Hacked! Mumbai man loses Rs 84,000 in 9 swipes in 5 nations


Write Comment     |     E-Mail To a Friend     |     Facebook     |     Twitter     |     Print
Mid-day

Mumbai, 09 Jun 2017: Bikash Kumar is a thrifty man; he used his credit card all of two times, and solely to pay his electricity bills. So imagine his shock when he realised that someone else had used his card, not once, but nine times and that too in five different countries and currencies - all in a single minute.

 

On Wednesday, Kumar was having a peaceful night until he received a message with a One-Time Password (OTP) for a transaction on his SBI credit card. "It was around midnight when I got the OTP. I was curious, as I hadn’t made any transaction," he recalled.

 

"When I checked my email, I found that nine transactions had been made at various international websites in various currencies," said Kumar, who lost R84,000 in a single minute.

 

Credit card fraud has been around for ages now, but this is a rare case where so many transactions were done across five different countries at the same time. The money was siphoned off in nine transactions in five currencies — Pounds, US Dollars, Rupees, Mexican pesos and the Euro. What’s stranger is that even though Kumar received the OTP message at midnight, the transactions all took place earlier, at 9.39 pm.

 

"It is a very rare case where so many transactions have been made in different locations at the same time. It’s possible several hackers planned simultaneous transactions to avoid getting caught," said cyber law expert Prashant Mali.

 

Kumar said he used his credit card twice to pay electricity bills, and had never shared his OTP with anyone. "I am an educated man and know very well that OTP is not to be shared with anyone. My card’s limit is R85,000, so after the ninth transaction, the bank automatically blocked my card," he said. "I have two children and I am the only breadwinner of the family. This is a huge amount for me and I can’t repay it to the bank," said the marketing manager, who has now given a written complaint to the MIDC police station and will also approach the Bandra Cyber Cell.

 

The transactions included video game purchases, automobile parts and travel – indications that the culprits are likely a group of young hackers, perhaps even college students. "Considering the pattern of transactions, it can be a group of young hackers. Most hackers are aged between 15 and 30 years," said the expert, Mali.

 

While it seems like they were working in concert, they may not all be part of one group. Instead, one of the hackers likely ’bartered’ the credit card details with the rest. "These young hackers follow a barter system, wherein they sell the information to others. For example, if a card’s limit is R1lakh, they sell the information for Rs 50,000," added Mali.

 

As per cyber experts, it is easier to misuse cards on international websites. Unlike Indian websites, these sites don’t require OTP or CVC for transactions. The hackers need to acquire only the card numbers and expiry date. "As per the RBI rules, for transactions on any website based in India, OTP is compulsory, as it is essential while tracking the source of leakage," Vicky Shah, cyber lawyer.

 

However, the first transaction was made in Indian rupees without an OTP. "If the victim didn’t share his OTP, there are chances that the website’s server is based out of India. That’s why they could siphon the money," explained Shah, adding, "Banks need to be more alert and notify customers, especially in cases of multiple international transactions."

 

Prashant Mali, cyber law expert’It is a very rare case where so many transactions have been made in different locations at the same time. It’s possible that several hackers planned simultaneous transactions to avoid getting caught’

 

"It is unheard of, for so many transactions to be made in so many countries at a single time. It needs timely coordination between the hackers. We will look into the new modus operandi," said a senior IAS officer.

 

Write Comment     |     E-Mail To a Friend     |     Facebook     |     Twitter     |     Print
Comments on this Article
Armando, urwa Sun, June-11-2017, 10:39

Dear Prashant Mali, OTP is requirement of whom, Credit card provider (SBI credit card here or fraud websites mercharnt websites. I dont know why you are called expert. Money will be taken from SBI credit card so they so send OTP their software should have all sequrity checks, is it not their responsibilities. Tell all veiwers here who is resposible for OTP

Write your Comments on this Article
Your Name
Native Place / Place of Residence
Your E-mail
Your Comment   You have characters left.
Security Validation
Enter the characters in the image above
    
Disclaimer: Kindly do not post any abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful material or SPAM. BelleVision.com reserves the right to block/ remove without notice any content received from users.
GTI MarigoldGTI Marigold
Anil Studio
Badminton Sports AcademyBadminton Sports Academy

Now open at Al Qusais

Veez Konkani IllustratedVEEZ Konkani

Weekly e-Magazine

New State Bank of India, Customer Service Point
Cool House ConstructionCool House Construction
Uzvaad FortnightlyUzvaad Fortnightly

Call : 91 9482810148

Your ad Here
Power Care
Ryan Intl Mangaluru
Ryan International
pearl printing
https://samuelsequeira.substack.com/publish
Omintec
Kittall.ComKittall.Com

Konkani Literature World

Konkanipoetry.com
Bluechem