Streamyx Customer Care vulnerable to social engineering-based attacks
Do you know that the simple security measure is from Streamyx?
Do you know that you can pretend to be someone when you call to Streamyx?
Do you know that people easily can get your personal information simply by calling Streamyx?
Oh! so you don’t believe it? Why don’t you try?
Ok first of all, you need to have username. Just think of any username that might be registered to Streamyx and then pick up your phone and start calling 100 or 1300888123 if from other OLNOS. Then Streamyx agent will pick up the call and start greeting. Let’s start.
-
Streamyx Agent: Thank You for calling TM (agent) speaking, how may i assist you?
Customer: My username is “whatsoever” (just think any of username that you might think it exist).
Streamyx Agent: Let me repeat back, your username is “whatsoever”.
Customer: Yes.
Streamyx Agent: Before we proceed, I need to do some verification, am I speaking to Mr A?
Customer: Yes.
Streamyx Agent: Mr A, is your contact number is 01X-XXXXXXX.
Customer: Yes (so do you got the number?)
Streamyx Agent: Alright, May i know what are the issue?
Customer: I need to check whether my billing address is updated or not? Could you tell me inside your system what is my current address.
Streamyx Agent: Let me check first Mr A, in my system shows that your billing address is XXXX. (so do you have the address? want to proceed more?)
PS: So still don’t believe in what I said? it’s all up to you to decide. Just another tips for you guys!
Wireless Broadband War – Part One TMNet Streamyx Combo
Social-engineering is one of the hackers popular techniques to gain info from the target.
ur right…
but still i have no coment on that..
depend on Streamyx laa…
Depends on people that assist you(customer)
Actually, they cannot read the billing address. If u want to know.
If u want to know that, they will ask the registered name,. ic number, and the service number. If u failed to give that information, they wont read.
tmadmin
>> if i twist my word like this * i just want to know with you my billing address since your TMnut bill are not being sent to me every month! and for *tut* what is my billing address?*
can i have it?
Firstly you are totally wrong..for tehnical support youcan get freely but for account info such as billing address they will asked security question such as ic, full name etc
Based on your statement I believe you are working w ith streamyx competitor or against the streamyx
may be to improve better on their call center?
funny hah? ok…let me explain..if 100 ask ur name, and the service number or login id that u want to report sometimes customer agreed to give and not talk so much just follow what 100 want..but for a few customer just want to give service number also refused..thats why when customer gave username (whatsoever) and it is match in 100 system they will serach at contact searching by the name that u given..if got they will reconfirmed the service number..if u want to cheat its up to you..at 100 side they are already passed the verification..and that only for the simple report..
but when it come up with to know more further..they will ask u registered name for streamyx, ic no and the address..if either 1 is incorrect they will not proceed till all the 3 things are match in 100 system..so if u want to know more try to call 100 again..
hahaha : did u know u just give to people on how u as 100 ( i’m assume) work?
u need to think out of the box for a while..
let me give you 1 good example.
you know 1 username of Streamyx user such as company.
How many people can be call MR CHAN? MR MUTHU? MR LIM? MR ALI?
So can if i’m guessing right… can i have their ctc number?