Experts called the signs of a fake support service in the chats
Cases of fraudulent attacks are increasingly being recorded in messengers, in which attackers disguise themselves as service support services and try to gain access to user accounts. Experts spoke about how to recognize such schemes and effectively counteract them. All the details are in the Izvestia article.
Mechanisms of deception
Information security expert "Kontur.Aegis and Staffcop Daniil Borislavsky noted that a real support service almost never writes to a user first without first contacting them. An alarm signal is a sudden message demanding that you confirm your data or log in via a link.
"The second important sign of deception is an attempt to take a person to a separate bot or to a third—party page to enter a username, password, or text message code. These services use specific information in official communication: order numbers, addresses, or booking details. Fraudsters more often use impersonal phrases like "dear user" or "there is a problem with your order," the expert explained.
The main task of scammers through such chatbots is to gain full control over the user's account. Hijacking a messenger profile is just the beginning of a two-step scheme. Daniil Borislavsky warned that after gaining access to the account, attackers can call a person on behalf of an "investigator" or "security service" to convince him to commit actions with money.
Psychological traps
The success of malicious schemes is largely due to the use of human psychology. Olga Kushnareva, a family psychologist and psychotherapist, explained that scammers imitate the communication style of familiar brands using their logos and polite tone. The human brain sees familiar elements and perceives correspondence as safe, especially if the user is really waiting for confirmation of a service.
"The main trick of scammers is the substitution of trust. They don't try to convince from scratch, but build on the existing trust in the brand. A person does not trust a specific account, but a familiar name, interface, and logo. Then they include urgency: "you need to confirm now," "otherwise the booking will be canceled," "there is little time left." At this point, a person begins to act faster than they think. And that's exactly what scammers need," Olga Kushnareva said.
People become especially vulnerable when traveling due to the high information load. Attempts to scare by canceling a reservation or demanding to "urgently save the situation" force a person to act faster than he has time to think. Psychologists recommend pausing when an alarm occurs and checking information only through official applications.
What to do in case of data theft
An information security expert stated that if the data has already been transferred to intruders, you must immediately log into your account from a trusted device and end all active sessions. After that, you should change your password and enable two-factor authentication. The incident must be reported to the official support of the service through the website or application, bypassing links from suspicious correspondence.
In cases where access to government services or banking information is compromised, Borislavsky advises contacting a financial institution separately to warn about the risks. The main rule of protection remains the refusal to follow instructions inside suspicious chats and the transition to manual verification of data in official sources.
Переведено сервисом «Яндекс Переводчик»