S/N

E-Products

Mode of operations

Likely E-fraud

1

Internet Banking

Financial services are delivered to consumers through the Internet (World Wide Web). Consumers transact their banking services (Payment to third parties for goods and services, confirmation of account balance etc.) through laptops, desktops and mobile devices connected to the internet. The banks provide login details (username, initial password) and physical tokens for transactions’ authentications to the consumers.

Phishing through scam email to harvest login details and subsequent bypass of system security through expert and superior knowledge of cybersecurity infrastructure.

Wrong account mapping with the intent to commit e-fraud by financial institution employees.

2

Mobile Banking Services (USSD)

These are banking services delivered to customers of DMBs through mobile phone technology. It requires the use of a registered telephone line of the banks’ customers at the account opening stage. The GSM line will receive banking transaction alerts and Unstructured Supplementary Service Data (USSD) platform could be used to transfer fund, pay bills, check account balance and request for account statement.

SIM swaps either through theft or in collusion with Telcom agents which will allow the e-fraudster to take over the account from the real owner.

3.

Telephone Banking Services

Banking services are rendered to customers through pre-programmed telephone voice communication. The customers must supply Personal Identification Number (PIN) for authentication. It is mainly used for mainly inquiry on account details.

Theft of Personal Identification Number (PIN) could allow e-fraud perpetrator to gain access to account sensitive details.

4

Electronic (Smart) Card services

These are electronic purses that are preloaded by DMB’s customers for making payment and settlement of bills. The card could be used on Automated Machine and Point-of-Sales (POS).

Pharming or Malware to harvest the security features of the card could be launched by e-fraud perpetrators against the victims.

5

Debit/Credit Cards

While debit cards are linked to the account of the customers in DBM, credit cards are linked to the credit account on availment of credit facilities to customers of DMB. They are secured with chip and PIN and could be used on ATM, POS and WEB to carry out banking services.

Pharming and Skimming attacks.

Theft of cards and PIN by the insider e-fraud perpetrators.

Unsuspecting victims of e-frauds could also be called over the phone for his security details of the cards by e-fraudsters.

6

Web Purchases Services

This is e-payment systems that allow DMB customers to pay for goods and services online through the internet without the use of the physical cards on the websites of the Merchants (Airline operators, supermarkets, Telco operators, Government agencies, Schools etc.). It requires the knowledge of the card numbers, PIN and CVV at the back of the e-cards.

Phishing, Malware, etc. There could also be Theft of cards and PIN by the insider e-fraud perpetrators.

Similarly, unsuspecting victims of e-frauds could also be called over the phone for his security details of the cards by e-fraudsters.