Meerkat Alert

Spoofing and App Shenanigans

Back in the day, a spoof was a device used to entertain us in a humorous and/or satirised way. A bit of harmless fun, something to laugh at before moving on. Recently though, “spoofing” has taken on an additional and more sinister meaning.

Here’s what’s currently happening in Meerkat-land…

The reported fraud attempt happened on a Saturday morning in May. It involved spoofing of the dodgy variety: an impersonation (in this case of an airline) intended to deceive and defraud and it was a multi-layered, technical operation.

Here’s how the story unfolded:

Our fraud victim took a quick scroll through Facebook and saw a promotion advertising a discount on flights on a large international airline. Being a regular passenger, she clicked through to check it out.

The “click” opened what appeared to be the large international airline’s WhatsApp business account on her phone, which was nothing unusual: she had often communicated with the airline via their WhatsApp Business Bot in the past.

She requested a promotional code but when it took a long time to arrive, she headed out for a run, leaving her phone at home.

Saturday morning then took an unexpected turn…

When she returned, there was a missed call from a number which started with the digits 060. The large international airline was listed as the caller name. The missed call was followed up by a WhatsApp message on the supposed “large international airline’s WhatsApp business account” saying, “Can I phone you to assist with the promo code?”

After she confirmed her availability, a call came through, this time from a number starting with 072, with no specific name appearing on her phone screen.

The caller identified himself as “Edward” and instructed her to download the large international airline’s application to her phone, despite the fact that she already had the official app installed. He insisted that she navigate to the Play Store, scroll to a particular app listed under the large international airline’s application options, and download THAT specific app.

Suspicious, much? Yes, indeed.

Once she had downloaded and opened the new app on her phone, she was required to create a new account by entering her name and email address, creating a password, and then confirming the password.

The new app then opened an authentication prompt; she had to upload her fingerprint – three times – at which point the app displayed an icon which said “Loading”, but took a VERY long time to move from 0% towards 100% complete.

Edward (in retrospect, clearly stringing her along to extend the time for the crooks to work behind the scenes) told her for a guy he had talked to the day before, it had taken four hours to assist with the downloading of the app to get to the promo code.

At this point the process was just taking too long, and our victim stated that she was rather going to leave it. Edward responded irritably, saying “Just give it 5 minutes!” and finally his tone alerted her that all was not above board.

She ended the call immediately and switched off her phone. After waiting a while, she switched her phone back on and called both her banks: Bank A (where she has most of her savings) and Bank B (where her salary is received and from which all her debit orders are paid).

And here’s what had happened while the icon was “Loading”:

Bank A asked if she had made a withdrawal and when she said no, they told her that R31 000 had nevertheless been taken from her credit card as well as R31 000 converted from her loyalty membership points. Other savings were also accessed which took the total amount withdrawn from her account to R200 000.

In a similar vein, Bank B informed her that R200 000 had been paid into her account and a R400 000 personal loan had subsequently been taken out in her name. A portion of the loan amount was immediately transferred to an unknown Bank C account and the balance into a Bank D account. (This should not have been possible, as she always kept her daily transaction limits set very low).

What the victim did right:

She took prompt action to limit further access by changing all her passwords and banking details, and switching to a new mobile phone. She also went to the police station to report a case of fraud and get a case number.

Was there a happy ending? Not entirely, not yet.

Of the R400 000 stolen, Bank B managed to recover R350 000 and absorbed the remaining R50 000. Despite this, Bank B has not yet cancelled the fraudulent loan facility they granted in her name to the scammers and a monthly repayment amount has been deducted from her account in both May and June. The interest she is being charged on this fraudulent loan is extremely high.

Equally disconcerting is the fact that the the large international airline’s scam post is still live on Facebook for any unsuspecting person to click on.

Red flags spotted (in retrospect):

  1. Having to download a second, “new” app (and “create a new account”).
  2. When she was required to give her fingerprint more than once.
  3. When she was asked to carry out a facial recognition (fortunately she was in a room too dark for the phone to scan adequately for facial recognition).

Preying on the power of our trust.

Once again, this scam demonstrates how our trust in brands can be exploited. Facebook allows advertisers to target people who have interacted with a particular Page in the past – even if that Page does not belong to the scammer. For example, an advertiser can target people who visit a competitor’s page, in an attempt to show them similar goods.

This means that scammers can target us more easily. And Facebook is notorious for not reacting timeously to complaints about advertising scams of this nature.

In addition, scammers can set up channels of communication (such as the WhatsApp business account) and label them with the names of official, legitimate businesses, even when they are nothing of the sort. This is classic “spoofing” in cybercrime terms.

How then do we reduce the chances of becoming a target?

  • Be extremely wary of any offer made via advertisements on social media.
  • If an offer catches your eye, go directly to the business website, rather than clicking on an advertisement.
  • Use trusted channels of communication (i.e., those you have used before, or those on official websites).
  • If you feel you are being put under pressure for any reason, whether it is to make a quick decision or being chided into waiting too long for an action to complete, suspect a scam and act accordingly. Break off the transaction process immediately, report the incident to your bank(-s) and change all your banking and communication account passwords.

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Other Alerts

Red Flags to Watch Out for

📲 Ah, smart phones! Super-convenient, right? Instant access to information, easy contact with your loved ones right across the globe and the added convenience of paying your bills without signing cheques or licking stamps while sitting at a desk. At this point your...

Same tip on repeat

Do you ever feel worn-down by the relentless fraud attempts? Given the pace of them, it would be understandable if you feel that eventually a scammer will catch you off-guard. This Meerkat Alert is rather disconcerting as it indicates just how deeply corruption and...

Investment Diversion Scam

This cyber-fraud story was reported in the local newspapers and it's a real nail-biter. A fellow Capetonian sold his business and retired. At 78 years old, after two decades of hard work, he suddenly had R10.6 million on hand and he developed an investment plan with...

Property Rental Scam Case Study

Anywhere that money changes hands, scammers will watch out for an opportunity. When there is a scarce supply, a sense of urgency makes it even easier for criminals to target you. Estate agents are reporting increasing levels of fraudulent impersonation, specifically...

Race Entry Case Study

Do you or any of your family or friends ever enter running or cycle races? If so, this Meerkat Tip is right on topic for you! Here are the details: "I encountered a fraudulent scheme while attempting to purchase an entry for last year's Knysna Forest Marathon.   After...

Facebook Ad Fraud Case Study

Valentine's Day has come and gone, but gift-purchasing happens year-round. As a result, this experience of a Netto Invest contact who got scammed buying a gift for her husband could easily happen to any of us. Here is the case study story, straight from the horse's...

“Vishing” Case Study

Real-life case study story, exactly as relayed to us: I’ve just been phoned by the “ABSA Fraud Department”. According to them, a Chinese company was trying to set up a direct debit order from my account (and the Fraud Department wanted to cancel this “by going into...

What’s dodgy about digital menus?

Cast your mind back to the COVID-19 era - you’ll remember that when restaurants re-opened, there was a great deal of anxiety around anybody touching anything. Of course, an item that passed from hand-to-hand countless times a day was… a menu. Physical menus can’t be...

Trojan horses – reinvented

Back in the day when the Greeks wanted to invade the city of Troy, the only way their army could get past the fortified gates was by trickery. They built a colossal wooden horse statue, which just happened to have a hollow belly. Then they hid a small fighting force...

How you charge your smart phone

"There's an app for that!" Apple's iconic phrase birthed in 2009 has been the punchline of countless jokes and memes. Fifteen years on, more phone apps exist than ever before and as a result, it's almost impossible to live life conveniently without your smart phone to...

Notify