IDENTIY THEFT RESPONSE FROM VODACOM
<p>Date: 19 January 2017</p> <p> </p> <p>Name of customer: Mrs. Annalize McPetrie</p> <p> </p> <p>Via email: ********** <p> </p> <p>Dear Mrs. McPetrie</p> <p> </p> <p>VODACOM (PTY) LTD (“Vodacom”) / YOURSELF</p> <p> </p> <p>CELLULAR NUMBERS 082 *******</p> <p> </p> <p>Your query regarding the above mentioned cell phone numbers refers;</p> <p> </p> <p>The SIM swaps to the above numbers was done as follows;</p> <p> </p> <p>1st SIM swap was done on 21/11/2016 17:18</p> <p>2nd SIM swap was done on 01/12/2016 14:12</p> <p>3rd SIM swap was done on 02/01/2017 15:20</p> <p> </p> <p>Our investigations and analysis have revealed that the SIM Swaps was unauthorised and **********.</p> <p> </p> <p>In general, ********** sim swaps have the objective of intercepting mainly banking messages, verification numbers and one-time pins (OTP’s) sent via SMS for electronic banking transactions, and in other lesser instances *****ing airtime balances or loyalty points. ********** usually require a bank account details, including an internet banking password, and other personal identifying information which they obtain through phishing or smishing, prior to the sim swap taking place. The ********* also needs a cellular number which number may be obtained from various sources, including but not limited to consumer databases.</p> <p> </p> <p>As a result of development in technology and an increase in demand from business and customers, Vodacom introduced multiple ways in terms of which a sim swap can be requested. For the purposes of this incident, we wish to amplify that one of the ways in which a sim swap can be requested, is by way of a Vodacom Call Centre. It is imperative to note that each Call Centre agent is allocated a unique username and password, known only to them, so as to control access to the relevant Vodacom systems. It is apparent from our investigation at this point in time, that in this incident the unique username and password of the relevant Call Centre agent was **********ly utilised to ********ly manipulate the system and circumvent security processes to perform the sim swap. </p> <p> </p> <p>Past investigations have shown that methods such as “spyware” and “keyloggers” are being used effectively by syndicates / ********* to ********ly obtain personal information. Please note that advanced technology and software are in certain instances utilised by the syndicates / ********* which requires a lengthy and complex investigation and in most instances require legal access to third party systems and platforms. </p> <p> </p> <p>Vodacom is committed to combat any ******** transactions and continually upgrades their systems to detect and prevent sim swap *****. We would like to suggest that you report this matter to the South African Police and Vodacom will gladly assist the SAPS in their investigation wherever possible to successfully conclude this investigation and identify the perpetrators.</p> <p> </p> <p>Following our investigation, and whilst we sincerely regret any loss that you may have suffered, Vodacom denies that it was the cause of any such loss. In the circumstances, Vodacom disavows liability herein.</p> <p> </p> <p>We trust you will find the above in order and wish to advise that all our rights herein are and remain reserved. </p> <p><br /> <br />Daniel Makuwa<br /> Senior Investigator</p> <p>Forensic services <br /> Landline: 082 ********** </p> <p>Mobile: ********** 442<br /> Email : ********** /> Address: Vodacom Service Park, <br /> 082 Vodacom Boulevard, Midrand 1685<br /> www.vodacom.co.za</p> <p>Fax to email: ********** <br /> </p> <p>So my problem is - we RICA our cell numbers for private and business use. We give Vodacom access to all our personal and business documents. </p> <p>In this case did a sim swap on my business account number and who authorised it, I am the account holder, my staff cannot even upgrade without my authority. It is my number, my privacy. If Vodacom and or RICA protected the customer - me, ********** would not have been able to take money from my bank account as they need the cell number for the OTP.</p> <p>When I asked who did it, I was told it is third party information.</p> <p>It didn't happen once, but three times. Surely Vodacom is liable. Where is the first and second internal and external investigation?</p> <p> </p> <p> </p> <p> </p> <p> </p>
Dear Customer,
Thank you for making us aware of your complaint.
Kindly be advised that a consultant will make contact with you in due course to assist with your query.
***Please note*** Beware of phishing ****s.
Vodacom will not contact you via Whatsapp to request your personal details
Regards,
Vodacom Consumer Website Team
Dear Customer,
Thank you for making us aware of your complaint.
Kindly be advised that a consultant will make contact with you in due course to assist with your query.
***Please note*** Beware of phishing ****s.
Vodacom will not contact you via Whatsapp to request your personal details
Regards,
Vodacom Consumer Website Team
