Attention Wi-Fi users! They could access your mobile banking
Recently, fraud incidents involving public Wi-Fi networks have been on the rise. The risk is significantly higher for those connecting to public Wi-Fi networks in places like hospitals and cafes. So, how do scammers perform 'phishing'? What should those who have had money withdrawn from their accounts or loans taken out in their names without their knowledge do?
12punto
Those who use mobile banking services, save card information in various applications or on their phones, and shop online can fall into the traps of scammers; loans can be taken out in their names without their knowledge, and their accounts can be emptied even while they are asleep at night.
'300 THOUSAND TL LOAN TAKEN OUT IN HIS NAME AT NIGHT WITHOUT HIS KNOWLEDGE'
Recently, many incidents regarding such fraud cases have been reported in the press. In a news report that surfaced recently, a person had a 300 thousand TL loan taken out in their name via mobile banking during the night without their knowledge. A total of 433 thousand TL, including the money in their account, was transferred to two different accounts.
On the other hand, there are also risks associated with performing mobile banking transactions over public Wi-Fi networks used in places like hospitals, chain coffee shops, and restaurants. So, how do scammers obtain card information?
In cases where money is transferred from an account or a loan is taken out without the person's knowledge, does the responsibility lie with the bank? What should citizens do in potential fraud situations?
What should individuals do to keep their bank information and card details safe? What should one pay attention to during online shopping?
'PUBLIC AREAS ARE VULNERABLE TO ATTACKS'
Cyber Security Expert Emrullah Akdemir, who explained everything curious about the subject to Milliyet, stated the following:
“Since public areas are generally unmonitored spaces, it is more likely for malicious users to carry out attacks against users on these networks compared to other private networks.”
'DO NOT PERFORM SENSITIVE TRANSACTIONS ON PUBLIC NETWORKS'
“It is strictly not recommended to perform transactions on websites where you receive an SSL certificate error while accessing the internet via networks in public areas. When you accept this untrusted certificate and continue, it becomes possible for all your traffic to be monitored openly, and if the permitted certificate belongs to a malicious user, your data has likely been captured for malicious use. Therefore, I recommend that you do not perform sensitive transactions on public networks as much as possible.”
IS THE BANK TO BLAME FOR LOANS TAKEN OUT AND MONEY TRANSFERRED WITHOUT THE PERSON'S KNOWLEDGE?
“Banking transactions in Turkey are strictly monitored, and security measures are implemented rigorously according to the rules set by the BRSA (BDDK). Despite all this, there are many user complaints on social media about these grievances occurring at certain banks in particular. Taking the complaints of the victims into account, the BRSA and USOM (National Cyber Incident Response Team) must investigate the matter seriously and inform the public transparently. If the bank claims that these unauthorized actions occurred through malicious software installed on the user's phone, it must provide evidence within the scope of the investigation that sufficient information and security measures were taken. We see rumors circulating that mobile applications are accessed by cloning GSM lines; as is known, according to the regulation introduced by the Information and Communication Technologies Authority (BTK), bank customers cannot use mobile applications in case of any GSM line renewal or operator change without notifying the bank of the new change in person at a branch. Without concrete evidence that such security measures have been bypassed, these possibilities seem low. If all of the bank's security measures were bypassed due to the user's own error, it is quite wrong to hold the bank responsible. However, if there is any deficiency in the confirmation and notification processes from the user after loan approval, the bank will be responsible for the violations. Clarifying this issue to the public through a serious investigation is very important for both the bank's reputation and the safety of the users.”
PAY ATTENTION TO THESE DETAILS TO PREVENT BANK INFORMATION THEFT
“Citizens should definitely not share their card passwords with other people, should not write them down in places where everyone can access them, and should take care not to use simple, predictable passwords.”
'USE VIRTUAL CARDS'
“You should definitely use virtual cards for online shopping, and you should not enable your physical cards for online shopping and international use unless necessary. Since the possibility of these cards being copied during physical shopping is quite high, taking these precautions will prevent their use even if your card information is captured. You can easily perform all these precautions through your mobile banking apps.”
'DO NOT SAVE CARD INFORMATION'
“Card information should definitely not be saved to third-party applications unless necessary. If it needs to be saved due to recurring transactions, you must save information for a virtual card with a limit set by you. Such simple precautions will prevent many grievances.”
IS IT SAFE TO GRANT PERMISSIONS FOR APPLICATIONS?
“Actually, if you look at it, SMS messages from sensitive places like banks can be read through insecure applications that have access to your messages and calls, bank calls can be manipulated and redirected, and all security measures can be disabled in this way without the users realizing it. Therefore, it is important not to install just any application on your personal phones and not to grant any unnecessary permissions to applications. For example, many applications that children install randomly for gaming purposes may be applications found in malicious marketplaces. Therefore, you should definitely not install untrusted applications.”
'MONITOR APPLICATIONS INSTALLED UNCONSCIOUSLY'
“You should monitor the applications your children install unconsciously. In these processes where you increase device privileges by performing operations we call Root/jailbreak on your devices unconsciously, you may invite other applications to take control of your device. Therefore, users should not endanger the security of their mobile devices by performing such operations without being aware of what they are doing. Many malicious applications used for purposes such as call hiding and blocking, SMS spam prevention, and caller ID are being circulated in marketplaces. These applications may be used to access your phone logs and messages indiscriminately. Users should definitely not install such untrusted applications on their devices.”