Lord777
Professional
- Messages
- 2,577
- Reaction score
- 1,563
- Points
- 113
What are the most popular carding methods, what to do if fraudsters found out your bank card details, how to protect yourself from theft, and what are the chances of getting your funds back?
The most common methods of stealing funds from bank cards (carding) are based on psychological methods of persuading, deceiving or intimidating customers. According to the Russian Central Bank, more than 80% of all attacks are related to social engineering. The most popular method among scammers is phone phishing — which is the process of luring out personal data from bank customers.
According to statistics, about a quarter of cardholders are willing to disclose a three-digit security code to outsiders, as well as the validity period of the card and the code from an SMS message (3DSecure), which cannot be reported.
In 2022, the Central Bank initiated the blocking of more than 756 thousand phones of fraudsters — more than four times more than in 2021.
Another popular method of fraud is related to sales on ad sites, where the buyer uses a fake link to enter data to pay for a non-existent product.
In social networks, scammers send mailings to the list of friends from the hacked account with a request to transfer money to the card. Such information should always be rechecked through other communication channels.
Important! You don't need to click on links from suspicious emails and download unknown programs. Beware of paying for purchases on suspicious sites. Don't transfer money if you are not sure about the recipient. Monitor all operations on the account and use antivirus programs.
In 2022, the Central Bank sent more than 15 thousand resources for blocking. These included social media pages, mobile apps, and others.
Important! Не нужно извлекать из банкоматов чужие карты. В случае если карта уже извлечена и поступают угрозы, рекомендуется вызвать полицию.
The Central Bank estimates the average volume of one transaction in 2022 at 15.32 thousand rubles.
What should I do if scammers received the data and withdrew money from the card
1. Call the bank, block the card, and report unauthorized use of funds
2. Draw up a document of disagreement with the transaction at the bank's office
3. File a police report about the theft of money from the card
Expert comment by Denis Kalemberg, Founder and CEO of SafeTech:
"If the card details have become known to fraudsters, then in most cases they use them to transfer them to drop cards issued on fake or foreign passports. Usually," drops " withdraw stolen funds within a few minutes after the transfer. Also, purchases of equipment in online stores with subsequent resale are often used for theft.
You can't make a purchase or transfer just by knowing the card number, but this doesn't mean that you can share it with anyone, because this number is often used to restore access to mobile banking. For payment, at least one more validity period and the owner's name are requested. However, in this case, you can challenge the purchase and get a refund if the 3DSecure code was not used (usually sent in a text message to confirm payment). The online store is responsible for accepting payments without confirmation."
"If fraudsters steal all the card details, plus they find out the 3DSecure code, then it will be extremely problematic to return the money. In this case, the rules of payment systems impose responsibility on the client. If the payment was made without confirmation by the code, then there are definitely chances. Also recently, insurance services against theft from a bank card have become widespread.
To minimize the risk of losing money, it is best not to tell anyone over the phone about card details and SMS codes, do not enter card details on sites that you do not trust 100%, do not download mobile applications from unverified sources, and use antivirus software. But the best thing is to never keep more than the amount on a plastic card that you are not sorry to part with, " advises Denis Kalemberg.
(c) Mikhail Malaev, Direct Speech group
The most common methods of stealing funds from bank cards (carding) are based on psychological methods of persuading, deceiving or intimidating customers. According to the Russian Central Bank, more than 80% of all attacks are related to social engineering. The most popular method among scammers is phone phishing — which is the process of luring out personal data from bank customers.
How scammers work
- Posing as bank employees ("security service" or "financial monitoring service"), they report suspicious activity and offer to dictate the card details so that the bank takes measures to protect funds.
- They are persuaded to transfer money to a separate account, ostensibly to protect it. You can do this online or by withdrawing money from an ATM — in this case, the client can even order a taxi to it.
- They ask you to install special software to "protect funds", with which fraudsters can steal card data and issue a pre-approved loan, and then withdraw funds.
- Since the beginning of the pandemic, scammers have been actively exploiting the topic of coronavirus, whether it is "free" diagnostics, medical care, benefits, compensation, refunds for air tickets and other pretexts, the ultimate goal of which is to transfer money.
- They inform elderly people about the required payments on behalf of Pension Fund employees. In this case, they need to find out the bank card number and other data ostensibly to transfer money. In some cases, the attackers offer to transfer money to a third-party account to pay the state fee for future compensation.
- Call 10-15 minutes after receiving the card and offer to activate it. Although the user performs this process himself. This is how scammers try to find out the card details.
According to statistics, about a quarter of cardholders are willing to disclose a three-digit security code to outsiders, as well as the validity period of the card and the code from an SMS message (3DSecure), which cannot be reported.
In 2022, the Central Bank initiated the blocking of more than 756 thousand phones of fraudsters — more than four times more than in 2021.
Email phishing, social networks, and fake websites
Emails sent by fraudsters may contain links to fake websites that mimic the pages of online stores with big discounts, as well as hotels, air ticket sales services, insurance companies, and various departments. Emails are also sent under the guise of utility bills or in the form of official notifications from banks and other organizations.Another popular method of fraud is related to sales on ad sites, where the buyer uses a fake link to enter data to pay for a non-existent product.
In social networks, scammers send mailings to the list of friends from the hacked account with a request to transfer money to the card. Such information should always be rechecked through other communication channels.
Important! You don't need to click on links from suspicious emails and download unknown programs. Beware of paying for purchases on suspicious sites. Don't transfer money if you are not sure about the recipient. Monitor all operations on the account and use antivirus programs.
In 2022, the Central Bank sent more than 15 thousand resources for blocking. These included social media pages, mobile apps, and others.
ATM fraud
Theft with the use of special readers (skimmers) and overlays on ATM pin pads is becoming less and less due to the improved technical equipment of banks. They are being replaced by situation modeling with elements of social engineering. In one scenario, a fraudster (usually an elderly person) "forgets" a card at an ATM and then asks someone nearby to retrieve it. After receiving the card back, the attacker, along with his accomplices, checks the account balance and claims that the money is missing, after which he demands to return it.Important! Не нужно извлекать из банкоматов чужие карты. В случае если карта уже извлечена и поступают угрозы, рекомендуется вызвать полицию.
How much money did the scammers steal
According to the Central Bank, in 2022, fraudsters conducted about 876.59 thousand unauthorized operations, and about 14.165 billion rubles were stolen from customers.The Central Bank estimates the average volume of one transaction in 2022 at 15.32 thousand rubles.
What should I do if scammers received the data and withdrew money from the card
1. Call the bank, block the card, and report unauthorized use of funds
2. Draw up a document of disagreement with the transaction at the bank's office
3. File a police report about the theft of money from the card
Expert comment by Denis Kalemberg, Founder and CEO of SafeTech:
"If the card details have become known to fraudsters, then in most cases they use them to transfer them to drop cards issued on fake or foreign passports. Usually," drops " withdraw stolen funds within a few minutes after the transfer. Also, purchases of equipment in online stores with subsequent resale are often used for theft.
You can't make a purchase or transfer just by knowing the card number, but this doesn't mean that you can share it with anyone, because this number is often used to restore access to mobile banking. For payment, at least one more validity period and the owner's name are requested. However, in this case, you can challenge the purchase and get a refund if the 3DSecure code was not used (usually sent in a text message to confirm payment). The online store is responsible for accepting payments without confirmation."
Can I return stolen funds
Since 2014, the law "On the National Payment System"has been in force in Russia. According to it, the bank is obliged to return the stolen money, but subject to a number of conditions on the part of the client. First of all, the client must inform about the operation no later than one day after receiving the notification. According to the law, the bank must return the money if the data was compromised through no fault of the client, that is, the client met the following conditions:- didn't tell fraudsters your bank card details;
- didn't store the pin code with the card / didn't write it down on the card itself;
- didn't allow me to take photos of my card, etc.
"If fraudsters steal all the card details, plus they find out the 3DSecure code, then it will be extremely problematic to return the money. In this case, the rules of payment systems impose responsibility on the client. If the payment was made without confirmation by the code, then there are definitely chances. Also recently, insurance services against theft from a bank card have become widespread.
To minimize the risk of losing money, it is best not to tell anyone over the phone about card details and SMS codes, do not enter card details on sites that you do not trust 100%, do not download mobile applications from unverified sources, and use antivirus software. But the best thing is to never keep more than the amount on a plastic card that you are not sorry to part with, " advises Denis Kalemberg.
(c) Mikhail Malaev, Direct Speech group