Back in the day, a spoof was a device used to entertain us in a humorous and/or satirised way. A bit of harmless fun, something to laugh at before moving on. Recently though, “spoofing” has taken on an additional and more sinister meaning.
Here’s what’s currently happening in Meerkat-land…
The reported fraud attempt happened on a Saturday morning in May. It involved spoofing of the dodgy variety: an impersonation (in this case of an airline) intended to deceive and defraud and it was a multi-layered, technical operation.
Here’s how the story unfolded:
Our fraud victim took a quick scroll through Facebook and saw a promotion advertising a discount on flights on a large international airline. Being a regular passenger, she clicked through to check it out.
The “click” opened what appeared to be the large international airline’s WhatsApp business account on her phone, which was nothing unusual: she had often communicated with the airline via their WhatsApp Business Bot in the past.
She requested a promotional code but when it took a long time to arrive, she headed out for a run, leaving her phone at home.
Saturday morning then took an unexpected turn…
When she returned, there was a missed call from a number which started with the digits 060. The large international airline was listed as the caller name. The missed call was followed up by a WhatsApp message on the supposed “large international airline’s WhatsApp business account” saying, “Can I phone you to assist with the promo code?”
After she confirmed her availability, a call came through, this time from a number starting with 072, with no specific name appearing on her phone screen.
The caller identified himself as “Edward” and instructed her to download the large international airline’s application to her phone, despite the fact that she already had the official app installed. He insisted that she navigate to the Play Store, scroll to a particular app listed under the large international airline’s application options, and download THAT specific app.
Suspicious, much? Yes, indeed.
Once she had downloaded and opened the new app on her phone, she was required to create a new account by entering her name and email address, creating a password, and then confirming the password.
The new app then opened an authentication prompt; she had to upload her fingerprint – three times – at which point the app displayed an icon which said “Loading”, but took a VERY long time to move from 0% towards 100% complete.
Edward (in retrospect, clearly stringing her along to extend the time for the crooks to work behind the scenes) told her for a guy he had talked to the day before, it had taken four hours to assist with the downloading of the app to get to the promo code.
At this point the process was just taking too long, and our victim stated that she was rather going to leave it. Edward responded irritably, saying “Just give it 5 minutes!” and finally his tone alerted her that all was not above board.
She ended the call immediately and switched off her phone. After waiting a while, she switched her phone back on and called both her banks: Bank A (where she has most of her savings) and Bank B (where her salary is received and from which all her debit orders are paid).
And here’s what had happened while the icon was “Loading”:
Bank A asked if she had made a withdrawal and when she said no, they told her that R31 000 had nevertheless been taken from her credit card as well as R31 000 converted from her loyalty membership points. Other savings were also accessed which took the total amount withdrawn from her account to R200 000.
In a similar vein, Bank B informed her that R200 000 had been paid into her account and a R400 000 personal loan had subsequently been taken out in her name. A portion of the loan amount was immediately transferred to an unknown Bank C account and the balance into a Bank D account. (This should not have been possible, as she always kept her daily transaction limits set very low).
What the victim did right:
She took prompt action to limit further access by changing all her passwords and banking details, and switching to a new mobile phone. She also went to the police station to report a case of fraud and get a case number.
Was there a happy ending? Not entirely, not yet.
Of the R400 000 stolen, Bank B managed to recover R350 000 and absorbed the remaining R50 000. Despite this, Bank B has not yet cancelled the fraudulent loan facility they granted in her name to the scammers and a monthly repayment amount has been deducted from her account in both May and June. The interest she is being charged on this fraudulent loan is extremely high.
Equally disconcerting is the fact that the the large international airline’s scam post is still live on Facebook for any unsuspecting person to click on.
Red flags spotted (in retrospect):
- Having to download a second, “new” app (and “create a new account”).
- When she was required to give her fingerprint more than once.
- When she was asked to carry out a facial recognition (fortunately she was in a room too dark for the phone to scan adequately for facial recognition).
Preying on the power of our trust.
Once again, this scam demonstrates how our trust in brands can be exploited. Facebook allows advertisers to target people who have interacted with a particular Page in the past – even if that Page does not belong to the scammer. For example, an advertiser can target people who visit a competitor’s page, in an attempt to show them similar goods.
This means that scammers can target us more easily. And Facebook is notorious for not reacting timeously to complaints about advertising scams of this nature.
In addition, scammers can set up channels of communication (such as the WhatsApp business account) and label them with the names of official, legitimate businesses, even when they are nothing of the sort. This is classic “spoofing” in cybercrime terms.
How then do we reduce the chances of becoming a target?
- Be extremely wary of any offer made via advertisements on social media.
- If an offer catches your eye, go directly to the business website, rather than clicking on an advertisement.
- Use trusted channels of communication (i.e., those you have used before, or those on official websites).
- If you feel you are being put under pressure for any reason, whether it is to make a quick decision or being chided into waiting too long for an action to complete, suspect a scam and act accordingly. Break off the transaction process immediately, report the incident to your bank(-s) and change all your banking and communication account passwords.



0 Comments