Indonesian Political, Business & Finance News

New Bank Account Hacking Method: Fake Couriers Send Links via WhatsApp

| Source: CNBC Translated from Indonesian | Technology
New Bank Account Hacking Method: Fake Couriers Send Links via WhatsApp
Image: CNBC

Online shoppers must remain extra vigilant due to a new fraudulent modus operandi targeting e-commerce users.

Cybersecurity expert from Vaksincom, Alfons Tanujaya, revealed that perpetrators are now relying on leaked detailed order data to deceive victims and drain funds from their bank accounts. Technical investigations conducted by Alfons, shared via his Instagram account, uncover the chronology and structured flow of this attack pattern.

Initially, the perpetrators initiate contact by impersonating fake couriers. They contact victims via WhatsApp, pretending to represent Pos Indonesia. They then claim that a package is experiencing issues or has been lost, requesting proof of order under the pretext of re-delivery or a refund.

Pos Indonesia has clarified that they never contact customers personally via private WhatsApp messages. In this scheme, scammers possess precise sensitive data, including names, addresses, phone numbers, item prices/weights, tracking numbers, and even internal booking codes and corporate logistics customer IDs. This high level of accuracy is what makes victims easily believe the messages.

Analysis suggests that this data leak likely does not originate from the main e-commerce servers, but rather from the logistics chain or third-party expeditions managing internal data fields, such as booking codes and corporate customer IDs. “Data this complete most likely leaks from the third-party courier/expedition chain,” Tanujaya wrote in his report.

Once trust is established, victims are directed to a fake website link that mimics an official e-commerce page. There, victims are prompted to log in using their phone numbers and enter e-wallet PINs and OTP codes. All entered data is transmitted in real-time to the perpetrators’ Telegram bot.

The phishing system then redirects victims to a second domain specifically designed for stealing bank card data. The perpetrators utilise the transition between two or three different domains to confuse the victim before requesting a second OTP to finalise the bank fund theft.

Tanujaya warns that data accuracy is no guarantee of legitimacy; complete order details do not prove that the sender is an official courier or e-commerce representative. He urges customers to maintain strict confidentiality and never share account screenshots, PINs, or OTP codes with anyone.

Customers must also verify any order issues only through official e-commerce applications, rather than via WhatsApp or SMS links. If data has already been compromised, individuals should immediately block their cards or accounts and report the incident to their bank and the police.

View JSON | Print