Types of Fraud
Social Engineering
It is a practice used by criminals to obtain personal, work, or financial information through deception. It works as follows:
The attacker identifies you as a victim and collects your data
Establishes contact seeking to gain your trust
Uses manipulation techniques to achieve the goal of extracting your information
The attacker will try not to leave traces to access again if desired
What tactics do attackers use?
They impersonate trusted brands or authority figures
They induce fear or a sense of urgency
They take advantage of the goodwill or curiosity of the victim
Social Engineering Methods
Phishing
Identity theft through fraudulent emails.
Vishing
Obtaining financial information through deceptive phone calls.
Smishing
Looking over the shoulder when someone enters sensitive information.
Shoulder Surfing
Looking over the shoulder when someone enters sensitive information.
Dumpster Diving
Searching through trash to retrieve useful information.
Hunting
Performing a single interaction to affect the largest number of users.
Farming
Establishing multiple interactions with the victim to obtain information and plan an attack.
Spoofing
Identity theft to download malware or viruses.
Other types of fraud
Other types of fraud can also occur in the following forms:
- Banking: It is the use of illegal practices to obtain money or benefits from a banking institution, such as document forgery or fraudulent use of cards.
- Computer or virtual: It is the use of digital means to commit fraud, such as identity theft, impersonation, or malware distribution.
- Electronic or telephone: It is the use of telecommunications, such as phone calls or emails, to deceive victims and obtain personal or financial information.
How to avoid these attacks?
Be cautious with the information you share, limit the personal and professional information you share on social media and other public sites, attackers often collect data from these sources to make their manipulation attempts seem credible.
Be careful with Phishing emails, avoid clicking on links or downloading attachments from suspicious emails, pay attention to details, phishing emails often contain grammatical errors, dubious senders, or links that seem legitimate but are not, hover over the link to see the full URL.
Verify the identity of the person or institution before giving any information, use official contact methods, such as phone numbers from official websites to confirm that the request is legitimate.
Strengthen your passwords and enable two-factor authentication (2FA), use strong passwords (like a passphrase) and different for each account and enable the second authentication factor, by activating 2FA, an additional layer of security is added by requiring the additional code to access your accounts, even if an attacker has your password.
Be careful with the information you give over the phone, if a request seems urgent or unusual, contact the person or institution directly through an official phone number.
Review privacy options on social media and other public sites, limit who can see your posts and personal data.
If you identify a suspicious profile or unusual behavior on social media, report it to: contactenos@fna.gov.co. This way, you can alert other users and prevent them from falling into cybercriminal traps.
If you are a victim of cybercrime, such as personal data breach or website impersonation, report it through the following channels:
Go to www.caivirtual.policia.gov.co
Provide your name, surname, and email. You can chat with authorities and report your situation.
Select the "CAI VIRTUAL" option.
Use social media to share your report, tagging @caikirvirtual.
