GLGT - [BREAKING!] ICA temporarily suspends e-service after 80 unauthorised attempts to change residential address

BlackWing1977

Greater Supremacy Member
Joined
Mar 1, 2006
Messages
96,537
Reaction score
34,599
Yes, received a call from a scammer purportedly working in a bank anti-fraud department. Told me my cc card chalked up unauthorized transactions.

But the truth is I do not have any cc with that bank. So I questioned the scammer how was it possible to apply for cc on in the first place and didn't receive the card or otp to activate the card.

Scammer mentioned about identity theft via compromised singpass. So hacker got in and changed address and hp no. And applied for cc without my knowledge.

He told me to mare a police report some more.

What gave him away was he offered to link me up with MAS anti-fraud department to file a report. This second scammer told me to make a video recording of myself holding my ic ...of course no no. Told him I see him personally at MAS building

The scary part is that the two scammets sound like locals..with our accent...and could give me details like Ang MO address that the card was mailed to etc.

Fortunately, it's just a scam. I called up the bank hot line. No cc under my name. Also reported to MAS

Come to think of it, if I made a video, I think they can use AI to unlock my Face ID, change the IC details and hack into singpass. Probably access my cpf too.


Nowadays, be careful of sending digital copies of your nric. They can phish for the date of issue.
tkthao219-bubududu.gif
peach-goma.gif
 

TopGun

High Supremacy Member
Joined
Jan 1, 2000
Messages
44,495
Reaction score
6,921
There are fixed periods for ic issuance… for adults 1 update at 30 years old another at 55 years old. The first 2 digits of nric gives your year of birth Liao ….. so it’s a matter of 365 guesses

I think they should make online change of address to require singpass login. Not just input issue date. And if you cannot receive your Singpass mailed due to the change of address, it has to be self collect at govt agency.

You can change it 1 year from your birthday I recall. So it can be between 1 June 2025 to 31 May 2026.

More than 365 guesses.
 

SkyNinja

Arch-Supremacy Member
Joined
Oct 18, 2008
Messages
14,324
Reaction score
2,573
it’s easy to guess the date of issue - can narrow it to the year.

if adult means 30 years old it changed. If senior means 55 years. The first 2 digits of the nric gives the year liao. So add 30 or add 55. Just need to brute force 365 times

not many would have an odd / off cycle issue date due to lost / replacement.

Should change the Issue Date to 16 digit randomly generated number.
 

lockks

Supremacy Member
Joined
Nov 1, 2008
Messages
6,503
Reaction score
220
There are fixed periods for ic issuance… for adults 1 update at 30 years old another at 55 years old. The first 2 digits of nric gives your year of birth Liao ….. so it’s a matter of 365 guesses

I think they should make online change of address to require singpass login. Not just input issue date. And if you cannot receive your Singpass mailed due to the change of address, it has to be self collect at govt agency.
Omg 😱 then it is a wrong decision to use that. I surprised this is approved by the directors. Must be 😴. Else the one overseeing this is an IT idiot.
 

prudie

Supremacy Member
Joined
Oct 19, 2010
Messages
7,150
Reaction score
1,441
You can change it 1 year from your birthday I recall. So it can be between 1 June 2025 to 31 May 2026.

More than 365 guesses.
with the type of supercharged computers that scammers use these days..even 1000 guesses is like what a handful of seconds? Problem is this 'solution' narrows down the 'guessing' game for these scammers even more!
 

TopGun

High Supremacy Member
Joined
Jan 1, 2000
Messages
44,495
Reaction score
6,921
with the type of supercharged computers that scammers use these days..even 1000 guesses is like what a handful of seconds? Problem is this 'solution' narrows down the 'guessing' game for these scammers even more!

Isn't it for the ICA system to have safeguards against bots?

You mean the scammers can brute force ICA systems in seconds?
 

Nickypigu

Supremacy Member
Joined
Mar 1, 2019
Messages
5,335
Reaction score
2,489
Omg 😱 then it is a wrong decision to use that. I surprised this is approved by the directors. Must be 😴. Else the one overseeing this is an IT idiot.
Cannot be lah. They following MDDI circular to not NRIC is Authenticator. Just that they forgot NRIC is also user account for Singpass.
 

AndroidComa

Arch-Supremacy Member
Joined
Jan 13, 2021
Messages
14,213
Reaction score
6,830
Our passport must change every 10 years. So nric should change too.
they are just lazy
if popular vote drops again, i think they just might
actually what's so difficult to change NRIC numbers for everyone?
 

tExtra

Arch-Supremacy Member
Joined
Nov 7, 2018
Messages
10,347
Reaction score
7,644
and keep monitoring for few more years until they got an effective solution, right?
Umm accountability and resolving the issue are separate matters bah. It’s understandable that you prefer the former. :)
 

prudie

Supremacy Member
Joined
Oct 19, 2010
Messages
7,150
Reaction score
1,441
Isn't it for the ICA system to have safeguards against bots?

You mean the scammers can brute force ICA systems in seconds?
can never be too sure these days
even if not brute force, 10 scammers try 10 times each for a week, might be able to succeed. Is the system smart enough to discern such pattern?
 

AK311212

Member
Joined
Jan 15, 2018
Messages
142
Reaction score
0
can never be too sure these days
even if not brute force, 10 scammers try 10 times each for a week, might be able to succeed. Is the system smart enough to discern such pattern?
Die Die , all the VEP applicants, should be more than 100K ?
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ. Forum members and moderators are responsible for their own posts.

Please refer to our Community Guidelines and Standards, Terms of Service and Member T&Cs for more information.
Top