{"id":20576,"date":"2022-11-10T03:30:04","date_gmt":"2022-11-10T11:30:04","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/11\/10\/news-14309\/"},"modified":"2022-11-10T03:30:04","modified_gmt":"2022-11-10T11:30:04","slug":"news-14309","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/11\/10\/news-14309\/","title":{"rendered":"Scammers pretend to be financial regulators | Kaspersky official blog"},"content":{"rendered":"<p><strong>Credit to Author: Olga Svistunova| Date: Thu, 10 Nov 2022 11:26:56 +0000<\/strong><\/p>\n<p>Online fraud knows no bounds. Cybercriminals are adapting \u2014 not always successfully \u2014 their usual schemes for new countries. To wheedle out victims&#8217; personal and banking data, they send e-mails purporting to be from, among others, <a href=\"https:\/\/www.kaspersky.com\/blog\/spam-with-vishing-phone-numbers\/41055\/\" target=\"_blank\" rel=\"noopener\">online marketplaces<\/a>, <a href=\"https:\/\/www.kaspersky.com\/blog\/netflix-phishing\/42927\/\" target=\"_blank\" rel=\"noopener\">video streaming services<\/a> and, of course, <a href=\"https:\/\/www.kaspersky.com\/blog\/data-leak-compensation-scam\/32057\/\" target=\"_blank\" rel=\"noopener\">government agencies<\/a>. Today we look at two separate scams in which cybercriminals impersonate financial regulators investigating, you guessed it, fraud. Under this pretext, they extract an array of personal information from their hapless victims.<\/p>\n<h2>A German tragedy in two parts<\/h2>\n<p>The first scam targets German residents. It starts with an e-mail in which an organization calling itself Finanzmarktaufsicht (the name suggests it has something to do with with financial regulation) states that Osnabr\u00fcck police has supposedly arrested some criminals and confiscated their hard drives, which were found to contain citizens&#8217; decrypted personal data \u2014 including the recipient&#8217;s.<\/p>\n<div id=\"attachment_46104\" style=\"width: 1859px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2022\/11\/10061144\/scam-for-scam-victims-screen-1.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-46104\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2022\/11\/10061144\/scam-for-scam-victims-screen-1.jpg\" alt=\"E-mail seemingly from \"German financial regulator\" Finanzmarktaufsicht\" width=\"1849\" height=\"763\" class=\"size-full wp-image-46104\" \/><\/a><\/p>\n<p id=\"caption-attachment-46104\" class=\"wp-caption-text\">E-mail seemingly from &#8220;German financial regulator&#8221; Finanzmarktaufsicht<\/p>\n<\/div>\n<p>The e-mail goes on to state that, given the large number of victims, &#8220;Finanzmarktaufsicht&#8221; suspects organized crime to be at work. Hinting that the recipient of the e-mail could be one of the victims, the scammers ask them to assist in the investigation. Nothing complicated is required for this: simply follow the link to fill out a special online form, or call the number given in the e-mail.<\/p>\n<p>The message itself resembles an official e-mail: it contains the the logo of the &#8220;sender&#8221; government agency, the actual address of a Berlin business center (home to several financial organizations, but none bearing the name Finanzmarktaufsicht), and contact details. At the end, the scammers have gone to the trouble of adding a perfectly genuine link to an article about a real investigation published on the website of one of Germany&#8217;s most popular TV news shows.<\/p>\n<div id=\"attachment_46105\" style=\"width: 1310px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2022\/11\/10061220\/scam-for-scam-victims-screen-2.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-46105\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2022\/11\/10061220\/scam-for-scam-victims-screen-2.jpg\" alt=\"One of the links in the e-mail points to a real article about a financial fraud investigation on the genuine website of a popular German TV news show\" width=\"1300\" height=\"1100\" class=\"size-full wp-image-46105\" \/><\/a><\/p>\n<p id=\"caption-attachment-46105\" class=\"wp-caption-text\">One of the links in the e-mail points to a real article about a financial fraud investigation on the genuine website of a popular German TV news show<\/p>\n<\/div>\n<p>Although at first glance the e-mail comes across very well, upon closer inspection certain tell-tale signs can be found showing it&#8217;s bogus. First of all, the sender&#8217;s address is suspicious. It has nothing to do with the government agency that allegedly sent it. And the agency itself looks dubious: A quick search online reveals that <a href=\"https:\/\/de.wikipedia.org\/wiki\/Finanzmarktaufsichtsbeh\u00f6rde\" target=\"_blank\" rel=\"nofollow noopener\">Finanzmarktaufsicht<\/a> is in fact an Austrian, not German, agency. The German equivalent goes by an even more officious-sounding name: <a href=\"https:\/\/en.wikipedia.org\/wiki\/Federal_Financial_Supervisory_Authority\" target=\"_blank\" rel=\"nofollow noopener\">Bundesanstalt f\u00fcr Finanzdienstleistungsaufsicht<\/a>.<\/p>\n<p>A user who fails to spot the deception and clicks the link is taken to an online form on the website of the bogus Finanzmarktaufsicht. And to receive &#8220;expert assistance&#8221;, they need to enter the following details:<\/p>\n<ul>\n<li>Surname<\/li>\n<li>First name<\/li>\n<li>E-mail address<\/li>\n<li>Contact phone number<\/li>\n<li>Name of the organization they recently invested in<\/li>\n<li>Deposit date, amount and purpose of the investment<\/li>\n<\/ul>\n<div id=\"attachment_46106\" style=\"width: 1310px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2022\/11\/10061259\/scam-for-scam-victims-screen-3.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-46106\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2022\/11\/10061259\/scam-for-scam-victims-screen-3.jpg\" alt=\"Form for entering personal data on the fake Finanzmarktaufsicht site\" width=\"1300\" height=\"770\" class=\"size-full wp-image-46106\" \/><\/a><\/p>\n<p id=\"caption-attachment-46106\" class=\"wp-caption-text\">Form for entering personal data on the fake Finanzmarktaufsicht site<\/p>\n<\/div>\n<p>Further down the page the cybercriminals promise to help return the funds stolen by the scammers, for which reason they allegedly need information to prepare documents, including past correspondence, details of bank transactions, etc. It&#8217;s most likely that later the victim will be asked for their bank card number (supposedly to reimburse the damage), be required to pay a bogus fee, or part with their money in some other way.<\/p>\n<p>The bogus Finanzmarktaufsicht site itself looks as though it belongs to a bona fide government agency. The user sees several menu sections, plus detailed information about the agency including its activities, history, opening hours, contact details, and a lot more besides. Even the logo of the Austrian government agency is there on display. However the e-mail address given there is wholly unlike the one from which the message came; it looks more like the real deal, and at least contains the abbreviated name of the agency. But it&#8217;s fake too, of course. As already mentioned, there&#8217;s no organization with that name in Germany, so anyone could register such a .de domain name. Which is precisely what the scammers did.<\/p>\n<div id=\"attachment_46107\" style=\"width: 1310px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2022\/11\/10061331\/scam-for-scam-victims-screen-4.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-46107\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2022\/11\/10061331\/scam-for-scam-victims-screen-4.jpg\" alt=\"Information about the organization on the fake Finanzmarktaufsicht website\" width=\"1300\" height=\"800\" class=\"size-full wp-image-46107\" \/><\/a><\/p>\n<p id=\"caption-attachment-46107\" class=\"wp-caption-text\">Information about the organization on the fake Finanzmarktaufsicht website<\/p>\n<\/div>\n<h2>Swiss letter<\/h2>\n<p>The second scam focuses on Switzerland. This time, the e-mail &#8220;reminds&#8221; the recipient that back in 2015\u20132017 they supposedly invested in a company called SolidCFD. Too bad, since now it&#8217;s been closed down due to some illegal activity. And the &#8220;recovery and resolution manager&#8221; of the independent financial regulator wants to help return the investment. The pseudo-employee, alas, could not reach the recipient by phone, so the latter is asked to reply by e-mail to discuss the fate of their investment.<\/p>\n<p>In this instance, the cybercriminals have chosen a financial regulator that does exist in the target country. The e-mail makes reference to <a href=\"https:\/\/en.wikipedia.org\/wiki\/Swiss_Financial_Market_Supervisory_Authority\" target=\"_blank\" rel=\"nofollow noopener\">FINMA<\/a>, an independent financial regulator operating in Switzerland. The company mentioned in the e-mail \u2014 SolidCFD \u2014 was also real, and did have a <a href=\"https:\/\/www.fca.org.uk\/news\/warnings\/solidcfd\" target=\"_blank\" rel=\"nofollow noopener\">dubious reputation<\/a> (but more in the UK than in Switzerland).<\/p>\n<p>As for a website, the attackers in this second scam don&#8217;t even bother with one. Most likely they&#8217;re hoping they&#8217;ll just get lucky and the user will agree to discuss their investments first by e-mail, then possibly by phone or messenger app. At that stage, employing various social engineering techniques, they&#8217;ll be able to squeeze personal information, and likely money, out of the victim.<\/p>\n<h2>How to protect yourself<\/h2>\n<p>To avoid unpleasantness and the loss of personal data and\/or money, we recommend as follows:<\/p>\n<ul>\n<li>Paying attention to the e-mail address of the sender. If it has nothing to do with the company it purportedly comes from, or consists of random letters and numbers, you can be sure it&#8217;s a scam.<\/li>\n<li>If the e-mail mentions a law, regulation, or high-profile case, do an online search for information about it. Can&#8217;t find anything, or what you found doesn&#8217;t match the content of the e-mail? Again, it&#8217;s no doubt fraudsters at work.<\/li>\n<li>To learn how to spot scams, read our post on <a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-protect-from-online-scam\/43908\/\" target=\"_blank\" rel=\"noopener\">ways to detect online scam<\/a>.<\/li>\n<li>Even if you&#8217;re confident in your abilities to unmask scammers, it&#8217;s better to play it safe just in case. With that in mind, use a <a href=\"https:\/\/usa.kaspersky.com\/premium?icid=usa_bb2022-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\">reliable security solution<\/a> that automatically recognizes danger and warns you when visiting a suspicious website.<\/li>\n<\/ul>\n<p> <input type=\"hidden\" class=\"category_for_banner\" value=\"premium-generic\" \/> <br \/><a href=\"https:\/\/www.kaspersky.com\/blog\/scam-for-scam-victims\/46101\/\" target=\"bwo\" >https:\/\/blog.kaspersky.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2022\/11\/10061120\/scam-for-scam-victims-featured.jpg\"\/><\/p>\n<p><strong>Credit to Author: Olga Svistunova| Date: Thu, 10 Nov 2022 11:26:56 +0000<\/strong><\/p>\n<p>Scammers are sending e-mails purporting to be from financial oversight authorities, asking victims for personal data.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10425,10378],"tags":[3924,3985,10438,10428],"class_list":["post-20576","post","type-post","status-publish","format-standard","hentry","category-kaspersky","category-security","tag-phishing","tag-scam","tag-threats","tag-tips"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/20576","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=20576"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/20576\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=20576"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=20576"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=20576"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}