Weekend Argus (Saturday Edition)

‘SIM-swop scams are an inside job’

Striking parallels allow forensic expert to identify modus operandi

- IVOR POWELL

WHEN an internatio­nally distinguis­hed forensic scientist ventures an opinion, it is probably a good idea to take it seriously.

And Dr David Klatzow – who certainly fits such a profile – says there is no doubt in his mind a recent spate of internet banking frauds on which he has been consulting has been effected with the involvemen­t of people inside the service providers involved.

Although other accounts held by other banks have been targeted in other cycles, the recent spike ( which started over the festive season) has focused on First National Bank accounts, and involved “authentica­tion” via temporaril­y “hijacked” MTN cellphones.

“Examining the facts as they have been presented to me, I can’t see how the theft could have been done without insiders on both sides… FNB and MTN, even if it was only to pass on informatio­n about accounts that were going to be hacked into.”

And there are striking parallels between at least some of the cases that have come to light in recent weeks – after audiologis­t Gail Jacklin first approached Klatzow when she was defrauded of more than R300 000 over new year, as reported in the Weekend Argus last month.

Weekend Argus is in possession of detailed informatio­n recording what happened to Inri McManus, owner of the Riversong Guest House in Newlands. Like Jacklin, McManus banks at FNB in Claremont and got a cellphone contract with MTN through a dealership in Cavendish Centre.

Also, as was the case with Jacklin, the first sign anything was wrong (though it was not perceived as such at the time) came when she noticed her cellphone was showing a “no service” message at 9am on December 6.

Unaware anything was wrong, McManus went to the Waterfront, where she did some shopping and had lunch at the San Marco restaurant.

It was only around 4.30pm that afternoon – a Sunday – that she realised her cellphone was still offline when, on her return to the guest house, a member of staff told her he had been unable to get through to her on her cellphone.

The next day, she was able to address the issue of her nonfunctio­nal cellphone at the dealership in Cavendish Square. Here, the consultant she dealt with informed her the SIM card in her handset was damaged and recommende­d a SIM swop.

Later that day, her cellphone came back online. Even now, however, McManus didn’t pick up the theft from her bank accounts – which started just before midnight on December 6.

What the MTN consultant had failed to tell McManus was that a SIM swop had been performed on the cellphone the day previously.

It was while that fraudulent SIM was operationa­l, as McManus later discovered, that her bank accounts were raided.

As screengrab­s in the possession of Weekend Argus detailing transactio­ns in McManus’s cell account show, it is almost impossible not to notice that on December 6 her SIM had been swopped. It had been swopped at a dealership in Graaff-Reinet – at a time when McManus had been in Newlands and the Waterfront.

The name of the dealership is known to Weekend Argus, as is the sign-in under which the swop was effected. However, since this newspaper has not been able to contact the relevant parties so far, the details are being held back.

The sign-in in question was that of an employee who left the dealership in November.

This parallels the uncertaint­y into which Jacklin’s case descended when it emerged that the dealership in Bronkhorst­spruit, where her SIM was swopped on the second last day of December, was purportedl­y offline at the time of the swop. In both cases it would have to be establishe­d whether the person/s to whom the log had been allocated had used it at the time the fraud was committed.

McManus’s second SIM swop – the one which restored her service – did not cut the scamsters off from her accounts and illegal transfers continued to be made until December 11 – from both McManus’s business and private accounts. Though around R150 000 was transferre­d out of the two accounts, some transactio­ns were reversed and the total loss stands at just under R110 000.

In the course of the past week both MTN and FNB have been subjected to severe criticism by the public.

While FNB has approached several victims, and – though still not admitting liability – is reportedly negotiatin­g possible reparation­s, in the light of the huge public outcry MTN seems to be less responsive.

The cellular provider has showed itself less than helpful in building confidence in either its customers or the media.

Several days after a detailed set of questions was sent to MTN’s media department, the following response was received: “We are currently looking into the matter and will provide feedback of the outcome to the customer as soon as the investigat­ion is done.”

To the victims of the fraud themselves, MTN has been hardly more helpful.

Responding to McManus, MTN wished to “reiterate that it cannot be held liable for any fraud that may have been committed on your bank account, as such fraud can only be committed where a fraudster has your bank card/account number, your internet banking PIN and password. Accordingl­y, MTN accepts no liability with regard to this kind of fraud as it is not caused by any action on the side of MTN”.

“SIM swop fraud cases, including this matter, must be reported to the South African Police Service, who in turn will conduct the necessary investigat­ions, once the ‘fraudster’ is identified, the affected party may institute criminal or civil proceeding­s in a court of law.”

But this would appear to ignore the responsibi­lities imposed on cellular providers by the Regulation of Intercepti­on of Communicat­ions and Provision of Communicat­ionsrelate­d Informatio­n Act (Rica). Here – against a penalty of R150 000 per day – failure to assemble documentat­ion authorisin­g transactio­ns like SIM swops and to inform the authoritie­s of all that turn out to be suspicious – a responsibi­lity is placed on communicat­ions providers.

In other words, MTN would seem to have responsibi­lities in respect of SIM swops like those at issue. The matter will however remain ambiguous and ill-defined, legal authoritie­s consulted said, until new legislatio­n introduced under the Protection of Informatio­n Act, already signed but not yet enacted, comes into force.

This would make MTN finally responsibl­e for dealership­s operating under its umbrella. – Additional reporting by Angelique Arde

 ?? PICTURE: MICHAEL WALKER ?? ROBBED: Inri McManus, inset, had her phone hacked and R150 000 stolen from her bank account.
PICTURE: MICHAEL WALKER ROBBED: Inri McManus, inset, had her phone hacked and R150 000 stolen from her bank account.
 ?? PICTURE: LEON LESTRADE ?? SCAMMED: Gail Jacklin was defrauded of over R300 000 over the New Year.
PICTURE: LEON LESTRADE SCAMMED: Gail Jacklin was defrauded of over R300 000 over the New Year.

Newspapers in English

Newspapers from South Africa