{"id":708620,"date":"2023-08-02T17:04:49","date_gmt":"2023-08-02T15:04:49","guid":{"rendered":"https:\/\/businesstech.co.za\/news\/?p=708620"},"modified":"2023-08-02T17:04:49","modified_gmt":"2023-08-02T15:04:49","slug":"warning-over-new-tap-and-go-banking-scam-in-south-africa","status":"publish","type":"post","link":"https:\/\/businesstech.co.za\/news\/banking\/708620\/warning-over-new-tap-and-go-banking-scam-in-south-africa\/","title":{"rendered":"Warning over new tap-and-go banking scam in South Africa"},"content":{"rendered":"\n<p>The Ombudsman for Banking Services (OBSSA) has identified a new banking scam in South Africa that allows criminals to make fraudulent purchases via a digital wallet.<\/p>\n\n\n\n<p>The ombud said that the scam works by exploiting near-field communication (NFC) technology and tap-and-go payment systems.<\/p>\n\n\n\n<p>Tap-and-go or contactless payments &#8211; such as tapping your card or using your smartphone or smartwatch at a point of sale (POS) machine &#8211; are becoming increasingly popular due to their convenience, the ombud said.<\/p>\n\n\n\n<p>Although banks have developed fraud detection and prevention systems, such as SIM Swap detection, transaction monitoring, 2-factor authentication (2FA) and other customer identification methods, fraudsters are constantly devising new ways to bypass these systems, making it an ongoing battle for banks to stay one step ahead.<\/p>\n\n\n\n<p>The OBSSA said it is receiving hundreds of complaints and phone calls per month related to fraud, evidencing the evolution of techniques adopted by the fraudsters to bypass the vulnerabilities and loopholes, as well as consumers not being aware of the dangers and methods employed by the fraudsters.<\/p>\n\n\n\n<p class=\"has-medium-font-size\"><strong>New scam<\/strong><\/p>\n\n\n\n<p>According to the OBSSA, the<strong> <\/strong>growing number of NFC tech scams involve fraudsters using stolen bank card information, such as the card number, expiry date and the CVV number (card data), to make fraudulent purchases via digital wallets.<\/p>\n\n\n\n<p>Reana Steyn, the Ombudsman for Banking Services, said that NFC\/digital wallet payments differ from typical card-not-present (CNP) fraud transactions. <\/p>\n\n\n\n<p>In CNP fraud, thieves use stolen card information to make online purchases, triggering a one-time password (OTP) to be sent to the legitimate cardholder&#8217;s registered phone number for each transaction.<\/p>\n\n\n\n<p>However, <strong>NFC\/digital wallet payments do not require OTPs for every transaction.<\/strong><\/p>\n\n\n\n<p class=\"has-medium-font-size\"><strong>How it works<\/strong><\/p>\n\n\n\n<p>According to Steyn, stolen card information is used by fraudsters to link their smart devices (smartphones and smartwatches) to payment platforms such as Samsung Pay, Apple Pay, Garmin Pay, Google Pay, etc. <\/p>\n\n\n\n<p>Then, the fraudster\u2019s smart device performs fraudulent purchases on the victims\u2019 accounts without OTPs being sent to cardholders to validate the transactions.<\/p>\n\n\n\n<p>Steyn pointed out that for the fraudsters to be able to link their devices to the stolen bank card information of the legitimate bank customer, an OTP or a \u201cSmart inContact notification\u201d required to complete the linkage process is sent to the bank customer\u2019s registered number or Banking App. <\/p>\n\n\n\n<p>Only after the transaction\/registration\/linkage is approved via an OTP or approve-it authenticated is the fraudster\u2019s device linked to the bank customer&#8217;s bank card. <\/p>\n\n\n\n<p>After that, the fraudster&#8217;s device can be tapped at POS machines allowing transactions to take place on the card with no further verification required for the approval of the individual purchases from the bank customer.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><a  data-lightbox=\"post-image\" href=\"https:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2023\/02\/tap-to-go.jpg-bank-s.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2023\/02\/tap-to-go.jpg-bank-s-1024x683.jpg\" alt=\"\" class=\"wp-image-662011\" width=\"706\" height=\"471\" srcset=\"https:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2023\/02\/tap-to-go.jpg-bank-s-1024x683.jpg 1024w, https:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2023\/02\/tap-to-go.jpg-bank-s-300x200.jpg 300w, https:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2023\/02\/tap-to-go.jpg-bank-s-768x512.jpg 768w, https:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2023\/02\/tap-to-go.jpg-bank-s.jpg 1200w\" sizes=\"auto, (max-width: 706px) 100vw, 706px\" \/><\/a><\/figure><\/div>\n\n\n<p>Based on the complaints the Ombudsman\u2019s office received and the patterns identified by banks whose clients fell victim to this fraud, it was evident that<strong> fake websites and emails purporting to be from legitimate businesses such as the South African Post Office, Courier Services, and VodaBucks are involved.<\/strong><\/p>\n\n\n\n<p>Through these fake website links and email addresses, the fraudsters could obtain all the details they required to approve the linking of their devices to the payment platforms.<\/p>\n\n\n\n<p class=\"has-medium-font-size\"><strong>This type of fraud is on the rise <\/strong><\/p>\n\n\n\n<p>Steyn confirmed that approximately 124 NFC fraud-related complaints have recently formally been reported and investigated by her office. <\/p>\n\n\n\n<p><strong>The losses suffered are in the millions of rands<\/strong>, <strong>with customers\u2019 accounts fraudulently drained through tap-and-go purchases<\/strong> made with smart devices in mostly foreign jurisdictions such as Dubai, France, and Spain while the legitimate cardholders were in South Africa. <\/p>\n\n\n\n<p>\u201cThis is a clear indication that an international crime syndicate is operating within this space and has South African consumers in its sights\u201d, said Steyn.&nbsp;<\/p>\n\n\n\n<p>She added that just one of the central banks in South Africa was confirmed to have received over 6,000 related complaints between January 2022 and 1 June 2023. <\/p>\n\n\n\n<p>The bank\u2019s stats show that between January and June 2022, about 553 customers fell victim to this fraud, with their losses amounting to approximately R427,487. <\/p>\n\n\n\n<p><strong>This year the number of victims jumped to over 5,450, with combined monetary losses of over R6,5\u00a0million.\u00a0<\/strong><\/p>\n\n\n\n<p class=\"has-medium-font-size\"><strong>Tips to prevent OTP fraud<\/strong><\/p>\n\n\n\n<p>Steyn outlined five tips to help banking customers avoid becoming victims.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Be cautious of any unsolicited communication requesting an OTP;<\/li>\n\n\n\n<li>Verify the authenticity of any request for OTPs by directly contacting the organization or individual purportedly making the request. Do not use contact details provided in suspicious messages; instead, use verified contact information from official websites or sources;<\/li>\n\n\n\n<li>Enable two-factor authentication (2FA) methods other than OTPs whenever possible, such as using biometric authentication or hardware security keys. Enquire from your bank about the security measures available to you;<\/li>\n\n\n\n<li>Regularly update passwords and avoid using the same password across different accounts; and<\/li>\n\n\n\n<li>Keep personal information private and ensure it is not shared with unknown or unverified individuals or service providers.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>Read: <a href=\"https:\/\/businesstech.co.za\/news\/banking\/707096\/fnb-warns-of-serious-financial-crime-how-not-to-become-a-victim\/\">FNB warns of serious financial crime \u2013 how not to become a victim<\/a><\/strong><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Ombudsman for Banking Services has recorded a rise in criminals tapping into contactless payment systems to defraud South Africans out of millions of rands.<\/p>\n","protected":false},"author":10,"featured_media":643545,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[961],"tags":[18340,853],"class_list":["post-708620","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-banking","tag-obssa","tag-south-africa"],"_links":{"self":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/708620","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/comments?post=708620"}],"version-history":[{"count":5,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/708620\/revisions"}],"predecessor-version":[{"id":708696,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/708620\/revisions\/708696"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media\/643545"}],"wp:attachment":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media?parent=708620"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/categories?post=708620"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/tags?post=708620"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}