How do phishing and merchant scams occur?
Phishing and merchant scams involve tricking users into providing sensitive card details or authorising transactions under false pretences. These scams have evolved in recent years, often leveraging social media, misleading websites, and fake OTP prompts.
Types of Merchant and Phishing Scams
Scam Type | Description | Red Flags to watch out for |
Declined Transaction Scam | Fake online shopping sites prompt OTPs, then show "payment failed", pushing users to re-enter details. Scammers collect card and OTP data repeatedly. |
|
Phishing Scam | Impersonating official websites or channels by targeting individuals using emails, aiming to trick victims into clicking links and providing sensitive data |
|
Social Media Scam | Using spam emails and/or using social media platforms such as Facebook, Instagram, and TikTok to advertise their website and attract potential victims |
|
Online Shopping Scam | Fake websites that sell products at unrealistically low prices. Victims either receive nothing or poor-quality knockoffs. |
|
Hidden Subscription Scam | Victims sign up for free trials or samples and are unknowingly enrolled in difficult-to-cancel recurring billing. |
|
Travel Visa Scam | Fake visa application sites that charge high fees or sell your information. |
|
Here's how these scams work:
- The Bait: Scammers create fake advertisements on social media or search engines, leading unsuspecting users to counterfeit e-commerce websites mimicking legitimate platforms.
- Data Phishing: Victims are prompted to enter their card details to complete a "purchase," where scammers steal this information. They may even display a fake two-factor authentication (2FA) confirmation page to appear secure.
- Card Exploitation: Scammers use the stolen details to link the victim’s card to mobile wallets like Apple Pay or Google Pay. Submitting card information unknowingly permits scammers to add the card to their device.
- Rapid Transactions: Once linked, scammers use the wallets to make unauthorised purchases, often depleting accounts within minutes. Most of these transactions originate overseas.
⚠️ Note: YouTrip does not send OTPs for transaction confirmations. Instead, you must swipe within the app to approve 3DS authorisation.
How YouTrip Helps Protect You
- 🔔 Instant alerts: Get real-time push notifications for all transactions and mobile wallet link attempts
- 🔒 Card lock: Instantly lock your card from the YouTrip app if you notice suspicious activity
-
⚙️ Custom limits: Set transaction limits
If you notice an unfamiliar transaction in your account, read our FAQ article What should I do if there are unrecognised transactions in my YouTrip account? on what you should do next.
If you are a victim of fraud or scam, read our FAQ article What do I do if I'm a victim of fraud or scam? on what you should do next.
If you're certain that you did not make the transaction, temporarily lock your card using the YouTrip app and contact us via fraud-reporting@you.co immediately, or call us at +65 6904 9334 instead.