1

Case Study: Online Fraud and Cyber Hygiene

Désolé, cet article est seulement disponible en en et ru.

What’s wrong?

Recently Kateryna Kobernik, editor-in-chief of Ukrainian magazine « Babel », ordered a tablet on the OLX platform and was left with nothing.

The cybercriminal faked the official service number and sent her an external form to enter the credit card data. After she transferred 14 thousand hryvnias, the seller disappeared. In her post on Facebook, Kateryna accused OLX of ignoring security, but is it true and what does cyber hygiene have to do with it?

Who’s to blame?

In this case, the user made a mistake. Before purchasing something, each customer should read a complete usage guide, which states that in case of OLX delivery it is not allowed to go outside the platform – there should be no SMS, links, etc.

Imagine that you came to the shopping mall and bought a Louis Vuitton bag for 500 UAH. Then you found out that it was a fake, and started to demand explanations from the management of the shopping mall.  But they only rent out space. As well as the OLX does.

Regarding the possibility of phone number spoofing, it is a problem with systems that were created 40-50 years ago. « Quality modern applications are based on almost paranoid security, and about the old GSM mobile communications system we cannot say the same, » – says our Operations Director Vitaly Yakushev.

Therefore, it is possible to spoof the number. And you don’t have to be a hacker or a coder to do this. There is a lot of information about it on the Internet as well as ready-made services.

« You pay 1 or 10 UAH and can send SMS from any number to any number. That is why the rules are always the same: stick to the basics of cyber hygiene, be alert and careful, do not disclose financial information, and check where you enter data (even if the site looks identical), » – explains Vitaliy.

So how do you check who sent the message?

It’s very simple – just call and ask. If it is a service like OLX or bank – you need to call the support team. It is important to find a phone number on an official website by yourself, instead of using a number from the message you received. There are no other ways. Only a mobile operator can see the fact of phone number spoofing. And it is a privilege of engineers, not regular call center employees. To get this information, you need to file a complaint.

« It’ s important that people learn from their mistakes and think about security, rather than blaming everyone around them and stepping on the same rake again. We’ve launched a project about the daily cybersecurity on the internet called Cyber Nanny. You can also find there some short funny videos about shopping on the Internet, » said Vitaliy.

What if Internet fraud succeeded?

First of all, contact the OLX service to block the seller. And then file a complaint with the cyber police, where you specify the phone number of the scammer, give your account details, and all information you have. After that, you can cross your fingers and hope that the scammer was inexperienced and left a digital trace.

Source: mc.today

Related Posts

card__image

Secure by Design: From Concept to Cybersecurity Imperative in 2025

Désolé, cet article est seulement disponible en en et ua. In a rapidly evolving digital landscape, the Secure by Design (SbD) philosophy is proving strategically essential and measurably effective. A report from Secure Code Warrior, analyzing data from 600 enterprise customers over nine years, found that large organizations that train developers in secure-by-design practices can […]

card__image

CrowdStrike’s 2025 Threat Report: GenAI Powers Social Engineering Attacks, Chinese Cyber Espionage Jumps 150%

Désolé, cet article est seulement disponible en en, ru et ua. CrowdStrike’s 2025 Global Threat Report highlights a sharp increase in cyber activity linked to China, alongside a rising adoption of GenAI and escalating attacks on cloud infrastructure. The report delivers a stark warning to business leaders: underestimating adversaries comes at a significant cost.   […]

Laisser un commentaire

Votre adresse e-mail ne sera pas publiée. Les champs obligatoires sont indiqués avec *