Omsk scammers robbed a taxi service using a vulnerability in the application

Tomcat

Professional
Messages
2,656
Reputation
10
Reaction score
650
Points
113
Four Russians (one from the Krasnoyarsk Territory, the rest from the Omsk Region) found a way to exploit the vulnerability they discovered in a taxi ordering application. According to the Ministry of Internal Affairs Media portal, the scheme has been in operation since November 2022.

“The attackers, using photographs of forged IDs made in a graphic editor, registered in the service program as drivers. Then, using disposable SIM cards, they created customer accounts on whose behalf trips were ordered. By replacing the location coordinates, they were recorded as completed,” said official representative of the Russian Ministry of Internal Affairs Irina Volk.

The essence of the scheme was to receive bonuses from a taxi service on a bank card for completing a certain number of successful trips, which in fact did not happen. If the accounts of virtual taxi drivers were blocked, the scammers simply created more and more new accounts. Thus, cybercriminals managed to earn more than five million rubles.

Searches and arrests of fraudsters were carried out simultaneously in two regions of the country. Smartphones, computers, bank and SIM cards, money and documents were confiscated from them. All were charged under Article 159 of the Criminal Code of the Russian Federation.

“A preventive measure in the form of detention was chosen against two of the defendants, one is under house arrest and another is under a written undertaking not to leave the place and proper behavior,” concluded Irina Volk.

Previously, hackers from the Saratov region managed to pull off a similar scam. Then, a vulnerability discovered by cybercriminals made it possible to illegally receive money, which was transferred by taxi passengers as payment.
 
Top