Account takeover
Criminals take over their victims’ accounts. They often obtain the necessary login details through phishing or by infecting the device with malware. For example, this could be done with accounts with online shops, e-banking, TWINT and other payment services. If criminals gain access to an account, they can make purchases ostensibly on behalf of their victim, initiate or authorise payments, change limits or alter the password.
Typical warning signs
Be suspicious if:
you receive SMS codes or login notifications even though you haven’t made any login attempts or initiated any payments yourself;
you receive notifications about password changes or new device registrations that you did not undertake yourself;
you are asked to confirm authorisation in a card or banking app for alleged “security updates”, “card verifications” or “paybacks” / “refunds”;
you are informed, for example, that you have paid a bill to the Tax Office or your health insurance provider twice and will therefore receive a refund;
you are asked to confirm receipt of a payment from a third party.
Here’s how to protect yourself
Enable two-factor authentication if it is available.
Check payment requests and authorisations carefully. In particular, check the amount and the recipient, and cancel the authorisation if you did not initiate the transaction yourself.
In your card or banking app, only authorise transactions that you have entered yourself.
Never disclose access data, SMS and e-mail codes to third parties.
Never log in to your online banking or TWINT account to confirm an alleged incoming payment or a refund.