Wrong password - sophisticated scam targeting bank customers

Minh Ánh (Theo CyProtek) |

Hackers impersonate bank employees and use the "account locking" trick to steal assets via OTP code.

Wrong password and perfect phishing scheme

In June 2023, the CyProtek investigation team of the Anti-Fraud project received a series of complaints from users about bank accounts being suddenly locked for no apparent reason. The victims all told a similar story: After their accounts were locked, they received a call from a "bank employee" asking for an OTP code to recover them. Just a few minutes later, the assets in the account "evaporated".

Initial analysis suggests that these are not isolated incidents, but rather part of a larger fraud campaign targeting banks in Vietnam. The CyProtek team decided to get involved, assigning the investigation code 23xPH03NIX, part of an international cyberattack campaign called GoldFactory.

"Account Lock" Tricks - The Starting Point of a Scam

According to the investigation, hackers start by collecting victims' information from leaked data sources or online black markets, including phone numbers, emails, login names, and even passwords. Notably, many of the data are accidentally revealed by the victims themselves through social networks or unsecured online platforms.

Once they have enough information, the hacker logs into the victim’s bank account. They intentionally enter incorrect information multiple times to lock the account. This is the perfect “knot” to start the scam scenario.

Mot truong hop dien hinh ve mot ngan hang tam khoa tai khoan trong 30 phut do nhap sai mat khau 5 lan (du dang tren mot thiet bi moi hoan toan). Anh: CyProtek
A bank account was temporarily locked for 30 minutes after entering the wrong password 5 times (even on a completely new device). Photo: CyProtek

Fake bank employee call

When an account is locked, the victim receives a call from someone claiming to be a bank employee. This person informs that the account has been locked due to suspected unusual activity. They quickly provide accurate information about the victim's account - from account number to recent transactions - to build trust.

The hacker then asks the victim to provide an OTP code to “verify and reopen the account” through a fake website in order to hijack the bank account. In a state of panic, most victims do not suspect anything and follow. But when the OTP code is sent, the hacker immediately makes money transfers or steals assets.

Hacker gia danh nhan vien ngan hang va goi dien truc tiep de tiep can nan nhan. Viec biet so dien thoai cua ban khong phai la tro ngai lon, boi thong tin ca nhan, bao gom so dien thoai, thuong duoc giao dich tran lan tren thi truong cho den. Chi can bo ra vai chuc nghin dong, hacker da co the mua duoc thong tin cua ban thong qua cac bot tren Telegram hoac cac hoi nhom chuyen mua ban du lieu ca nhan. Anh:
Hackers impersonate bank employees and call victims. Knowing your phone number is not a big obstacle, as personal information is often traded widely on the black market. Photo: CyProtek.

The hacker's well-organized system of operations

CyProtek’s analysis shows that the hackers in the GoldFactory campaign did not operate alone, but in a systematic manner. They would perform several steps:

Buying personal data: From black markets that trade data, including leaked data from large corporations.

Understand banking security procedures: Exploit loopholes in locked account handling mechanisms.

High-tech: Using tracking software and fake apps to optimize attacks.

Over the past two years, the hacker group has created more than 421 fake websites to spread malware and deceive victims. This network not only operates in Vietnam but also has links with cybercrime groups in Cambodia, Myanmar and China.

Identify and protect yourself from new tricks

The CyProtek investigation team of the project emphasized that users need to be aware of the following signs to protect themselves:

Never provide OTP code over the phone: Banks do not ask for this information in any form.

Beware of calls from unknown numbers: Check information through the bank's official switchboard before taking any action.

Check transaction history regularly: Detect suspicious transactions promptly.

The investigation team's journey has exposed an organized cybercrime network with sophisticated and large-scale tricks. These findings are not only a wake-up call for users, but also pose a challenge for banks to improve their security systems.

As hackers become more and more professional, users' vigilance and understanding will be the most important shield. "One minute of carelessness, a lifetime of paying the price" - always be careful when using online banking services.

Minh Ánh (Theo CyProtek)
TIN LIÊN QUAN

Security flaw discovered in iPhone's USB-C port

|

Security holes in iPhone's USB-C port can be exploited to install malware and steal user data.

HCMC is about to start construction of 3 bridges worth nearly VND5,000 billion to relieve traffic jams

|

HCMC - Nguyen Khoi Bridge, Rach Tom Bridge and Ong Nhieu Bridge with a total investment of nearly VND5,000 billion are expected to start construction in the second or third quarter of 2025.

World gold price lost momentum, fell to nearly 3,300 USD/ounce

|

World gold prices fell sharply last night, down to $3,304.9/ounce due to US employment data positively exceeding expectations and the Bank of England cutting interest rates.

The desolate scene at the traditional house worth more than 3.4 billion VND that just collapsed

|

Dak Nong - After a period of disuse, the Dak R'moan Traditional House, Gia Nghia City (Dak Nong) worth more than 3.4 billion VND has completely collapsed.

The 3 billion view song musician said that when he sold the song, no one bought it

|

Musician Nguyen Van Chung - owner of the song "Continuing the story of peace" - shared an interesting memory when he first entered the profession.

The Law on Health Insurance will be amended, moving towards free medical examination and treatment for people

|

The health sector is orienting to amend the Law on Health Insurance, to specify some contents towards free medical examination and treatment for people under the direction of General Secretary To Lam.

Ho Chi Minh City Party Secretary Nguyen Van Nen has a new task

|

HCMC - Secretary of the HCMC Party Committee Nguyen Van Nen is the head of the Steering Committee for the development of the HCMC urban railway network system.

Metro No. 1 in Ho Chi Minh City asks to postpone construction by another year despite commercial operation

|

HCMC - The HCMC Urban Railway Management Board (MAUR) proposed that the HCMC People's Committee adjust the completion time of Metro Line 1 project to the end of the fourth quarter of 2025.

Security flaw discovered in iPhone's USB-C port

TRÍ MINH (THEO phonearena) |

Security holes in iPhone's USB-C port can be exploited to install malware and steal user data.

Tìm bị hại trong vụ lừa đảo bất động sản tại Hải Dương

Công Hòa |

Hải Dương - Công an tỉnh Hải Dương vừa bắt giữ đối tượng lừa đảo chiếm đoạt tài sản và đăng thông tin tìm kiếm các bị hại liên quan.

Cựu nhân viên ngân hàng lừa đảo chiếm đoạt tài sản

BẢO TRUNG |

Đắk Lắk - Với thủ đoạn đưa ra thông tin gian dối là làm hồ sơ đáo hạn ngân hàng, Phạm Kiều Hưng đã vay tiền của nhiều người rồi lừa đảo chiếm đoạt tài sản.