How to counter CPF scams

  • Have you been Scammed?
    Follow this advisory from National Crime Prevention Council (NCPC) or call ScamShield Helpline 1799. More info

polyglob

Senior Member
Joined
Jun 24, 2009
Messages
1,047
Reaction score
139
Any IT-minded forum members can explain what likely happened and what protective steps to take? Known measures:

- Don't anyhow install 3rd party apps into our phones
- ... what else?

I saw a YT video by Mr 1M65 suggesting creating a 'fortress' account, doesn't sound very practical.
 

Mephist0pheLes

Arch-Supremacy Member
Joined
Mar 26, 2014
Messages
10,524
Reaction score
8,531
Dont anyhow scan qr code
Read the web address before u log in online banking
Dont click any banking link in email or sms
 

wira

Supremacy Member
Joined
May 6, 2000
Messages
5,773
Reaction score
772
the CPF scams happen as victims are tricked into installing malicious malware apps and give the apps all the permissions. app can then remote access your device and control all your apps.

steps to take :
1. DO NOT sideload any suspicious apps (means apps download from url and not installed from playstore )
2. Be aware what accessibility permissions any app is asking and if in double, click DO NOT ALLOW
3. Most of these scams advertise on social media selling good deals for durian, cleaning services, concert tickets, pet grooming , etc and then ask you download their app to 'pay deposit' and make booking. Be suspicious if anyone ask you download any app from a separate link and not from app stores.
4. Best to use iPhone instead of Android. So far the malware scams are mainly attacking android devices.
5. Use common sense.
 

bombshell

Arch-Supremacy Member
Joined
Jan 1, 2022
Messages
18,306
Reaction score
15,064
The CPF scam was pretty darn sophisticated. If what the CNA article says is accurate, just by clicking a wrong link, they managed to install a malware and bypass all the bank and singpass 2FA authentications to withdraw all the money.
At this level, really have to treat all strangers as scammers. Soon with AI and deep fakes, it may not even be "strangers" scamming you.
Scary.
 

white_prince

High Supremacy Member
Joined
May 14, 2012
Messages
26,869
Reaction score
6,666
Any IT-minded forum members can explain what likely happened and what protective steps to take? Known measures:

- Don't anyhow install 3rd party apps into our phones
- ... what else?

I saw a YT video by Mr 1M65 suggesting creating a 'fortress' account, doesn't sound very practical.

Get 2 phones🔽 for segregation of duties
1 iphone for banking n finances
1 android for facebook, tiktok, whatsapp and communications
 

BlueRobin

Member
Joined
Mar 22, 2018
Messages
295
Reaction score
111
The CPF scam was pretty darn sophisticated. If what the CNA article says is accurate, just by clicking a wrong link, they managed to install a malware and bypass all the bank and singpass 2FA authentications to withdraw all the money.
At this level, really have to treat all strangers as scammers. Soon with AI and deep fakes, it may not even be "strangers" scamming you.
Scary.
I watched the video which is here:



The malware is obviously side-loaded to his android phone, a feature that is so liked by many android users. After that it took control of his phone and intercept 2FA authentications over the next 12 hours.

We just need to be very careful because scammers will come up with different approach once a method is exposed. Using a safer platform helped too.
 

creatrixnator

Junior Member
Joined
Jul 28, 2007
Messages
74
Reaction score
3
I watched the video which is here:



The malware is obviously side-loaded to his android phone, a feature that is so liked by many android users. After that it took control of his phone and intercept 2FA authentications over the next 12 hours.

We just need to be very careful because scammers will come up with different approach once a method is exposed. Using a safer platform helped too.

Oh noes
It’s coming to iPhone

https://www.forbes.com/sites/kateof...is-coming-but-how-safe-is-it/?sh=4ce948d64ce0
 

Froggyman

Senior Member
Joined
Apr 24, 2008
Messages
912
Reaction score
112
Is thinking whether the old times method of another token for generation of OTP for transaction /transfer purpose only helps? But then at the expense of convenience:rolleyes:
Just a thought if all banks and governments agencies use the same token that is link to personnel identification to minimise the inconvenience
 

reddevil0728

Great Supremacy Member
Joined
Dec 16, 2005
Messages
66,305
Reaction score
5,879
Is thinking whether the old times method of another token for generation of OTP for transaction /transfer purpose only helps? But then at the expense of convenience:rolleyes:
Just a thought if all banks and governments agencies use the same token that is link to personnel identification to minimise the inconvenience
actually the token still exists what. just that it is digital. there is still 2FA
 

royalmix

Master Member
Joined
Feb 23, 2016
Messages
4,266
Reaction score
1,271
Security is as strong as the weakest link - you!

I always use internet banking, no apps where possible. I dun even link my CPF to singpass nor findex nor use the CPF app. Everything to do with money, I use my desktop!
 

reddevil0728

Great Supremacy Member
Joined
Dec 16, 2005
Messages
66,305
Reaction score
5,879
Security is as strong as the weakest link - you!

I always use internet banking, no apps where possible. I dun even link my CPF to singpass nor findex nor use the CPF app. Everything to do with money, I use my desktop!
what do you mean don't link CPF to singpass?

it's not a choice no?
 

polyglob

Senior Member
Joined
Jun 24, 2009
Messages
1,047
Reaction score
139
actually the token still exists what. just that it is digital. there is still 2FA

Using the phone running the banking app as the 2FA device weakens security since (as seems the case with successful scams) malware controlling the phone can perform the 2FA without the phone user's interaction or awareness.

A separate token like what Froggyman wrote is less convenient but more secure. Add costs, for sure. Remember when each bank had its own token? Maybe gahmen will chut a centralized 2FA device a la Singpass?

Is thinking whether the old times method of another token for generation of OTP for transaction /transfer purpose only helps? But then at the expense of convenience:rolleyes:
Just a thought if all banks and governments agencies use the same token that is link to personnel identification to minimise the inconvenience
 

reddevil0728

Great Supremacy Member
Joined
Dec 16, 2005
Messages
66,305
Reaction score
5,879
Using the phone running the banking app as the 2FA device weakens security since (as seems the case with successful scams) malware controlling the phone can perform the 2FA without the phone user's interaction or awareness.

A separate token like what Froggyman wrote is less convenient but more secure. Add costs, for sure. Remember when each bank had its own token? Maybe gahmen will chut a centralized 2FA device a la Singpass?
is it really the consensus in the cyber security space that the same device 2FA isn't as safe?
 

royalmix

Master Member
Joined
Feb 23, 2016
Messages
4,266
Reaction score
1,271
once upon a time, someone introduced the one token, meant to be the single point of 2fa, somehow it died, singpass came to the rescue.

so the story goes!:ROFLMAO:

Why I prefer desktop or ibanking, real 2fa in work! You use app, it somehow become one physically or however you describe it!

Eg HSBC ega, ibanking need password on first device, then need to generate otp from app (second device). You use app, just need your mobile and pin, all in one device.
 
Last edited:

BBCWatcher

Arch-Supremacy Member
Joined
Jun 15, 2010
Messages
24,622
Reaction score
5,605
The decision to get rid of the plastic 2FA token devices isn’t looking so brilliant is it?

I agree with Polyglob that the government ought to consider a national 2FA device that’s hooked into a common 2FA service for both public and private sector entities. One possible way to do that in a more consumable way is to issue NRICs with embedded OTP displays. Here’s an example. A few years ago Standard Chartered issued credit cards like that example (as I recall). But everyone needs to assume that a single device is compromised. The second factor has to be genuinely second.
 

BBCWatcher

Arch-Supremacy Member
Joined
Jun 15, 2010
Messages
24,622
Reaction score
5,605
The CPF Board recently added facial scans to try to combat these risks. But facial scanning has many shortcomings too.
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top