A Nigerian Twitter user has exposed a new social engineering scam that steals the identity of Nigerians living outside the country. The scam implicates fintech, PalmPay, which does not confirm the identity of users, as the user claims.
How does the PalmPay scam work?
The user, @thetobigeorge, claimed that the scammers create a WhatsApp account with your details as soon you relocate out of the country and then, create a bank account with PalmPay using your name. Since the fintech does not require identification, the bad actors can use any name, including yours.
The next thing they do is browse through your social media and collect contacts of people in your online circle, that is, users who you exchange comments with and so on. Then, they wait until it is night wherever you are and start reaching out to these people on WhatsApp, asking for help.
They go to your Instagram comments and look out for people who engage the most with your posts. They get their numbers, I can’t figure out how they do this.
They wait till it’s night time wherever you are. They start to reach out to these people on WhatsApp to ask for help. pic.twitter.com/G0AWDSn5Xf
— Tobi (@thetobigeorge) October 20, 2022
Their request is usually urgent, they ask you to send Naira for them to their account because they were having issues with their contact or something like that. It is easier to believe that you are getting your money back when they sound so sincere and in haste, also, the Dollar, Pound, or Euro equivalent usually looks so small that victims quickly do them the ‘favour’.
Also, since they are asking at night time where you are, even potential victims with some doubt may be unable to reach you through Instagram or Twitter DM, which is where they know you from. And if the ‘mark’ proves too difficult and keeps asking uncomfortable questions, they block them and move on.
While the scam does not result in personal loss for you, it could create distrust and it is affecting real people. So, what can you do?
What you can do:
Most people who relocate set their Instagram accounts to private to ensure that not everyone can follow their online activities. Although, this may mean losing out on some engagement.
In addition, don’t share sensitive details about yourself with strangers on the internet. If bad actors get hold of these kinds of info, they can pass themselves off as you more effectively. You can read more tips on how to escape social engineering here.
Meanwhile, it goes without saying that PalmPay needs to begin putting checks in place to make it harder to abuse its no verification policy. It is curious that as of when this article was published, the fintech had not issued a statement concerning the story.
For your daily dose of tech, lifestyle, and trending content, make sure to follow Plat4om on Twitter @Plat4omLive, on Instagram @Plat4om, on LinkedIn at Plat4om, and on Facebook at Plat4om. You can also email us at firstname.lastname@example.org and join our channel on Telegram at Plat4om. Finally, don’t forget to subscribe to OUR YOUTUBE CHANNEL.