Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card...

76
Investigation of Vishing Fraud

Transcript of Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card...

Page 1: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Investigation of

Vishing Fraud

Page 2: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 3: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential / information used in identity theft schemes from individuals

Page 4: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Sri Janardana Padhy received an unknown telephonic call from the fraudster and the fraudster posing himself as the ATM Relations Manager calling from Head Office, Mumbai informed the victim that “your ATM Card is at risk, it will be blocked soon”. The fraudster assured the victim to activate the ATM Card and asked for the ATM –cum-Debit card details i.e., ATM-cum-Debit card Number & PIN Number. The fraudster also instructed the victim to switch off his Mobile Phone Number for technical reasons & for smooth updating process. The fraudster advised the victim not to inform anyone as the process is very confidential in nature. After receiving the ATM Card details, the fraudster made a number of online transactions (purchase of goods, electronic equipment's, online payments, mobile /DTH recharge, etc.) in various websites / online payment gateways and defrauded an amount of Rs.2,50,000/-.

Page 5: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Applicable Sections of Law:-

IPC:- 419/420Information Technology Act-2000:- 66C/66D

Page 6: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Steps:- Victim received an unknown call from the fraudster

Accused fraudster posing himself/herself as the ATM Relations Manager calling from Head Office to the victim

Informing the victim over Mobile Phone that “your ATM Card is at risk, it will be blocked soon”

Assuring the victim to activate the ATM Card, if the victim will furnish the ATM –cum-Debit card details

Page 7: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 8: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Modus Operandi

Asked for the ATM –cum-Debit card details i.e., ATM-cum-Debit card Number PIN Number

Accused instructing the victim to switch off his/her Mobile Phone Number for technical reason & for smooth updating process

Fraudster instructing the victim not to inform anyone as the process is very confidential in nature

Page 9: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Modus Operandi

After receiving the ATM Card details, the fraudster made a number of online transactions (purchase of goods, electronic equipment's, online payments, mobile /DTH recharge, etc.) in various websites / online payment gateways

Page 10: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Pre-Requisite for Investigation

Victim received a telephonic call from the fraudster

Victim has given his ATM Card details to the fraudster

Accused had made a number of online transactions in various websites / online payment gateways by using the ATM Card details of the victim

Page 11: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

From the Complainant

Mobile Phone Number of the fraudster to be ascertained from the victim

Seizure of the following documents on production by the victim complainant:- • ATM-cum-Debit card in original• Updated Savings Passbook• SMS details received from the Bank about the online transactions made by the accused with date & time written in a paper by the complainant•Mobile Phone Handset along with SIM Card (in which the SMSs were received) be seized and after seizure be kept in zima

Page 12: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 13: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 14: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 15: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Different Online Payment

Gateways

Page 16: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 17: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 18: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 19: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 20: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 21: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 22: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 23: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

In respect of Complainant Correspondence to be made with the Mobile Service Provider to furnish the report in respect of the mobile phone number of the complainant as well as of the fraudster :-• Subscriber Details• Date of Activation• Customer Acquisition Form {in original}• CDR for the alleged period• IMEI Number of the handset• Certificate u/s 65-B of the Indian Evidence Act

Page 24: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

IMPORTANT NOTE IN CD

Co-relation to be made and reflected the same in the case diary as found in the CDR

Page 25: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Correspondence to be made……

To the concerned Bank:-•Name and address of the account holder• Account Statement for the alleged period of unauthorized online fraudulent transaction • The details of each transaction in brief • Account Opening Form of the Victim•Whether the victim was issued with any ATM-cum-Debit Card:- • ATM Card Number• Date of issuing of ATM Card• Details of the ATM Card

Page 26: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Correspondence to be made with online Payment Gateways / Shopping websites

Account Registration Details in respect of the Merchant ID through which the online transaction was made IP details type of operating system of the computer system of the

fraudster type of browser software Physical address of the computer system

IP Address, Time stamp and other server log details for each fraudulent transaction

Payment gateway details along with used credentials for authentication and transaction

Page 27: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Correspondence to be made with online Payment Gateways / Shopping websites

All other traceable details like mobile numbers used for OTP or any

authentication or used to call your customer service number

email addresses for transactions mailing address of the merchant and any

other detailsBeneficiary details [ Mobile Phone Number recharged / DTH reference] available at your side or provided by merchant to bank against these transactions

Cookies

Page 28: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Correspondence to be made with online Payment Gateways / Shopping websites

Credit history information Purchase history in respect of the Merchant IDproducts the fraudster viewed or searched forCounterfoil receipt in respect of delivery of goods by the online shopping website to the fraudster

The details of the company personnel along with his contact number who delivered the goods to the fraudster

Date & time of delivery of goodsAddress of delivery of goods

Page 29: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 30: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 31: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 32: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 33: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 34: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 35: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 36: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 37: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 38: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 39: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 40: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 41: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Wallet:-• Recharges, • Bill payments, • Bus tickets, • Shopping from hundreds of categories• Send & receive money to & from friends• Avail of services at partner destinations• Cash back to the accounts• Bill payment or recharge through toll free number or SMS

Page 42: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 43: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

SAMPLE REPORTS

Page 44: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Report of EBS:-

Page 45: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Report of Bill Desk:-

Page 46: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Report of Freecharge:-

Page 47: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Report of Mobikwik:-

Page 48: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Report of PayU:-

Page 49: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Report of PayTM:-

Page 50: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Report of PayTM:-

Page 51: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Report of Pay4India:-

Page 52: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

From reports of Online Payment Gateways we found:- Registered Mobile Phone Number IP Address of the computer system used for registration of the account in the online payment gateway along with date & time

Beneficiary Mobile Phone Number/ Recharge ID

E-mail ID furnished by the fraudster in the payment gateway

Details of shipping items Shipping Address along with name & particulars of the beneficiary

Page 53: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Correspondence to be made……

E-mail Service Provider:-

• Notice u/s 91 of Cr.P.C. submitted to the Nodal Officer of E-mail Service Provider to furnish the account registration details along with log details in respect of E-mail account

Page 54: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Information in respect of e-mail ID:- Account Registration Details Date & time of creation of the e-mail account IP log at the time of creation of the accountPhysical address if any of the computer system used by the fraudsterBrowser information Mobile Phone Number used at the time of registration and updation of the e-mail account {registered mobile phone number}Secondary e-mail accountLog details of the e-mail account

Page 55: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Google report

Page 56: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

From the E-mail Service Provider

Name:-E-mail:-Status:-Services:-Secondary E-mail:-Created on (with date & time):- IP Address:-SMS:- Log details:-

Page 57: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Sample Reports from E-mail Service Provider

Page 58: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Yahoo report

Page 59: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Rediffmail report

Page 60: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 61: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 62: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 63: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 64: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Correspondence to be made……Internet Service Provider:-• User Subscriber Details of the IP address• Telephone number in case of DSL/CDMA/3G, and Dial up• other relevant information in respect of the User Subscriber

• address of correspondence• contact number • e-mail IDs • billing details

• MAC ID of the alleged computer system or• IMEI Address of the computer resources with respect of the

relevant IP address• CAF / NTC in respect of the User Subscriber in respect of

the alleged IP address.

Page 65: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Request Letter to ISP

Page 66: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Report from ISP {Aircel}

Page 67: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Sample report from ISP {BSNL}

Page 68: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Sample report from ISP {ORTEL}

Page 69: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Sample report from ISP {TATA}

Page 70: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Correspondence to be made……Mobile Service Provider:-

Subscriber DetailsDate of Activation (DOA)Customer Acquisition /Application Form (CAF) {in original}

CDR for the alleged periodCertificate u/s 65-B of the Indian Evidence Act

Page 71: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Investigating Officer will seizeFrom the possession of accused:- Laptop with charging adapter Computer system, its other components (Monitor, CPU, UPS,

Keyboard, Mouse) Hard Disk from the seized CPU Modem Pen Drive /USB Drives /CDs/ DVDs Mobile Handsets SIM Cards Memory SD Card Dongles Cables Telephone Bills Different fake ID Proof documents

Page 72: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 73: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Modus Operandi:-

The accused person is using different mobile phone numbers for communication with courier agency and delivery of shipping items

The accused person is using different identity particular documents created in different names (Voter ID Card, PAN Card, Aadhar Card, College ID Cards)

The accused person sent different persons to receive the shipping items

Mainly operated in the area of Jharkhand Jamtara, Mohanpur village areas

Page 74: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 75: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.
Page 76: Investigation of Vishing Fraud Voice phishing is typically used to steal Credit Card /ATM Card numbers, PIN Numbers, CVV Number or other Banking credential.

Seized Exhibits be sent to CFSL for examination

Seized exhibits be sent to Director, Central Forensic Science Laboratory, Directorate of Forensic Science Services, Govt. of India, Ministry of Home Affairs, 30, Gorachand Road, Kolkata- 700014, (T) S.D.J.M., for examination and opinion