ADVERTISEMENT

Stop sharing, stop phishing

Published Feb 1, 2019 12:00 am
OTP BPI reminds clients to do their part: Don’t answer phishing emails and never share OTPs One early morning in December last year, Kean, an employee in a business process outsourcing (BPO) company, was awakened by an anonymous call on his smartphone. Still feeling disoriented from the previous night's drinking session with his peers combined with sleepiness, Kean grudgingly answered the phone call, guessing that the caller was from a credit card company. Eventually, he realized that it was a call from his bank. After the conversation, he went back to sleep, confidently believing that the call was simply one of those routine calls that he typically receives from banks and credit card companies. But that was just the beginning of a nightmare. From that point, Kean noticed a huge online purchase under his bank account that he never initiated or authorized. Kean's experience was just one of the many cases of fraud that might be involving confidential information such as the One-Time PIN (OTP) in order to get access to the victim's bank account. Primarily designed as an additional security feature when doing an online transaction, BPI's OTP helps in authenticating one's identity in every financial transaction through a unique 6-digit passcode which will be sent to the account holder’s registered mobile number via SMS. An OTP is valid for a single online transaction and will expire five minutes from the time it was sent. Unfortunately, fraudsters these days are keen on using time-tested methods and finding new ways to exploit it for their own advantage. Now considered as a traditional cybercrime tool, fraudsters still employ phishing as an effective way to gather customer information through email. Fraudsters usually make phishing emails appear as legitimate ones coming from the customer's bank, asking them to provide information for ‘verification purposes.’ Once the perpetrator gets the client’s confidential information (such as account number, password, mobile number, etc.) via a phishing email, the fraud act moves on to the second phase called vishing (voice phishing), wherein further gathering of customer information is done through a phone conversation. The fraudster, pretending to be a bank agent, calls the target customer. To cause worry and a sense of urgency, the caller may cite any of the following reasons to the customer:
  • To update information needed for a new mobile application
  • To deactivate compromised online access
  • To update account to credit incoming deposit, transfer or remittance
  • To cancel unauthorized transaction made using the account
To further make the call appear legitimate, the caller verifies the customer's account based on the phished information, then proceeds with initiating a financial transaction. The caller asks the customer to provide the OTP for additional verification. The customer then discloses the OTP and the caller uses it to complete the fraudulent transaction. Looking back and assessing the workflow of the fraudsters, the chance for customers to stop the cybercriminals from succeeding remains high. By being aware and vigilant, customers can hinder the fraudsters from advancing to the next level of their activity by not responding to the phishing email. Customers receiving emails from a bank should be cautious before providing information. It would be better for customers to call the bank first to confirm the email's validity. For BPI customers, they can call BPI Phone Banking via 89-100 to check the legitimacy of the email. By eliminating phishing, customers can stop vishing and avoid becoming a victim of a potential fraudulent activity. And last but not the least, remember that OTP is a personalized and confidential information. BPI will never ask its customers to send any confidential information such as the OTP via email, phone, text message or social media.
ADVERTISEMENT
.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1561_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1562_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1563_widget.title }}

{{ articles_filter_1564_widget.title }}

.mb-article-details { position: relative; } .mb-article-details .article-body-preview, .mb-article-details .article-body-summary{ font-size: 17px; line-height: 30px; font-family: "Libre Caslon Text", serif; color: #000; } .mb-article-details .article-body-preview iframe , .mb-article-details .article-body-summary iframe{ width: 100%; margin: auto; } .read-more-background { background: linear-gradient(180deg, color(display-p3 1.000 1.000 1.000 / 0) 13.75%, color(display-p3 1.000 1.000 1.000 / 0.8) 30.79%, color(display-p3 1.000 1.000 1.000) 72.5%); position: absolute; height: 200px; width: 100%; bottom: 0; display: flex; justify-content: center; align-items: center; padding: 0; } .read-more-background a{ color: #000; } .read-more-btn { padding: 17px 45px; font-family: Inter; font-weight: 700; font-size: 18px; line-height: 16px; text-align: center; vertical-align: middle; border: 1px solid black; background-color: white; } .hidden { display: none; }
function initializeAllSwipers() { // Get all hidden inputs with cms_article_id document.querySelectorAll('[id^="cms_article_id_"]').forEach(function (input) { const cmsArticleId = input.value; const articleSelector = '#article-' + cmsArticleId + ' .body_images'; const swiperElement = document.querySelector(articleSelector); if (swiperElement && !swiperElement.classList.contains('swiper-initialized')) { new Swiper(articleSelector, { loop: true, pagination: false, navigation: { nextEl: '#article-' + cmsArticleId + ' .swiper-button-next', prevEl: '#article-' + cmsArticleId + ' .swiper-button-prev', }, }); } }); } setTimeout(initializeAllSwipers, 3000); const intersectionObserver = new IntersectionObserver( (entries) => { entries.forEach((entry) => { if (entry.isIntersecting) { const newUrl = entry.target.getAttribute("data-url"); if (newUrl) { history.pushState(null, null, newUrl); let article = entry.target; // Extract metadata const author = article.querySelector('.author-section').textContent.replace('By', '').trim(); const section = article.querySelector('.section-info ').textContent.replace(' ', ' '); const title = article.querySelector('.article-title h1').textContent; // Parse URL for Chartbeat path format const parsedUrl = new URL(newUrl, window.location.origin); const cleanUrl = parsedUrl.host + parsedUrl.pathname; // Update Chartbeat configuration if (typeof window._sf_async_config !== 'undefined') { window._sf_async_config.path = cleanUrl; window._sf_async_config.sections = section; window._sf_async_config.authors = author; } // Track virtual page view with Chartbeat if (typeof pSUPERFLY !== 'undefined' && typeof pSUPERFLY.virtualPage === 'function') { try { pSUPERFLY.virtualPage({ path: cleanUrl, title: title, sections: section, authors: author }); } catch (error) { console.error('ping error', error); } } // Optional: Update document title if (title && title !== document.title) { document.title = title; } } } }); }, { threshold: 0.1 } ); function showArticleBody(button) { const article = button.closest("article"); const summary = article.querySelector(".article-body-summary"); const body = article.querySelector(".article-body-preview"); const readMoreSection = article.querySelector(".read-more-background"); // Hide summary and read-more section summary.style.display = "none"; readMoreSection.style.display = "none"; // Show the full article body body.classList.remove("hidden"); } document.addEventListener("DOMContentLoaded", () => { let loadCount = 0; // Track how many times articles are loaded const offset = [1, 2, 3, 4, 5, 6, 7, 8, 9, 10]; // Offset values const currentUrl = window.location.pathname.substring(1); let isLoading = false; // Prevent multiple calls if (!currentUrl) { console.log("Current URL is invalid."); return; } const sentinel = document.getElementById("load-more-sentinel"); if (!sentinel) { console.log("Sentinel element not found."); return; } function isSentinelVisible() { const rect = sentinel.getBoundingClientRect(); return ( rect.top < window.innerHeight && rect.bottom >= 0 ); } function onScroll() { if (isLoading) return; if (isSentinelVisible()) { if (loadCount >= offset.length) { console.log("Maximum load attempts reached."); window.removeEventListener("scroll", onScroll); return; } isLoading = true; const currentOffset = offset[loadCount]; window.loadMoreItems().then(() => { let article = document.querySelector('#widget_1690 > div:nth-last-of-type(2) article'); intersectionObserver.observe(article) loadCount++; }).catch(error => { console.error("Error loading more items:", error); }).finally(() => { isLoading = false; }); } } window.addEventListener("scroll", onScroll); });

Sign up by email to receive news.