Plugging the 'hole' in personal data security

Gia Huy DNUM_BJZAHZCACD 08:41

(Baonghean.vn) - From July 1, 2023, Decree No. 13/2023/ND-CP of the Government on personal data protection officially comes into effect. This is one of the solutions to prevent and stop the increasingly increasing situation of information and personal data leakage and online fraud.

In trouble from personal information disclosure

Recently, many Facebook and Zalo users have had their accounts hijacked, and then the subjects used the accounts and personal information of the hijacked people to text many acquaintances to borrow money and appropriate property, causing many consequences. More dangerous is the trick of calling impersonating state agencies, functional agencies (police, prosecutors, etc.) to call the victims, informing them that they are involved in a case, a special case that the police are investigating, verifying, and have an arrest warrant from the People's Procuracy, etc.; asking the victims to declare their assets, current cash and the amount of money deposited in bank accounts.

cuoc-goi-lua-dao-8562.jpeg
Many forms of fraud through strange phone calls. Illustration: Internet

After that, the subjects used threatening words to the victims and asked them to transfer money or read the OTP code so that they could transfer money to their own accounts under the "cover" of verification and investigation. Although many victims did not commit any wrongdoings, the threats and urgings of the subjects led to anxiety and they were not alert enough to recognize the fraud.

Like student NTTTr. residing in Nghi Phu commune, Vinh city, is a student at a university in Ho Chi Minh City. In early 2023, Tr. received a call claiming to be a police officer investigating an illegal money laundering case, which also mentioned that Tr., in difficult times, had sold other people's information for money. The subject also sent a (fake) industry card to Tr. via Zalo. Then asked him to temporarily transfer money to the account he provided to serve the investigation.

According to the subject, after verifying that Tr. did not commit any crime, he would return the money. To strengthen the student's trust, the subject also sent Tr. a decision approving the temporary detention order of the Procuracy (forged) in which Tr.'s name, year of birth, ID card number, and address in Vinh City were recorded.

z4527637941016_6aa0b9f6a398b03c635a65bbf08a271c.jpg
The decision to approve the detention order of the Procuracy that the subject forged with full personal information to deceive NTT TR.

Panicked, Tr. transferred 5 million VND to the subject. After that, the person impersonating a police officer continued to ask Tr. to transfer more. Because he had no more money, Tr. called his mother and asked her to "transfer 20 million to me at the end of the day, I will transfer it back". Seeing that her child seemed panicked and worried, Ms. HTL, who was working at a press agency, asked the reason and discovered that her child had been scammed.

Similarly, on March 3, Ms. LTH (53 years old, residing in Dien Yen commune, Dien Chau district) received a phone call from a person claiming to be the Captain of the Economic Crime Investigation Team of Nghe An Provincial Police. This person informed Ms. H. that she had a large amount of money deposited at a bank whose information had been leaked, and that if she did not keep it confidential in time, she would lose the money. This person asked Ms. H. to provide her personal information and transfer 1 billion VND to an account under the name of Do Van Quynh at another bank for "confidentiality".

Believing the subject, Ms. H. immediately went to the bank transaction office to withdraw 1 billion VND from her savings book and transferred the above amount to the provided account number. After transferring the money, Ms. H. contacted the person claiming to be a police officer to inform her, but the phone was unreachable. Suspecting that she had been scammed, Ms. H. reported it to the authorities.

Upon receiving the report, the police force immediately requested the transaction office of the bank where Ms. H. deposited and transferred the money to suspend the above money transfer transaction. Fortunately, the above amount was promptly frozen by the bank to return to the victim. Although the authorities have continuously issued recommendations and warnings, the situation of people being scammed like the above cases still occurs.

bna-tang-vat-7068.jpeg
Fake ID cards (evidence of the case). Photo: Ho Hung

Recently, on July 3, 2023, the Criminal Police Department (Provincial Police) received a report from a bank branch about a group of people using high technology to appropriate a huge amount of property.

After a period of synchronous use of professional measures, the Criminal Police Department identified the perpetrators as Nguyen The Tuan (born in 1989) and Vo Trong Huy (born in 1988), both residing in Ha Tinh province. The Criminal Police Department arrested Tuan and Huy. At the same time, they urgently searched the residences of the two subjects. During the search, the authorities seized many fake ID cards, bank cards, 4G sim cards, documents recording information of bank accounts and passwords, etc.

The police agency determined: From May 2023 to July 2023, Nguyen The Tuan and Vo Trong Huy, as "henchmen", used fake ID cards to go to bank offices in Nghe An, Ha Tinh, Thanh Hoa provinces... to create fake bank accounts. Then they sold information including login passwords and OTP codes to a Telegram account named "HN" for prices ranging from 1 million VND to 1.5 million VND. With this method and trick, Nguyen The Tuan and Vo Trong Huy successfully carried out many transactions, earning large sums of money.

After purchasing fake accounts from their "henchmen", the subjects with the account name "HN" used tricks to hack into bank accounts to appropriate nearly 2 billion VND.

bna-2-doi-tuong-1650.jpeg
Two subjects Vo Trong Huy and Nguyen The Tuan. Photo: Pham Thuy

According to the assessment of the representative of the Criminal Police Department, this incident shows that this is a new method and trick of criminal activity. Criminals have taken advantage of loopholes in the security of customer information of banks, telecommunications services... to commit crimes.

According to statistics from the authorities from the beginning of 2023 to now, there have been 17 online scams in the province with 26 participants, causing losses of 5-7 billion VND. In addition to scam calls, many people are also upset with the behavior of calling to offer services or calling to harass, advertise...

Ms. Tran Thi Le, residing in Hamlet 2, Trung Phuc Cuong Commune (Nam Dan), said: “Many times, while I was busy with work, participating in traffic or taking a nap, suddenly someone called to offer to buy goods, services, buy real estate, introduced themselves as a TV station recruiting collaborators, announced that my subscription was about to be blocked two-way... which made me very upset. Sometimes I told myself not to answer the strange number, but because I was in business and was afraid that it was a customer's number, I had to answer the phone.”

In fact, many people encounter harassing and annoying calls like Ms. Le's case, but are helpless and have to press the mute button or block the number.

Raising awareness of personal information protection

Faced with the widespread disclosure and loss of personal data in cyberspace, on April 17, 2023, the Government issued Decree No. 13/2023/ND-CP on the protection of personal information. The Decree takes effect from July 1, 2023.

The issuance of the Decree regulating the protection of personal data is extremely necessary to prevent acts of personal data infringement, affecting the rights and interests of individuals and organizations; and to enhance the responsibility of agencies, organizations and individuals, first of all, of data processors, in the processing of personal data.

Nhóm đối tượng lừa đảo bằng hình thực gọi điện thông báo trúng thưởng sau đó yêu cầu chuyển tiền cọc để chiếm đoạt tài sản bị công an thanh chương bắt giữ. Anh tu lieu pham thuy.jpeg
A group of scammers who called to inform them of winning a prize and then asked for a deposit to appropriate property were arrested by Thanh Chuong Police. Photo: Pham Thuy

Article 8 of Decree No. 13 stipulates prohibited acts including: Processing personal data contrary to the provisions of law on personal data protection; Processing personal data to create information and data against the Socialist Republic of Vietnam; Processing personal data to create information and data affecting national security, social order and safety, and the legitimate rights and interests of other organizations and individuals; Obstructing personal data protection activities of competent authorities; Taking advantage of personal data protection activities to violate the law.

Notably, Decree 13 stipulates: Organizations and individuals providing marketing services and advertising product introduction are only allowed to use personal data of customers collected through their business activities to provide marketing services and advertising product introduction when there is consent from the data subject. Processing of personal data of customers to provide marketing services and advertising product introduction must have the consent of the customer, on the basis that the customer clearly knows the content, method, form and frequency of product introduction. Organizations and individuals providing marketing services and advertising product introduction are responsible for proving that the use of personal data of customers whose products are introduced is in accordance with the provisions of Clauses 1 and 2 of this Article.

Along with Decree No. 13, the Prime Minister also issued Decision No. 964 approving the national cybersecurity strategy, proactively responding to challenges in cyberspace until 2025, with a vision to 2030; Decision 1907 approving the project "Propaganda, raising awareness and disseminating knowledge on information security for the period 2021-2025". Implementing the Prime Minister's decisions, on June 26, 2023, the Ministry of Information and Communications issued Official Dispatch No. 2416 on participating in the Action Month campaign to propagate identification and prevention of online fraud nationwide, lasting until July 20, 2023.

Công an TP Vinh thực nghiệm điều tra nhóm đối tượng người trung quốc sử dụng thiết bị điện tử đánh cắp thông tin cá nhân làm thẻ ATM giả chiếm đoạt tài sản. Anh tư lieu PB.jpeg
Vinh City Police conducted an experimental investigation into a group of Chinese people who used electronic devices to steal personal information to make fake ATM cards and appropriate property. Photo: Pham Bang

The document stated: In recent times, incidents of information leakage, personal data, and online fraud have increased. One of the main causes of information insecurity is determined to come from users' awareness. Therefore, propaganda and dissemination to equip each individual with basic knowledge and skills to ensure information security on the network is a key factor in creating a safe cyberspace.

On that basis, on June 28, 2023, Nghe An Provincial People's Committee issued Document No. 5188 directing provincial departments, branches and unions; People's Committees of districts, cities and towns to actively participate in the "Month of action to propagate, identify and prevent online fraud" launched by the Ministry of Information and Communications to raise awareness and skills for officials, civil servants, public employees, students, people, agencies, organizations and businesses to ensure safety in cyberspace, accelerate the digital transformation process, and develop sustainable digital economic and social infrastructure.

Previously, the People's Committee of Nghe An province issued Directive No. 17 on strengthening solutions to prevent and combat high-tech crimes. It requires departments, branches, and organizations at the provincial, district, city, and town levels to direct the promotion of propaganda, dissemination of laws, and warnings about methods and tricks of criminal activities so that officials and people know and are vigilant. At the same time, proactively take measures to improve the security and safety of computer networks and data when connecting and accessing cyberspace.

12012023141-323.jpeg
Beware of fake calls. Illustration: Internet

However, in addition to the participation in warning and propaganda work; perfecting the system of regulations and sanctions that are strong enough to deter violations of the law on personal data protection; strictly handling acts of exchanging, trading, disclosing, and leaking personal information from the functional sector.

Each citizen needs to raise awareness in protecting personal information; consider carefully before providing personal information such as CCCD number, ID card number, bank account number... to others, limit sharing information on social networks, to protect themselves from the risk of information disclosure and leakage.

Featured Nghe An Newspaper

Latest

x
Plugging the 'hole' in personal data security
POWERED BYONECMS- A PRODUCT OFNEKO