Tag Archive for: Scams

At least 2 Android users lose nearly $100k of CPF savings in June in malware-related scams


SINGAPORE – At least two Android users lost $99,800 of their Central Provident Fund (CPF) savings in June to scams involving malware.

The police said on Saturday that the victims came across advertisements marketing groceries like seafood on social media platforms, including Facebook.

The victims contacted the businesses through their social media platforms or WhatsApp.

They were sent a URL to download an Android Package Kit (APK) file, an application created for Android’s operating system, to order groceries and make payment. 

APKs are installation files for Android apps that can be downloaded from the Internet and third-party app stores, instead of the Google Play Store.

Apps or APK files from the Internet or a third party could contain phishing malware.

The victims were unaware that the application contained malware that would allow scammers to access the victims’ devices remotely and steal passwords. These included Singpass passcodes, among other details stored in the victims’ devices.

“The scammer might also call the victims to ask for their Singpass passcode, purportedly to create an account on the application,” said the police.

Victims were directed to fake bank sites to key in their login credentials to make payment within the app.

The malware would capture the credentials entered.

The scammers were then able to access the victims’ CPF accounts remotely using the stolen Singpass passcode and make a request to withdraw funds through PayNow.

The police did not state the victims’ ages. CPF members can withdraw some of their savings when they turn 55 and receive monthly payouts under the CPF Life scheme when they reach the eligible age, which is currently 65.

Once the CPF funds were deposited into the victims’ bank accounts, the scammer accessed the victims’ bank applications and transferred the money out via PayNow.

The victims realised they had been scammed when they discovered unauthorised transactions on their bank accounts.

Source…

When you buy a criminal’s phone, and paying for social media scams • Graham Cluley


Smashing Security podcast #322: When you buy a criminal’s phone, and paying for social media scams

Personal information is going for a song, and the banks want social media sites to pay when their users get scammed.

All this and much more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault.

Hosts:

Graham Cluley – @gcluley
Carole Theriault – @caroletheriault

Episode links:

Sponsored by:

  • Bitwarden – Password security you can trust. Bitwarden is an open source password manager trusted by millions of individuals, teams, and organizations worldwide for secure password storage and sharing.
  • Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Zero Trust for Okta. Watch a demo today!
  • Outpost24 – Understand your shadow IT risk with a free attack surface analysis.

Support the show:

You can help the podcast by telling your friends and colleagues about “Smashing Security”, and leaving us a review on Apple Podcasts or Podchaser.

Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed!

Follow us:

Follow the show on Twitter at @SmashinSecurity, or on Mastodon, on the Smashing Security subreddit, or visit our website for more episodes.

Thanks:

Theme tune: “Vinyl Memories” by Mikael Manvelyan.
Assorted sound effects: AudioBlocks.

Found this article interesting? Follow Graham Cluley on Twitter or Mastodon to read more of the exclusive content we post.


Graham Cluley is a veteran of the anti-virus industry having worked for a number of security companies since the early 1990s when he wrote the first ever version of Dr Solomon’s Anti-Virus Toolkit for Windows. Now an independent security analyst, he regularly makes media appearances and is an international public speaker on the topic of computer security, hackers, and online privacy.
Follow him on Twitter at @gcluley, on Mastodon at @[email protected], or drop him an email.

Source…

QR code scams, Chinese hackers win big & speed up your old computer


May 8, 2023

Plus, Temu and Shein pose big security threats — here’s what to look out for. I talk to a guy that wants to play music in his car through a thumb drive. One state was blocked by world’s largest p*rn site, an ADHD-friendly web browser and how to set a photo timer on your Android or iPhone.

Previous episode

May 5, 2023

Plus, are robots overworked? One tired bot faceplanted on the factory floor. Strangely, parrots love to gossip online. Find the best seat for your flight, upgrade your email management and new tricks to transform how you use Google Docs. 

Source…


Tesla workers spy on drivers, and Operation Fox Hunt scams • Graham Cluley


Graham wonders what would happen if his bouncing buttocks were captured on camera by a Tesla employee, and we take a look at canny scams connected to China's Operation Fox Hunt. Smashing Security podcast #318: Tesla workers spy on drivers, and Operation Fox Hunt scams

Graham wonders what would happen if his bouncing buttocks were captured on camera by a Tesla employee, and we take a look at canny scams connected to China’s Operation Fox Hunt.

All this and more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault.

(Oh, and when Carole mentioned Colin the Accountant as her “Pick of the Week” she really meant “Colin from Accounts”. Sorry!)

Warning: This podcast may contain nuts, adult themes, and rude language.

Hosts:

Graham Cluley – @gcluley
Carole Theriault – @caroletheriault

Episode links:

Sponsored by:

  • Bitwarden – Password security you can trust. Bitwarden is an open source password manager trusted by millions of individuals, teams, and organizations worldwide for secure password storage and sharing.
  • Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Zero Trust for Okta. Watch a demo today!
  • Drata – With over 14 frameworks including SOC2, GDPR, HIPAA, and ISO 27001, Drata gets you audit-ready for crucial security standards needed to scale your business. As a listener to Smashing Security you can save 10% off Drata and have implementation fees waived.

Support the show:

You can help the podcast by telling your friends and colleagues about “Smashing Security”, and leaving us a review on Apple Podcasts or Podchaser.

Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed!

Follow us:

Follow the show on Twitter at @SmashinSecurity, or on Mastodon, on the Smashing Security subreddit, or visit our website for more episodes.

Thanks:

Theme tune: “Vinyl Memories” by Mikael Manvelyan.
Assorted sound effects: AudioBlocks.

Found this article interesting? Follow Graham Cluley on Twitter or Mastodon to read more of the exclusive content we post.


Graham Cluley is a veteran of the anti-virus industry having worked for a number of security companies since the early 1990s when he wrote the first ever version of Dr Solomon’s Anti-Virus Toolkit for Windows. Now an independent security analyst, he regularly makes media appearances and is an international…

Source…