The OTPs may have been intercepted by malware on victims' phones, or were diverted to overseas telcos that had been hacked, say cybersecurity experts.

  • Have you been Scammed?
    Follow this advisory from National Crime Prevention Council (NCPC) or call ScamShield Helpline 1799. More info

Prime 13

High Supremacy Member
Joined
Feb 22, 2014
Messages
27,852
Reaction score
11,620
Information asymmetry.
Most pple donch know if what the IT sexperts said ish true or notch.
Plus no way to verify.

They claim it's chuir phone kenna hackered therefore chiu lose monies ish chuir fault to ownself clear ownself, who ish cano verify?
 

Ev0d3vil

High Supremacy Member
Joined
Mar 17, 2006
Messages
36,149
Reaction score
6,661
Gong jiao Wei is it? Or should everyone use apple then it’s safe ?
 

cleffa3000

Honorary Member
Joined
Jun 16, 2006
Messages
141,832
Reaction score
15,310
howPJi2.jpg



https://www.straitstimes.com/tech/tech-news/why-some-ocbc-customers-in-sms-scams-did-not-get-otps
win liao lor

mobile devices also less protection so easily tio malware also

as long got 1 weak point gg liao

if server side cant tio, then tio client side.
 

sTiCkY

Banned
Joined
Sep 13, 2005
Messages
60,054
Reaction score
9,573
moi wonder how many haxx0rs they have working round the clock to achieve this mass targeted attack...

the time it takes to plan and recon alr not worth it... 8mil nia....

if 80mil return they sure do la... this way la... maybe even buy a bunch of femtocells to deploy in the neighbourhoods...
 

cleffa3000

Honorary Member
Joined
Jun 16, 2006
Messages
141,832
Reaction score
15,310
A huge insult to Singapore's cybersecurity and highly regarded digital systems~ There is the Singpass app which displays my digital NRIC without the need for a password, now am worrying about my phone getting hacked~ :frown:
boh lang install antivirus in phone mah

even if got antivirus , also dunno it will detect and stop the malware or not
 

cleffa3000

Honorary Member
Joined
Jun 16, 2006
Messages
141,832
Reaction score
15,310
think most secure is atm lah
want withdraw/transfer huge cash then go to bank
 

Apex01

Supremacy Member
Joined
Jan 2, 2020
Messages
8,687
Reaction score
2,655
always the fault of others!!!
SG banking system is 500 percent safe!!
 

86technie

High Supremacy Member
Joined
Jun 8, 2006
Messages
39,176
Reaction score
5,155
Does it mean it’s worth to pay for subscription like bitdefender for protection ?
Yes but that is not the point here.
Point here is they claimed is malware/virus.
However why the SMS and website so identical to the real one?
 

Dougiehowsia

Senior Member
Joined
Apr 3, 2017
Messages
2,365
Reaction score
176
What about other incidents overseas? Surely this is not th first attack of its kind in the world
 

lalalalalala

Great Supremacy Member
Joined
Dec 25, 2005
Messages
51,957
Reaction score
14,234
lol, i like how they say "divert to overseas telcos that might be hacked"

they got proof first anot
 

lalalalalala

Great Supremacy Member
Joined
Dec 25, 2005
Messages
51,957
Reaction score
14,234
Cyber security expert. Please show how to intercept sms and divert to overseas telcom? Dont talk rubbish
it's actually extremely difficult to do, you need the person to be using a cracked sms app. and usually people use the default app for sms, iphone use imessage, android use the default one provided by os

if anything i'd say the otp is legit, just that hacker managed to bypass or delay the sms trigger on ocbc end, either via ddos or sth
 

86technie

High Supremacy Member
Joined
Jun 8, 2006
Messages
39,176
Reaction score
5,155
it's actually extremely difficult to do, you need the person to be using a cracked sms app. and usually people use the default app for sms, iphone use imessage, android use the default one provided by os

if anything i'd say the otp is legit, just that hacker managed to bypass or delay the sms trigger on ocbc end, either via ddos or sth
This I agree, user phone are just the client so it must come from "somewhere."
The way they put it as it came from the user phone.
Whoever these experts are, opt to check their cert real or not.
 

Towelie

Supremacy Member
Joined
Dec 18, 2019
Messages
5,789
Reaction score
2,893
it's actually extremely difficult to do, you need the person to be using a cracked sms app. and usually people use the default app for sms, iphone use imessage, android use the default one provided by os

if anything i'd say the otp is legit, just that hacker managed to bypass or delay the sms trigger on ocbc end, either via ddos or sth
Actually the simplest explanation is

They cloned the ocbc website design, triggered an sms using spoofed phone number that used url shortener that directed to the fake site.

Got a list of ocbc customers or some banking list sold on those dark web. Did the above, then the customers went in, type in login credentials, auto "login". Real otp sent to user's phone. User typed the otp on that fake site and voila.

Not sure if additional step was done to show the balance, but this would have been quite easily done also, only needs the hacker to edit the figures, so long as he or she has the ocbc website interface after login

might need to insert a "delay" tactic here during login so that the OCBC users will not suspect for that 10-15seconds

This move can potentially delay the more "savvy" IT users response and cause them to call the bank only much later

The other end, they spoofed singapore IP maybe? Then the hacker just typed in credentials and otp.

How this didnt trigger ocbc's alarm bells is worrying, how the large amounts of money simply sent overseas just like that.

I think this was a carefully planned one time operation... Done by like those scam centers u see on youtube
 
Last edited:
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ. Forum members and moderators are responsible for their own posts.

Please refer to our Community Guidelines and Standards, Terms of Service and Member T&Cs for more information.
Top