THE WINDING ROAD

Avoiding scams - need to 'ownself check ownself'

We as consumers must take steps to protect ourselves from falling for financial frauds and phishing attacks

Vivien Ang
Published Fri, Mar 4, 2022 · 09:50 PM

    AFTER an almost 1-minute wait for the one-time-password that never arrived, Ellen Low (not her real name) started to have a nagging suspicion that something wasn't right.

    "I was looking at my phone after doing my duties at the hospital and there was a message from OCBC that informed me someone was trying to access my account from KL. The next line prompted me to click on a link if it wasn't me."

    Instinctively, Low clicked on it, which brought her to what seemed like the Internet banking page, and started to key in the data requested.

    "However, while waiting for the OTP, I felt that something didn't add up. Hence, I called the bank and was one of the lucky few who managed to settle the issue before any money was siphoned off."

    The 35-year-old's experience is unfortunately going to become more prevalent as we transition to a Smart City, and as an increasing number of processes become automated.

    The same technology that has brought us convenience and connectivity can also be exploited by those with malicious intent - and I feel that there are only so many times that an organisation can make restitution out of goodwill.

    Asean Intelligence

    Get insights into businesses across South-east Asia

    Get the free report

    So how do we protect ourselves - besides going with our basic instincts, which certainly aren't foolproof?

    Associate Professor Chang Ee-Chien has a few tips to share. The most straightforward way is to check the address bar of the website and ensure that there is always a padlock next to the URL. "That way, you can be sure that you are visiting the website as indicated in the address bar."

    The next red flag to watch out for is the domain name of the page, he adds. But how do we identify the domain name in the address bar? It is not obvious and can be confusing for the uninitiated like me.

    "And that is what the hacker exploits", says Prof Chang, who is from the School of Computing at the National University of Singapore. "Although confusing, by learning from a few examples, readers should able to identify them easily."

    It is important to make sure the "domain name" matches the intended site exactly. Any slight difference hints at it being a possible phishing site.

    Prof Chang cites the DBS's webpage as an example.

    "Let's suppose your bank is DBS. In this case, the domain name would be dbs.com.sg or dbs.com. Some hackers may typosquat, which is something like brand jacking - hence when you see URLs such as dbs-bank-internet.com, dos.com.sg or dbs.sg.com, be immediately aware that these are scams." He adds that the placement of the domain name is also crucial, and it should never be in the sub-domain - which is an extension of the domain name.

    "The sub-domain is usually found at the front of the URL. Hence, dbs.com.sg.12348798.com is commonly seen in phishing as dbs.com.sg is placed at the front of the URL, which is the sub-domain, and not the main domain. This is in contrast to the actual website, the link of which is shown as internet.banking.dbs.com.sg/IB/Welcome."

    Online shopping has also replaced brick and mortar shops, especially since the pandemic, and I am guilty of sometimes doing my trigger-happy activities in cafes, to Prof Chang's consternation.

    "One of the online hygiene tips consumers should adhere to is to not use untrusted devices, such as desktops in Internet cafes, to carry out online banking. The above-mentioned method of checking could fail if the victim is using a hacked desktop. If the system has serious implementation flaws - that unfortunately are first discovered and used by attackers - the above check might not be sufficient."

    And while I thought financial gain is usually the impetus for the perpetrators, Samuel Chng, who heads the Urban Psychology Lab in the Lee Kuan Yew Centre for Innovative Cities at the Singapore University of Technology and Design, says that other motivations include recreation, ideology and sexual impulses.

    "Hackers and scammers often use psychological manipulation (such as impersonating a person of authority) and target our cognitive biases to trick users into making security mistakes or give away confidential information such as our account credentials. Hence, we need to stay alert to the fact that scams and malicious activities exist and remain vigilant about who and when we are sharing our personal information with."

    Digital-related scams have also evolved with technological advances, and voice phishing and QR code frauds are becoming more rife. QR codes contain certain information which could include the recipient's account number . And while hackers might create a QR code and attempt to convince the victim that it is authentic, some may use it to attempt an account takeover fraud.

    So what I want to know is, how then do we tell that something is amiss with the code, as to the untrained eye, or at least mine, they all look the same. Prof Chang says: "If the message source can be trusted, that would be fine; otherwise take extra precaution - eg if the QR code came in an email and points to a website address, we have to assume that it might be fake and first check the domain name in the website URL - which points back to my earlier response."

    For Low, her near-scam experience was a close shave, and she was glad that her moment of folly didn't cause her savings to be wiped out.

    But while OCBC's scam victims were compensated, I do wonder - how many others weren't? Companies aren't obliged to do goodwill payouts. Hence, at the end of the day, as we drive technology forward, we as consumers need to do our own due diligence to continually update the security software on our devices, and educate ourselves, as well as those around us who may not be as tech-literate to "ownself check ownself" - as best as we can - so as not to fall for the chicanery of scammers.

    Decoding Asia newsletter: your guide to navigating Asia in a new global order. Sign up here to get Decoding Asia newsletter. Delivered to your inbox. Free.

    Copyright SPH Media. All rights reserved.