Ensuring the security of online payments

Обеспечение безопасности осуществления платежей в сети Интернет
Currently, cybercrime poses a serious threat to the development of the economy and society. In recent years, the number of cybercrimes has significantly increased, requiring urgent measures to protect information and ensure cybersecurity. One of the main problems is the insufficient awareness of cybersecurity among the population. Many citizens do not take sufficient precautions when using the Internet, which makes them vulnerable to criminals.
According to statistics, women are twice as likely to become victims as men. The absolute majority live in cities. People with higher education are equally susceptible to deception as those with secondary education. Among the victims of cybercriminals are mainly economically active citizens representing almost all spheres of activity – accountants, economists, directors, deputy directors of private and public institutions, heads of departments and divisions of state institutions, teachers, doctors and nurses, students, lawyers, programmers, and representatives of other professions.
Scammers regularly change their schemes to deceive citizens and steal their money. The main forms of deception are telephone and internet fraud, as well as phishing resources.
TELEPHONE FRAUD – VISHING
Scammers, posing as bank employees, telecommunication operators, or government agencies, contact citizens, create a stressful situation, inform them of a problem, and then offer assistance in resolving it. In order to gain trust, they may send photos of official documents or even initiate a video call via a messenger.
A common method involves fraudsters using various fictitious scenarios to persuade potential victims to download a file sent via messenger or install a specific mobile application. In both cases, fraudsters gain the ability to remotely control the device on which it is installed. This allows them to access users' personal data, including the ability to take out online loans. Additionally, attackers persuade individuals to take out loans from banks and transfer the money to a "secure" account.
One should always be vigilant and not trust strangers, never install unverified programs or files received via messenger from unknown sources under any pretext, and never hand over money to anyone or transfer it to bank accounts at the instruction of strangers.
In Orsha, a woman received calls from unknown numbers for several days. Eventually, she agreed to listen to a pseudo-investigator. He shocked her by claiming that illegal operations were being recorded from her account to fraudulent accounts and that it was necessary to prevent them and apprehend the perpetrators. The woman refused to believe him, so a supposed employee of a well-known bank, dressed in business attire with bank insignia, continued the conversation via video call. The woman believed the callers and, following their recommendation, installed an application that allowed the fraudsters to see everything happening on her phone, including SMS codes. During the conversation with the fake banker, she revealed her mother's maiden name, which was her security word. Accomplices of the fraudsters then used this information to arrange an overdraft and an online loan in the woman's name during the call itself and transferred the funds to their own accounts. In total, 18,000 rubles were stolen from the woman.
Scammers study their victims to commit crimes, collecting data about them, their interests, social circle, and other information online. Using voice samples or photos of acquaintances, they can create fake text or video messages.
For example, several similar incidents were registered in May. In a messenger, scammers created an account of a state organization's head and wrote to an employee in their name, stating that lists of workers suspected of financing extremist groups had been received, and a search of the woman's home might soon be conducted to seize undeclared funds. The woman was very frightened for her money because she trusted her supervisor. Subsequently, the scammers, acting as her supervisor, suggested she communicate with the Head of the Regional Financial Investigations Department, who in turn connected her with an investigator. For three days, the woman lived in fear for her savings. To preserve them, the scammers "advised" her to transfer them to a supposedly special secure account. Additionally, within a week, the woman took out a loan, cashed it out, and transferred it to the same account, from which all the money, totaling 55 thousand, was soon stolen.
 
Similar cases have been recorded involving pedagogical workers in the region, where scammers wrote in messengers impersonating the directors of educational institutions. More than 7 teachers contacted the police within 3 days, with some reporting later. Primarily, scammers persuaded teachers to take out loans from banks.
Scammers regularly devise new methods of deception to obtain money. They post advertisements on the Internet for seemingly investment platforms that do not actually exist, in order to lure investors and steal their money. The first step to contact a curator is to fill out a form where you need to leave your name and phone number. Then, the so-called curator contacts the interested party, under whose guidance, in the hope of making easy money, the potential victim transfers money to an electronic wallet themselves. To get at least their invested money back, scammers demand payment of commissions, fees, etc. For some time, scammers show the victim their profits, until the deceived person runs out of money, after which contact with them is terminated. The money remains in the fraudulent accounts.
A young man from Vitebsk became interested in the opportunity to invest his money in an investment project. After he followed the curator's instructions and transferred money to a digital wallet, the amount of his money supposedly began to increase; the young man saw profits in his account on the platform. However, as soon as he tried to withdraw the money, he was immediately blocked. He twice found firms on the internet offering assistance with withdrawing money, but none of the "firms" provided him with the proper services, after which the man contacted the police. In total, he lost more than 20 thousand rubles.
To avoid becoming a victim of a cybercriminal, end the conversation with an unknown person as soon as possible, no matter who they claim to be.
FAKE STORES on social media
Every day, the police receive reports from individuals who have prepaid for goods found in advertisements on social networks and marketplaces, only to not receive them. Scammers intentionally create accounts in the name of stores, where they post advertisements for non-existent goods at reduced prices (shoes, clothing, mobile phones, bedding, Christmas trees, hanging pod chairs, and other items). A potential buyer contacts the "store" administrator, is promised delivery after full payment, and is offered to pay via bank card or through the ERIP system. However, after receiving the funds, the goods are not shipped, and the buyer is blocked.
PHISHING
In order to obtain personal account holder data, scammers create clone pages of banks, theater websites, hookah lounges, and investment (trading) exchanges.
A young mother from Orsha, on maternity leave, transferred 2,000 rubles via ERIP to a provided account for a phone but did not receive it. The scammers then offered to return her money to her bank card. They sent a link via messenger, and upon clicking it, the young woman entered her card number and the secret code from the back, intended only for outgoing transactions. Having obtained this information, the scammers defrauded her again, withdrawing all the money from her card.
To prevent such incidents, it is necessary to:
 consider the reasons for a low product price that differs from the price of the same product on other websites, or be wary if a store lacks a website;
 carefully check information about the store: contact the seller via a Belarusian mobile number, not via the Internet;
 use a separate card for online payments;
 do not click on links from unknown persons;
 check the address of the page where you enter card details (for Belarusian organizations, the address bar should look like: "website name".BY/"website section");
 enable the free "3-D Secure" service from your bank in the card settings.
SWATTING
A trend called "swatting" is spreading in the youth gaming cyber environment. Its essence lies in creating an unfavorable situation for government agencies, disrupting their work, or taking revenge on an offender by creating problems for them with law enforcement agencies. In the first half of 2024, 4 schoolchildren were identified in the region, and in the previous 2 years – eight schoolchildren, who organized the distribution of emails to the mailboxes of organizations in Belarus and other countries with false reports of mining objects.
All identified individuals are minors, the youngest swatter is 12 years old, and all of them intentionally used deanonymization methods and special software, which they believed would allow them to hide their tracks. Teenagers were interested in the topic of swatting and in most cases knew that criminal liability for committing these acts arises from the age of 14 and provides for up to 7 years of imprisonment.
 

INVOLVEMENT IN CYBERCRIME
To receive stolen money abroad and to obscure "digital footprints," fraudsters need to transfer it through intermediary accounts opened in Belarusian banks in the names of nominees, so-called "drops." Often, there are more than a dozen intermediary accounts. There are cases where illegally obtained money has passed through 72 intermediary bank accounts, access to which fraudsters purchased from their owners.
In our country, a bank account can be opened by a legally capable citizen from the age of 14, meaning even minors can open bank accounts. Criminals take advantage of this. While abroad, offenders select individuals who agree to open a bank account in their name and sell access details for a small sum – these are logins and passwords for accessing the internet banking personal account, as well as providing a one-time SMS code or a code card.
Fraudsters cannot directly post advertisements online seeking such individuals, so they conceal their interest by offering various other seemingly legitimate earning opportunities. For example, in Telegram, they send out advertisements seeking couriers in any city with stable wages, or people for unloading goods, or people for the "mystery shopper" position, or they lure them with promises of high and fast payment.
Most often, individuals with unstable or low incomes, predominantly young people, respond to such vacancies. Initially, the advertiser disappoints those interested in the part-time job, stating that the vacancy is already filled, and immediately offers an alternative way to earn money, for example, opening a bank account and transferring access details for it in exchange for a reward.
In addition to money stolen by cybercriminals through intermediary accounts, funds obtained from illegal drug trafficking may also be processed. Account holders are responsible for the money that has passed through their bank accounts.
It should be noted that under our legislation, Article 222 of the Criminal Code provides for penalties of up to 10 years of imprisonment for the manufacturing for sale or sale of bank payment cards or other payment instruments, such as bank accounts or electronic wallets, as well as the dissemination of access data to them.
There are cases where minors have been involved in criminal activities.
16 teenagers from two secondary vocational education institutions in the region, after contacting a customer online, opened bank cards in their names and, for a reward of 15 to 50 rubles, handed them over for use by unidentified individuals. Cybercriminals used these bank cards to transfer stolen money. Criminal cases have been initiated against 8 teenagers, and investigations are ongoing for the rest, with a decision pending on initiating criminal proceedings.
Furthermore, there are examples of teenagers being involved in criminal schemes in other ways.
A 14-year-old student from a Vitebsk school asked to borrow his 15-year-old classmate's bank payment card for a while. The boy registered an account on a cryptocurrency exchange. Unknown individuals contacted him and offered him an opportunity to earn money. The young man provided the bank card details of his classmate, onto which he received 10,000 rubles, and then purchased cryptocurrency for the entire amount for them. During the investigation, it was established that the received money had been stolen from a pensioner from Vitebsk.
Thus, the student provided services for the purchase and sale of cryptocurrency to third parties, which entails liability for illegal entrepreneurial activity under Part 3 of Article 13.3 of the Code of Administrative Offenses of the Republic of Belarus. The involvement of minors in cryptocurrency exchange transactions is not an isolated case. Over 450 thousand rubles passed through another teenager's crypto wallet.
Engaging in cryptocurrency transactions for the benefit of third parties carries a significant fine and forfeiture of up to one hundred percent of the income received from such activities to the state.
Attachment: leaflet on liability
   

CYBERCRIMES aimed at seizing funds from business entities, including state enterprises of the Republic of Belarus, are registered in the enterprises of the region.
Hackers plan in advance and gain unauthorized access to an organization's data, transform it into a jumbled set of characters, and offer to decrypt it after a monetary payment is transferred to a specified account. Attackers primarily rely on human errors and weaknesses rather than software vulnerabilities, which are much more difficult to overcome.
It is important to understand that an attacker will not be able to achieve their goal and steal funds if the attack is detected and stopped in a timely manner. This is possible at any stage of the attack by taking appropriate protective measures aimed at preserving well-being, including by employees adhering to the following rules:
1. ensure an adequate level of information security in accordance with the development and updating of software, as well as the regulatory legal acts of the Republic of Belarus;
2. regularly back up important data;
3. never trust the sender of an email, double-check the information provided, as well as the main identification data and service headers of emails (you can find out and analyze the sender's IP address and other necessary information) before replying to the email, even if it is from a long-term partner using a new address;
4. do not click on links or open attachments if the sender of the email is not who they claim to be;
5. in case of changes in the partner's settlement account details, establish this fact through any other communication channels (in person, by phone, etc.);
6. use the EDS (electronic digital signature) key directly when working with the relevant software, remove it from the USB port after finishing work;
7. carefully check the website address and domain, and its creation date;
8. timely change account passwords, including when relocating, dismissing, or hiring a new employee;
9. immediately change the password and/or block accounts in case of entering access details on a suspicious website; 
10. always be vigilant and verify the information received.
Cybercrime Counteraction Department 
Department of Internal Affairs of the Vitebsk Regional Executive Committee