Showing posts with label scam. Show all posts
Showing posts with label scam. Show all posts

27 September 2026

Experian: more consumers trusting AI for financial services

Source: Experian landing page. Three quarters of
respondents would be comfortable
using AI related to a trusted financial provider.
Consumers are ready to take the next step in their relationship with AI, according to AI in Risk: The Rise of Agentic Commerce*, new research from data and technology company Experian.

Conducted by Forrester Consulting, the study of 6,247 credit-active consumers across 13 EMEA and Asia Pacific markets found that more than half (54%; 49% in Singapore) of respondents are comfortable with AI agents applying for credit on their behalf. 

Experian said the findings point to the next stage in the evolution of financial services, where consumers are becoming comfortable allowing AI to move beyond providing information to supporting parts of the lending journey, including comparing lenders, checking eligibility, completing applications and securely submitting authorised documents.

"Consumers are already changing the way they engage with financial services," said Mariana Pinheiro, CEO of Experian EMEA & Asia Pacific. 

"They are not just experimenting with AI anymore; they are beginning to trust it with more meaningful parts of their financial lives. Our research shows that 82% of the surveyed respondents already trust LLMs to compare loans across providers. For banks and lenders, the question is no longer whether AI will influence the next step of that journey, but how to prepare for it while continuing to earn and protect consumer trust. 

"What began as using LLMs to better understand financial products is already moving towards asking AI agents to help them navigate complex financial journeys.” 

Consumers are embracing AI agents because they see practical value, not simply because the technology is new, Experian noted. The research found that 85% of the survey respondents believe AI agents could help them compare more options than they could manually, while 84% say AI could help them save money by finding better prices or rates. 

A further 83% believe AI agents could help them avoid missing important details such as hidden fees or contract terms, while 81% believe AI could reduce decision fatigue by handling research and routine tasks on their behalf.

The findings suggest consumers are looking for AI that simplifies complex financial decisions, saves time and helps them make more informed choices. The research also shows that consumers have different comfort levels when it comes to how much autonomy they would give an AI agent, Experian disclosed. 

For credit applications, many still want to retain oversight, while others are open to greater delegation: 23% would allow an agent to act when certain pre-agreed rules are met, while 5% would be comfortable giving it full autonomy. 

Research highlights:

- Over half (54%) of consumers are comfortable with AI agents applying for credit on their behalf. 

- A little over than eight in 10 (82%) trust AI to compare loans across providers. 

- Over eight in 10 (85%) also believe AI agents could help compare more options than they could manually. 

- More than eight in 10 (84%) believe AI agents could help them find better prices or rates. 

- Three quarters would feel more comfortable using an LLM connected to a financial institution they already trust.

In Singapore, consumers are embracing AI agents because they see practical value, not simply because the
technology is new, Experian observed. However, comfort declines the further a task moves from research into commitment. Over a third (37%) of Singapore consumers would grant an AI agent no autonomy at all when applying for a loan or credit card; 36% would allow it to act only after their approval, and 27% would allow conditional or full autonomy.

More than three-quarters (77%) of Singapore respondents said they would feel more comfortable using AI
connected to a financial institution they already trust, highlighting the opportunity for banks and lenders to build AI experiences within trusted customer relationships rather than treating AI as a standalone service.
At the same time, 82% of Singapore consumers say AI agent manipulation - through fake offers or
impersonation by cybercriminals - is their top concern, the highest level of concern recorded for this risk
across the study's 13 markets. 

This mirrors a wider pattern in Singapore, where scams remain a national concern despite recent declines. Scam losses fell 17.9% year-on-year to around S$410.6 M in the first half of 2026, from approximately S$500.2 M in the same period a year earlier, according to Singapore Police Force figures reported by local media. 

E-commerce and phishing scams remain the most common case types, underlining why identity verification and fraud prevention will be critical as AI-assisted financial journeys take hold.

The research also lands against a backdrop of rising household borrowing. Singapore's total household liabilities reached S$415 B in the Q126, up 8.2% year-on-year - the fastest pace of growth in nearly five years - while personal loans rose 14.6% over the same period, according to Singapore Department of Statistics data reported by local media. 

As more consumers turn to credit - and increasingly compare and apply using AI - the need for secure, trusted AI-assisted journeys becomes more pressing, Experian observed. 

Kabir Khanna, GM, Experian Credit Services Singapore, said: “The opportunity is not simply to
make financial services faster with AI, but to make it possible for AI agents to act safely on a consumer’s
behalf. That requires a new layer of trust: being able to establish who the agent represents, what the
consumer has authorised it to do and whether the interaction can be trusted. Getting that foundation right will be critical to unlocking agentic finance at scale.” 

*Experian commissioned Forrester Consulting in July 2026 to survey 6,247 credit-active digitally literate consumers across Australia, China, Denmark, Germany, India, Italy, Malaysia, New Zealand, Norway, Singapore, South Africa, Spain and Turkey. Respondents represented a balanced mix of generations and employment groups and were selected based on recent experience using digital financial services. 

**LLM stands for large language model. 

25 November 2025

Indosat’s Anti-Spam and Anti-Scam capability has stopped hundreds of millions of digital fraud attempts

Amid rising digital crime and the increasing volume of harmful spam calls and messages, Indosat Ooredoo Hutchison (Indosat) has reinforced its commitment to safeguarding customers through the integration of AI across its network. 

Since its launch on 7 August 2025, Indosat’s Anti-Spam and Anti-Scam feature has blocked over 200 M risky calls, alerted users to more than 90 million suspicious messages, and protected an average of 11.5 M customers per month from potential digital fraud.

This innovation forms part of Indosat’s AIvolusi5G journey, a synergy between AI and 5G network capabilities, designed to deliver a digital experience that is secure, inclusive, and empowering. Operating at the network level, the system screens suspicious calls and messages automatically, without requiring additional apps or special devices.

Urgency for this protection is underscored by the GASA State of Scams in Indonesia 2025 report released in late August. The report found that 66% of Indonesian adults encountered scam attempts in the past year, with 14% losing money totaling IDR49 T. Most scams occurred via direct-message platforms such as instant messaging and SMS. 

Bilal Khazmi, Director and Chief Commercial Officer, Indosat Ooredoo Hutchison said: “This technology is designed to help our customers of all age groups explore the digital world with greater confidence. With fast connectivity, accessible products, and strong protection, we remain committed to deliver world class digital experiences, connecting and empowering every Indonesian."

Based on internal data, more than 290 M spam calls have been identified on Indosat's VoLTE network. When extrapolated to the entire customer base, this figure amounts to over 500 M identified scam and spam SMS and calls within just 2.5 months since the launch of the Anti-Spam and Anti-Scam feature. In addition, more than 145 M spam and scam messages have been flagged, including 110 M scam (fraudulent) messages.

Although the system does not yet fully block harmful calls or messages, its role as an early-warning system has proven effective in reducing financial losses and strengthening public digital awareness, Indosat said. Customers receive alerts before potential harm occurs, enabling them to take timely preventative action.

Indosat believes that technological progress must go hand-in-hand with digital literacy enhancement. Guided by the Zero Trust principle — never assume trust, always verify — this principle forms the foundation of Indosat’s approach in introducing this feature, helping the public remain vigilant toward suspicious messages, links, and calls.

The Anti-Spam and Anti-Scam feature, powered by Indosat’s AIvolusi5G technology, provides protection without requiring premium devices or additional app installations. For IM3 mobile customers, this protection is introduced as SATSPAM (Satuan Anti Scam dan Spam). SATSPAM BASIC is automatically active for all IM3 prepaid users with an active data package, and SATSPAM+ offers enhanced protection with the ability to detect malicious links.  

Tri mobile customers have a similar feature called TRI AI. AntiSpam/Scam features are available through visual detection with three colour codes: turquoise for a safe number, yellow for an unknown number, and red for high-risk numbers. 

Customers from IM3 and Tri can also access the Plus+ protection feature through the myIM3 and bima+ apps. This feature is automatically activated for users with an active data package, providing alerts via phone notifications and SMS for numbers flagged as suspicious or potentially harmful. It also offers clearer SMS warnings, colour-coded notification popups, and a call history summary accessible directly through the apps. 

3 November 2025

Meta helps Singaporeans stay safe online

Meta is stepping up its efforts to help Singaporeans stay safe online by introducing a range of new anti-scam tools and expanding digital literacy initiatives across the country. These updates are designed to make it easier for people to spot scams and protect their personal information. 

The new safeguards combine proactive scam detection with user education, empowering people to identify risks and stay protected. The company also offers practical advice for staying safe online. 

In the first half of 2025 alone, Meta took action against nearly 12 million scam-linked accounts globally, including the removal of over 68,000 fake accounts and 650,000 scam-related ads in Singapore. These numbers highlight the scale of the challenge and demonstrate the company’s ongoing commitment to building trust and integrity on its platforms.

Clara Koh, Head of Public Policy, Central Southeast Asia & ASEAN said: “At Meta, protecting our users from scams is a top priority. The launch of these anti-scam tools in Singapore and our ongoing public education campaigns underscore our continuing commitment to user safety and empowering Singaporeans with essential digital literacy skills. Tackling online scams requires a collaborative approach, which is why we work closely with governments, technology partners, banks, and law enforcement to collectively detect and stop scammers.”

In Singapore, WhatsApp users will now receive an on-screen alert if they attempt to share their screen with someone who isn’t saved in their contacts during a video call. This new safeguard is designed to help prevent scammers from accessing sensitive information. 

Meanwhile, Meta is rolling out enhanced scam detection on Messenger. This tool notifies users if they receive a suspicious message from an unknown sender and allows them to submit recent chat messages for an AI review. Both of these tools are part of Meta’s ongoing commitment to helping people spot and avoid scams before any damage is done.

Meta has also made it easier for people to secure their accounts with passkeys, a safer alternative to traditional passwords, on Facebook, Messenger, and WhatsApp. In addition, users can take advantage of privacy and security checkup tools to manage their settings, enable strong passwords, set up two-factor authentication or two-step verification, and control who can see their information.

As a Digital for Life (DfL) partner, Meta recently participated in the Singapore Infocomm Media Development Authority’s (IMDA) Digital for Life Festival. 

Doreen Tan, Assistant Chief Executive of Strategic Planning and Digital Readiness at IMDA said: "We are grateful for Meta’s continued support for the DfL movement. At the DfL Festival this year, Meta stepped forward to equip parents and youths with practical tools and resources to develop healthy digital habits, and educate everyone on how to stay safe against scams. Through collaboration with DfL partners like Meta, IMDA will continue to foster a more inclusive digital society as Singapore digitalises more.”

Source: Meta. From left: Corrinne Quek, Senior Programme Head, IMDA; Doreen Tan, Assistant Chief Executive, Strategic Planning & Digital Readiness, IMDA; Gan Kim Yong, Deputy PM and Minister for Trade and Industry, Singapore; Clara Koh, Head of Public Policy, Central Southeast Asia & ASEAN, Meta; Priyanka Bhalla, Head of Safety Policy, Meta; and Tanya Wilson, Education Lead, EYEYAH!
Source: Meta. From left: Corrinne Quek, Senior Programme Head, IMDA; Doreen Tan, Assistant Chief Executive, Strategic Planning & Digital Readiness, IMDA; Gan Kim Yong, Deputy PM and Minister for Trade and Industry, Singapore; Clara Koh, Head of Public Policy, Central Southeast Asia & ASEAN, Meta; Priyanka Bhalla, Head of Safety Policy, Meta; and Tanya Wilson, Education Lead, EYEYAH!

To further spread awareness, Meta has collaborated with local podcasts to encourage Singaporeans to enable two-step verification and use block and report features on WhatsApp. The company also encourages open conversations about scams, and recommends following trusted sources like ScamShield or the Singapore Police Force for real-time scam alerts.

Explore

For tips on staying safe online, visit about.meta.com/sg/actions/safety/anti-scam

21 July 2023

Facebook flooded with fake pages luring victims with generative AI

Source: CPR. Sample posts on fake Facebook pages inviting viewers to download malware.
Source: CPR. Sample posts on fake Facebook pages inviting viewers to download malware.

A new scam uncovered by Check Point Research (CPR) uses Facebook to scam victims by taking advantage of the interest in generative AI.  Many of these fake pages have tens of thousands of followers, with a mix of real content and malware, Check Point said.

Criminals first create fake Facebook pages or groups for a popular brand, even including engaging content. The pages can offer tips, news and enhanced versions of AI services Google Bard or ChatGPT, for example. 

Unsuspecting Facebook users end up passionately discussing the role of AI in the comments and like or share posts, thereby ensuring it shows up on the feeds of their friends and attracting them to the page as well.

The scam occurs when visitors are invited to obtain new services or special content via a link on the page. Most of the Facebook pages lead to landing pages which encourage users to download password-protected archive files that are allegedly related to generative AI engines. When the link is clicked, victims unknowingly download malware, designed to steal their online passwords, crypto wallets and other information saved in their browser.

There are many versions, from Bard New, Bard Chat, GPT-5, G-Bard AI and others. Some posts and groups also try to take advantage of the popularity of other AI services such as Midjourney and Jasper AI. Seemingly small details matter, such as the fact that the real Jasper AI page has 2 million fans or the length of time the page has been in operation, in telling the genuine from the fake.

According to Sergey Shykevich, Threat Intelligence Group Manager, Check Point Research: "Unfortunately, thousands of people are falling victim to this scam. They are interacting with the fake pages, which furthers their spread – and are even installing malware which is disguised as free AI tools. We urge everyone to be vigilant in ensuring they are only downloading files from authentic and trusted sites."

CPR observed that criminals have gone to great lengths to ensure their pages appear authentic. When a user searches for ‘Midjourney AI’ on Facebook and encounters a page with 1.2 million followers, they are likely to believe it is an authentic page. The principle applies to other indicators of page legitimacy: when posts on the fake page have numerous likes and comments, it indicates that other users have already interacted positively with the content, reducing the likelihood of suspicion.

Additionally, the links to malicious websites are mixed with links to legitimate Midjourney reviews or social networks.

CPR attributed the surge to expanding underground markets, where initial access brokers specialise in acquiring and selling access or credentials to compromised systems. Additionally, the growing value of data used for targeted attacks such as business email compromise and spear-phishing, has fuelled the proliferation of infostealers.

As authentic AI services make it possible for cybercriminals to create and deploy sophisticated, credible scams, it is essential for individuals and organisations to stay vigilant, CPR said. Some rules of thumb to protect yourself include:

- Ignore display names: Phishing sites or emails can be configured to show anything in the display name. Instead of looking at the display name, check the sender’s email or web address to verify that it comes from a trusted and authentic source.

- Verify the domain: Phishers will commonly use domains with minor misspellings or that seem plausible. For example, company.com may be replaced with cormpany.com or an email may be from company-service.com. These misspellings are good indicators.

- Always download software from trusted sources: Instead of downloading software from a Facebook group, go directly to a trusted source, such as the official web page for that software. Do not click on downloads from groups, unofficial forums etc.

- Check the links: URL phishing attacks are designed to trick recipients into clicking on a malicious link. Hover over the links within an email and see if they actually go where they claim. Enter suspicious links into a phishing verification tool like phishtank.com, which will tell you if they are known phishing links. If possible, don’t click on a link at all; visit the company’s site directly and navigate to the indicated page.

19 September 2022

Crypto giveaway scams are on the rise

Source: Group-IB. A screen capture from a fake YouTube video purporting to feature Elon Musk. Musk is talking to three other men.
Source: Group-IB. A screen capture from a fake YouTube video purporting to feature Elon Musk.

Group-IB, a Singapore-headquartered cybersecurity provider, has found a fivefold increase in the number of domains used for crypto giveaway scams that involve fake YouTube streams in 1H22. Since Group-IB’s first report on the scheme, crypto giveaway scams evolved into a market segment with multiple services for fraudulent operations.

According to Group-IB, 63% of the new fraudulent domain names were registered with Russian registrars, but the fake websites are primarily designed to target English and Spanish-speaking crypto investors.

For the first time, the Group-IB Computer Emergency Response Team (CERT-GIB) observed a sharp increase in the number of fraudulent YouTube streams “featuring” big names. Videos purporting to be from Elon Musk, the founder and CEO of SpaceX and Tesla; Brad Garlinghouse, CEO of Ripple Labs; MicroStrategy's co-founder and Executive Chairman Michael J. Saylor, as well as Cathie Wood, the founder and CEO of Ark Invest were found in February this year. 

The scammers used the footage of famous entrepreneurs and crypto enthusiasts to encourage users to visit a promotional website to double their crypto investment. Victims would be invited to transfer crypto to a specified address or disclose the seed phrase of their crypto wallet to receive even better terms.

Group-IB experts have discovered that the scheme has scaled significantly in six months. In 1H22, CERT-GIB identified more than 2,000 domains registered explicitly to be used as fake promotion websites. This figure increased almost five-fold compared to 2H21 and 53-fold in comparison with 1H21. In Q122 Group-IB researchers discovered 583 fake websites involved in the scheme. The next quarter the Group-IB team found an additional 1,500-plus domains newly set up by scammers to promote fake giveaways.

Scammers also advertised promo sites featuring Nayib Bukele, the President of Salvador, as well as the soccer player Cristiano Ronaldo. Both names were chosen for a reason, Group-IB said. In 2021, mainly on the initiative of its president, El Salvador became the first country to adopt Bitcoin as its national currency. Ronaldo, on the other had, became the first football star paid with cryptocurrency: the player was awarded a bonus of 770 crypto tokens from his club Juventus, one for each goal scored in his career. In June 2022, Binance, a crypto trading platform, announced an exclusive partnership with Ronaldo.

Group-IB advises crypto owners to be vigilant about free giveaways and not to share confidential data on rogue websites. Other advice included:

- Double-check the legitimacy of the streams and the websites you visit using official sources only. If you cannot find any information about the promotion taking place, you are likely being deceived.

- Seed phrases must be kept secret and stored securely. To do so, use password management tools.

- To minimise the risk of leakage, prioritise desktop solutions over cloud-based ones.

- You risk being deceived twice if you have already transferred your crypto to fraudsters and want your money back. People who message victims on forums offering help often turn out to be scammers themselves.

10 November 2021

Imperva warns against Singles Day scams

Imperva, the cybersecurity leader whose mission is to help organisations protect their data and all paths to it, has launched a new e-commerce report and issued advice around safe retailing in conjunction with the world’s biggest online shopping event on November 11.

The company noted that Chinese e-commerce firms Alibaba and JD.com racked up a record-breaking US$115 billion in sales across their platforms during Singles Day 2020, and that as the number of online shoppers grow, so do the scams. Imperva’s new The State of Security Within eCommerce 2021 report projects the number of victims in 2021 to surpass that of last year’s.

In Singapore, for instance, the number of security incidents in retail increased 31% from April to September 2021 compared to the previous six-month period, Imperva said, highlighting the following trends:

Malicious bots

Online retail has remained a prime target for automated bot activity in 2021. Bots can carry out disruptive or malicious, activities on retail sites including price and content scraping, scalping, denial of inventory and other types of online fraud.

According to Imperva, the volume of monthly bot attacks on retail websites rose 13% in 2021 compared to the same months of the previous year. Imperva Research Labs found that 57% of attacks recorded on e-commerce websites this year were carried out by bots. In comparison, bad bots made up just 33% of the total attacks on websites in all other industries in 2021.

Incidentally, the top type of security incident in the Singapore retail industry in the past 12 months (October 2020 − September 2021) has been bad bot traffic (44%). In the December shopping period last year in particular, Singapore’s retail industry saw a marked rise in simple bot traffic of 60% above the monthly average.

The proportion of sophisticated bad bots on retail websites reached 23.4% in 2021. This breed of bot is the hardest to stop because they are capable of producing mouse movements and clicks that closely resemble human behaviour. Sophisticated bots evade simple defences and are responsible for account takeover, fraud or denial of inventory that makes it harder for legitimate shoppers to get the goods they want, Imperva said.

Distributed Denial of Service (DDoS) attacks

Imperva Research Labs is already seeing an uptick in DDoS attacks − spiking 200% in September 2021, compared to the month prior. Part of this uptick in activity is tied to the Meris botnet that has impacted organisations globally.

Throughout the past 12 months, the retail industry experienced the highest volume of application layer (layer 7) DDoS incidents per month of all industries. Layer 7 attacks are highly effective because they consume both network and server resources. Defending against application layer attacks is difficult because it requires the ability to distinguish between attack traffic and normal traffic.

Website attacks

Attacks on retail industry websites from Q420 through the first half of 2021 were notably higher than all other industries, and were characterised by more sporadic peaks in attacks. 

Retail sites experienced slightly higher volumes of data leakage attacks (31.3%) in 2021 compared to all industries (26.9%) as e-commerce sites are prime targets because they host shoppers’ payment information or loyalty reward points. Data leakage occurs when data is transmitted from an organisation’s corporate network to an external destination, whether accidentally or deliberately, without authorisation. In January 2021, the Singapore retail industry saw a 59% increase above the monthly average for data leakage attacks, coinciding with the Chinese New Year shopping period.

Imperva's advice for shoppers includes:

  • Before you shop, ensure your software and apps are updated so you have all the latest security patches. 
  • Do not shop through a public Wi-Fi connection. Instead use a VPN or your phone as a hotspot. 
  • Make sure you shop through a reputable site with a padlock symbol and ‘https’ at the start (not http). 
  • Be careful of the apps/extensions you download onto your devices. 
  • Stick to well-known brands or applications. Be especially wary of free apps. 
  • When setting up your shopping accounts be sure to use strong, differentiated passwords for each account, and set multifactor authentication where possible. 
  • Use secure payment methods like PayPal or your credit card. 
  • Never send your bank or credit card details via email or SMS. 
  • Don't let your online shopping accounts or browser save your payment details. 

Imperva's advice to retailers includes:

  • Ensure your organisation is compliant with all data privacy regulations in your jurisdiction. 
  • Prepare for a high volume of traffic, as well as DDoS attacks. 
  • Be sure to have a bot management strategy in place to only allow legitimate customers onto your website. 
  • Encourage your customers to practice good password practices and offer multifactor authentication. 
  • Protect your existing website functionalities and make sure newly-added ones are safe, too. 
  • Take inventory of all your JavaScript-based services. 

“The 2021 holiday shopping season is shaping up to be a nightmare for both retailers and consumers,” said Peter Klimek, Director of Technology, Office of the CTO, Imperva.

“With the global supply chain conditions worsening, retailers will not only struggle to get products to sell in Q4, but will face increased attacks from motivated cybercriminals who want to benefit from the chaos. Retailers and consumers alike need to take the necessary steps to protect themselves.”

Explore

Download the State of Security within e-Commerce Report

2 March 2020

MAS warns against phone and messaging scams

The Monetary Authority of Singapore (MAS) has warned that there have been fraudulent messages and calls to members of the public that purport to be from MAS staff. These calls request personal or bank account information.

"MAS officers will never ask members of the public for personal banking information nor security login credentials," MAS said in a statement.

According to MAS, the calls may be received as regular phone calls or via applications such as Viber or WhatsApp. Perpetrators can even use caller ID spoofing technology to mask their actual phone numbers, instead displaying a genuine MAS contact number. MAS’ logo can appear as the profile picture on Viber or WhatsApp.

The person receiving the call will typically be told that his or her bank account has been locked or suspended, and then offered assistance to resolve the matter. The victim is asked to provide details of his or her bank account, Internet banking user ID and password. Scammers may also pretend to be staff from banks.

"Anyone who receives such messages or calls should not disclose personal information including Internet banking or credit card details, bank account username, personal identification numbers (PINs) or one-time passwords (OTPs)," MAS added.

MAS advises the public to:

- Never disclose Internet or mobile banking details or credit card details such as bank account user ID, passwords, PINs or OTPs to anyone through phone, email or SMS/messaging applications.

- Not authorise any suspicious authentication request. For example, they should not respond to digital token authentication or OTP requests via phone calls if Internet/mobile banking transactions were not initiated.

- Be suspicious of unsolicited messages or calls purporting to be from MAS or banks.

Those who receive a suspicious call, should hang up and report the call to MAS at webmaster@mas.gov.sg. Numbers provided by the caller should not be called, and the number should be blocked or reported as spam on the mobile application.

The scams can be reported to the police at hotline 1800 255 0000, or submitted online at www.police.gov.sg/iwitness. All information will be kept strictly confidential. For urgent police assistance, dial 999.

Scam-related advice is available from the anti-scam hotline at 1800 722 6688 or, at www.scamalert.sg.

Phishing-related advice is available from the MoneySense website.

5 February 2019

Microsoft: Singapore Millennials impacted greatly by online risk

- Millennials and teenagers are the hardest-hit by online risks in Singapore, a new Microsoft study has revealed.

- The most common type of online risks faced by the Singapore respondents include sexual risks (68%); hoaxes, scams and frauds (61%); behavioural risks (54%); and unwanted content (45%).

- Many of those who have been a victim of online risks said that the perpetrators were people that they knew.

- In terms of their propensity to seek help, only slightly over half (55%) of Singapore teens said that they would reach out for help following an online risk encounter.

In observance of Safer Internet Day (5 February), new Microsoft research has revealed that Millennials (aged 18 to 34) and teenagers (aged 13 to 17) in Singapore were the hardest hit by online risks compared to other consumer groups. 

Source: Microsoft. Microsoft Digital Civility Index featuring the 22-country ranking.
Source: Microsoft. Figure 1: Microsoft Digital Civility Index featuring the 22-country ranking.

According to the 2019 Microsoft Digital Civility Study, 69% of Millennials and 66% of teenagers in Singapore have encountered at least one form of online risk – including exposure to unwanted contact; hoaxes, scams and fraud; behavioural risks and sexual risks – in their lifetime, ahead of the Generation X (59%) and Baby Boomers (48%).

The study, which placed Singapore 10th out of 22 countries for the rate of exposure to online risks, also found local teenagers to be less likely to seek help compared to others. Teenagers here faced an average of 2.6 online risks in their lifetime, with teenage girls being more vulnerable, averaging three online risks compared to the 2.2 faced by teenage boys. Millennials, on the other hand, averaged 2.5 online risks, significantly higher than the Generation X and Baby Boomers, who averaged 2.1 and 1.4 online risks respectively.

Conducted with 11,000 respondents in 22 countries, including 500 Singapore adults (aged 18 to 74) and teenagers in May 2018, the Microsoft Digital Civility Study was specifically designed to uncover insights into consumers’ lifetime exposure to a wide range of online risks, to shed light on the impact of online risks to their wellbeing, while informing them about how to stay safe and secure online.

Having yielded insights that 63% of Singapore respondents have encountered at least one form of online risk in their lifetime, lower than the global average of 66%, the study placed Singapore 10th out of 22 countries for the overall rate of exposure to online risks.

Encountering offensive content and fake news stood out as top online risks in Singapore. While the overall incidence of exposure to online risks for Singaporeans was lower than the global average, the country stood out for its rate of exposure to specific types of risks. According to the study, the most common type of online risks faced by the Singapore respondents include:

Sexual risks: Receiving unwanted sexual messages or images topped the list with 68% of the local respondents saying that they have encountered this situation before, higher than the global average of 67%.

Hoaxes, scams and frauds: Encountering fake news came in second, with 61% of local respondents saying that they have encountered this situation before, higher than the global average of 57%.

Behavioural risks: Being called offensive names came in third, with 54% of local respondents saying that they were called offensive names before, higher than the global average of 51%.

Unwanted contact: Being contacted by a stranger to collect personal information came in fourth, with 45% of local respondents saying that they encountered this situation, higher than the global average of 42%.

And while 29% of the online risks encountered by Singapore respondents came from strangers, 41% of these risks came from people that the respondents knew, including online acquaintances, casual acquaintances and co-workers. Additionally, 24% of the online risks encountered by Singapore respondents came from their own family and friends.

Overall, Singapore respondents expressed lower levels of pain from the online risks encountered. Sixty-four percent of the respondents reported mild to moderate pain, with only 15% reporting severe levels of pain from their online risk encounters.

Microsoft notes that the results show that more needs to be done to help local teenagers seek help when facing online risks. According to the research,  51% of Millennials and teenagers reported moderate to severe pain following their online risk encounters. The pain experienced can include widespread emotional, psychological as well as physical pain.

The study additionally revealed that only slightly over half (55%) of the Singapore teens would reach out for help following an online risk encounter. Thirty-two percent of Singapore teenagers who have encountered such risks would ask their parents for help, lower than the global average of 42%; while 23% would ask an adult for help, lower than the global average of 28%.

“As we continue to interact with and in the digital world, we can no longer sit back and allow these online risks to have a negative impact on our lives. Each day, we are being bombarded with unsolicited online content ranging from emails sent by unknown third parties to the circulation of fake news and unwanted sexual messages. And these represent just a fraction of the common scenarios that Singaporeans face in everyday living. 

"Today on Safer Internet Day, it’s time for us to take a stand. By participating in the Microsoft Digital Civility Challenge and committing to making the four digital civility ideals a reality, we can do our part to help a build a better and safer digital environment for everyone,“ said Richard Koh, CTO, Microsoft Singapore.
On Safer Internet Day, Microsoft is encouraging all Internet users to take part in the annual Digital Civility Challenge and practise the four digital civility ideals to create a more positive online environment for everyone:

Living the golden rule: I will act with empathy, compassion and kindness in every interaction, and treat everyone I connect with online with dignity and respect.

Respecting differences: I will appreciate cultural differences and honour diverse perspectives. When I disagree, I will engage thoughtfully and avoid name-calling and personal attacks.

Pausing before replying: I will pause and think before responding to things I disagree with. I will not post or send anything that could hurt someone else, damage someone’s reputation, or threaten my safety or the safety of others.

Standing up for myself and others: I will tell someone if I feel unsafe, offer support to those who are targets of online abuse or cruelty, report activity that threatens anyone’s safety, and preserve evidence of inappropriate or unsafe behaviour.

Users can also encourage their friends and family on social media to join in the challenge with the hashtags #challenge4civility or #Im4digitalcivility.

Explore:

1 November 2018

Millennials, males most prone to tech support scams

- Globally, the incidence of tech support scams has declined compared to 2016, but still poses a threat to consumers globally.

- In Singapore, 57% of consumers said that they have encountered a tech support scam in the form of an unsolicited call, redirect to website, unsolicited email or a pop-up ad or window in 2018.

- While over half of Singaporeans have encountered a tech support scam in the past year, 43% of Singapore respondents chose not to interact with scammers.

- Millennials and males in Singapore are found to be most prone to tech support scams as compared to other demographic groups.

- Popup ads/windows are the most common types of tech support scams encountered by Singapore consumers, followed by redirect to website, unsolicited emails and unsolicited phone calls.

Ad popups are the most prevalent type of tech support scam.
Ad popups are the most prevalent type of tech support scam.

While the incidence of tech support scams has declined compared to two years ago, the issue remains a problem globally, with Millennials and males among the most prone to tech support scams. Microsoft has released a new global survey*providing insights into the state of tech support scams in 2018 and its impact on consumers worldwide.

Conducted by Microsoft’s Digital Crimes Unit with 16,048 respondents globally, including 1,000 from Singapore, the survey found that while the incidence of tech support scams have declined compared to 2016, it still poses a threat to consumers globally. The survey found that three in five people have experienced a tech support scam and one in five has lost money to fraudsters globally in the past year.

Tech support scams can occur in various forms. For years, scammers have tricked consumers into handing over control of their computers and personal information by peddling bogus security software and services over the phone. They ask for credit card details, and do not deliver anything; the victims typically receive credit card bills for purchases that they did not make later on.

Today, scam artists have adapted to changing technology by finding more sophisticated tactics to target users online. They can now use phishing emails, phony websites, and popup windows to gain access to a person’s computer. Some will even ask permission to access the victim's computer to solve a problem, enabling them to steal personal and financial information that is already on the computer.

According to Mary Jo Schrade, Assistant General Counsel and Regional Director, Digital Crimes Unit (DCU), Microsoft Asia, callers often impersonate Microsoft (or HP, Dell, Symantec, Google and Apple) or may send a popup that says Windows has encountered a virus that can only be cleaned by calling a specific number. Schrade said less tech-savvy people are typically selected as victims through focusing on owners of fixed lines - the more tech-savvy typically rely on their mobile numbers.

"They're assessing all the time whether you're sophisticated or not," she said of scammers who take control of a victim's computer. "They will pull up random things and highlight them to make you think that it is a virus."

Scammers can also install malicious software to extort money from victims for fake tech support that purportedly “fixes” fraudulent computer problems.

According to the survey, fewer consumers in Singapore have encountered a tech support scam in 2018 compared to 2016. More than half (57%) of the consumers said that they have encountered a tech support scam in the form of an unsolicited call, redirect to website, unsolicited email or a popup ad or window in 2018, a significant decline from the 65% who encountered one in 2016.

While over half of Singaporeans have encountered a tech support scam in the past year, the city state is ranked among the most savvy countries globally when dealing with tech support scams. Four in 10 (43%) Singapore respondents chose not to interact with scammers – the fourth highest percentage globally - behind Japan (65%), China (57%) and Germany (48%).

Additionally, while a minority (15%) continued interacting with scammers after encountering a tech support scam, only 4% of respondents have lost money as a result of tech support scams in 2018, down from the 7% who lost money as a result of the issue in 2016.

When comparing demographic groups, Millennials in Singapore aged between 24 and 37 emerged as the group that is most prone to tech support scams, followed by Gen X (aged 38 to 53), Gen Z (aged 18 to 23) and Baby Boomers (aged 54 and above). Globally, Millennials were also most likely to believe that the unsolicited contact is normal.

When comparing across gender, male consumers were also found to be more vulnerable to tech support scams, as compared to females.

Among consumers who have lost money as a result of tech support scams, activities that they frequently engage in include sharing email information in exchange for content, downloading movies, music and videos, or visiting torrent sites. This implies that these activities can be considered risky online behaviour that increase one’s exposure to potential scams.

Additionally, the survey also found that monetary loss was not the only consequence of tech support scams, with its impact extending to one’s mental well-being as well. Half of the Singaporean respondents who continued engaging with scammers ended up spending time checking or repairing their computers, while 81% of Singaporean respondents reported moderate to severe levels of stress as a result.

In terms of the most common types of tech support scams encountered by Singapore consumers, popup ads and windows emerged tops, ahead of redirect to website, unsolicited emails and unsolicited phone calls.

Types of scams encountered by Singapore respondents

Rank
Tech support scam
Percentage of respondents who encountered this
#1
Popups: Online advertisements that seem to be from a trustworthy company. These claim that your computer is infected with a virus and that they can help resolve the issue.

43%
#2
Redirect to website: Been redirected to a website that appears to be from a reputable company. These claim that your computer is infected with a virus and that they can help resolve the issue.

37%
#3
Unsolicited emails: The most common emails appear to be from a reputable company which claim that your computer is infected with a virus and that they can help resolve the issue.

35%
#4
Unsolicited phone calls: An unsolicited telephone call from someone claiming to be from a reputable company. The caller shares that your computer may be infected with a virus or some other security or network problem, and that they can help resolve the issue.

20%

Schrade said that globally, Microsoft receives 2,500 complaints a week and reviews 200,000 popup images daily. She also shared that Microsoft is now using artificial intelligence and machine learning to make the identification of scam-related popups easier. Instead of looking for a particular sequence of words and numbers which could change as scammers change names and phone numbers, AI can shortlist which of the many popups are suspicious very quickly, with accuracy of 80% to 100%.

The results can be used to connect consumer complaints to popup images, gaining intelligence in realtime to help with case development enrichment, disruption at scale, as well as evidence for law enforcement to strengthen investigations, she said.

"Bing has a fraud alert – when people buy advertising, we can check if it's a tech support scam," Schrade disclosed. "We have rejected 130 million ads as a result of that."

Microsoft recommends the following tips for consumers to protect themselves:

- Be wary of any unsolicited pop-up message on your device, don’t click on it, and don’t call the number.

- Never give control of your computer to a third party unless you can confirm that it is a legitimate representative of a computer support team with whom you are already a customer of.

- Hang up and contact Microsoft directly at the Microsoft Answer Desk

“While consumers in Singapore have shown that they are increasingly more knowledgeable about tech support scams, it is important to note that tech support scam methods will continue to evolve. Always remember that companies like Microsoft will never proactively reach out to consumers to provide unsolicited PC or technical support and do take action to report a scam to the authorities whenever you encounter one.

"At Microsoft, our Digital Crimes Unit uses a data-driven approach to investigate tech support fraud networks and work with law enforcement to combat them. At the same time, we are always making sure that we continue to strengthen our products and services to better protect consumers from the constantly-evolving nature of fraudulent practices,” said Richard Koh, CTO, Microsoft Singapore.

Details:

Read the survey report

If you think you may have been the victim of a tech support scam, report your experience at www.microsoft.com/reportascam and also file reports with law enforcement authorities, such as your local consumer protection authority

Learn how to protect yourself from tech support scams

Read the WorkSmart Asia blog post about the Microsoft PC Test Purchase Sweep

*The global study was conducted with 16,048 respondents in 16 markets: Australia, Brazil, Canada, China, Denmark, France, Germany, India, Japan, Mexico, New Zealand, Singapore, South Africa, Switzerland, the UK and the US.

7 October 2016

Scammers set more lures after Kardashian news trends

News about a celebrity goes viral, and the scammers go to work. Earlier this week scammers capitalised on reports that US social media star Kim Kardashian West was robbed at gunpoint in her private Paris residence.

Norton reported that within 24 hours after the incident was made public, there was a 2,400% increase in Kim Kardashian-related spam and scams. In order to make money, steal personal information or do damage, Norton notes that attackers use current events as a hook to play on people’s emotions and attract attention. As a result, nearly 100 different subject-line variations were seen in spam messages alone associated with Kardashian’s name, including “Breaking News” and “Photos of” in the subject line. The majority of messages Norton has tracked so far are in English, French and German.

Media reports commenting on the rubbery point to social media as a way for intruders to enter personal lives. Norton's tips for Snapchat and Instagram users include:

Geotagging
o By default, Snapchat provides no information about someone’s location. However, users can use geofilters which apply a special overlay to their snaps. This information is usually the name of the city, state or associated with a landmark or business, but it does not pinpoint the users’ approximate location.

o Instagram on the other hand allows users to geotag their photos or videos with a specific landmark/location. The only other way to identify someone’s location would be by identifying any landmarks in the images themselves. So remember, don’t geotag photos from personal locations (like your home, office, a friend or family members’ home)!

Privacy settings
o Ensure that you regularly review your privacy settings
o Remove geotags on previously posted photos from these personal locations by viewing your photomap (Instagram)
o If you’re a Snapchat user, be sure you know who can view your Snapchat stories and who can contact you

Social engineering scams come in many forms, Norton adds. Some files of thumb include:

- Don’t open e-mails or click on attachments from those you don’t know

- Be sceptical: just because you’ve seen it on your newsfeed doesn’t mean it’s not a scam. Your friends may have fallen victim to a click-jacking scam and may not not even be aware of it. They may have clicked on a link which then hijacks their address book and sends phishing requests to their friends without their knowledge.

- Hover over the URL before clicking to see what kind of site you’ll be redirected to – it is best to visit only websites you know and trust. Tools like Norton Safe Search can verify a website’s legitimacy

- Be suspicious of any calls to action such as filling a form (phishes personal details), downloading a plug-in (could be malware) or the need to share with friends before actually watching or reading the promised content

- Report suspicious activities or content to the social media platform or your e-mail service provider

posted from Bloggeroid

17 July 2016

Avoid Pokemon Go scams, malware

Source: Niantic blog. A seadra captured on-screen.
Source: Niantic blog.
Pokémon Go, the augmented reality mobile game that has become a global sensation since its launch in early July, has already attracted the attention of scammers and cyberattackers. While yet to arrive (legally) in Asia*, there are risks that players should be aware of, says Symantec.

In a recent blog post Symantec has detailed several Pokémon scams, from free PokeCoins and fake versions of the mobile game, to permission and privacy issues:

Free PokeCoin scams
Pokémon Go has in-app purchases, where users can spend real money to buy a virtual currency called PokeCoins. Players can spend the PokeCoins on items, such as incense to lure Pokémon to their location or eggs that hatch rare Pokémon . Those who search for discounted or free PokeCoins online are likely to encounter classic survey scams. 

"These links are widespread across the Internet, from posts on gaming forums to dedicated scamming sites. The majority of fraudulent results are posts on social media sites or videos with alleged proof that the PokeCoin hacking tool works," Symantec noted in the blog post.

Trojanised Pokémon Go apps
Trojan versions of the game targeting Android devices have appeared, including the remote access Trojan (Android.Sandorat) disguised as Pokémon Go. The threat was distributed on various download sites and gaming forums. If the malicious version of the app is installed, it displays the Pokémon Go start screen while giving the attacker complete access to the phone.

Those looking to cheat by getting rare Pokémon in a particular physical location have spoofed their GPS locations with readily-available apps that can be installed on rooted Android devices or jailbroken iPhones. While Symantec has not seen attackers disguise their malware as GPS spoofers yet, it could happen, the company warns.

Tips to stay safe with Pokémon Go include:

· Avoid downloading Pokémon Go from unofficial marketplaces, as attackers can use these sites to deliver malware disguised as legitimate apps

· Install the Pokémon Go update that removes the request for full access to Google accounts

· Stay away from game-cheating tools, as they could be fraudulent or may contain malware

· Keep your smartphone's firmware updated to prevent vulnerabilities from being exploited

· Use strong and unique passwords for your Pokémon Go account

· Pay close attention to the permissions that apps request

· Install a suitable mobile security app, to protect the device and data

Interested?

The blog post also details scam methods, privacy issues and how gamers are trying to cheat in Pokemon Go.

Follow the official Twitter account for updates on availability

Hashtag: #PokemonGO

*As of the time of writing Niantic had just released the game in 26 more European countries: Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, Greece, Greenland, Hungary, Iceland, Ireland, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Romania, Slovakia, Slovenia, Sweden, and Switzerland. On July 14, the game was released in Italy, Spain and Portugal, and in the UK on July 13, and in Germany on July 12. It was originally made available in the US, Australia and New Zealand.

17 June 2016

Cheap Ray-Ban sunglasses? It's a scam

Source: ESET. Chart for number of spam emails blocked by ESET.
Source: ESET.

ESET spam filters have detected a rise in scam emails luring recipients to buy luxury goods, mostly heavily discounted Ray-Ban sunglasses. The bogus websites where the fakes are offered use no encryption and may have been created to steal victims’ payment card details. ESET had previously warned that this scam, but that was when it had largely targeted Facebook. By adding email as an attack vector, the range of potential victims increases significantly.

“Those who enter their payment card data into these bogus website forms put their money at a serious risk,” says Lukáš Å tefanko, ESET Malware Researcher.

Over the last few months, ESET researchers have detected tens of thousands of these scam emails. Parallel to adding email as a new attack vector, the criminals behind the scam have also extended their geographic reach. The bogus sunglasses stores often target countries using their currencies to appear more genuine.

A few months ago, they almost exclusively accepted US dollars, the Eurozone’s euro, British pounds, Canadian dollars and Australian dollars. However, the latest email spamming campaigns have been redirecting to pages that also accept less popular currencies such as New Zealand dollars and the Singapore dollar.

“Internet users should not lose their security instincts when pursuing extremely cheap deals, be it for sunglasses or anything else. Your payment card details open your wallet – so think twice about entering them at websites that have suspicious addresses, offer suspiciously priced goods or use unsecured communications channels,” recommends ESET’s Å tefanko.

Recommendations on protecting yourself:

If you receive an email from an untrusted person with similar characteristics selling discounted goods, do not open any URL links, do not download any attachments and report the email as spam

If you are about to enter your payment card details, consider if the store is trustworthy and check if it uses encryption (there must be “https”, not “http” in the address bar, for example, and the link should not be a variation of a more well-known store)

Follow basic rules for safe online behaviour when using the Internet, such as ensuring the system is up-to-date, use a quality security solution or, at least, in case of any suspicion use a free tool to scan your computer.

24 April 2016

DBS discloses phone-based phishing campaign targeting Singapore residents

DBS has warned that a phishing campaign is targeting Singapore residents with automated phone calls. With over 4 million customers in Singapore alone the likelihood of scammers locating a DBS account holder is high.

According to a statement on the DBS website, the calls start with an automated voice message in English or Mandarin, claiming to be from DBS Bank and that an urgent message awaits them. The call recipient is then directed to enter “0” or “1”. This connects them to a Mandarin-speaking person posing as a DBS staff member who will claim there were credit cards applied for in their name and that they owe money to a Shanghai company. When the customer states they did not apply for the credit card, the alleged staff member will request personal and/or bank information, or transfer the call to another person who will claim to be a Shanghai police officer and request personal and/or bank information.

DBS advises recipients of such calls not to provide personal or bank information to unsolicited callers. "Never give out any sensitive personal information (including login passwords or one-time passwords) over the phone or via email. Our staff will never ask you for such information," the bank stated.

Interested?

Recipients of such calls and those who have disclosed personal information should inform the DBS customer centre at 1800 111 1111 (in Singapore) or +65 6327 2265 (calling from overseas) immediately.

3 August 2015

Senate Resolution 1454 requests Philippines Senate to address investment and networking scams

Senator Grace Poe has asked the Philippines Senate to revisit securities and investment laws to plug loopholes being exploited by unscrupulous companies to deceive the public into joining bogus investment schemes and networking scams.

Poe has filed Senate Resolution 1454, urging the Senate Committee on Banks, Financial Institutions and Currencies to conduct an "omnibus inquiry and assessment in aid of legislation, on relevant securities and investment laws, regulations and measures, with the end goal of introducing remedial amendments to better battle deceptive investment schemes and stop insidious networking scams."

The chairperson of the Senate Committee on Public Order and Dangerous Drugs filed the resolution in the aftermath of the P3-billion investment scam involving Batangas-based firm One Dream Global Marketing.

The lawmaker noted that One Dream is registered with the Securities and Exchange Commission (SEC) as a firm involved in trading, buying and selling of various goods, but it has no permit to engage in selling and marketing investment products.

"With One Dream being an SEC-registered firm, unsuspecting investors could have been made to believe that it is safe to invest their money into the company. Amendments may have to be made to prevent companies engaged in deceitful means from circumventing existing securities and investment laws, regulations and measures," Poe said.

Investors have filed a syndicated estafa* against One Dream officers led by owner Arnel Gacer after the company refused to return their money after repeated demands. Complainants alleged that One Dream deceived them through a "system profit scheme" in which investors were required to put in P888 with the promise of a "payout" of P1,300 after four days.

"Would-be investors are enticed by 'networking groups' by emphasising the seeming lavish lifestyle of their 'successful members' through their posts in social media showcasing their money, cars, watches, free trips or other material things," the senator said.

A few days after the One Dream scam broke out, the SEC also warned the public of other investment scams particularly against business entities "Freedom Life Advanced Global Prosperity Marketing Incorporated (Flag Prosperity)" in Laguna province, and Metro Manila-based "SUCCESS200 International Marketing Corporation," with operations in other parts of the country and overseas. Both firms have no SEC registration.

"Desiring to improve one's financial status and one's quality of living by investing one's hard-earned money is commendable and is beneficial not only to the investor but to the economy, but to prey on our countrymen through deceitful and unscrupulous means is simply wrong and the government ought to step in to ensure the protection of our countrymen's investments and dreams," Poe said.

*An estafa is a criminal offence involving fraud.

11 August 2014

Philippines senator warns public against investment scams

Senator Bam Aquino of the Philippines has advised the public against schemes that sound too good to be true, with descriptions like "easy money", "quick money", or "double your money".

He noted that various scams are common in popular social networking sites such as Facebook. Some are based on pyramid schemes, where money from new victims is given to earlier victims to show that their initial investments are making a profit and to attract more investments. 

"We should be prudent especially when it comes to money. Think twice before you put your hard-earned money into something, especially when it promises high returns of investment," said Aquino, who is Chairman of the Senate Committee on Trade, Commerce and Entrepreneurship.

Aquino spoke after the arrest of several individuals who were behind an investment scam advertised on Facebook. Another investment scam that duped 100 individuals of around P100 million was discovered recently. 

A July 29 article in the Manila Bulletin sheds more light, describing a pyramid scheme advertised by a company called Upwarm on Facebook. Upwarm was found to focus on recruitment and did not actually sell products. In a typical pyramid scam, recruited victims would pay fees for being part of the scheme, variously described as registration fees, money for paperwork, or money to buy products, but would profit more if they recruited others than if they actually sold any products. A portion of the money from new recruits would be used to reward those who had recruited them, with the company pocketing the rest.

"Before investing, we must tread on the side of caution by checking with the Securities and Exchange Commission if an investment company is registered," Aquino said.

"Just to make sure, we also must ask for documents that will prove the legitimacy of a company's operation," the senator added. He also called on authorities to intensify their campaign against syndicates involved in other scams to prevent more people from being victimised.

15 July 2014

Scammers using Singapore Airlines brand in attempts to harvest personal data

Singapore Airlines has warned that its brand is being used by scammers to harvest personal details. 

A May travel alert states that scammers are using emails and phone calls that claim to be from Singapore Airlines, and which inform recipients that they have been selected for a draw or have won air tickets, and then proceed to request their personal data. 

"To appear more authentic, such callers are also able to modify their caller ID to imitate our official telephone numbers," states the warning on the website.

The company advises recipients to verify calls and emails by sending details here. It also asks recipients to 
exercise discretion when revealing personal data and if they have any doubts to lodge a police report.

11 July 2014

New phishing technique brings in the government, warns against phishers

The phishers are at it again, but this time they've called in reinforcements. Rather than offering to work directly with the potential victim, this email claims to be from authorities which have discovered unusual activity, and want to be contacted about it. To add further authenticity, the message further warns that there are scammers out there, and not to deal with them. 

For the negligible sum of US$195, they promise to send the victim either US$75,000 or US$7,500,000 (depending on where you feel the comma should lie, no pun intended). There is no need to contact the victim further as payment instructions are conveniently listed.

This type of email is not yet common, but if it works, more phishers will definitely be trying some variation of it. It could work well as a two-part series, first with the offer to send a prepaid card with the money in it, and then later on to send this email asking for further details. 

The text of the email follows:

From: Koffi Annan 
Sent: Monday, 16 June, 2014 3:08 AM
To: Recipients
Subject: YOUR IMMEDIATE CONTRACT PAYMENT.(CASE FILE 54AC003)

YOUR IMMEDIATE CONTRACT PAYMENT.
CONTRACT#: MAV/NNPC/FGN/MIN/011.

Attention:


The Federal Government of Nigeria has been seriously warned by the United States Government, International Monetary Fund (IMF), World Bank, United Nations (UN) and other international bodies to make sure we settle most of our outstanding foreign debts we owed to Next of Kin's. Fund Beneficiaries and foreign contractors that executed contract with us immediately, this program is organized by the Board of Trustees and Directors for the end of the Year "POVERTY REDUCTION AND ERADICATION". We are using our reputable and well known organization to let you know that you are one of our chosen beneficiaries for this program of "POVERTY REDUCTION AND ERADICATION" in your country e-mail directory.

We hereby inform you that you have successfully being chosen and compensated for an International ATM card written out in your name in the amount of $750, 000, 00 here in the state (U.S.A). Now, for the compensated price, you will have to contact the Finance House and the Compensation Department for your perusals and claims of your compensated price and my dear beneficiary, below is the contact of the Finance House and Compensation Department (FHCD) for the collection and claims of your international certificated ATM card:

But, a very surprising record was discovered in your payment file that is why you have not been contacted about this since then. Records showed that your inheritance payment has been approved four times and duly completed two times. Also we found out that these funds totaling $750,000,00 was transferred directly from the central bank of Nigeria to the below stated bank account on your authorization and an international ATM CARD was also sent to your house address. This has now resulted in bringing the USA and British Government into the case and we really want you to explain to us what you know about this transfer/payment and delivery.


BANK NAME: STANDARD CHATTERED BANK,
BANK ADDRESS, 138-141 1ST FLOOR, EDINBURGH TOWER, THE LANDMARK, 15 QUEENS ROAD, CENTRAL HONG KONG, ACCOUNT NAME: INDO-CHINA GROUP LTD, A/C #: USD114-102-5567-8, SWIFT CODE: SCBL 11K111


The most baffling part is this payment keeps coming up in every period of debt reconciliation and verification always receives approval like now. NOW OUR QUESTION IS, HAVE YOU RECEIVED YOUR FULL PAYMENT OR ANY PART OF YOUR FUND ENTITLEMENT OWED TO YOU BY THE NIGERIAN GOVERNMENT? WE NEED AN ANSWER FROM YOU WITHIN 24HOURS FROM NOW. AND IF WE DO NOT HEAR FROM YOU IMMEDIATELY YOU RECEIVE THIS MESSAGE TODAY, WE WILL ASSUME YOU ARE INVOLVED AND HAVE RECEIVED OVER PAYMENT, WHICH ONE SHOULD BE RETURNED TO NIGERIA


Help us to help you, If not call him immediately you receive this message today on is direct number(  +1 760 422 5040 ) or send me a details email disclaiming the information so that you will be issued with claim identification code (CIC) which will help you to secure your claim and payment from fraudulent officials. And also you will be advised and guided accordingly on how you will receive your legitimate fund entitlement from the Nigerian Government, which will be credited into your nominated bank account within 72hours from now or delivered to you as well to your door step.


Therefore, i would advise you to contact FBI Agent Rev. Kelvin Williams for assistance and inform him that your CASE FILE is 54AC003. Contact him directly via the information below if you are yet to receive your funds.


UNITED NATIONS COMPENSATION AWARD PROGRAM CONTACT Officer: Rev. Kelvin Williams EMAIL :(yahoo email account listed) CELL PHONE:  (US number listed)

Once again it is important to note that your Fund/Payment was released with the following particulars attached to it.

(1) File Number: F1267-2009
(2) Ref. Code: KP23/857/MCL5 /CO
(3) Grant Number: MICC/97846563459/206
(4) Personal Identification Number (PIN): 0866750


Once again stop contacting those people. I advise that you contact Rev. Kelvin Williams so that he can help you in the collection of your ATM CARD payment instead of dealing with those liars that will be turning you around asking for different kind of money to complete your transaction and the FBI agent can also direct you to the paying bank.

Finally remember that I have forwarded instruction to the finance house on your behalf to send the International ATM card to you as soon as you contact them without delay. Please be informed that you should treat this as confidential as ever and in good faith from the Board and Management of the Organization, Also be informed that the International ATM CARD must get to you through a courier company which you will be responsible for the fees as soon as you contact the agent and also if you want the fund to be transferred as well through the paying bank.

What you have to do now is to contact the Rev. Kelvin Williams as soon as possible to know when they will deliver your package to you because of the expiring date, The only money you will send to the agent to deliver your International ATM card to your postal Address in your country is ($195USD) Dollars only being documentation and Security Keeping Fee of the Courier Company so far. Again, don't be deceived by anybody to pay any other money except $195USDollars, beside if you fail to comply with the needed $195 US Dollars required there’s no way we can deliver the International ATM card to your country.

You are to provide the following information.

Your Full Name:....................
Your Address:...............
Personal Telephone Number:................
Age:...................
Sex:....................
Occupation:................
Nationality:....................
Country:.................

Thanks. God Loves and Bless you and your family.

Hope to contact the F.H.C.D soon.

Your's Faithfully,

Koffi Annan

FORMER UN SECRETARY GENERAL

(CHAIRMAN OF FUND RELEASE)