09 March 2020

National Scam Awareness Campaign

Announcement

Dear Valued Customers / Pelanggan Yang Dihormati,

Update: 6 July 2023
 

Jika anda menerima mesej mencurigakan daripada syarikat penghantaran, ia adalah scam! Jangan sekali-kali:

  1. Klik pautan dan muat turun fail .apk.
  2. Berikan kebenaran kepada aplikasi untuk mengambil alih peranti anda.

Jika terkena scam, segera hubungi 03-5516 9800 atau Pusat Respons Scam Kebangsaan di 997 (8am - 8pm, setiap hari) dan buat laporan polis.

--------------------------------
 

The banking industry, has launched the National Scam Awareness Campaign on 30 October 2022. This National Scam Awareness Campaign is a continuation of the banking industry's efforts to combat scams as well as to educate consumers regarding scams while sharing easy tips to stay safe online. The Campaign complements the 5 key measures to be implemented by the banks to combat financial scams as stated in ABM's press release dated 27 September 2022 (click here). As part of the campaign, the banking industry urges the public to remember 3 simple steps to keep safe and not fall victim to scams: STOP, THINK, BLOCK (or AWAS. FIKIR. BLOK in Bahasa Malaysia), when they receive any calls, messages or emails from unknown parties.

The tagline "Ingat 3 Saat OK" and the hashtag #JanganKenaScam will be carried by all member banks towards a cohesive and targeted nationwide campaign to ensure the public are continuously informed and equipped with the necessary information and awareness on the different types of modus operandi employed by scammers and best practices to keep themselves safe online, which will make it harder for scammers to succeed in luring victims.

Links to Press Release – English (click here), Bahasa Malaysia (click here)

 

Avoiding e-Commerce Scams

Avoiding Investment Scams

Avoiding Loan Scams

Avoiding Money Muling

Be a Responsible Online Seller

AR Filter Education

SMSSpy campaign to steal Malaysian banking user credential

Large-scale Phishing Campaign Bypasses MFA

Scammers are posing as seller at various e-commerce sites (i.e. Shopee, Lazada) and social media sites (i.e. Facebook, Instagram) and are scamming buyer by:

  • Requesting buyer to make payment outside of e-commerce or social media sites (i.e. direct payment to seller’s bank account).
  • Blocking buyer from contacting seller after payment is made

Buyer should:

  • ALWAYS purchase or make payment within the official e-commerce or social media sites.
  • ALWAYS purchase from verified seller (i.e. seller verified by past buyers or e-commerce/social media sites)

Phishing is a tactic used to obtain sensitive information for malicious intent by impersonating a trustworthy source, such as a bank. This is usually also referred to as ‘baiting’ the victims.

Scammers will trick the victims into giving out their login/user IDs, account details, passwords, PINs and other sensitive information to gain access to the victim’s banking accounts or for identity theft.

The most common modes of phishing are via SMS, telephone calls and emails.

The information obtained by the scammer could be used to make unauthorised purchases using the victim’s credit card(s), withdrawal/transfer of money from the victim’s bank accounts, or may be used to apply for loans. This will result in potentially significant financial and reputational loss to the victim.

SMS

Immediately call the bank’s customer service number stated at the back of the credit card or on the bank’s website to check whether such a transaction has actually been charged.

Do not call the number provided in the SMS if you are uncertain or suspect dubious activity.

Immediately hang up and call the bank’s customer service number directly. The list of bank’s helpline can be found on the back of your credit card or on the bank’s website.

CALLS

Banks will never call to ask for sensitive information from customers. If in doubt, hang up and check with your bank by calling the customer service number stated on the back of your credit cardv or on the bank’s website or go to the nearest branch for verification.

Scammers have ways to modify the caller’s number that you see on your phone to make it look like it is from the bank by using Voice over Internet Protocol, also known as VoIP.

If you have any suspicions, hang up and call the bank directly at the number stated at the back of the credit card or on the bank’s website to verify the legitimacy of the call.

Do not disclose any information to the caller. Hang up immediately. If you are worried that your identity has been used to apply for a credit card at that bank, call the bank directly or visit the nearest branch to confirm that there is no credit card issued to your name. You should lodge a report with the bank concerned.

Do not panic. Hang up immediately. If you are worried that your identity has been used to apply for a loan at that bank, call the bank directly or visit the nearest branch to confirm that there is no loan facility in your name. You may wish to lodge a report with the bank concerned or the police.

EMAILS

Never click on links or icons in unsolicited e-mails and do not reply to such e-mails. Delete them immediately.

In a new browser, go to the bank’s legitimate site by typing the bank’s website/URL directly into the address bar. The online banking sites of all Malaysian banks are secure so please look for the closed padlock icon next to the website address. The site should also begin with https:// instead of http://.

All banks’ online banking sites are secure. Look out for the closed padlock icon next to the address bar or in the bottom status bar. Also, the secure website address will begin with https:// instead of http://.

Note that all secured websites will have a Secure Sockets Layer (SSL) which is the standard security technology for establishing an encrypted link between a web server and a browser. This link ensures that all data passed between the web server and browsers remain private and integral. The icon of an SSL will appear as illustrated below. Note that this icon will appear whenever a secured connection is located by your web browser.

Consider installing security software such as those offered by anti-virus specialists that can help detect virus, filter SPAM and/or ensure secure internet usage (firewalls).

Turn off your computer when not in use to avoid criminals gaining access and misusing it for fraudulent purposes, which includes launching phishing attacks.

It would be wise to change your passwords periodically as well and always use hard to guess passwords combining uppercase, lowercase and numbers. Whenever possible, also include a special character such as *, &, $ and !

Click HERE to view The Association of Banks in Malaysia scam alerts listing.
 
  • November 2024:
    1. 2 keldai akaun ditahan babit kerugian RM54,000 - Read Here
  • October 2024:
    1. Guru, pesara, warga emas sasaran Macau Scam - Read Here
  • September 2024:
    1. Guru, pesara, warga emas sasaran Macau Scam - Read Here

  1. Always check your transaction alerts in a timely manner. Regularly check your account balance and/or bank statements. Call us immediately if you notice any unusual, unauthorised transactions or discrepancies in your account.
  2. Always verify the authenticity of messages received from Alliance Bank. Avoid clicking on links from unknown sources or opening email attachments from unfamiliar senders.
  3. Please take note of the security tips and warnings provided on the bank’s website and allianceonline (web and mobile banking applications). Ensure you thoroughly read and understand our Privacy Notice to know how we manage and safeguard your personal data.
  4. Avoid sharing your banking credentials, including online banking log in usernames, passwords, personal identification numbers (PIN) with others.
  5. Only download mobile applications from official app stores, such as Google Play Store, Apple App Store & Huawei AppGallery. Make it a habit to regularly update your device’s operating system to the latest version. You may want to consider installing antivirus and anti-malware software on your device. Be cautious of clicking on suspicious links or downloading Android Package Kit (APK) files from untrusted resources.
  6. If you have shared your banking credentials such as username and password with others, or lost your device, or suspect you’ve been scammed, please call us immediately.