src='https://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js?client=ca-pub-2513966551258002'/> Rightways: Cybersecurity Infolinks.com, 2618740 , RESELLER

Pages

Share This

Deepseek https://www.deepseek.com/./深度求索 DeepSeek | 深度求索 https://askaichat.app/chat
Showing posts with label Cybersecurity. Show all posts
Showing posts with label Cybersecurity. Show all posts

Monday, August 10, 2026

Don’t install apps under pressure, ‘I watched them take control of my phone remotely’

 

Compromised: Scammers are finding more sophisticated ways to bypass safeguards, such as malicious apps disguised as legitimate services. — Pic from magnific.com

PETALING JAYA: As smartphones become central to banking and daily life, scammers are finding increasingly sophisticated ways to seize control of the devices and the accounts within.

Universiti Sains Malaysia Cybersecurity Research Centre director Prof Dr Selvakumar Manickam said criminals were now turning to remote-access tools and malicious applications to bypass conventional scam safeguards.

He said victims could be persuaded to install apps such as AnyDesk or TeamViewer or malicious Android Package Kit (APK) files disguised as legitimate banking, delivery or other services.

Once installed and given permissions such as accessibility access, scammers could potentially view and operate the victim’s phone, including banking applications.

“An unsolicited caller asking the victim to download an app to ‘resolve’ an issue, a request to enable accessibility, SMS or ‘install unknown apps’ permissions, or being asked to remain on a call while installing something, should raise alarm bells,” he said when contacted.

Unexpected battery drain or unusual phone behaviour after installing an application, particularly one downloaded outside authorised sources, are also warning signs.

Selvakumar said scammers were increasingly exploiting psychology rather than simply trying to defeat technical security measures.

“They may create a sense of urgency by claiming a bank account has been frozen, a police matter needs to be resolved or an unpaid bill requires immediate action.

“Generative AI is also making scams more convincing with criminals able to produce polished phishing messages in local languages and clone voices to impersonate family members, bank officers or government officials,” he said.

Beyond screen control, malware can quietly intercept SMS messages and push notifications, including one-time passwords and two-factor authentication codes, before forwarding them to scammers.

Some newer malware could also identify a victim’s SIM card and mobile carrier before subscribing them to premium services through mobile billing systems.

“Fake cellular base stations have also been detected locally, allowing criminals to send fraudulent SMS messages while bypassing some telco-level filtering,” he added.

Selvakumar said the affected phone should subsequently be reset after important data has been backed up or checked by a trusted technician.

“The lesson is simple – never allow urgency or fear to override basic security precautions,” he said.

Cybersecurity expert Fong Choong Fook said social engineering remained one of the biggest threats despite growing public awareness.

“Don’t install any unknown or suspicious software. Have good practices such as not clicking on links from strangers or SMS,” he said.

Fong added that scammers impersonating bank employees, law enforcement officers and government officials could now use AI-generated voice and video to make their identities appear more convincing.

“Users should avoid public WiFi where possible as compromised networks could expose devices to additional risks.”

‘I watched them take control of my phone remotely’


PETALING JAYA: A routine phone call can quickly turn into a financial nightmare when unsuspecting victims lose control of their smartphones to scammers.

Confidential information and other personal details will then be manipulated by these fraudsters, causing financial and emotional distress to the victims.

For a Shah Alam resident who wished to be known only as Lim, the scam started with a phone call from a “bank officer”, warning him about suspicious transactions.

The caller instructed him to download an application, purportedly to verify his identity and secure his account.

Thinking he was following a security procedure, Lim installed the application and granted the requested authorisation.

“After installing it, it seemed that someone had taken control of my phone.

“I could see apps opening by themselves, but I could not control what was happening,” said the 42-year-old.

Within minutes, the scammers had gained access to his banking application and made several transactions.

Lim claimed that he lost about RM7,800 from his account before he managed to disconnect the phone from the Internet and contacted the bank.

“I always thought scams happened because people clicked suspicious links.

“I never expected that scammers could take over my phone while I was still holding it.

“By the time you realise it is the work of a scammer, it is too late, as you have probably already suffered financial losses,” he said.

Another victim, who wished to be known as Tan, 56, from Ipoh, said she was contacted through WhatsApp on July 1.

The caller informed her that she had won a RM3,000 prize and was offered a choice between shopping vouchers or cash credited to her e-wallet.

Tan said she opted for a cash reward, and the call was subsequently transferred to a “manager”, who sounded like a foreigner.

“I just followed his instruction to claim the reward.

“He then took control of my phone screen and kept directing me from one site to another without giving me time to think,” she said.

Tan said she then contacted the platform’s customer service through the app, activated the kill switch and lodged a police report within an hour.

She also said the official complaint submitted through the app, together with screenshots and supporting documents, later disappeared from her phone.

Tan claimed that RM4,500 was charged to her pay-later account while another RM6,000 was withdrawn through the platform’s loan facility, bringing her total losses to RM10,500.

“The RM6,000 purported loan was converted into a 24-month repayment plan, requiring a monthly instalment of over RM300.

“The sum of RM4,500 was transferred to an entity listed as ‘Lucky Boy Trading’, although I had not purchased any items,” she said.

A victim from Subang, who identified himself as Ravi, 35, said scammers posing as delivery company employees convinced him to install an application to reschedule a parcel.

After granting the application access to his phone, he noticed that messages and notifications were appearing and disappearing without his involvement.

“I thought I was only following instructions to receive a parcel. I never expected them to be able to take control of my phone.”

Sunday, May 24, 2026

Enhance fraud detection, checking banking fraud

 

CLICK TO ENLARGE

CLICK TO ENLARGE


Calls for improvements in detecting suspicious banking transactions

The issue has come under renewed focus following a Sessions Court ruling ordering a bank to compensate a customer RM166,000 over suspicious online transactions that went undetected.

As scams evolve, banks are facing heightened urgency to identify unusual transaction patterns and act fast, particularly as fraudsters exploit human behaviour and then move in to breach banking systems.

At a Bank Negara workshop on consumer protection and fair conduct reforms, its officers said existing laws protect the confidentiality of customer information and personal data in the financial sector.

“Financial institutions are robust but there is always room for improvements,” the officers said yesterday.

They said enforcement actions had been taken in instances where breaches were identified, including requiring the institutions involved to implement corrective action plans.

The officers also said Bank Negara continued to monitor banks on consumer protection and compliance matters.

In its latest annual report, the central bank stressed the need to strengthen fraud detection systems and reinforce internal safeguards to combat sophisticated online scams.

The central bank said banks and non-bank financial institutions were required to adopt advanced fraud detection measures and strengthen internal safeguards to quickly intercept suspicious transactions.

It also stressed for a proactive approach to prevent fraudulent transactions from escalating.

The central bank said that in recent years, financial institutions had strengthened various security measures including tighter fraud detection rules and triggers, cooling-off periods for new device registrations and stronger authentication methods.

These measures contributed to a 52% decline in unauthorised fraudulent transactions involving malware and phishing reported in 2024, and prevented over Rm399mil in attempted fraudulent transactions, it said.

However, Bank Negara also acknowledged that fraud patterns were becoming increasingly complex and harder to distinguish from genuine customer activity.

Bank Negara said banks and consumers shared responsibility for safeguarding digital banking security, but reiterated that financial institutions had to determine whether weaknesses in their internal controls contributed to fraud incidents.

It also introduced the Selfcompensation Framework for Fraud Transactions (SEFT) under its Policy Document on Ensuring Fair Treatment for Victims of Unauthorised e-banking Transactions.

SEFT outlines how banks should assess fraud cases and determine compensation based on the responsibilities of both financial institutions and customers.

According to Bank Negara, more than 95% of online fraud cases in Malaysia involved authorised transactions – where victims were manipulated into willingly transferring money to scammers.

Federation of Malaysian Consumers Associations (Fomca) vice-president Datuk Indrani Thuraisingham agreed that banks should adopt more proactive intervention measures when transactions appear inconsistent with a customer’s normal behaviour.

“Banks are clearly not doing enough. Fraudsters now exploit human behaviour more than banking systems,” she said.

“Banks must transition from passive logging to active, pre-emptive intervention.”

https://www.thestar.com.my › nation › 2026/05/22 › sle...

Related post:

Banks must rethink fraud controls as AI risks rise



Tuesday, December 2, 2025

THINK BEFORE YOU CLICK OR PAY

 

Chow (second left) looking at a series of Malaysian banknotes with Abdul Rasheed (left) at the Financial Literacy Carnival in Queensbay Mall. — Photos: CHAN BOON KAI/The Star

A FINANCIAL literacy and awareness carnival by Bank Negara Malaysia (BNM) in Penang provided visitors with insight into online scams, insurance coverage and banking services.

Sales adviser Tammy Teh, 44, and her family liked the fun games and information provided by the various agencies, banks and companies.

“We were at the mall to eat and noticed booths set up all over.

“It is a good event as I have learnt quite a bit about how to make my money grow and protect it.

“We also didn’t realise how quickly one can fall for an online scam,” she said when met at the three-day event at Queensbay Mall.

Businessman David Yu, 49, and his daughter, Yu Shin Chi, 11, learnt how to avoid phone scammers and keep personal details safe.

“It was a fruitful day for me and my daughter.


“Usually, when I go to the shops to do it, they charge a sum or turn me away.

“I am a simple businessman who does not go out much, but a fair like this at a popular mall gives us the opportunity to learn new things,” he said.

The final event of the Finan­­-cial Literacy Month 2025, spearheaded by the Financial Education Network, saw 39 booths offering fun games and advice.

The public can now use self-service coin deposit machines at some banks for no extra charge. The public can now use self-service coin deposit machines at some banks for no extra charge.

BNM governor Datuk Abdul Rasheed Ghaffour said in his speech at the opening ceremony that like many countries, Malaysia faced challenges related to the cost of living, changes in the job landscape and technologies that evolve faster than people can adapt.

“In such circumstances, financial literacy becomes a core skill that helps people think carefully before spending.

“It helps them make sound financial decisions and build household resilience.

“Financial knowledge helps us understand our true needs, avoid excessive debt and be prepared for emergencies.”

Rasheed said the country had rapidly shifted into digital finance with almost nine out of 10 Malaysians using online services for payments, banking and insurance.

“This convenience however is accompanied by heightened exposure to scams, many of which are now powered by artificial intelligence that can mimic people’s voices and faces.

“Do not share personal information, check before you click and think before you pay.

“While we continue to strengthen cybersecurity with industry players and enforcement agencies, public awareness remains the strongest line of defence,” he said.

Penang Chief Minister Chow Kon Yeow, who was also the guest of honour, said financial literacy should reach all segments of society including students, factory workers, traders, retirees and housewives.

“A society that is financially literate not only protects its members from financial risks, but also builds the foundation for a stronger state economy,” said Chow.

Tuesday, December 10, 2024

Beef up cybersecurity now

 

Cyberattacks likely if action not taken, says bukit aman



KUALA LUMPUR: Companies and organisations must beef up cybersecurity to prevent breaches and cyberattacks, says Bukit Aman.

Bukit Aman Commercial Crime Investigation Department (CCID) director Comm Datuk Seri Ramli Mohamed Yoosuf (pic) said cyber attacks are quite prevalent worldwide with millions of attacks per year and tens of thousands daily.

“Thus, it is imperative for companies and organisations to beef up their cybersecurity systems such as firewalls to prevent breaches.

“If it is not done, sooner or later, an organisation or entity might face a cyberattack,” he told The Star recently.

Comm Ramli said the CCID is working closely with other agencies such as Cyber Security Malaysia and the Malaysian Communications and Multimedia Commission to take action on data breaches.

He said the CCID managed to bust a syndicate that attempted to sell stolen data in September.

“We detained five men, including a Pakistani, in an operation codenamed Ops Kapas, with other agencies, including Cyber Security Malaysia.

“The syndicate stole 400 million pieces of data of Malaysians, including names, MyKad, addresses, bank accounts and phone numbers.

ALSO READ: Smaller firms lack budget for cybersecurity

“They had hacked systems used by companies and agencies to obtain the data.

“Those who want access to the data are charged between RM200 and RM800 per month,” he said.

(Click To Enlarge)(Click To Enlarge)

Investigations showed the syndicate was operating for about a year.

“Two of those detained – a Malaysian and a Pakistani – were a web portal designer and a hacker.

“Three other individuals were agents and unlicensed debt collectors, who bought the stolen data,” he said.

Investigations showed the Pakistani man as the syndicate’s mastermind due to his hacking skills.

“We believe he entered Malaysia as a general worker 10 years ago,” he said.

Comm Ramli said syndicates are using the “shadow world” of the Internet to look for potential customers of the stolen data.

ALSO READ: Shields up around Malaysia’s cyberspace

“The syndicate would sell the stolen data on the dark web to other syndicates such as scammers as well as unlicensed debt collectors,” he said.

Meanwhile, checks by The Star on the dark web showed that transactions are made using cryptocurrency, particularly bitcoin, which makes following the money trail difficult.

Among the finds on the dark web was the alleged sale of staff members’ and customers’ data of a low-cost airline.

Another search result showed that hackers have sourced the login ID of users of different banks from different countries and were promoting their service which includes transferring any amount of money for a fee.

“We have gathered bank logins of different banks and countries as a result of automated Malware/Trojan we spread online once the individual logs into his/her online banking account, it grabs the person’s banking details, it is very powerful and can get access to accounts, bank database and bank server,” the promotional literature of the service read.

(Click To Enlarge)(Click To Enlarge)

“With these services, you just place an order to get any amount you need and we will look up the bank login we have available and make transfers to any account you provide.

Our services are efficient, reliable and safe,” it said, adding that bank transfers are available to countries such as Malaysia, the United States, the United Kingdom, the United Arab Emirates, Canada, Australia, Netherlands, China and Switzerland.

These hackers are charging US$450 (RM1,990) for bank transfers amounting to US$2,000-US$4,000 (RM8,848-RM17,696); US$750 (RM3,318) for bank transfers amounting to US$5,000-US$7,000 (RM22,122-RM30,969) and US$1,050 (RM4,645) for bank transfers amounting to US$8,000-US$10,000 (RM35,393 - RM44,241).

Source link

Related stories:

Smaller firms lack budget for cybersecurity

Shields up around Malaysia’s cyberspace

Make clear who’s in charge now, say stakeholders

Related posts:

Expert calls for NSRC overhaul as millions lost to scammers posing as NSRC officials

 


OTHERS:

Mohammed al-Bashir officially takes over Syrian ...