After 73 complaints in two months, T.N. Cyber Crime Police issue advisory on ‘SBI reward points scam’

Police said the scam involves fake messages about reward points expiring, after which victims are asked to click on a link and download an APK file, which eventually gives scamsters access to sensitive information such as banking credentials

Updated - July 09, 2024 05:32 pm IST

Published - July 09, 2024 05:02 pm IST - CHENNAI

Photograph used for representational purposes only

Photograph used for representational purposes only | Photo Credit: Getty Images/iStockphoto

The Cyber Crime Wing of the Tamil Nadu police has issued an advisory over a new cyber scam called the ‘SBI Reward Points Scam,’ after it received 73 complaints in two months. 

Police said the complaints were received on the National Cyber Crime Report Portal relating to this scam, from Tamil Nadu. Explaining the modus operandi, Additional Director General of Police, Sanjay Kumar said, “The fraudsters first hack into a victim’s mobile phone to gain access to their social media accounts, such as WhatsApp. This can be done through various means, such as phishing attacks or exploiting vulnerabilities in apps.”

Once they gain access to a social media account, the hackers send fake messages about SBI Reward Points to all the victim’s official and personal groups. The messages come with icons and names that say ‘State Bank of India’, and so they appear legitimate, he said.

The fraudulent messages contain links that claim to help victims update their bank details and redeem their SBI Reward Points. The messages states that the person’s reward points are about to lapse, creating a sense of urgency. When the victims click on the link, they are prompted to download an APK file (Android Package). This file is disguised as an official application or update related to SBI reward points. By downloading and installing the APK file, the victim unknowingly installs malware on their device. This malware can steal sensitive information, including banking credentials, passwords, and OTPs.

After entering their bank details, the victim is prompted to enter an OTP (One Time Password) sent to their phone. This OTP is supposed to secure the transaction but is intercepted by the fraudsters. With the captured bank details and OTPs, the fraudsters gain unauthorised access to the victim’s bank account. They can then transfer funds or perform other fraudulent activities, resulting in financial losses to the victim, said Mr. Kumar. 

Two-step verification

The police have advised the public to activate two-step verification protocols on their social media accounts, to add an extra layer of security. This requires a PIN in addition to the OTP sent to your phone. They have also advised the public to be cautious of messages from unknown contacts or unexpected messages from known contacts, especially those containing links or requests for personal information.

The advisory also asked the public to avoid clicking on suspicious links and never download APK files from unknown sources. Always verify the authenticity of any website or app by checking official sources, it said.

If you suspect that you have been a victim of fraudulent activity or have come across any suspicious activity, report the incident by dialing the Cyber Crime Tollfree Helpline 1930 or register a complaint at www.cybercrime.gov.in

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.

  翻译: