sent in large numbers to consumer email accounts.
“Vishing is when a fraudster phones their victim posing as a bank official or service provider and uses social engineering tactics to manipulate them into disclosing confidential information, while at the same time leading them to believe that they are speaking to the bank or service provider. This information is then used to defraud the victim,” said the police.
Meanwhile, smishing, short for ‘SMS phishing’ is like phishing, except that a user is tricked into downloading malware onto their mobile device, which is then used to fraudulently obtain sensitive information by sending out text messages asking users to call a number or click on a link.
Police said phishing, vishing and smishing are all methods of deceitfully obtaining personal information such as passwords, ID numbers and bank card details by tricking clients into believing that they are from trusted sources, such as banks or legitimate companies.
“Our advice is to not click on links or icons in unsolicited emails. Never reply to these emails; delete them immediately. Do not believe the content of unsolicited emails blindly. If you are concerned about what is being alleged in the email, use your own contact details to contact the sender and confirm. Always type in the URL or domain name for your bank in the address bar of your internet browser if you need to access your bank’s website. Check that you are on your bank’s genuine website before inputting any personal information,” said the police.
They urge the public to make sure that they are not on a spoof site by clicking on the security icon on their browser toolbar to see that the URL begins with https rather than http.
They added: “Create complicated passwords that are not easy to decipher and change them often. Banks will never ask you to confirm your confidential information over the phone. If you receive a phone call requesting confidential or personal information, do not respond and end the call. If you receive an OTP on your phone without having transacted yourself, it was likely prompted by a fraudster using your personal information. Do not provide the OTP telephonically to anybody. Contact your bank immediately to alert them to the possibility that your information may have been compromised.”
HAVE YOUR SAY
Like the South Coast Fever’s Facebook page
