Debated in Parliament on 16 Feb 2021.
Dr Tan Wu Meng asked the Prime Minister (a) over the past three years, how many reports have been made annually by consumers regarding unauthorised online bank transactions; (b) in what proportion of cases is there two-factor authentication (2FA) by token and SMS one-time password respectively; and (c) what is the recourse for consumers who suspect that they are victims of cybercrime or mobile device hacking leading to the unauthorised bank transactions.
In 2020, the Police received 1,848 reports of unauthorised online banking and card transactions involving criminals phishing for banking and card details from the victims before performing these unauthorised transactions. The cases are, unfortunately, on an upward trend. In 2018 and 2019, there were 114 and 329 cases respectively. I think this really reflects the advent and the growing number of electronic transactions that we are seeing.
Unfortunately, multi-factor authentication cannot eliminate all scams. Many victims have been tricked into revealing their user IDs, passwords, OTPs or credit card details to scammers.
Recently, some account holders have reported successful online card transactions when no SMS OTPs were received, or when no SMS OTPs were revealed to others. The Police and banks are following up on these cases and investigations are on-going. As a precaution, the banks have put in place additional measures, such as rejecting card payments made to some commonly disputed merchants, or placing limits on the transaction amounts that customers can transact with such merchants.
So, if you suspect that you have been a victim of fraud or cybercrime, the first step is to make a police report and contact your bank immediately so that investigations can take place promptly.
Customers play an important part in preventing scams, because guarding against online threats starts with practising good cyber hygiene. This includes keeping passwords secret and promptly updating the security patches and anti-virus software on computers and mobile devices. It is very important that consumers treat their online banking login information, including OTPs, as they would their ATM PINs.
We cannot emphasise this enough to the public. Never reveal your login information, including OTPs, to others. Employees of financial institutions will not ask for such information. So, if you are asked for it by a third party, do not provide it.
Consumers should also heed the security email advisories, notices and alerts disseminated by their banks, MAS, the Singapore Police Force and the National Crime Prevention Council, and share them with family and friends.