GrabPay users file police reports over unauthorised payments to Qoo10 and Razer
Users said they had not provided any OTP for payments of between S$13 and S$260
Singapore
THE police are investigating reports on unauthorised transactions, each involving hundreds of dollars, that were made via GrabPay to e-commerce marketplace Qoo10 and Razer Gold, the virtual gaming credits operated by Razer.
At least five police reports concerning the e-wallet transactions were filed in October, The Business Times understands.
The users said they discovered that their GrabPay e-wallet had been topped up using their credit card linked to the Grab app, although they did not perform such a transaction. The top-up amounts ranged from S$200 to S$900. An authorisation code is not needed for top-ups.
Shortly after, unauthorised transactions were made via GrabPay to Qoo10 and Razer Gold, the users said. In each case, the transactions happened either simultaneously or within minutes of each other.
Each payment to Razer Gold was S$100 and occurred across all cases. The payments to Qoo10 ranged from S$13.01 to S$260.20 and happened in three out of the five cases.
Two users told BT that they had brought the matter up with Grab, insisting that they did not provide any one-time password (OTP) that might have authorised the payments to either Qoo10 or Razer Gold. Both were told by Grab staff that the transactions were due to "user negligence", and that since the correct OTP was provided for the payments, the company was unable to give them refunds.
One user took the issue to his bank, which temporarily refunded the disputed amount to his account while investigations were ongoing.
The police issued an advisory on Oct 28, warning members of the public to be vigilant about phishing scams involving fake Grab advertisements and other fake deals. But in the scenarios described by the police, the victims were fooled into providing their mobile phone number and OTPs to a fake Grab website.
It is not clear whether the police cases involving unauthorised top-ups and payments to Razer Gold and Qoo10 are linked to these phishing scams. The police confirmed to BT that reports were lodged and investigations were ongoing.
Queried by BT, Grab did not reply directly, but published a post on Friday evening about phishing scams on its website. It then referred BT to the post.
Grab said in the post that based on completed investigations of reported cases to date, all users received at least one OTP on their phone number registered with Grab, which needed to be shared for the fraudulent transactions to be completed.
Grab also did not directly respond to BT's queries on why transactions that happened simultaneously were not flagged as potentially fraudulent. In its post on Friday, the company said it is implementing additional checks in the payment process; it is also tightening the validity duration of each payment session and using technology to make it harder for scammers to complete transactions.
Kevin Lee, the chairman of cyber security firm Horangi, said OTPs are not foolproof as a security measure because there are ways to access SMS messages without the user being aware.
"For example, other apps which they have installed on their phone can get access to their SMS messages. On Android phones, it is as simple as asking for permission during the app installation process - and many people unwittingly click to approve access when presented with a long list of various permissions requested upon installation," he said.
The phone's operating system could also have been hacked, especially if not regularly patched. A user's SIM card can be cloned so that another device may receive SMSes meant for the user, Mr Lee added.
Qoo10 said it is aware of the unauthorised transactions on GrabPay and is working with the police and Grab on these cases. "Qoo10 has several preventive measures in place to detect such frauds. We are also looking into implementing more stringent preventive measures at Qoo10," it said in a statement.
Razer said it is unable to comment as police investigations were ongoing.
Cyber crime has been on the rise in Singapore, with reported cases rising 51.7 per cent to 9,430 last year. The Cyber Security Agency of Singapore said phishing attempts almost tripled in 2019 and doubled during the Covid-19 stay-home period this year.
Consumers who were not careful have fallen prey to scammers impersonating known entities such as SingPost, StarHub, Netflix and PayPal.
Meanwhile, cases of hacking continue to be reported. Attempts to hack into media websites in Singapore to access personal user information more than doubled last year, a study by cyber security firm Akamai found.