A trick to steal information, appropriate money in the account on New Year’s Day
Cake Digital Bank has recorded many cases of impersonating a digital bank employee and asking users to provide card number, CVC2 code, OTP code to scammers.
Specifically, the main scenarios, frequently used by scammers, are impersonating the official fanpage to guide receiving gifts, impersonating an employee to help users increase their credit limit, support opening new cards…
In these cases, the bad guys trick users into downloading a banking app, opening a credit card, and providing a screenshot of the card and OTP code to the subject for verification or requesting to transfer money to the account with the reason of opening. saving account. After having the card information, the subject will perform transactions and block communication with the user.
Another method that is also frequently used is that the bad guy will send a message to recruit collaborators to do the purchase. The subject sends a link for the victim to register an account and guide the purchase. After users transfer and prepay, they block communications.
To prevent these scams, Cake has issued a warning that users absolutely do not participate in buying and selling virtual orders on e-commerce sites in the form of online collaborators, employees, etc.
Users do not enter information into strange links sent via SMS, Zalo, Facebook. In addition, absolutely do not share the screen of card number information, take screenshots with card number information, CVC2 code or provide or enter OTP code for any object or link, including the person claiming to be. Bank employee, police officer….
According to security expert Ngo Minh Hieu, a campaign has recently appeared to spread malicious links to collect information by forging Tet promotions of some brands, most notably Saigon Beer. . The trick is quite similar to the scams that fake the winning programs of famous brands such as CocaCola, Rolex, Coopmart… have existed before.
Websites pretending to be a winning program of brands often contain many images and brand logos, accompanied by promotions, but have strange link extensions such as “.xyz”, “.top”, “.online”. “,…
When clicking on a malicious link, the victim will be collected information about the device in use, IP address… Not only that, The message contains a strange link also automatically sent simultaneously to the victim’s friends. In the case of visiting a fake website link and providing more identity information, the bad guy will have more tools to use for malicious purposes.
This is a targeted attack campaign, hitting the psychology of users who want to win prizes and gifts. Brands that are pretended to be labels of drinks, beer and wine are often used during Tet. Before this complicated situation, Internet users need to be vigilant and absolutely do not provide personal information or access strange links.