On the prevention of property crimes and information security

April 11, 2023

In the Republic of Belarus, and the Gluboksky region is no exception, there has been an increase in illegal actions in the field of information technology, namely, theft from bank payment cards (hereinafter referred to as BPC) and accounts of individuals and legal entities. Examples of such cases are given below.

In the Republic of Belarus, and the Gluboksky region is no exception, there has been an increase in illegal actions in the field of information technology, namely, theft from bank payment cards (hereinafter referred to as BPC) and accounts of individuals and legal entities. Examples of such cases are given below.

After unauthorized access to user pages on social networks, the attacker sends messages to users in the "Friends" section, asking for help in transferring funds under various pretexts: "Hi, could you lend me some money, I'll pay you back in a couple of days," "Hi, please put 10 rubles on my phone, I'll pay you back," "Hi, can I transfer my money to your card, because my card has expired (or I can't transfer to my own)." Then, they gain the trust of concerned users and, allegedly to transfer money to them, ask for the BPC details and codes from SMS messages. The user, misled about the identity of the sender and unaware of the criminal intentions, provides this information, which allows the attacker to access the user's funds and steal them.

After carrying out an unauthorized money transfer operation, the attacker often informs the user that they cannot complete the operation due to technical reasons and asks them to repeat the action with another card (of a relative or acquaintance).

On trading platforms such as "Kufar," "Baraholka," and others, the offender finds an advertisement posted by a user for the sale of some property. Then, in various messengers, they write to this user stating that they would like to purchase the advertised property but are unable to pick it up for various reasons. They offer to pay by transferring funds to the user's BPC, and after the user

agrees, sends a link to a phishing website of a banking institution to his address (the page may visually resemble the internet banking page and differ only by a symbol in the address bar of the website's domain name). By following the specified link, the user does not notice that they are not on the active internet banking page of a particular bank.

In the opened window on the specified website, the user is usually asked to enter their login and password for internet banking or passport data, as well as codes from SMS messages. After entering the specified information, the user is usually informed of an error or non-payment. At this time, the attacker sees all the entered information and enters it on the actual bank website, thereby gaining access to the user's funds and stealing them. After conducting an unauthorized money transfer operation, the offender often informs the user that they cannot carry out the operation due to technical reasons and asks to repeat the specified actions with another card (of relatives or acquaintances).

On trading platforms such as "Kufar", "Baraholka", and others, the attacker posts an advertisement for the sale of a popular item and sets a price, as a rule, below market value. Users who see the advertisement write to the person who posted it, and during correspondence, the attacker states that they cannot meet to transfer the item specified in the advertisement and offers to use the services of "Kufar Delivery", "Belpochta (EMS)", "courier service (SDEK)", etc. If the buyer agrees, the attacker sends a link to a phishing website of a delivery service to the user's address, where they are asked to enter bank card details for payment of the goods, courier services, passport data, mobile phone number, as well as codes from SMS messages. After entering the specified information, the user is usually informed of an error, or the website stops loading (freezes). At this time, the attacker sees all the entered information and enters it on the actual bank website, gaining access to the user's funds and stealing them. After conducting an unauthorized money transfer operation, the attacker informs the user that they cannot carry out the operation due to technical reasons and asks to repeat the specified actions with another card (of relatives or acquaintances).

On a mobile phone

An individual's phone receives an incoming call from an attacker. As a rule, the attacker uses a phone number spoofing service and indicates a subscriber number belonging to a bank or similar to it. Then, they introduce themselves as a bank employee (they may address the user by name and patronymic, as well as mention part of the bank card number or information about recently made payments). The attacker reports suspicious large-sum money transfers to foreign bank accounts. When the user states that they have not made any such transactions, the attacker informs them that the mentioned operations need to be blocked, and therefore asks the user to provide specific bank card details or passport information, and states that they are sending SMS messages with codes to the user, which must be read out after an audible signal. At this time, the attacker enters all the obtained information on the bank's actual website and gains access to the user's funds, thereby stealing them.

All the information requested by the criminal in the situations described above is known to bank employees, who do not request it during a phone conversation.

To protect yourself and your funds from such theft methods, you must:

not disclose login credentials, phone numbers, passwords, PIN codes, bank account details, secret CVC/CW codes, information about recent payments, and the expiration dates of plastic cards to third parties;

when using a card, enable and use the "3D Secure" technology. Currently, this is the most advanced technology for ensuring the security of card payments on the Internet. It allows for unambiguous identification of the authenticity of the cardholder performing the transaction and minimizes the risk of card fraud. When using this technology, the bank cardholder confirms each transaction on their card with a special one-time password received via SMS message to their mobile phone;

refrain from transferring temporary passwords received in SMS messages for transaction confirmation, as well as your bank cards, to unauthorized persons in any way;

enter secret data only on websites protected by security certificates and encryption mechanisms. The domain names of these resources in the address bar of each browser begin with https://;

perform regular monitoring of completed operations using the payment history section;

do not refuse an additional security level (multi-factor authentication systems);

choose a complex password using a combination of numbers, uppercase and lowercase letters, which will be understandable only to the account owner. Change your password every 2-4 weeks if you use other people's computers to log into internet banking;

do not use automatic password saving in the browser if unauthorized persons have access to your personal computer or if you use a public computer to log in to the website;

while using internet banking, install antivirus protection, timely updating virus and spyware databases;

link your personal account login on the internet banking website to your MAC or IP address. This action will ensure the maximum level of security.

In case you find a lost bank card, do not post its photo on the Internet in order to find the owner. The information available in the image of the bank card is sufficient to perform operations using this data without the knowledge of the bank card owner, which is what criminals exploit.

 

Deputy Prosecutor

Gluboksky District                                                                    

Ya.I. Sosnovsky