Thursday, June 29, 2023

About $8m lost in over 700 malware-related scams in first half of 2023

About $8m lost in over 700 malware-related scams in first half of 2023

https://www.straitstimes.com/singapore/about-8m-lost-in-over-700-malware-related-scams-in-first-half-of-2023

2023-06-29

SINGAPORE - Victims lost about $8 million in more than 700 malware-related scams that were reported between January and June.

In ongoing investigations, the authorities have found that at least eight of these scams involved Central Provident Fund (CPF) savings, with losses amounting to $124,000, said CPF Board, Government Technology Agency (GovTech) and police in a joint statement on Thursday.

As a precaution, CPF Board and GovTech said they have introduced Singpass face verification during login to vulnerable members who access CPF e-services.

This additional security feature applies to suspicious or higher-risk logins. For example, Android users and those aged 55 and above may be prompted to log in with the feature to combat the latest scam tactics.

“While this may make it less convenient for members to access CPF online services, we seek CPF members’ understanding that it might be better to be safe than sorry,” said the statement.

CPF members can contact the Singpass helpdesk on 6335-3533 between 9am and 6pm, visit www.go.gov.sg/singpass-faq or head to any Singpass counter located islandwide for more information about face verification.

The agencies explained that in malware scams, the victim clicks on advertisements on social media where an item is sold cheaply and receives a link to download an installation file to an Android application from a third-party app store to buy the item.

A malware is installed on the Android phone when the file is downloaded.

The scammer then calls or texts the victim and instructs him to turn on accessibility services on the phone, which weakens the device’s security and allows the scammer to take control of it. For example, the scammer can record every keystroke and steal banking credentials.

The scammer is then able to log in remotely to the victim’s banking apps, add money mules as payees, raise payment limits and transfer money out. To cover his tracks, the scammer can even delete SMS and e-mail notifications of bank transfers made.

The scammer may also log in to the victim’s CPF account through Singpass to withdraw money.

The CPF withdrawal, which is paid to the CPF member’s verified bank account, can then be transferred out from the bank account by the scammer using stolen credentials.

Police said in a release in June that no less than two Android users lost at least $99,800 of their CPF savings to scams involving malware that month.

In an islandwide anti-scam enforcement operation conducted between June 19 and 23, seven men and a woman, aged between 20 and 28, as well as a 16-year-old were arrested for suspected involvement in banking-related phishing scams involving malware attacks on Android mobile devices.

Another two women and a man, aged between 27 and 57, are assisting in the investigations, police said in a separate release. Victims lost more than $221,000, including more than $114,000 of money from their CPF accounts, police added.


The police arrested seven men and a woman for banking-related phishing scams in an islandwide operation between June 19-23. PHOTO: SINGAPORE POLICE FORCE
The public, especially Android users, are advised to download only applications from official app stores to avoid malware being installed, the statement said.

People should also exercise caution when turning on the phone’s accessibility services or allowing access because it will weaken the security of the phone.

They should always promptly update their phones with the latest security patches.

For more information, visit www.scamalert.sg or call the Anti-Scam Helpline on 1800-722-6688.

To avoid being an accomplice in these crimes, the public should reject supposed money-making opportunities promising fast and easy payouts for others to use their Singpass or bank accounts, police said.


MORE ON THIS TOPIC
At least 2 Android users lose nearly $100k of CPF savings in June in malware-related scams
Woman loses nearly $30k after downloading third-party app via WhatsApp

No comments: