Showing posts with label online. Show all posts
Showing posts with label online. Show all posts

Saturday, 25 July 2015

Are you using many credit cards?

A credit card is a loan with a difference. Here, you get credit while you go spending or paying bills. However, the interest rates on credit cards are much higher than that on other loans. The more credit cards you have, the more you may be tempted to spend and the more difficult it will become to keep a tab of how much you have spent and when the repayments are due. Do remember that credit cards are the most expensive types of loans available in the market, and whether you miss your payment deadlines due to an oversight or because you have inadequate funds, you will have to pay heavily.
Credit card cautions
If you plan wisely to use each card to its advantage, but also keep a check on the rising charges so that the debt remained under control. Maintain your credit score over a period of time so that you could remain in the good books of the credit card companies. This is exactly what multiple credit cards holders should do to disentangle yourself from debt. However, if you cannot religiously keep a track on your spending or monitor each card prudently, then multiple credit cards can become a hindrance rather than an aid to money management, so step with caution depending on the kind of spending habits you possess!
Impact on credit report
While credit cards are extremely handy pieces of plastic, ideally, banks in India haven’t set any obligations on the number of cards you can carry. In India, you can easily find customers using four credit cards and the ones that don’t even have a single card. Due to the fact, your CIBIL credit score could be strained due to irrational credit card usage. In actuality, you must keep the number of credit cards which you can afford. Avoid using more than one card if you don’t have a good monthly income source.
Real, Money, Expenses, Credit Cards
Monitor your credit limit religiously
Your lenders will see you as a high risk candidate if you have high amount of outstanding balance to be paid. In fact, credit cards are the easiest way to fall into a debt trap that is a situation in which you borrow just to maintain your existing borrowings. So, to be on the safer side, you need to keep your outstanding balance about 10% to 30% of the overall credit limit. By doing this, you’ll get some relief and will also able to borrow more funds, if the need arises.
Never close your old card
Your oldest credit card age will do a significant role when the banks decide to open a new account under your name. In such cases, you can earn more points for keeping a long-established relation with the bank. The credit history of your old card is always better; and for taking loans, you could use your old credit card. If you wish, you could keep another card also for several other references and shopping online. Don’t ever close down your good old credit cards, even if you’re not using them frequently because they will definitely work towards building your good credit history.
Opt for right Credit Card
The credit card market in India is overwhelmed with attractive offers and deals that are quite tempting for the customers. As per the needs, every sensible card user can acquire several credit cards frequently. If you’re a constant traveller, then you could go for a travel credit card. Petro cards and special cards for getting discounts on restaurant bills are also highly popular in India. Whoever looking forward to multiple card options can decide buying these credit cards for a suitable experience.
Ideally, cards should be used as a temporary substitute for carrying cash. And, if that is the only motive you have when you carry a credit card, you will find that having one or at most two is quite sufficient.

Source- Secondary

Thursday, 23 July 2015

Danger: Credit card fraud! Protect yourself.

Credit Card Fraud is a harsh reality of digital age. Though in India, Reserve Bank of India (RBI) has done a commendable job to avoid credit card fraud. Some of the path breaking steps taken by RBI are:
1. Two level authentication for online transactions. 1st level when you enter Credit Card details & CVV. 2nd level authentication is implementation of 3D Secure Code (Verified by VISA and Mastercard SecureCode)
2. Issuance of EMV Chip & PIN enabled Credit Cards
3. Option to select / set limit for International usage
4. Data Security standards for POS Terminals
5. SMS Alert to customer’s registered mobile no for every Credit Card transaction
6. OTP for IVR based transactions
Awesome, Isn’t it. In India, the probability of Credit Card fraud is negligible except due to negligence of user. An example of negligence is that user lost the wallet with Credit Card and in the wallet PIN of Credit Card was written on piece of paper.
Unfortunately, International scenario is not as secured as in India. Most of the credit card frauds are executed offshore i.e. Credit Card information is stolen in India and then the Credit Card is used outside India. Best part is for international transactions, you only need Credit Card No. and 3 digit CVV No. Unlike India, there is no multi layer security authentication/verification. Its quite easy to carry out credit card fraud outside India. RBI or any law enforcement agency does not have any jurisdiction outside India. Last year, person's credit card was used to make international transactions on dubious e-commerce website of African country. Now he has lost all the hopes to recover the amount. The double whammy for him was that he had to pay the amount else his CIBIL Score would have been impacted adversely. Moreover with stricter norms in India, no one can escape under the shield of Credit Card Fraud. The only point of consolation is that if the user prove his innocence by proving that credit card fraud happened due to bank or its employees ignorance/fault/collusion. In this case, Bank will compensate for the loss due to credit card fraud.
 11 most important tips which can help you to avoid Credit Card fraud

Mask CVV No

Immediately after receiving the Credit Card, Remember CVV No and Mask/Scratch the same. You can mask with Permanent marker and than apply whitener coating over it.

Never Store Credit Card information online

Storing Credit Card Information online is most dangerous practice. Its an open invitation to credit card fraud. Recently while booking movie ticket on BookMyShow, the merchant offered me to save the Credit Card Details for next transaction. These e-commerce sites claim highest data security standards but recently Ebay’s 145 mn accounts were compromised so its safe to conclude that “WEB is not a safe place”.
A word of caution: On some e-commerce sites, the option to save Credit Card information for future transactions is by default selected. If you overlooked than without your knowledge, the information will be captured by merchant. The user has to very careful while making online transactions.

Avoid International Transactions, Avoid Credit Card Fraud

It is advisable not to use your Credit Card abroad and even avoid using Credit Card on International E-Commerce websites. If you are 100% sure about the merchant’s credibility & reputation than you may consider. Offline transactions are also risky as Credit Card Skimming is very common at POS terminals in countries like Thailand, Indonesia, African Countries etc

Credit Card Transactions at Petrol Pump

According to recent study, Credit Card Transaction at Petrol Pump is most unsafe. It is one of the favorite location for credit card skimming thus credit card fraud. We tend to handover Credit Card to pump attendant and Credit Card is unattended for 10-15 mins. The probability of Credit Card Skimming is high at Petrol Pumps specially the petrol pumps on highways & remote locations. Crux is that Credit Card should not be unattended and all Credit Card transactions should be in front of you. Secondly, don’t use Credit Card at Petrol Pumps on Highways and Remote locations to avoid credit card fraud.

URL in Browser

Before making any online payment, Please check the URL in Web Browser. Normally the URL starts with “http” whereas secured URL’s  have extra “s” i.e. secured URL will start with “https”. In-fact Google Chrome will show “https” in Green color if the URL is secured and site name will also appear in green.

Reputed SSL Seals & Trust Seals

As a thumb rule, you should make all online transactions only on websites with reputed SSL/Trust seals
SSL Seals: Norton Security Seal, Thawte, Trustwave, COMODO & GeoTrust
Trust Seals:  McAfee Secure, TRUSTe & BBB Accredited.
SSL Seals are more reliable & secure as they suggest Technical Security of Payment whereas Trust Seals are only reputation certification. To avoid credit card fraud rely on SSL Seals.

Use of Credit Card on Public Computer

 Public computers are most vulnerable for Credit Card Fraud. Never ever use Credit Card in cyber cafe, friends place or even in office. Always trust your own Desktop / Laptop for online transactions. Use reputed Anti-Virus, Anti-Malware & Firewall to avoid any data theft.

Credit Card Photocopy as Id Proof / Authorization letter

A Credit Card with Photograph is also accepted as valid Id proof e.g. for bank account opening etc. In case, you booked air ticket for your friend or family member, an authorization letter with xerox of credit card is required. We tend to give xerox of both front and back side of credit card. Some unaware users don’t even hide CVV on back side thus vulnerable to credit card fraud.  Please note that it is not necessary to give xerox of back side of credit card. Only front side is sufficient.

Fraudulent Calls

To avoid credit card fraud never ever trust incoming calls. If you receive any such call than call back bank’s helpline to check the truth.

Credit Card payment through Mobile / Mobile Apps

These days you might have observed that lot many merchants are promoting online mobile apps like RedBus, Flipkart, BookMyShow etc. These apps allow you to make payment over mobile app through Credit Card. Personally, it is not suggested to make any credit card payment through Mobile applications to avoid credit card fraud. In a recent article published in Business Standard, a survey done by Japanese security firm Trend Micro revealed that  39 Payment Gateways, 15 Bank related mobile Apps and other Mobile apps, Shopping apps, Social Networking Apps and Health Care apps used by Indian users are vulnerable to credit card fraud.

Prevention is better than Cure

If the situation demands and you carried out any risky/vulnerable transaction than immediately cancel your Credit Card and apply for replacement of credit card. In short, if you foresee or anticipate any Credit Card fraud than apply for replacement of credit card.
Visit- www.cibilconsultants.com
Source: Secondary

Wednesday, 15 July 2015

Online banking frauds can come to an end by new software

Scientists have developed a new software to prevent malware from sending spam emails and instant messages while blocking unauthorised money transfers.

Researchers at Georgia Tech have created a prototype software, Gyrus, that takes extra steps to prevent malware from sending spam emails and instant messages, and blocking unauthorised commands such as money transfers.
Current protection programmes might recognise the original user's intent to send email, transfer money or engage in other transactions but cannot verify the specifics such as email contents or amount of money.
Without context, it is impossible to properly verify the user's full intent, regardless of whether the software is protecting a financial transfer, an industrial control system or a wide range of other user-driven applications.
Gyrus is a transparent layer on top of the window of an application. The user experience with the application will be exactly the same as when Gyrus is not installed or activated.
Of course, if Gyrus detects that user-intended data has tampered with, it will block the traffic and also notify the user.
The research is based on the observation that for most text-based applications, the user's intent will be displayed entirely on screen, as text, and the user will make modifications if what is on screen is not what he or she wants.
Users help Gyrus do its job by establishing pre-defined rules that help the software determine whether commands - authorised or not - fit with established user intentions.

The idea of defining correct behaviour of an application by capturing user intent is not entirely new, but previous attempts in this space use an overly simplistic model of the user's behaviour.
For example, they might infer a user's intent based on a single mouse click without capturing any associated context so the attackers can easily disguise attacks as a benign behaviour.

           Man holding tablet pc and credit card indoor, Shopping Online
Instead, Gyrus captures richer semantics including both user actions and text contents, along with applications semantics, to make the system send only user-intended network traffic. Gyrus indirectly but correctly determines user intent from the screen that is displayed to the user.
There are two key components to Gyrus' approach. First, it captures the user's intent and interactions with an application. Second, it verifies that the resulting output can be mapped back to the user's intention. As a result, the application ensures accurate transactions even in the presence of malware.

To learn about Identity theft, visit- www.cibilconsultants.com
Source: Secondary

Sunday, 12 July 2015

SIM card block? It could be online fraud!

Online banking cheating cases on the rise in city, warn experts


A 35-year-old software engineer working with an information technology (IT) company in Chinchwad got an SMS that her ICICI Bank debit card had been used to make purchases worth Rs93,000. She almost fainted because she had never made any such transaction. But her nightmare did not end there. A short while later she received another SMS saying her debit card had been used to make another purchases of Rs 5,000.

The cases of online banking and mobile transactions are on the rise in the city. The officers of the cyber crime cell (CCC) of Pune police claimed people are not aware about fraudsters and their tricks. As a result, the cases have increased in the city.

The CCC officers said that people do not have adequate knowledge of safety and security measures for online transactions. They said as many as 60 such cases are being registered at different police stations in the city.

Fraudsters are using the technique of blocking the SIM card of the victims’ cellphones to ensure they don’t get alerts from the bank. Senior police inspector Sarjerao Babar of CCC told dna, “The present modus operandi of the fraudsters is to block the SIM card with the help of the telecom company employees. Thereafter, they send an application to the telecom company for a new SIM card on the victim’s name. Once the fraudsters get the new SIM card, they get the bank alerts.”

On that basis, fraudsters submit fake know your customer (KYC) forms on the name of the victim and open new accounts in their name and make transactions. “Thereafter, the fraudsters immediately transfer money to their different accounts,” Babar said.

Analysing the causes for the rise in number of cyber crimes in Pune, Babar said, “As more people use the Internet and cellphones for banking, the number of people falling prey to cyber crimes is increasing. People carrying out bank transactions using the Internet are falling prey to economic offenders on the prowl.”

Deputy commissioner of police (cyber) Sanjay Shinde told dna, “People do not have adequate knowledge of safety and security measures to be taken while carrying out online transactions. We have been trying to spread awareness by giving safety tips in dos and dont’s format. However, many Internet users do not pay enough attention to our advice. In recent cases, we have observed that if the SIM card was blocked, the victims could have contacted the nearest telecom office and get a confirmation on it, but they did not. As a result, the fraud took place.”

                       
Shinde said they had asked bank authorities to create awareness among customers about the latest security measures. “But the banks are slowly proactive in security aspects related to mobile banking,” Shinde said.

Besides, a major chunk of cyber crimes pertain to credit /debit card frauds.

Banks authorities asked to step on it

Deputy commissioner of police (cyber) Sanjay Shinde claimed that they had asked bank authorities to create awareness among customers about the latest security measures and to be vigilant during submission of KYC forms to weed out fake accounts. “But the banks are slow in responding to security aspects related to mobile banking,” he said.

Online shopping tips:
  1.  Shop with merchants you know and trust
  2.  Check whether the shopping website is secure
  3.  Be cautious of unsolicited phone calls or emails from merchants
  4.  Read merchant’s refund and exchange policies before making any purchase
  5.  Do not share your password
  6.  Always print and keep the order confirmation documents
  7.  Read the privacy statement
  8.  Never enter your personal information on a pop-up screen.
Internet Banking tips:
  1.  Keep your passwords/PIN codes safe and memorize them
  2.  Check if the online banking website is secure
  3.  Log out immediately after you complete your online transaction
  4.  Do not copy or click on any links that are not from a known source
  5.  Do not respond to emails asking for personal or banking related information
  6.  Read privacy and policy statements to ensure that no unauthorized transaction has taken place
  7.  Check your account statements regularly

To learn about Identity Theft, visit- www.cibilconsultants.com
Source: Secondary

Thursday, 9 July 2015

Prevent Identity Theft- Follow the Tips by Experts

Identity Theft is one of the by-product of technological evolution. World was more secure when there was no internet, photocopier or scanner. Identity Theft can be disastrous for any individual. Recently one lady's Home Loan was rejected because of low CIBIL Score. She was advised to pull out CIBIL Report. When  checked, her CIBIL Report, found that Rs 200000 outstanding was written off against her credit card. She never applied for this credit card. The credit card was issued at her old Delhi address before she shifted to Mumbai. It was a clear case of Identity Theft. 
Worst part is that complete onus is on an individual to prove that he is victim of Identity Theft. 
Normally on internet, the discussion on Identity Theft revolve around Online Identity Theft i.e. through internet. Offline Identity Theft is more dangerous and easy to execute. Secondly, there is more organized mafia whose job is find potential victims for Identity Theft. Mostly observed that online Identity Theft is because of mistake from user end which could have been easily avoided but scope of offline Identity Theft is vast. In this post we will discuss tips and tricks to prevent offline identity theft.

1. Photocopy of Documents: It was quite interesting episode, of one of TV serial, lady A gave her documents for photocopy and told shopkeeper that she will collect in 2 hours. Somehow fraudster steal the copy of documents. Documents were misused by fraudster to get job in Lady A’s  name. Fraudster committed fraud in her company and poor Lady A was caught based on documents. Though police finally caught the real culprit but imagine the trauma undergone because of Identity Theft.
Photocopy shops are soft and easy target for identity theft. With advancement of technology, photocopy machine can retain scanned copy of documents. It is advisable to take photocopy at home through printer only. If it is absolutely necessary to photocopy from outside because of volume then you should get it done only from known shopkeeper. You can also keep extra copies at your home for emergency.
2. Handover Documents only to Bank Executive and Take Acknowledgement: During our day to day financial transactions, we have to handover some imp documents to bank like PAN, Address proof etc. A businessman handed over his originals to employee and send him to bank for any such work. Yes, it is not feasible for businessman to do everything on his own. At the same time it is suicidal to handover either original or photocopy to 3rd party. It is advisable to handover documents only to authorized bank executive and insist on acknowledgement. In relevant document, also mention the details of documents submitted by you with the bank.
3. Watermark: One of the critical step to safeguard your identity is to watermark all the scanned documents and then take photocopy. Only use watermark copy for any future use. Watermarked copies are very difficult to temper with. Watermarking can be done using software like pdf writer or image editor. Though its a tiring job but you have to do only once in a lifetime.
4. PAN: Obtaining a PAN is one of the simplest govt process in my opinion. Last year CBDT madeverification of originals mandatory for PAN to reduce PAN based frauds. Analysts termed it as “Step Back”, “Return of License Raj”, “Bottle Neck” or “Retro Grade” step. Being an election year and under pressure from govt, CBDT withdrew the circular. PAN is lifeline for doing any financial transaction and process is so lax that anyone can manipulate.
PAN is one of the most misused document for financial frauds and is heart & soul of identity theft. PAN should not be issued / re-issued without verification of originals even if it cause inconvenience to general public. People don’t realize that its for their benefit only.
5. Inquiry in CIBIL Report
PULL out your CIBIL report atleast once in 6 months or preferable once every quarter. One of the important section to look out is “Inquiry Information”. Please check any suspicious entry in the report e.g. if bank A has posted entry related to Enquiry for issuance of Credit Card with credit limit 1 lakh. In case,  you have not applied for any such credit card then immediately you should bring it to the notice of the bank. Prevention is always better than cure and checking “Inquiry Information” in CIBIL Report is one such prevention.

6. Social Media: An open invitation to Identity Theft, social media is one of the most dangerous place if not handled responsibly and with caution. Even Afghanistan, Iraq and Somalia will rank after Social Media. Social Media is emerging as a new crime hub both for financial and non-financial crimes.
“Too Little on Social Media can be Too Much”. It is advisable to draw a thick line between privacy and social interaction before you post anything through social media channels. Privacy should not be compromised at all and at any cost. Remember for a small mistake you have to pay heavy price.
7. Letter Box: In the age of internet and email, people don’t check their letter box for months. It is quite visible from overflowing letter boxes next to mine in my apartment complex. Its again an open invitation for Identity Theft. We receive bills and statements through snail mail and anyone can easily steal your identity using these document. It is advisable to check your letter box regularly to prevent identity theft.
8. Change of Mobile or SIM: Now a days most of the people change their mobile every 6 months. Also many of us have habit of storing important information on mobile like bank account no, PAN, Passwords, PIN etc. As mobile is personalized device therefore danger of Identity Theft through mobile is manifold. It is advisable that all the data from mobile should be deleted when you are changing it. Mobile should be restored to factory settings. Remove micro SD card and also remove all installed applications. Log out from all accounts sync with the device and most importantly remove SIM card (if you are opting for Nano SIM in new device).
9. Purpose of document: Whenever you are handing over photocopy of your documents, don’t forget to mention the purpose for which the documents is being handed over. For example, if you are submitting document for Ration Card then don’t forget to mention on Watermarked document “Purpose: Application for Ration Card” in either Red or Blue Pen. It will help to prevent identity theft. Secondly, if fraudsters realize that particular person has taken necessary steps to prevent identity theft then they don’t mess around. Only people caught unaware become victims of identity theft.
10. Date of Birth: Besides PAN, DOB is important piece of information for Identity Theft.  Birth Certificate was not mandatory earlier but now it is also one of the important document.
11. Beware of Freebies: Last but not the least and most crucial. Don’t share your DOB, mobile no, name etc through feedback forms in Restaurants or to participate in some lucky draw. You can politely say NO. There are no free lunches in this world but others should not have free lunch at your cost.

Learn more about identity theft at www.cibilconsultants.com
Source-secondary

Wednesday, 8 July 2015

Banks seeking insurance cover because of rising online frauds

MUMBAI: Indian banks are increasingly seeking insurance cover against fraudulent online transactions, including those involving credit cards, as a rising use of plastic money and the ease of Internet business potentially increase lenders' exposure to cases of data breach.
Data from insurance companies show that large banks are opting for policies worth Rs 500 crore to shield against fraud, including online, while mid-sized banks are going for policies in the range of Rs250-300 crore. "Demand for insurance policy against phishing, skimming and Internet hacking has gone up in the last one year," said TR Ramalingam, head of underwriting at Bajaj Allianz General Insurance. "Inquiries have gone up and we are working on how to price the product and working on the wording."
               

Earlier, insurance policies did not include computer-related frauds, but now insurers expect it to be big in coming days. The premium, which depends on several factors, ranges between 1% and 2% of liability the bank is looking to insure. In 2012-13, domestic banks lost Rs17,284 crore on account of fraud, according to information obtained through the Right to Information Act. During the period, 62 banks filed a total of 26,598 cases related to online frauds. The situation has compounded the woes of the bank sector where lenders are facing huge non-performing assets. "The policy covers cyber extortion and breach of data privacy," said M Ravichandran, president, Tata AIG General Insurance. "There is a lot of talk around cyber insurance and people are actively looking to secure these exposures."
While companies like Tata AIG have underwriting capabilities for these policies, for others, it is reinsurance driven. Cyber extortion policy pays a ransom to a person who has hacked into the bank's website with a threat to divulge, destroy or steal confidential information. Last year, ATM cards of a leading private sector bank's customers were skimmed and about Rs15.48 lakh stolen from accounts.

If your Credit Score have been hampered because of Identity Theft, contact us- www.cibilconsultants.com


Source: Secondary

Signs that shows You've Been Hacked

In today's threats cape, antivirus software provides little piece of mind. In fact, anti malware scanners on the whole are horrifically inaccurate, especially with exploits less than 24 hours old. After all, malicious hackers and malware can change their tactics at will. Swap a few bytes around, and a previously recognized malware program becomes unrecognizable. 

To combat this, many anti malware programs monitor program behaviors, often called heuristics, to catch previously unrecognized malware. Other programs use virtualized environments, system monitoring, network traffic detection, and all of the above at once in order to be more accurate. And still they fail us on a regular basis.
Here are 11 sure signs you've been hacked and what to do in the event of compromise. Note that in all cases, the No. 1 recommendation is to completely restore your system to a known good state before proceeding. In the early days, this meant formatting the computer and restoring all programs and data. Today, depending on your operating system, it might simply mean clicking on a Restore button. Either way, a compromised computer can never be fully trusted again. The recovery steps listed in each category below are the recommendations to follow if you don't want to do a full restore -- but again, a full restore is always a better option, risk-wise. 
Sure sign of system compromise No. 1: Fake antivirus messages 
In slight decline these days, fake antivirus warning messages are among the surest signs that your system has been compromised. What most people don't realize is that by the time they see the fake antivirus warning, the damage has been done. Clicking No or Cancel to stop the fake virus scan is too little, too late. The malicious software has already made use of unpatched software, often the Java Run time Environment or an Adobe product, to completely exploit your system. 


Why does the malicious program bother with the "antivirus warning"? This is because the fake scan, which always finds tons of "viruses," is a lure to buy their product. Clicking on the provided link sends you to a professional-looking website, complete with glowing letters of recommendation. There, they ask you for your credit card number and billing information. You'd be surprised how many people get tricked into providing personal financial information. The bad guys gain complete control of your system and get your credit card or banking information. For bad guys, it's the Holy Grail of hacking. 
What to do: As soon as you notice the fake antivirus warning message, power down your computer. If you need to save anything and can do it, do so. But the sooner you power off your computer, the better. Boot up the computer system in Safe Mode, No Networking, and try to uninstall the newly installed software (oftentimes it can be uninstalled like a regular program). Either way, follow up by trying to restore your system to a state previous to the exploitation. If successful, test the computer in regular mode and make sure that the fake antivirus warnings are gone. Then follow up with a complete antivirus scan. Oftentimes, the scanner will find other sneak remnants left behind. 
Sure sign of system compromise No. 2: Unwanted browser toolbar 
This is probably the second most common sign of exploitation: Your browser has multiple new toolbar with names that seem to indicate the toolbar is supposed to help you. Unless you recognize the toolbar as coming from a very well-known vendor, it's time to dump the bogus toolbar. What to do: Most browsers allow you to review installed and active toolbar. Remove any you didn't absolutely want to install. When in doubt, remove it. If the bogus toolbar isn't listed there or you can't easily remove it, see if your browser has an option to reset the browser back to its default settings. If this doesn't work, follow the instructions listed above for fake antivirus messages. You can usually avoid malicious toolbar by making sure that all your software is fully patched and by being on the lookout for free software that installs these tool bars. Hint: Read the licensing agreement. Toolbar installs are often pointed out in the licensing agreements that most people don't read. 
Sure sign of system compromise No. 3: Redirected Internet searches 
Many hackers make their living by redirecting your browser somewhere other than you want to go. The hacker gets paid by getting your clicks to appear on someone else's website, often those who don't know that the clicks to their site are from malicious redirection. You can often spot this type of malware by typing a few related, very common words (for example, "puppy" or "goldfish") into Internet search engines and checking to see whether the same websites appear in the results -- almost always with no actual relevance to your terms. Unfortunately, many of today's redirected Internet searches are well hidden from the user through use of additional proxies, so the bogus results are never returned to alert the user. In general, if you have bogus toolbar programs, you're also being redirected. Technical users who really want to confirm can sniff their own browser or network traffic. The traffic sent and returned will always be distinctly different on a compromised computer vs. an uncompromised computer. What to do: Follow the same instructions as above. Usually removing the bogus toolbar and programs is enough to get rid of malicious redirection. 
Sure sign of system compromise No. 4: Frequent random popups 
This popular sign that you've been hacked is also one of the more annoying ones. When you're getting random browser pop-ups from websites that don't normally generate them, your system has been compromised. I'm constantly amazed about which websites, legitimate and otherwise, can bypass your browser's anti-pop-up mechanisms. It's like battling email spam, but worse. What to do: Not to sound like a broken record, but typically random pop-ups are generated by one of the three previous malicious mechanisms noted above. You'll need to get rid of bogus toolbar and other programs if you even hope to get rid of the pop-ups. 

Sure sign of system compromise No. 5: Your friends receive fake emails from your email account 
This is the one scenario where you might be OK. It's fairly common for our email friends to receive malicious emails from us. A decade ago, when email attachment viruses were all the rage, it was very common for malware programs to survey your email address book and send malicious emails to everyone in it. 
These days it's more common for malicious emails to be sent to some of your friends, but not everyone in your email address book. If it's just a few friends and not everyone in your email list, then more than likely your computer hasn't been compromised (at least with an email address-hunting malware program). These days malware programs and hackers often pull email addresses and contact lists from social media sites, but doing so means obtaining a very incomplete list of your contacts' email addresses. Although not always the case, the bogus emails they send to your friends often don't have your email address as the sender. It may have your name, but not your correct email address. If this is the case, then usually your computer is safe. 
What to do: If one or more friends reports receiving bogus emails claiming to be from you, do your due diligence and run a complete antivirus scan on your computer, followed by looking for unwanted installed programs and toolbars. Often it's nothing to worry about, but it can't hurt to do a little health check when this happens. 
Sure sign of system compromise No. 6: Your online passwords suddenly change 
If one or more of your online passwords suddenly change, you've more than likely been hacked -- or at least that online service has been hacked. In this particular scenario, usually what has happened is that the victim responded to an authentic-looking phish email that purportedly claimed to be from the service that ends up with the changed password. The bad guy collects the logon information, logs on, changes the password (and other information to complicate recovery), and uses the service to steal money from the victim or the victim's acquaintances (while pretending to be the victim). What to do: If the scam is widespread and many acquaintances you know are being reached out to, immediately notify all your contacts about your compromised account. Do this to minimize the damage being done to others by your mistake. Second, contact the online service to report the compromised account. Most online services are used to this sort of maliciousness and can quickly get the account back under your control with a new password in a few minutes. Some services even have the whole process automated. A few services even have a "My friend's been hacked!" button that lets your friends start the process. This is helpful, because your friends often know your account has been compromised before you do. If the compromised logon information is used on other websites, immediately change those passwords. And be more careful next time. Websites rarely send emails asking you to provide your logon information. When in doubt, go to the website directly (don't use the links sent to you in email) and see if the same information is being requested when you log on using the legitimate method. You can also call the service via their phone line or email them to report the received phish email or to confirm its validity. Lastly, consider using online services that provide two-factor authentication. It makes your account much harder to steal. 
Sure sign of system compromise No. 7: Unexpected software installs 
Unwanted and unexpected software installs are a big sign that your computer system has likely been hacked. In the early days of malware, most programs were computer viruses, which work by modifying other legitimate programs. They did this to better hide themselves. For whatever reason, most malware programs these days are Trojans and worms, and they typically install themselves like legitimate programs. This may be because their creators are trying to walk a very thin line when the courts catch up to them. They can attempt to say something like, "But we are a legitimate software company." Oftentimes the unwanted software is legally installed by other programs, so read your license agreements. Frequently, I'll read license agreements that plainly state that they will be installing one or more other programs. Sometimes you can opt out of these other installed programs; other times you can't. What to do: There are many free programs that show you all your installed programs and let you selectively disable them. My favorite for Windows is Autoruns. It doesn't show you every program installed but will tell you the ones that automatically start themselves when your PC is restarted. Most malware programs can be found here. The hard part is determining what is and what isn't legitimate. When in doubt, disable the unrecognized program, reboot the PC, and reenable the program only if some needed functionality is no longer working. 
Sure sign of system compromise No. 8: Your mouse moves between programs and makes correct selections 
If your mouse pointer moves itself while making selections that work, you've definitely been hacked. Mouse pointers often move randomly, usually due to hardware problems. But if the movements involve making the correct choices to run particular programs, malicious humans are somewhere involved. Not as common as some of the other attacks, many hackers will break into a computer, wait for it to be idle for a long time (like after midnight), then try to steal your money. Hackers will break into bank accounts and transfer money, trade your stocks, and do all sorts of rogue actions, all designed to lighten your cash load. What to do: If your computer "comes alive" one night, take a minute before turning it off to determine what the intruders are interested in. Don't let them rob you, but it will be useful to see what things they are looking at and trying to compromise. If you have a cellphone handy, take a few pictures to document their tasks. When it makes sense, power off the computer. Unhook it from the network (or disable the wireless router) and call in the professionals. This is the one time that you're going to need expert help. Using another known good computer, immediately change all your other logon names and passwords. Check your bank account transaction histories, stock accounts, and so on. Consider paying for a credit-monitoring service. If you've been a victim of this attack, you have to take it seriously. Complete restore of the computer is the only option you should choose for recovery. But if you've lost any money, make sure to let the forensics team make a copy first. If you've suffered a loss, call law enforcement and file a case. You'll need this information to best recover your real money losses, if any. 

Sure sign of system compromise No. 9: Your antimalware software, Task Manager, or Registry Editor is disabled and can't be restarted 
This is a huge sign of malicious compromise. If you notice that your antimalware software is disabled and you didn't do it, you're probably exploited -- especially if you try to start Task Manager or Registry Editor and they won't start, start and disappear, or start in a reduced state. This is very common for malware to do. What to do: You should really perform a complete restore because there is no telling what has happened. But if you want to try something less drastic first, research the many methods on how to restore the lost functionality (any Internet search engine will return lots of results), then restart your computer in Safe Mode and start the hard work. I say "hard work" because usually it isn't easy or quick. Often, I have to try a handful of different methods to find one that works. Precede restoring your software by getting rid of the malware program, using the methods listed above. Sure 
Sign of system compromise No. 10: Your bank account is missing money 
I mean lots of money. Online bad guys don't usually steal a little money. They like to transfer everything or nearly everything, often to a foreign exchange or bank. Usually it begins by your computer being compromised or from you responding to a fake phish from your bank. In any case, the bad guys log on to your bank, change your contact information, and transfer large sums of money to themselves. What to do: In most cases you are in luck because most financial institutions will replace the stolen funds (especially if they can stop the transaction before the damage is truly done). However, there have been many cases where the courts have ruled it was the customer's responsibility to not be hacked, and it's up to the financial institution to decide whether they will make restitution to you. If you're trying to prevent this from happening in the first place, turn on transaction alerts that send text alerts to you when something unusual is happening. Many financial institutions allow you to set thresholds on transaction amounts, and if the threshold is exceeded or it goes to a foreign country, you'll be warned. Unfortunately, many times the bad guys reset the alerts or your contact information before they steal your money. So make sure your financial institution sends you alerts anytime your contact information or alerting choices are changed. 
Sure sign of system compromise No. 11: You get calls from stores about nonpayment of shipped goods 
In this case, hackers have compromised one of your accounts, made a purchase, and had it shipped to someplace other than your house. Oftentimes, the bad guys will order tons of merchandise at the same time, making each business entity think you have enough funds at the beginning, but as each transaction finally pushes through you end up with insufficient funds. What to do: This is a bad one. First try to think of how your account was compromised. If it was one of the methods above, follow those recommendations. Either way, change all your logon names and passwords (not just the one related to the single compromised account), call law enforcement, get a case going, and start monitoring your credit. You'll probably spend months trying to clear up all the bogus transactions committed in your name, but you should be able to undo most, if not all, of the damage. Years ago you could be left with a negative credit history that would impact your life for a decade. 
These days, companies and the credit reporting agencies are more used to cyber crime, and they deal with it better. Still, be aggressive and make sure you follow every bit of advice given to you by law enforcement, the creditors, and the credit-rating agencies (there are three major ones- CIBIL, Equifax, Experian). 
Malware vector trifecta to avoid:
The hope of an antimalware program that can perfectly detect malware and malicious hacking is pure folly. Keep an eye out for the common signs and symptoms of your computer being hacked as outlined above. And if you are risk-adverse, as I am, always perform a complete computer restore with the event of a breach. Because once your computer has been compromised, the bad guys can do anything and hide anywhere. It's best to just start from scratch. Most malicious hacking originates from one of three vectors: unpatched software, running Trojan horse programs, and responding to fake phishing emails. Do better at preventing these three things, and you'll be less likely to have to rely on your anti malware software's accuracy -- and luck.

If your Credit Score have been hampered because of Identity Theft, contact us- www.cibilconsultants.com

Source: Secondary

Sunday, 5 July 2015

Catching a Credit Con

When did you last update your e-mail address and phone number with your credit card issuer? Many do not even bother. Now, imagine being billed for fraudulent purchases made from your card.

What do you do? First, of course, you inform the card issuer, who will probably ask you to fill a declaration form. Doing this quickly is important as, according to rules, if the issuer isn't informed within 30 days of you receiving the statement, it is assumed that you have accepted it as accurate. So, if you were out of station and didn't notice it on time, you would be legally bound to pay.

Of course, if you had updated your contacts with the card issuer and got an alert, which comes within minutes of the transaction, you could have called up the issuer immediately and saved yourself the loss.



"Important communication, these days, happens through mails and phones. So, it is crucial that the customer keeps his bank updated so that he can be reached any time for checking a transaction's authenticity." 



COMMON CATCHES
In India, according to a provision in credit card contracts, the card-issuing company isn't liable for any fraudulent transaction unless the customer files a report immediately. Once reported, the card holder is no longer liable. So, be alert and look out for the red flags. Card frauds range from purchases made on lost or stolen cards to phishing, identity theft and traps set up through unsecured Internet transactions.

Skimming or cloning is something to be cautious about, especially when travelling abroad. In this, data in your card's magnetic stripe is recorded when swiped at a machine. This information is then used to make duplicates. It can happen anywhere, at a petrol pump or a restaurant. So make sure the card is swiped in your presence.

"To minimise risk, banks also advice customers to replace cards after trips."

Do you use your card online? Beware of cyber swindles. These involve unauthorised use of card details, such as the card number, the Card Verification Value (three-digit code printed on the back side of the card), to make purchases online.

"One should register for online transaction passwords such as Verified by Visa or MasterCard Secure Code and avoid using public computers. Also, make sure that the transaction happens through a secure website, which begins with HTTP."

Fraudsters also try account takeovers and identity theft. This happens in two ways. One, a cardholders information is stolen and used for transactions where the card's physical presence isn't required, such as online purchases. Two, by placing a request for a new card using the stolen information. Monitoring your credit card report is your best defense.

"Check for unusual transactions, especially small ones, as fraudsters make these to check the card's validity."

Last but not the least, do not fall prey to phishing mails (that appear to be sent by an institution you deal with but are not), SMSes or calls.

FRAUD CONTROL
Usually, banks have dedicated transaction monitoring units and fraud detection systems to analyse suspicious patterns. So, if two transactions are made from different countries with the same card within a short period, the system will highlight this. However, it helps if the customer is also cautious. For instance, opting for cards with signature lamination and a photograph, registering for transaction alerts and transacting only through secured websites are common precautions.

If you are a frequent user, it may make sense to go for an insurance cover to take care of liabilities from loss and misuse. Banks usually have tie-ups with insurers. General insurers also offer standalone credit card policies, which cover all cards held by a customer under one policy. One alert to the insurance company can block all your cards, limiting your loss.

FOR YOUR GRIEVANCES
The RBI has appointed an ombudsman for redressal of complaints which your bank has failed to respond to satisfactorily. A bank must respond within 30 days from the date you lodged the complaint. In case of wrongful billing, the card company should provide documentary evidence within 60 days. If unsatisfied, the cardholder can go to the ombudsman.


Learn more about identity theft at www.cibilconsultants.com

Source- Secondary

Saturday, 27 June 2015

Be Smarter Than Technology, If Want to Defeat Cyber Crime

Information Technology(IT) is the driving force of almost all industry. Global markets and business are dependent on this huge and vast world of unseen intelligent radio waves which is practically running our lives today.
Think about those times when there was hardly anything called the internet, networking, mobile, Wi-Fi, GPS, GPRS, Cloud etc a whole new world around us so called virtual real world, in a nutshell IT has given a all new meaning to this global civilization.
Today no more distances matters neither time, with the ever growing technology the focus is getting sharper and clearer, we are one world, every one of us is under one roof, we are connected now.
Discovery of any new earth shattering innovations brings certain disturbances too. We the intelligent minds who thrive and drive our lives today primarily on technology are we safe enough? Do we really always thank this unseen intelligent friend or sometimes this friend gives us real problems?

Yes it does, with the ever increasing tools of communication we get more and more vulnerable to access, today saying hi to someone at north pole is as simple as knocking your next door neighbor. World today is enjoying the advancement of IT but along with that is also facing a battle against piracy and duplicity or rather cyber crime.
Countries across the world are setting up cyber laws to check crime but how effective are these laws are? Or is the thief smarter than the law?
We need to realize and counter this new wave of crime through the unseen radio waves, with the ever growing technology we are doomed to face new challenges but to balance a smart technology you have to be smarter.
Crime Files brings to light the growing online lottery frauds which is getting visible day by day with increase in cases registered. On a normal mail box you will find thousand of offers including strange messages. 
This same format is also used via mobile SMSs Such messages might not work or may not be able to fool people at large but, yes still there are people from small town who get trapped in this net or racket of cheaters and land up paying money in the name of huge gift.
To learn about identity theft, visit www.cibilconsultants.com

Source: Secondary