W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9 W W W - - PDF document
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9 W W W - - PDF document
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9 W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9 F E S T I V E AWA R E N E S S 1 4 N O V E M B E R 2 0 1 9 Todays agenda 11AM 11:30 11:35AM 11:40AM
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
F E S T I V E AWA R E N E S S
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
A R R I V A L , T E A & C O F F E E 11AM – 11:30 W E L C O M E
Louise van der Merwe SABRIC Media & Communications
11:35AM P R E S E N T A T I O N & Q & A
Susan Potgieter SABRIC Acting CEO
11:40AM – 12:15AM L U N C H 12:30AM
Today’s agenda
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
Hot off the press – an MO resurfaces
S O C I A L E N G I N E E R I N G
- Elderly people being targeted by criminals who con them
into withdrawing their savings in exchange for a job.
- The criminal approaches the elderly person and tells them
that his boss wants to recruit pensioners as drivers.
- The criminal then asks if they have a driver’s license and a
bank account.
- The criminal then tells the potential victim that his boss
needs to check their bank balance as he cannot employ them if they have money in their account.
- The elderly person is then encouraged to withdraw all
their savings. They are then robbed.
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
‘Tis the season to be social but don’t let it be ruined by social engineering.
G O T T H A T ‘ H O L I D A Y F E E L I N G ? ’
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
Social Engineering is manipulative. It exploits human vulnerability because criminals know that the weakest link in the information security chain is the human being.
S O C I A L E N G I N E E R I N G
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
Social Engineering is a manipulative tactic used to gather information about you. This information can be used to defraud you.
S O C I A L E N G I N E E R I N G
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
We are all #ImStaying But SABRIC says #NotSaying
S O C I A L E N G I N E E R I N G
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
I D E N T I T Y T H E F T
Don’t let ‘holiday mode’ see you give away your personal information.
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
Confidential information, which includes usernames, password and PIN numbers
I D E N T I T Y T H E F T
Personal information includes identity documents, driver’s licenses, passports, addresses and contact details amongst others. Only share it very selectively and on a need to know basis only.
Confidential information
N E V E R S H A R E T H E S E
Personal information
S H A R E O N LY O N A N E E D TO K N OW B A S I S
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
But you’ve got the power…
- Don’t carry unnecessary personal information in
your wallet or purse.
- Don’t write down PINs and passwords, and avoid
- bvious choices like birth dates and first names.
- Verify all requests for personal information and
- nly provide it when there is a legitimate reason
to do so.
I D E N T I T Y T H E F T
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
- Don’t use Internet cafes, hotels or conference
centres to do your banking.
- To prevent your ID being used to commit fraud if
it is ever lost or stolen, alert the SA Fraud Prevention Service immediately on 0860 101 248
- r at www.safps.org.za.
- Use strong passwords for all your accounts.
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
How else does it happen?
S O C I A L E N G I N E E R I N G
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
The opportunity is created by…
B E L I E V I N G that an email is from an authentic organisation or service provider.
1 2 3
C L I C K I N G
- n a link in the email.
E N T E R I N G Entering confidential information into a form
- n a spoofed website.
They log into your bank account and steal your money.
The criminal now has your confidential information.
P H I S H I N G
Y O U ’ V E B E E N P H I S H E D !
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
B E L I E V I N G that a phone call is from your bank or a legitimate service provider.
1 2 3
B U Y I N G into the story on the
- ther end – often out
- f fear and a sense of
urgency. G I V I N G A W AY your confidential information.
They log into your bank account and steal your money.
The criminal now has your confidential information.
V I S H I N G
Y O U ’ V E B E E N V I S H E D !
The opportunity is created by…
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
B E L I E V I N G that an SMS is from an authentic organisation
- r service provider.
1 2 3
C L I C K I N G
- n a link in
the SMS. I N S TA L L I N G M A L W A R E which either acts like a legitimate app or takes you to a fake site where you are tricked into typing in confidential information.
They log into your bank account and steal your money.
Your information is sent to cybercriminals.
S M I S H I N G
Y O U ’ V E B E E N S M I S H E D !
The opportunity is created by…
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
- Do not click on links or icons in unsolicited
emails.
- Know that criminals can mask their
telephone numbers seem as if a legitimate individual or company is making the phone call.
- Banks will never ask you to confirm your
confidential information over the phone.
P H I S H I N G , V I S H I N G A N D S M I S H I N G
But you’ve got the power…
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
- Do not click on links or icons in unsolicited
SMSs.
- If you lose mobile connectivity under
circumstances where you are usually connected, check whether you may have been the victim of a SIM swop.
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
Make sure your password is super- strong…
Try SABRIC’s password tester! www.becyberstrong.co.za
P A S S W O R D S
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
- The key to strong passwords is to make them
very long - the more characters, the better.
- Use a ‘passphrase’!
- This is a strong password that uses a short
sentence or a string of random words.
- Passphrases should be easy for you to
remember, but difficult for a criminal to guess.
P A S S W O R D S
But you’ve got the power…
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
Share our WhatsApp Vishing Video
V I S H I N G
PLAY
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
How else are criminals planning to exploit you this Festive Season?
F E S T I V E S E A S O N E X P L O I T A T I O N
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
B O O K I N G Y O U R H O L I D A Y
Criminals are depending on your last minute holiday booking!
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
The opportunity is created by…
S E A R C H I N G the Internet for last minute holiday accommodation and find an incredible deal.
1 2 3
B O O K I N G your holiday quick, quick. PAY I N G for your holiday in full via your bank card or EFT.
Your holiday accommodation does not exist and your money is gone.
But when you contact the ‘rental agent’ to make final arrangements but get no answer! You have been ghosted…
B O O K I N G Y O U R H O L I D A Y
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
What you don’t know is the website you used to book was bogus…
You entered your card details on the bogus website.
C A R D D E TA I L S
The transaction did not go through and you were directed to do an EFT into a specific bank account which you promptly do.
PAY M E N T
Your card details were compromised and the fraudster not only has your money, but your card details as well – which can be used to commit further fraud.
C O M P R O M I S E
B O O K I N G Y O U R H O L I D A Y
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
- Do not trust websites that are
unfamiliar.
- Don’t fall for offers that are available
at a very low price. If an offer seems to be too good to be true, it usually is.
B O O K I N G Y O U R H O L I D A Y
But you’ve got the power…
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
- Register for 3D Secure to secure your
card details.
- Don’t send emails that quote your card
number and expiry date.
- If you are requested to confirm your
banking or personal details via a link, don’t click on it.
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
Criminals want your bonus and holiday cash.
C A R R Y I N G H O L I D A Y C A S H
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
W I T H D R A W I N G large amounts of cash inside the bank or at an ATM – but someone knows!
1 2 3
L E A V I N G A L O N E alone with lots of cash on you. T R A V E L I N G alone through a remote location to get to you destination.
You are robbed at gun-point
You are then surprised by the robber – who knew
- r was informed…
C A R R Y I N G H O L I D A Y C A S H
The opportunity is created by…
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
- Consider making use of cell phone
banking or internet transfers.
- Identify another branch close by to
ensure that your banking pattern was not easily recognisable or detected.
- Avoid carrying money bags or a
briefcase.
C A R R Y I N G H O L I D A Y C A S H
But you’ve got the power…
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
- Carry as little cash as possible.
- Never make your bank visit public,
even to the people closest to you.
- Do not openly display the money you
are depositing while standing in the bank queue.
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
Criminals want your stokvel payout.
C A R R Y I N G H O L I D A Y C A S H
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
- Arrange for your stokvel savings club or
burial society members to deposit cash directly into the clubs bank account instead
- f collecting cash contributions.
- Arrange that club’s playout be electronically
transferred into each club member’s personal bank account or accounts of their choice.
C A R R Y I N G H O L I D A Y C A S H
But you’ve got the power…
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
- Refrain from making cash deposits for your
club members’ contributions on high risk days, for example, the Monday after month end.
- If you must deposit club cash contributions
- r make withdrawals ensure you are
accompanied by another club member.
- Always take another person with you when
going to deposit club cash contributions.
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
H O L I D A Y S H O P P I N G
Criminals are banking
- n your last minute
- nline holiday
shopping!
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
B E I N G E N T I C E D
by a really good deal online for an
- nline purchase that would make a
great holiday gift via a mailer or Facebook advert. 1 2
PAY I N G
for your purchase in full but never receiving the goods!
The goods never arrive and your money is gone.
But when you try to make contact with the online retailer, there is no response. They have simply disappeared.
H O L I D A Y S H O P P I N G
The opportunity is created by…
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
- Be aware that the ‘s’ in the ‘https’ no longer
guarantees that a website is secure.
- When registering on an e-commerce
website, always choose a strong password or even better, a passphrase and never save these on any computer or mobile device.
H O L I D A Y S H O P P I N G
But you’ve got the power…
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
- Protect your personal information. Online
merchants don’t need your ID number or date of birth to process your order.
- Check your bank balance after making any
shopping payment, and report any fraudulent transactions to your bank immediately.
- Again, register for 3D Secure to secure your
card details.
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
Holidays are a perfect opportunity for criminals to clone your card.
C A R D D A T A C O M P R O M I S E
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
H A N D I N G
- ver your bank card
at any payment point.
1 2 3
N O T PAY I N G AT T E N T I I O N when your card is swiped through a normal ‘POS device’. B U T Y O U R C A R D is actually being swiped through a small, inconspicuous skimmer.
Your account is debited when the criminal uses the counterfeit card.
Magstripe data is stolen from your cards magnetic strip. Lost, stolen and old cards are re-encoded with this information.
C A R D D A T A C O M P R O M I S E
The opportunity is created by…
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
- Just because you are on holiday, don’t
forget to view your card as if it were cash.
- Never let the card out of your sight
when making payments.
C A R D D A T A C O M P R O M I S E
But you’ve got the power…
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
W I T H D R A W I N G H O L I D A Y C A S H
Criminals know that holidays are for spending and that you will use an ATM…
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
PA N I C K I N G
1 2 3
A L L O W I N G E N T E R I N G
Your card and PIN are used to withdraw your money from the ATM around the corner
W I T H D R A W I N G H O L I D A Y C A S H
The opportunity is created by…
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
- Don’t insert your card if the screen layout is
not familiar or if it looks like the ATM has been tampered with.
- Be cautious of strangers offering to assist -
they could be trying to distract you in order to get your card or PIN.
A T M F R A U D
But you’ve got the power…
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
- If you were disturbed while transacting,
change your PIN or stop the card immediately.
- If you think the ATM is faulty, cancel the
transaction IMMEDIATELY, report the fault to your Bank and transact at another ATM.
- Avoid ATMs that are dimly lit or surrounded
by loiterers.
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
T R U S T Y O U R G U T
IF YOU SENSE THAT SOMETHING IS OFF, IT PROBABLY IS #NOTSAYING
W W W . S A B R I C . C O . Z A 1 4 N O V E M B E R 2 0 1 9
T H A N K Y O U S B I A R C