FA-4.2 - Payment Fraud, Identity Theft & Account Takeovers

shedontluv-U

shedontluv-U

Busy rn , off my notifications for 1-2 hours
Joined
Feb 21, 2026
Posts
10,993
Reputation
28,949

FINANCIALLY AESTHETIC · GUIDE 20/37
PAYMENT FRAUD, IDENTITY THEFT & ACCOUNT TAKEOVERS

FA-4.2 · Scamproof & Financial Security
━━━━━━━━━━━━━━━━━━━━



THREAT MODEL

A stolen payment credential can become a broader identity and account-control problem.


Unauthorized Credit and Debit Card Transactions

Visa, Mastercard, American Express, and Interac are committed to protecting you from financial loss. This applies in the event of unauthorized use of your credit card or debit card.

You must take reasonable precautions to protect your account information and personal identification number (PIN). If you have done so, they will usually repay you in full.

There is a maximum amount for which you will be liable if someone uses your credit card without your authorization.

If your credit card issuer is a bank, this amount is $50. There is an exception if you were grossly negligent (in Quebec, “gross fault”) in protecting:

  • your credit card and the information about your credit card account
  • your personal information that you use to authenticate yourself. This includes your PIN, passwords, or any other personal information used to verify your identity

A federally regulated financial institution other than a bank may have issued your credit card. In this case, the maximum amount is the lesser of the following:

  • $50
  • the maximum amount set out in your credit card agreement

You are not liable for financial losses resulting from circumstances beyond your control. For example, technical issues or the use of your card after you have already reported it as lost or stolen.

Generally, the maximum amount you are liable to pay cannot exceed your debit card’s withdrawal limit. In certain situations, you may be liable for an amount greater than your account balance, for example if:

  • your account is linked to a line of credit or has overdraft protection
  • your account is linked to one or more accounts

Your Responsibilities

If a refund is possible, to receive a full refund, you must:

  • notify your card issuer immediately if:
  • you notice an unauthorized or suspicious transaction
  • you lose your card
  • you lose a mobile device used to conduct banking transactions or to store banking information
  • your card or mobile device has been stolen
  • Keep your PIN confidential and never reveal it to anyone, not even a family member
  • Avoid choosing a PIN that is easy to guess, such as a date of birth or a phone number
  • Use different PINs for different accounts and cards

Generally, these terms and conditions are similar across card issuers. Contact your card issuer or review your credit card or debit card agreement to verify the applicable terms and conditions.

The Right to an Investigation

Federally regulated financial institutions cannot hold you liable for a transaction made without your authorization simply because someone used an authenticator to complete that transaction. An authenticator can be a PIN or any other password or piece of information created to verify your identity.

A federally regulated financial institution must always conduct a thorough investigation into any unauthorized transaction you dispute. This applies regardless of how the person carried out the transaction, including by using:

  • your PIN
  • a magnetic stripe reader
  • another technology

Your financial institution should take into account all circumstances that contributed to the unauthorized use of your credit card or debit card. This includes circumstances beyond your control, such as:

  • you were coerced
  • your card was stolen
  • the system malfunctioned
  • someone obtained your card number, PIN, or password by looking over your shoulder while you were using your card at an ATM or elsewhere

In the Event of an Unauthorized Transaction

Contact your card issuer immediately if:

  • You notice that an unauthorized or suspicious transaction has been charged to your credit card or debit card account
  • you lose your card
  • your card has been stolen
  • you lose your mobile device used to make transactions or store banking information

These rights and responsibilities apply when you do business with a federally regulated financial institution. For example, a bank, a federal credit union, or a payment card network operator.


Identity Theft: Definition and Consequences

Identity theft refers to the use of personal information that identifies an individual without their consent to carry out fraudulent activities.

Identity theft is a crime involving the use of personal and/or professional data that identifies an individual without their consent, and impersonating that person to carry out fraudulent activities.

In practice, cybercriminals may have obtained this information following the loss or theft of the victim’s identification documents, through a phishing message (phishing in English), by account takeover of one of the victim’s online accounts or devices, by hacking a website where this information was stored, or even by scavenging through the victim’s trash.

Depending on the information gathered, scammers can commit various crimes in the victim’s name: creating accounts on social networks, defrauding loved ones, posting fake classified ads, defamation, cyberbullying, blackmail, extortion, or even opening a phone line or bank account, taking out a credit, renting a car, and more.

Beyond the emotional distress, identity theft can have very serious consequences for victims, who may find themselves prosecuted for crimes they will have to prove they did not commit.

How to Protect Yourself

  • Never share sensitive personal information (ID, passwords, social security number, etc.) via text message, over the phone, or online, nor share identity documents (ID card, pay stub, tax notice, bank account information, etc.) with individuals or organizations you have not verified with certainty.
  • Mark copies of any identification documents you send by writing the reason for sending them, the date, and the recipient on the document to prevent your documents from being reused for fraudulent purposes.
  • Provide only the minimum amount of personal information that is absolutely necessary when registering on a website or online service. Whenever possible, use pseudonyms instead of your first and last name.
  • Be careful who you talk to online or over the phone, as cybercriminals also use digital tools (social networks, email, etc.) as well as the phone (text messages, calls) to impersonate official organizations or people you know in order to steal your personal information.
  • Check the privacy settings for your personal information (phone number, email address, etc.) and your posts on social networks to ensure they are not publicly visible.
  • Check your bank account statements regularly to identify any unusual transactions.
  • Keep your personal and banking information, as well as your identification documents, in a safe place to prevent them from falling into the wrong hands.
  • Shred all documents containing personal information before discarding them. They could be recovered and used by criminals to your detriment.
  • Use different, complex passwords for each website and app. If one of your accounts is hacked, there is a risk that cybercriminals will gain access to your more accounts that use the same password.
  • Enable two-factor authentication whenever the website or service supports it, to strengthen the security of your accounts and reduce the risk of account takeover.

What to Do in Case of Identity Theft

1\. Keep all evidence in your possession and take screenshots. Depending on the situation, this may include: the account name and address, messages, web page URLs, supporting documents, or any other information that may help you report the incident. These items will serve as legally admissible evidence in the event of future legal proceedings.

2\. Report the identity theft directly to the relevant organizations, whether it involves a social network, an email provider, or any other type of organization.

3\. File a complaint for each instance of identity theft at a police station or gendarmerie station, or in writing with the public prosecutor’s office of the court with jurisdiction over your area. Keep a copy of each complaint for use in your dealings with financial institutions, government agencies, etc.

4\. Immediately notify all banks or financial institutions where you have an account that you have been a victim of identity theft. If your banking information has been stolen, freeze your accounts immediately. The cybercriminal could carry out certain transactions without your knowledge, such as opening a bank account or taking out a credit.

5\. Have your identification documents used by the scammers canceled and replaced.

6\. Submit a sworn statement to all organizations that are holding you responsible to prove that you did not commit the alleged acts, attaching a copy of the police report you filed.

7\. Contact the Banque de France to report the incident and verify whether any credits have been taken out or a bank account opened without your knowledge. Also check the Central Check Registry (FCC), the Registry of Consumer Credit Repayment Incidents (FICP), and the National Registry of Bank Accounts and Similar Accounts (FICOBA) to verify whether any fraudulent transactions have been carried out in your name.

8\. Notify your contacts so they do not become victims themselves of malicious individuals who might contact them by engaging in identity theft.

9\. Secure your email and social network accounts: If the identity theft was made possible by the account takeover of one of your email or social network accounts, follow the advice for dealing with account takeover detailed below.

10\. For guidance on what to do, contact the Ministry of the Interior’s Info Escroqueries platform at 0 805 805 817 (toll-free call and service).


Account Takeover

Account takeover refers to the takeover or fraudulent use of an account to the detriment of its rightful owner. This can involve email accounts or apps, social network accounts, government websites, or e-commerce platforms.

In practice, attackers may have gained access to your account in several ways: your password may have been too simple; you may have previously fallen victim to phishing, in which you unwittingly disclosed your password; or you may have used the same password on multiple sites, one of which was hacked; or, in some cases, due to the presence of a password-stealing virus on one of the victim’s devices.

The goal is to steal personal, professional, and/or financial information for fraudulent purposes (reselling data, identity theft, fraudulent transactions, spam, etc.).

How to Prevent Your Account from Being Hacked

1\. Use different, complex passwords for each website and app you use to prevent cybercriminals from accessing more accounts that use the same password if one account is hacked.

2\. When the website or service allows it, enable two-factor authentication to increase security.

3\. Never share sensitive information (such as passwords) via email, over the phone, or online.

4\. Regularly and consistently install system security updates for your system and the software installed on your computer.

5\. Keep your antivirus software up to date and enable your firewall. Make sure it only allows legitimate applications and services through.

6\. Do not open emails or their attachments, and never click on links from chain messages, unknown senders, or a known sender whose message content is unusual or empty.

7\. Check the website address displayed in your browser. If it doesn’t exactly match the intended site, it’s almost certainly a fraudulent site. Sometimes, a single changed character is enough to mislead you.

8\. If the site allows it, check the date and time of the last login to your account to identify any unusual logins.

9\. Avoid logging in on a public computer or Wi-Fi network. Since they aren’t under your control, they could be compromised by a hacker.

10\. Always log out of your account after use to prevent anyone from accessing it after you.

Account Hacked: What to Do

1\. If you can no longer log in to your account: contact the relevant service to report the account takeover and request a password reset.

2\. As soon as you can log in to your account, make sure your phone number and recovery email address are correct: if these contact details do not belong to you, save the evidence (screenshot, photo) and immediately delete these unknown email addresses and phone numbers. Cybercriminals may have entered them to maintain control over your account or your communications. For an email account, check its settings to ensure there are no forwarding rules or filtering rules in place.

3\. Change your password immediately: Change your password as soon as possible and choose a strong one. Use different, complex passwords.

4\. Enable two-factor authentication: If you’ve been hacked and this option is available on the relevant website or service, enable two-factor authentication: this will prevent such a hack from happening again by requiring an additional confirmation code - known only to you - for any new login attempt to your account.

5\. Log out any unknown devices or active sessions from your account: Check your login history in your account settings. If you identify any active devices or sessions that do not belong to you, save the evidence and then log out of or remove these suspicious connections. Otherwise, the cybercriminal might still be able to stay logged into your account even after you’ve changed your password.

6\. Immediately change the compromised password on all other websites or accounts where you may have used it: this will prevent malicious individuals from hacking into those other sites or accounts and causing you further harm.

7\. Notify all your contacts about this hack so they don’t become victims themselves of cybercriminals who might contact them by engaging in identity theft.

8\. Check to make sure no posts or orders were made using the hacked account. If they were, save any evidence, delete those posts, or cancel those orders by contacting the relevant service if needed.

9\. Notify your bank: If your bank information was available on the hacked account, monitor your accounts, notify your bank immediately, and, if needed, block the affected payment methods.

10\. File a police report: Depending on the harm you believe you have suffered, file a report with your local police station or gendarmerie unit. If your email or social network account has been taken over and the hacker is demanding something from you in exchange (money, goods, or services) or is attempting to defraud your contacts through identity theft, you can also file a complaint online via the Ministry of the Interior’s THESEE platform.

Testimony from a victim of account takeover

“Some of my family members called me because they were very worried after receiving emails from me saying that I had a serious illness and needed money. The next day, my bank advisor called me to ask me to confirm that I had indeed authorized the transfer request I had supposedly sent him by email.


In panic, I checked my emails and saw that messages I hadn’t sent had been sent to all my contacts. I never thought I’d fall victim to this kind of scam, which I hadn’t really paid much attention to before. Since then, I’ve taken steps to secure my email account because I realize this type of hacking could have had much more serious consequences. ”


Email Account Hacking

Email account takeover refers to the takeover of an account by a malicious individual at the expense of its rightful owner, with the aim of stealing personal, professional, and/or financial information for fraudulent purposes (reselling data, identity theft, fraudulent transactions, etc.) as well as carrying out other malicious actions: for example, sending spam or phishing messages. In practice, the attacker may have gained access to the email account in several ways: a password that was too easy to guess, using the same password on multiple sites - one of which was hacked - or as a result of a phishing message; in some cases, even due to the presence of a password-stealing virus on one of the victim’s devices.

Signs to Watch For

Here is a list of the main signs that may indicate you’ve been the victim of an email account hack:

  • You can no longer log in to your account with your credentials;
  • You find emails in your sent items that you did not send;
  • You receive messages that you don’t understand or that are in response to a message you didn’t send;
  • People claim to have received emails from you that you didn’t send;
  • You receive a notification indicating an attempt to log in to your account from a device, location, or IP address you don’t recognize;
  • You notice an unfamiliar device in your login history;
  • personal information (last name, first name, date of birth, phone number, etc.) or your account settings have been changed without your knowledge;
  • You discover that rules for filtering or redirecting your messages have been set up without your knowledge;
  • you notice that contacts have been added to or removed from your account without your consent.

The biggest challenge with account takeover is realizing quickly that you’ve been targeted. In fact, most of the time, affected individuals only become aware of it when they accidentally discover that they’ve suffered a loss.


SIM swap (SIM swapping)

A Subscriber Identity Module (SIM) card is a microchip that stores mobile network user information, such as the phone number and the authentication key used to provide network access.

Given the information they store, SIM cards are prime targets for threat actors.

SIM swapping is an attack that targets your mobile phone account and transfers your phone number to a threat actor’s SIM card or eSIM without your knowledge. This attack is also known as SIM swapping or SIM card hijacking.

If a threat actor successfully carries out a SIM swapping attack, they can use their device to intercept communications intended for you and impersonate you. This type of fraud also allows access to more accounts - such as your bank account - that use your phone number as a method of identity verification.

How SIM Swapping Works

Threat actors attempt to perform SIM swapping by following a process similar to the one mobile carriers use when transferring a phone number from an old device to a new one during an upgrade. Threat actors may attempt to transfer their victim’s phone number to their own device by calling the mobile network provider and fraudulently impersonating their victim. They can bypass standard identity verification security measures by searching for personal information shared online.

Threat actors may also attempt to access mobile phone account information on the provider’s website to initiate and authorize a SIM swap. They use stolen usernames and passwords to carry out credential stuffing attacks or collect personal information posted online or on social media to answer security questions during authentication.

SIM swapping can occur due to an insider threat. Employees and others with internal access to a mobile service provider may authorize changes to a customer’s account and sell spoofed SIM cards.

Consequences

If your SIM card is compromised, the threat actor will receive your calls, text messages, and notifications on their device. Since mobile devices have become a form of authentication, a threat actor can impersonate you to access your accounts and information.

SIM swapping poses several risks to individuals. A threat actor can:

  • alter and steal other account credentials;
  • prevent you from accessing and managing your account;
  • steal your money and financial information;
  • control and process information passing through your personal accounts;
  • impersonate you and commit fraud against your contacts.

Signs of SIM swapping

There are signs that can help you recognize when a threat actor is attempting to impersonate you or when your SIM card has already been impersonated. For example:

  • an unusual decrease in the number of messages received on your device;
  • the absence of verification messages for AMF;
  • phishing messages asking you to verify your account by entering a personal identification number (PIN) or clicking a link to log in;
  • messages indicating activity on your account that you do not recall;
  • changes to your account information that you did not make;
  • loss of access to online accounts (e.g., bank account, email, social media);
  • unknown transactions on your accounts;
  • loss of cellular network connectivity.

If your SIM card has been compromised through SIM swapping, you will not have access to cellular service or Wi-Fi calling capabilities. Remember that a sustained Wi-Fi connection can keep your data connection active. If you switch between the cellular network and Wi-Fi automatically and frequently, you may not immediately realize that your SIM card has been compromised.

How to Protect Your SIM Card

It’s important to take preventive security measures to reduce the risk of falling victim to SIM swapping. The best ways to protect yourself include the following:

  • Use any verification requirements offered by your service provider to protect your account;
  • Ask your service provider to enable access protection or lock the SIM card to your account, if possible;
  • Enable AMF (two-factor authentication), which includes methods other than your phone number (for example, a PIN, biometrics, or an authentication app);
  • Keep sensitive information related to account security private (for example, date of birth, home address, mother’s maiden name);
  • Use unique and separate email addresses for financial accounts and social media accounts;
  • Create different passwords and passphrases for each account;
  • Stay informed about security advisories from your service provider and security notices and notifications from the Canadian Centre for Cyber Security.


RESPONSE RULE

Lock the affected access, contact the institution through a trusted channel and preserve a timeline of every action.


 

Similar threads

shedontluv-U
Replies
8
Views
47
Klassek
Klassek
shedontluv-U
Replies
8
Views
71
shedontluv-U
shedontluv-U
shedontluv-U
Replies
2
Views
26
niggawhat
niggawhat
shedontluv-U
Replies
4
Views
42
shedontluv-U
shedontluv-U
shedontluv-U
Replies
9
Views
131
Brava
Brava

Users who are viewing this thread

Back
Top