On this Carousell Ride, the Crooks Take the Brass Ring.

Stu Sjouwerman | Aug 22, 2022

ICrooks Take the Brass Ringn a variation on a recently seen theme in which scammers pose as buyers on e-commerce platforms, victims in Singapore are being taken in by people offering to buy goods from them.

Carousell is a popular (and legitimate) Singapore-based consumer-to-consumer and business-to-consumer platform on which people can buy and sell both new and second-hand goods. The contact message from the scammer typically reads something like this: “I would like to pay for an item via FedEx. It’s easy. I will need your phone number to place the order, now I will send you a link to receive funds for the goods, you confirm the transaction and receive the money for the goods,” etc.

The link to “receive funds” is malicious, designed to harvest the victim’s banking credentials. The victims have been realizing something is amiss only after they find unauthorized transactions on their accounts. The Singapore Police urge anyone with information about the scam, whether they’re victims or witnesses, to call the police hotline or report what they know online. So far people have lost more than S$17,000 to the scammers.

This is a scam directed against consumers, but it’s not difficult to see how similar approaches might be made to employees of a business, especially of business-to-consumer firms whose transactions include trading over e-commerce platforms. New school security awareness training can help your employees spot scams like the ones currently taking a ride on Carousell.

The Star has the story.

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.