Automatically translated.View original post

Warning SMS crooks hit slick as official account 🤔

# Grow up and know that

Update the situation fresh, everyone. Yesterday we just met ourselves after a long silence. Now, the crooks SMS, also called Smishing, are back on the outbreak. This time it came in the hit concept, "Stale the Fines," but the attempt to hit the slick is a message that was included in the same Thread as our real Official Account! 😱

So today we took the data and showed you exactly what happened, why the hoax message was included with the real message, and how to deal with it. 💛

Why does fake SMS get into Official Chat? 📱

Many people may wonder why our mobile systems allow fake messages to mix with real OTP. The answer is that crooks exploit the vulnerability of sending SMS through a foreign network by naming the sender ID to match that brand or agency. Our mobile operating system, whether iOS or Android, will group the messages according to the "alphabet name" without checking who the real sender is. As a result, fake messages are pulled into the same chat window as the real message, allowing us to reduce caution and trust.

Fake SMS observation point. Where to see? 🧐

1.Context: Like us, the sender uses the name "Google," but the content is a penalty, which is not consistent at all. "Eh" is easy.

2.URLs are not official web: usually a strange link ending in .cc, .xyz, or a link that has been shortened.

3. Create panic: Like to use words that cause us to rush to make decisions, such as suspend accounts, take urgent action, freeze fines.

4. Request for Personal Information: The real agency will not ask us to enter OTP, password or account number through the link in SMS.

How to cope (Do & Don't) 🛡️✨

The safest iron rule is that if you encounter a strange message, whether it is a reward notification, a discount coupon, unsuccessful delivery or a problem account, do not click any link.

If you are not sure, use the call center directly. And most importantly, don't forget to press Report and Block those strange messages as a cyberprotection aid.

📍: AOC Center, online hotline 1441 24 hours a day, official bank / agency or 1212 hotline complaint center (ETDA), but from the DEA, if the money is lost is irrevocable or very difficult 😭, so we have to, uh, and be careful. Notifications only help not to be damaged further.

👉 Save This post is kept to remind yourself and share to those around you. Be careful of crooks.

✅ Page We are AI + Storytelling = Everyday magic 🌸.

# crook # Includes IT matters # IT should know # Known IT

3/19 Edited to

... Read moreถ้าใครเจอ SMS ชื่อ “ขยันบอก SCB” (หรือข้อความที่ดูเหมือนมาจากธนาคาร/แบรนด์ดัง) แล้วมีแนวๆ แจ้งเตือนด่วน ค้างค่าปรับ บัญชีมีปัญหา หรือให้กดลิงก์เพื่อยืนยันตัวตน—ขอให้ตั้งการ์ดสูงไว้ก่อนเลยค่ะ เพราะแพตเทิร์นแบบนี้มักเข้าข่าย “Smishing” คือหลอกให้คลิกลิงก์/กรอกข้อมูลผ่าน SMS จากที่เราเคยเจอและสังเกตเอง สิ่งที่ทำให้หลายคนพลาดคือ “มันมาอยู่ในเธรดเดียวกับข้อความจริง” เลยเผลอคิดว่าเชื่อถือได้ ทั้งที่จริงมือถือส่วนใหญ่จัดกลุ่ม SMS ด้วย “ชื่อผู้ส่ง (Sender ID)” เป็นหลัก ไม่ได้ยืนยันตัวตนผู้ส่งแบบละเอียด มิจฉาชีพเลยตั้งชื่อให้เหมือน/ใกล้เคียงกับของจริง แล้วส่งผ่านช่องทางที่ทำให้ดูเนียน พอมาอยู่แชทเดียวกัน ความระแวงจะลดลงทันที วิธีเช็กแบบเร็วๆ ก่อนทำอะไร (ใช้ได้กับเคส ‘ขยันบอก SCB’ ด้วย) 1) อ่านเนื้อหาให้จับ “บริบท” ก่อน: ถ้าชื่อดูเป็นธนาคาร แต่เนื้อหาเป็นค่าปรับ/พัสดุ/คูปองแปลกๆ หรือภาษาไม่เป็นทางการ ให้ถือว่าน่าสงสัย 2) ส่องลิงก์แบบไม่ต้องกด: ลิงก์ที่เป็นโดเมนแปลกๆ (.cc .xyz) ลิงก์ย่อ หรือสะกดคล้ายของจริง (ตัวอักษรสลับกัน) เสี่ยงมาก 3) ข้อความที่เร่งให้กลัว/รีบ: คำว่า “ด่วนที่สุด”, “ระงับบัญชี”, “ภายใน 24 ชม.” มักใช้กดดันให้เราคลิก 4) ถ้าขอข้อมูลส่วนตัว/OTP: หน่วยงานจริงแทบไม่ให้กรอก OTP/รหัสผ่านผ่านลิงก์จาก SMS ถ้าเผลอกดลิงก์ไปแล้ว (แต่ยังไม่กรอกอะไร) - ปิดหน้าเว็บทันที และอย่าดาวน์โหลดไฟล์/ติดตั้งแอปเพิ่ม - ล้างประวัติ/แท็บเบราว์เซอร์ และสแกนเครื่องด้วยแอปความปลอดภัยที่เชื่อถือได้ ถ้าเผลอกรอกข้อมูล/รหัสผ่าน/OTP ไปแล้ว - รีบเปลี่ยนรหัสผ่านทันที (เริ่มจากอีเมล/บัญชีธนาคาร/โซเชียลที่ผูกกัน) - ติดต่อธนาคาร/หน่วยงานผ่านเบอร์ทางการ เพื่ออายัด/ตรวจสอบธุรกรรม - เก็บหลักฐาน: แคปหน้าจอ SMS, ลิงก์, เวลา, เบอร์/ชื่อผู้ส่ง แล้วแจ้งศูนย์ AOC 1441 หรือ 1212 (ETDA) ทริคที่เราใช้กันพลาด: “ไม่กดลิงก์จาก SMS ไม่ว่ามันจะดูทางการแค่ไหน” ถ้าจำเป็นต้องเช็กจริงๆ ให้เข้าแอปธนาคารเอง หรือพิมพ์เว็บทางการเองในเบราว์เซอร์ (ไม่กดจากข้อความ) จะปลอดภัยกว่ามากค่ะ