Xossip

Go Back Xossip > ChitChat> Life, Lifestyle, Personal Advice & Tips > How is Debit Card fraud done without OTP

Life, Lifestyle, Personal Advice & Tips Post your questions and problems on any subject. Fellow members will try to help you.

Reply Free Video Chat with Indian Girls
 
Thread Tools Search this Thread
  #1  
Old 2 Weeks Ago
tobermory's Avatar
tobermory tobermory is offline
 
Join Date: 2nd May 2014
Posts: 836
Rep Power: 9 Points: 1234
tobermory is a pillar of our communitytobermory is a pillar of our communitytobermory is a pillar of our communitytobermory is a pillar of our communitytobermory is a pillar of our communitytobermory is a pillar of our community
How is Debit Card fraud done without OTP

Hi. A relative recently got defrauded on his SBI debit card (I'll just narrate it in first person for ease). Now, whatever he did was imbecile and I know all of that, so I'm not looking for tips on card safety here. What I'm really curious is how was it done?

I got a call from someone purporting as calling from my bank. On his asking, I gave him my sixteen digit debit card number and also CVV number. About 10-15 minutes later, I got an SMS of Ola Money purchase worth Rs.9,999. I had received OTP SMS from the bank, but had not disclosed it to the fraudster. So how did he manage to use my card number and CVV number to make a transaction inside of 10-15 minutes of knowing it without OTP or my PIN.

I heard a similar incident before, where a friend was defrauded through an online purchase at iTunes on his CC though he had not disclosed any OTP to anyone.

How do they do it? Fake cards? Some way to bypass OTP?
______________________________
Jack n' Jill went up the Hill
God knows what went up there
Jill came down screaming i-pill i-pill

Reply With Quote
  #2  
Old 2 Weeks Ago
VJ2009's Avatar
VJ2009 VJ2009 is offline
Custom title
Visit my website
 
Join Date: 15th October 2009
Location: on beach
Posts: 5,966
Rep Power: 28 Points: 6151
VJ2009 has celebrities hunting for his/her autographVJ2009 has celebrities hunting for his/her autographVJ2009 has celebrities hunting for his/her autograph
UL: 265.06 mb DL: 0.99 gb Ratio: 0.26
Some cards, still allow USD transactions without OTP, may be of that case. But OLA money is strange.
______________________________
My New Thread on HQ pics of Sania
Sania Mirzas pierced navel

My fav thread
Marathi actress navel show

Reply With Quote
  #3  
Old 2 Weeks Ago
tobermory's Avatar
tobermory tobermory is offline
 
Join Date: 2nd May 2014
Posts: 836
Rep Power: 9 Points: 1234
tobermory is a pillar of our communitytobermory is a pillar of our communitytobermory is a pillar of our communitytobermory is a pillar of our communitytobermory is a pillar of our communitytobermory is a pillar of our community
Quote:
Originally Posted by VJ2009 View Post
Some cards, still allow USD transactions without OTP, may be of that case.
Does it mean a card like, say HDFC or Citibank is safer than State Bank of India?

Quote:
Originally Posted by VJ2009 View Post
But OLA money is strange.
Any particular reason about OLA money? The Bank Statement reads Ola Money - Zipcash, to be precise.
______________________________
Jack n' Jill went up the Hill
God knows what went up there
Jill came down screaming i-pill i-pill

Last edited by tobermory : 2 Weeks Ago at 02:48 PM.

Reply With Quote
  #4  
Old 2 Weeks Ago
Amitwithhotwife.83 Amitwithhotwife.83 is offline
 
Join Date: 19th March 2017
Posts: 433
Rep Power: 1 Points: 430
Amitwithhotwife.83 has many secret admirersAmitwithhotwife.83 has many secret admirers
If they called you, they had your mobile number. A sim card can be copied if a person has access to the tools and these guys do!

Then they need ur debit card number and cvv number which u gave them. When u received the OTP, tgey too recieved the OTP on the copy sim at that moment. That's all to it!


Now why OLA money?

They can sell ola money at 30% off for cash. Untraceable and clean method.

Sorry for ur 9999 loss!


And yes, government banks have least and poorest security on their cards as they are verrrrrrrry sloooooooow to upgrade their systems as needed.

Last edited by Amitwithhotwife.83 : 2 Weeks Ago at 08:18 PM.

Reply With Quote
  #5  
Old 2 Weeks Ago
swon's Avatar
swon swon is offline
aka platform
 
Join Date: 13th August 2010
Location: platform
Posts: 6,792
Rep Power: 27 Points: 6589
swon has celebrities hunting for his/her autographswon has celebrities hunting for his/her autographswon has celebrities hunting for his/her autographswon has celebrities hunting for his/her autographswon has celebrities hunting for his/her autograph
UL: 308.22 mb DL: 33.28 mb Ratio: 9.26
international transaction supported cards usually don't require otp password. if that's the case then mere card no and other details like ccv and expiry is only required to initiate transaction. so its very important you not even show such cards to anyone as those numbers can be easily memorized from just glancing. its always risky yo do offline transactions with such cards as money can be withdrawn from anywhere from the world. for offline purchases always stick with india only supported cards like what provided by sbi and others. these card require otp password for every online transaction so even if number is leaked they can't initiate online transaction without otp.

Reply With Quote
  #6  
Old 2 Weeks Ago
coconutpalm's Avatar
coconutpalm coconutpalm is offline
www.FilesFlash.net
 
Join Date: 10th April 2006
Location: Aruba
Posts: 24,870
Rep Power: 56 Points: 11372
coconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universe
UL: 84.11 gb DL: 40.21 gb Ratio: 2.09
If a debit card doesn't require OTP for online transactions, why would the bank send an OTP? It makes no sense.
______________________________

Reply With Quote
  #7  
Old 2 Weeks Ago
coconutpalm's Avatar
coconutpalm coconutpalm is offline
www.FilesFlash.net
 
Join Date: 10th April 2006
Location: Aruba
Posts: 24,870
Rep Power: 56 Points: 11372
coconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universe
UL: 84.11 gb DL: 40.21 gb Ratio: 2.09
Quote:
Originally Posted by Amitwithhotwife.83 View Post
If they called you, they had your mobile number. A sim card can be copied if a person has access to the tools and these guys do!

Then they need ur debit card number and cvv number which u gave them. When u received the OTP, tgey too recieved the OTP on the copy sim at that moment. That's all to it!


Now why OLA money?

They can sell ola money at 30% off for cash. Untraceable and clean method.

Sorry for ur 9999 loss!


And yes, government banks have least and poorest security on their cards as they are verrrrrrrry sloooooooow to upgrade their systems as needed.
Amit ji, maybe if they have the right tools, they can clone the SIM card, but that would require physical access to the SIM card, noh?

How likely is it that a SIM card has been cloned remotely? Maybe even that is possible if the right app/malware is installed on the phone? I don't know.

But we're talking of pretty far-fetched scenarios.
______________________________

Reply With Quote
  #8  
Old 2 Weeks Ago
coconutpalm's Avatar
coconutpalm coconutpalm is offline
www.FilesFlash.net
 
Join Date: 10th April 2006
Location: Aruba
Posts: 24,870
Rep Power: 56 Points: 11372
coconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universe
UL: 84.11 gb DL: 40.21 gb Ratio: 2.09
Here's a more tried-and-tested approach, one that requires physical manipulation of the ATM environment.

Quote:
BENGALURU: In less than a week, 200 Bengalureans have lost more than Rs 10 lakh due to illegal withdrawals from ATMs. Police suspect that gangs have placed advanced card skimmers, which can read debit and credit card data during usage, with pinhole cameras in ATMs across the city to copy card data and capture PINs.

...

http://timesofindia.indiatimes.com/c...w/59449643.cms
______________________________

Reply With Quote
  #9  
Old 2 Weeks Ago
tobermory's Avatar
tobermory tobermory is offline
 
Join Date: 2nd May 2014
Posts: 836
Rep Power: 9 Points: 1234
tobermory is a pillar of our communitytobermory is a pillar of our communitytobermory is a pillar of our communitytobermory is a pillar of our communitytobermory is a pillar of our communitytobermory is a pillar of our community
Quote:
Originally Posted by swon View Post
sbi and others. these card require otp password for every online transaction so even if number is leaked they can't initiate online transaction without otp.
But my card was SBI

Quote:
Originally Posted by coconutpalm View Post
If a debit card doesn't require OTP for online transactions, why would the bank send an OTP? It makes no sense.
Right. I received an OTP. I didn't do anything with it. In fact, I noticed this OTP SMS only after I had seen the purchase SMS!

Quote:
Originally Posted by coconutpalm View Post
but that would require physical access to the SIM card, noh?

How likely is it that a SIM card has been cloned remotely? Maybe even that is possible if the right app/malware is installed on the phone? I don't know.

But we're talking of pretty far-fetched scenarios.
What devilry is this

To add, if that sheds any light. Some minutes after I had received the SMS for fraud transaction of Rs.9,999 I received another SMS from bank. This second SMS was giving OTP for a Rs.19,999 transaction this time. I immediately blocked the debit card. A few hours later, I received an SMS from the bank stating that a transaction has failed because the card is blocked.
______________________________
Jack n' Jill went up the Hill
God knows what went up there
Jill came down screaming i-pill i-pill

Last edited by tobermory : 2 Weeks Ago at 02:13 PM.

Reply With Quote
  #10  
Old 2 Weeks Ago
coconutpalm's Avatar
coconutpalm coconutpalm is offline
www.FilesFlash.net
 
Join Date: 10th April 2006
Location: Aruba
Posts: 24,870
Rep Power: 56 Points: 11372
coconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universecoconutpalm is one with the universe
UL: 84.11 gb DL: 40.21 gb Ratio: 2.09
You can get rid of the SMS message entirely if you change your SBI account settings to use State Bank Secure OTP.

I don't know if it's any more secure, but this app will allow you to use OTP, without SMS, and even when the phone is not connected to the internet.

Don't forget to read the FAQ for the app before you install/change your SBI account settings.
______________________________

Last edited by coconutpalm : 2 Weeks Ago at 02:34 PM.

Reply With Quote
Reply Free Video Chat with Indian Girls


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT +5.5. The time now is 09:59 PM.
Page generated in 0.04549 seconds