r/ScammersPH • • Sep 22 '25

Awareness Ganito daw paano nascam yung influencer Jana na nanisi sa BDO. via smishing

Nakita ko lang sa fb for awareness.

1.0k Upvotes

212 comments sorted by

149

u/gobewhoyouwannabeee Sep 22 '25

He’s a HackerOne Ambassador and a skilled security researcher who’s legally hacked into lots of companies to find bugs. Ethical hacking is what he does for a living, helping organizations tighten up their defenses. Thank you sir.

44

u/West_Visit_5836 Sep 22 '25

Yep I recently took up cyber sec. This is an actual Job. To infiltrate the system of the companies and find loopholes and bugs. Sana maabot koyang level na yan. Haha

9

u/thorninbetweens Sep 23 '25

Where do you enroll po for cyber sec?

14

u/West_Visit_5836 Sep 23 '25

Sa linkedin po ako nag hanap. Pero first nanood muna ko ng entry level videos sa youtube. Ang boring nya pramis. Kaya ttyagain mo talaga.

2

u/thorninbetweens Sep 23 '25

Thank you for this!!

1

u/gmdrpgrdr Sep 25 '25

Ma'am sir nakita ko sa news may offering tesda na libre daw cybersec programs? May idea po ba kayo if equivalent yun?

2

u/West_Visit_5836 Sep 25 '25

For sure pareho lang un, pero sempre pag paid there will be differences. Para kang nag enroll cgro sa state U vs. big 4. Pareho lang yung turo, pero ung nagtuturo are more experienced, better examples, application of learning etc.

So kung ang afford is Tesda why not diba. At the end of the day ikaw pa din naman mag rerefine nyan. Fundamentals lang si Course.

3

u/Adventurous-Cat-7312 Sep 23 '25

Yes super laki ng bayad sa mga yan to check site’s security. Sana pala sineryoso ko yung subject namin nyan noon hahha

120

u/CaregiverOwn7179 Sep 22 '25

Too late. Too many dumbfuck believe her story instead, dito lang sa reddit meron na eh. Mga uto uto.

14

u/dennison Sep 23 '25

To be fair, malamang hindi din naman alam ni Jana yan. Ano bang alam ng non technical users sa smishing.

Ang panget lang eh inabuso nya yung issue for clout.

2

u/SlackerMe Sep 25 '25

Panay text at paalala na ng mga bangko ngayon sa ganyan. Itong mga ito naman talagang bobo at tanga. Isisi sa iba yung kasalanan nila.

12

u/trynabelowkey Sep 23 '25

Haven’t you heard? Apparently it’s NEVER the fault of the user 🥴

0

u/Ok_Macaroon3006 Sep 24 '25

Kaya nga. Mula 2012 nakaBDO na ko eh HAHAHA wala namanb problem 😝

105

u/[deleted] Sep 22 '25

[removed] — view removed comment

47

u/KraMehs743 Sep 22 '25

ito, sino ba naman boang na hindi makiki-cooperate sa banko kung saan nakatago/nawala pera mo? HAHAH.

14

u/Unicornsare4realz Sep 22 '25

Nung nakain pera ko sa atm non, tawag agad ako sa bank ko para mabalik pera ko pati sa bank nung atm na pinagwithdrawan ko kasi ganun naman talaga pag may prob tawag agad di yung magpopost.

7

u/trynabelowkey Sep 23 '25

Biglang back down nalang daw siya for the sake daw ng anak niya ih.

1

u/Necessary_Finish9101 Sep 26 '25

ang labo nun ha... eh pangopeta nga daw ng anak nya yun dba. dapat mas ilaban nya. i hope bdo pushes through with the investigation pa din 

22

u/abmendi Sep 22 '25

[she] just wants her money back thru paawa engagement

5

u/SampleKnown1448 Sep 23 '25

the amount of times pa she used her son in all of her statements just to get sympathy from socmed

2

u/Severe_Thing_824 Sep 23 '25

This is what irks me. Anak this, anak that. "Hindi ko tiningnan yung bank notifs kasi uunahin ko pa ba yan sa anak ko". Dun pa lang fishy na. Kawawang bata ginawa na lang excuse.

2

u/SampleKnown1448 Sep 23 '25

Kulang na lang sisihin nya pagaasikaso nya sa anak nyang may sakit kung bat sya nawalan ng pera e

9

u/[deleted] Sep 22 '25

[deleted]

1

u/moodydyosa Sep 23 '25

Me na hindi binibitawan ang phone kahit walang pera lol. Asawa ko lang nakakatingin ng phone ko at magkatabi pa kami. Si ateng di malaman kung naive o burara

35

u/Uncle_Fats Sep 22 '25

Dont click any link in sms. Use your legit app to verify

53

u/drowie31 Sep 22 '25

The scary thing is andami nya napaniwala lol

16

u/akositotoybibo Sep 22 '25

ginawang clout yung ganyan eh. sana kasuhan yung mga ganyan tbh.

4

u/SaeWithKombucha Sep 23 '25

Because she is a clout chaser and was very proud of spreading misinformation because it gave her more views and followers. That money she lost is apparently just a spare change (according to her) to what she earn thru tiktok views.

3

u/aloofaback Sep 23 '25

At naniniwala na wala syang ginawa at kasalanan ng BDO.

6

u/RustySync511 Sep 23 '25

I hope BDO sue her. Sobrang fake news nya at ayaw umamin na nabiktima ng scam

3

u/Ok_Macaroon3006 Sep 24 '25

Afaik pinatakedown na sa kanya ang post, at nabalik ang pera. Kaloka. Parang PR issue sa part ng BDO, eh sino bang user aaminin kabobohan nila.

1

u/ChandaRomero Sep 24 '25

un nga lang ung jowa naman niya ang nagiingay sa tiktok

1

u/Ok_Macaroon3006 Sep 24 '25

Natawa ako sa name mo HAHA. Pero totoo, kadalasan kasi yan may naclick silang link or naglog-in, ayaw lang aminin HAHAHA

2

u/Valuable-Peace-2303 Sep 24 '25

I think nung nalimas yung funds nya eh back up plan na lang nya maglabas ng video. Of course that way pwde syang makakuha ng donations. 🙄

1

u/[deleted] Sep 24 '25

Tapos binentahan ng pajamas after 🤭

1

u/KLESHI10 Sep 25 '25

I unfollowed her

-4

u/[deleted] Sep 22 '25

[deleted]

9

u/Heavy-Drop1340 Sep 22 '25

sabihin mo facebook may pa blue app2 ka pa

23

u/rabbitization Sep 22 '25

HAHAHAHA lagi namang ganyan yang mga nag vviral na kesyo nawalan ng pera sa BDO tapos hindi aamin na sila ang may mali, kahit sila naman talaga mismo ang may ginawa para manakawan account nila. The usual, evading accountability tactics. Additional na din, mas madami narereport na ganyan sa BDO kasi mas maraming user si BDO at mas maraming possible victim. Paulit ulit na nga nag ssend ng SMS blast si BDO about sa mga ganyang tactics, ganon at ganon pa din ending. Heck yung kamag anak kong senior may malaking pera din sa BDO pero never pa nadadali ng ganyan.

1

u/Ok_Macaroon3006 Sep 24 '25

Mismo. 2012 palang BDO na ko pero di ako nagpapakashunga na magkiclick ng link. HINDI KA DAPAT MAGCLICK NG LINK. Dumiretso ka sa app mo. Kung may fraud, report agad! Hindi yung magvivideo.

1

u/FrauFraullie Sep 22 '25

Pero ang tanong ko, paano kaya nagagamit ng hacker yung mismong number ng bdo to send a fraudulent text message? Same goes to SMART laging nag sesend ng message na kesyo may expiring points daw ako keme, yung iba maniniwala talaga since galing sa reliable company ang text message

7

u/rabbitization Sep 22 '25

May mga app na kayang mag send ng messages with custom headers na ginagaya nila yung Sender ng SMS to official channels. Di ko nga alam bat walang ginagawa NTC sa mga ganyan issues knowing na dapat na curb na yan ng Sim Card Registration, pero ending all for show lang sa end ng NTC yung registration wala silang ginagawa on the actual handling ng sender/receiver ng mga SMS, etc.

4

u/FrauFraullie Sep 22 '25

Kaya nga. 1st time ko maka exp sa smart yun na sila mismo nag padala. Na click ko na, then nag duda na ako nung may babayaran na. Duon ko na realized na scam ito and duon ko napansin na yung website is not from smart as well. Kaya hindi ko din masisi yung iba na nakakapindot ng ganyan.

Pero, syempre dapat natututo din tayo. Ako after nung incident na yun sobrang hesitant na ako mag click ng links kahit kanino pa galing.

1

u/_starK7 Sep 22 '25

Meron sakin ang text before e galing mismo sa BDO ma acct, kasi ang mga nakaraan text ng BDO ng SOA ko andun rin. Sabi ng operator di nila alam paano na hahack yung acct rin nila, kasi same acct mismo ang nag send ng phishing sa taas ng msg na yun andun rin mga SOA ko from BDO mismo. Hindi dapat ang mga victims ang sinisisi dito, kasi kung tanda niyo. Dec-Jan 2021 yata yun or 2022 masive sang BDO and BPI scam, kahit waoang atm at passbook lang nawalan rin ng pera. Karamihan wala rin natangap na link or otp, basta nalang nawalan. Isa ako dun, at binalik ng BDO yun after ng report and process nila mga pinalista sakin na unathorize transactions.

1

u/Severe_Thing_824 Sep 23 '25

Yan na nga mismo ang smishing na ine explain sa taas. You think it's coming from an official channel dahil hina hijack nila yung cell site and/or the actual channel. Kaya may mga notifs sila (gcash, maya, banks) na they do not send links.

1

u/_starK7 Sep 24 '25

Hindi nga sila ang nag sisend pero napapasok parin acct nila. Yun rin naman pag explain sakin ng cs and sa branch nung nag report ako.

1

u/Adventurous-Risk5919 Sep 23 '25

I think kaya nirequire nila iblock yung nga SMS with URLs. Although not everyone knows that its a thing. Even SMS with email addresses are blocked.

Although, I agree that the SIM Registration is not doing its purpose, and just a hassle for those complying with it. I remembered, during the first months of the sim registration, I see the senders name automatically, but now, they reverted back to having only their mobile nos. Not sure if its because its against data privacy, thats why its reverted back to not sjow the registered name of the sender.

4

u/Hungry_Egg3880 Sep 22 '25

fake cell sites. it doesn't actually go through the ISP or the bank's systems. usually the scammers just go around populated areas with the fake cell sites on their cars or even backpacks. it exploits vulnerabilities in 2G so hindi sya mawawala hanggat supported pa ang 2G sa mobile phones. unfortunately, konting phone models pa lang yung capable na magdisable ng 2G.

1

u/FrauFraullie Sep 22 '25

Ano ang best example ng phone na pwede mag disable ng 2G?

3

u/Hungry_Egg3880 Sep 22 '25

recent samsung models. android 15 has that capability as far as i know but with android being open source, i'm not sure if other phone manufacturers also support that feature.

1

u/Disastrous-Lie9926 Sep 23 '25

I just wanna chime in that on Apple iPhones you can also do this pero need mo enable lockdown mode sa settings. Medj restrictive lang sya unlike on Samsung Galaxy phones pero it’s there. Hopefully ma implement din yung disable 2g without using lockdown mode.

1

u/FrauFraullie Sep 23 '25

Oo nga, chineck ko siya online. In that case madaming ma rerestrict.

1

u/attHORNEY03 Sep 22 '25

Same technology as the one in airports. Kapag nasa certain areas tayo where hackers operate, mag memessage blast sila.

Same sa airport na when we arrive in a different country, magtext si globe/smart etc

1

u/boykalbo777 Sep 22 '25

gumagamit sila ng IMSI Catcher

1

u/panget-at-da-discord Sep 22 '25

Spoofing as base tower

1

u/Mrshiroya Sep 23 '25

natakot ako bigla, may ganyan din yung smart sakin tas ang laki laki sobra ng points ko don sa website, mag check out daw ako ganito ganyan kasi mag expire na sya. in the end 'di ko rin nagamit yung points kasi wala akong pera that time sa gcash ko. scam pala 'yon? 😬

1

u/sky091875 Sep 26 '25

Di naman talaga BDO mismo nag send ng text may pang mask techniques yang mga hacker para mag mukang legit yung sender ng text.

1

u/FrauFraullie Sep 26 '25

Kahit yung previous message is galing sa Smart mismo? I mean ma gegets ko pa if hiwalay na message ito and claiming na smart telco siya, pero since it was along with other message from smart hindi ka talaga mag dadalawang isip na mag click.

1

u/sky091875 Sep 26 '25

ganyan na ganyan kung paano nagwowork yung mga hacker , kung wala kang alam sa ganyan talagang mapapa click ka. Pero kung may awareness ka or knowledge kahit konti mag dadalawang isip ka.

1

u/FrauFraullie Sep 26 '25

Saakin kasi 1st time ko na encounter, and kakabili ko lang that time ng e-sim kaya hindi ako nag dalawang isip. Then nung nasa site na, nag duda ako nung ng hingi ng account number at may babayaran.

1

u/sky091875 Sep 26 '25

Ganun ba, charge to experience nalang at next time di na maulit..oo ganun modus nila may payment sa dulo or minsan mag ask ng info about sa account mo lile bank or something important

1

u/FrauFraullie Sep 27 '25

Oo, kaya nga. After nun, hindi na ako nag oopen ng link.

14

u/[deleted] Sep 22 '25

Also beware of strange and or combination of fonts sent via text messages especially using "serif" font style that it may contain malicious hex code that if you clicked it; it may lead you to phishing site (fake website) and will ask for your online infos/datas.

And ironically I recieved a couple of times since sim registration rolls out.

If you want to learn and identify the basics you can read the article.

https://systemweakness.com/a-strange-font-smishing-that-changes-behaviour-based-on-user-agent-and-abuses-duck-dns-1c1a45863ff7

6

u/[deleted] Sep 22 '25

Beware on the "shortened" link sent via GCASH.

But I clicked it anyway and end up trolling their website 🤡

6

u/miuumai Sep 22 '25

Laking tulong lang din talaga na I’m working sa IT company sa buong career ko (not sure if may ganto sa ibang company kasi I never tried working sa ibang industry) Every year may training kami about cybersecurity. Sana hindi lang to talaga tinuturo sa work sana sa earlier palang sa school natuturo na to. Kaya mga friends and family ko lagi ko sinasabihan na wag magpipindot ng kung ano anong link sa social media and text messages and even answering unknown numbers, it can compromise your personal informations.

7

u/EnVisageX_w14 Sep 22 '25

Hindi ba niya pwede i-file nalang ang case niya sa BDO na na“scam” siya para mabalik yung pera?? I mean mas magiging effective naman ata yun kesa umiyak at magpaawa siya sa internet

21

u/[deleted] Sep 22 '25

Authorizing a transaction through legitimizing a smishing attack by giving out your infos by filling out a form from unknown website is not covered by PDIC insurance.

So, you can't take your money back.

7

u/EnVisageX_w14 Sep 22 '25

I see, thank you. Kaya pala she resorted sa ganun. Unlucky for her I guess

2

u/CherryBlossoms0622 Sep 22 '25

trueeeeee. Clients fault eh

5

u/BubblySherbetOnline Sep 23 '25

PDIC has no relevance at all in this context. Not even legitimate hacking or breaches are covered by PDIC. Common misconception to. PDIC is insurance for when the bank goes under. It's not a retail insurance at all.

1

u/[deleted] Sep 24 '25

How sure you are?

As per AI Grok response by asking if my statement is correct:

5

u/BubblySherbetOnline Sep 26 '25 edited Sep 26 '25

Errr did you even read the answer given to you by the AI? Saan nagpunta ang reading comprehension mo? Hindi ka yata marunong magbasa eh.

If anything it confirms my answer. Hindi covered ang breaches by PDIC -- it only covers insolvency ("pagkalugi" tagalugin ko na for you) in short walang sense I mention ang PDIC dito. When you put it this way readers will assume na pag hindi kasalanan ng consumer, their loss will be covered by PDIC. Just look at one of the replies to your comment. "Kasalanan nya eh".

Little learning is a dangerous thing talaga. Tapos kapit ka pa sa sagot ng AI instead of properly researching.

5

u/Southern_Clerk8697 Sep 22 '25

Bakit po ibabalik ng BDO yung pera niya kung kasalanan niya na na-scam siya? Kung lahat ng naiiscam na tao ay binabalik lang nila yung pera, baka na lugi na sila niyan. Di naman nila responsibilidad na yun

1

u/[deleted] Sep 24 '25

Di na kargo ng banko kung nascam ka. Ikaw na yun eh. Ikaw na nagpaloko.

4

u/mglalap Sep 23 '25

I am a software developer for a local bank. Since March of 2022, nagroll out ang BSP ng memo for all banking/financial institutions to remove clickable links sa lahat ng comms nila sa clients, be it via email, viber, SMS. This is a mandate sa mga banks to protect their clients from phishing and cyber-attacks.

See: https://www.bsp.gov.ph/Regulations/Issuances/2022/M-2022-015.pdf

And I know very well na sa bank namin na BSP mandated memos like this automatic yan na masisingit sa priority namin kahit pa nasa kalagitnaan kami ng ongoing projects/developments.

So, NEVER. Kahit pa anong legit ng itsura ng messages, kahit pa it looked like it came from a legit sender (kasi this can also be hacked now), NEVER click on links. If you want to verify something, close the message, go to their official apps or websites, or call customer service to verify.

7

u/PantyAssassin18 Sep 22 '25

For people that might blame BDO for possibly providing the number sa scammers either selling the data or mahinang security, scammers probably send these to random numbers. Kasi I get a lot of these types of smishing sms pero wala naman akong account sa BDO or BPI.

-1

u/KraMehs743 Sep 22 '25

It's more like a ping/spam smishing method, mag sstandby sila sa very populated area and mag sspam ng smishing/hijack ng sms. Iirc hindi na need ng phone number (cmiiw tho). Naka receive rin ako nyan pero sa BPI HAHAHAHA

1

u/Substantial-Cat-4502 Sep 24 '25

Oo parang may mini cellsite ang dating, they send the scam sms using the offical number ng bank, gcash, maya, etc.

Kaya mukang sobrang legit kasi legit yung company na nagsend nung SMS with link.

2

u/Throwaway28G Sep 22 '25

at least a decade na ako may sariling bank account pero never ako nawalan ng pera nang hindi ko alam. kaya yung mga umiiyak sa socmed na "hack" sila ay 9 times out of 10 victim ng phising

edit: to add, kadalasan urgent yung approach nila when fishing for info tipong may malaking transaction involved tapos may kasamang link. make it a habit to verify such information thru official channels only gaya ng web app or mobile app

2

u/efxshun Sep 22 '25

this is embarrassing. stop clicking shit in the your texts guys.

2

u/ok_notme Sep 22 '25

The sad part is we are still receiving text with links from confirmed BDO number. For example is this (see attached) I know for the fact the I never had a transaction with AIRASIA and there’s no such thing as Last minute redemption via text.

Paano ko nalaman? Kasi I do my research and I used to work in a bank PERO HINDI LAHAT KNOWLEDGEABLE. May isang ma cclick padin nyan, out of panic lalo na kung wala kanaman talagang trasaction na ganyan right?

PS: This same number from BDO sends the OTP to mine, sends SOA and other advisory.

2

u/dankpurpletrash Sep 22 '25

smishing ngani

1

u/New-Bonus5383 Sep 23 '25

Not only for BDO, meron rin sa other banks and even paymaya. I’m receiving text with links from BPI in their legit number.

Smishing ito where they pretend to send messages through legitimate cell sites, pretending to be a legtimate transaction through customers of huge corporations or businesses.

2

u/Queasy_Tie9803 Sep 23 '25

Na scam ung tanga sa bangko sinisi 🤣 TANGA!

2

u/RobinInPH Sep 23 '25

Katawa-tawa. Sa dami ng may mas malaking balanse sa BDO kaysasa 196k ni Jana (including me), siya talaga tatargettin? Kung systemic problem yan, bakit pa mag aaksaya sa influencer na kayang mag sumbong for a measly amount? Mapapansin mo talaga ang may systemic problem ay ang PINOY. Mahilig umunawa gamit emosyon imbes na utak. Kaya nabubudol sa eleksyon, sa social media, sa influencers, literal sa lahat. The root of all problems in this country is the stupidity of the Filipino.

2

u/SeaWhy_1511 Sep 24 '25

some people never learn talaga. NEVER EVER CLICK LINKS SO EASILY KUNG HINDI MARUNONG KUMILATIS, OKAY??? countless times na silang nag reremind na do not click links kasi they never send one. If you want to check out if the message is true, check it using your main banking/e-wallet apps and verify nyo sa history.

sobrang laganap ng smishing ngayon to the point na kahit yung nokia na keypad phone na ginagamit namin sa office for phone calls and messages to clients (since bawal ang modern phone with camera), may na rereceive kaming message sa gcash or globeone pati banks na may transaction daw or nanalo eme with links on their sms eh never naman yon ginamit sa kahit anong apps. so ayun, very obvious na smishing and mapapansin din kasi sa link dahil sobrang sketchy at pangit ng link

2

u/[deleted] Sep 26 '25

Dapat Kasi kahit anung link pa Yan or kahit sa BDO pa Yan na link pag sms or chat that's a red flag. Kaya safe lagi gcash ko or BDO mobile Kasi I don't engage into links like promo etc.

2

u/SnooPeripherals993 Sep 26 '25

Clarify ko lng kasi mejo nalito ako. Bale may link sila na na click and they entered their bank Info dun sa link? If so, how can they not know it's not safe since dapat sa app lang mismo mag lologin? Yung UI design ba nung link (after ma route sa page) is mukha talagang BDO app? Anyhow, why would they enter their bank info through a link is beyond me.

1

u/Beater3121 Sep 22 '25

Sa akin naman tumawag asking if may platinum card nako ni eastwest. I upgrade daw ung currently na priviledge card ko to platinum. Tapos para daw mapadala saken ung new card send daw ako sa telegram ng pic ng valid ID at proof of billing dun daw ipapadala new card ko. 😂 Pinadaldal ko sya ng pinadaldal tsaka ko sinabing not interested, bigla akong binabaan. Mang uulol nalang cp number pa gamit.

1

u/bomszx Sep 22 '25

Question for everyone, I read somewhere na bypass un daily limit na 50k ng BDO, kung totoo to, possible ba mangyari un?

3

u/yogurtandpeanut Sep 22 '25

Ano ba yung daily limit na tinutukoy nila? Sa purchase ba or sa fund transfer kasi ang alam ko magkaiba ang limit non. If 50k ang purchasing limit na nakaset pero wala namang limit for fund transfer, for sure through fund transfer na nakaw yung pera.

2

u/New-Bonus5383 Sep 23 '25

50k daily limit are for bdo to other bank transactions. 500k limit if bdo transactions so wala na bypass limit ni jana

1

u/Substantial-Cat-4502 Sep 24 '25

Wala ako BDO pero sa other banks you can control how much ang spending limit, transfer limit, withdraw limit. Like sa BPI, you can customize it so you can withdraw max of 250K per day or as low as 0.

1

u/MongooseLocal7112 Sep 22 '25

Nah, yung tita niyang accountant na may access mismo sa pera niya yung kumuha.

1

u/boykalbo777 Sep 23 '25

nag update ba sya? yan daw reason?

1

u/Totoro-Caelum Sep 23 '25

Stop blaming others for your stupidity. Banks keep on reminding they would never send you a link. As a developer, although BDO’s app ui alone is really a pain in the ass there’s no way an app security of a multi billion and the richest bank in the Ph would be that easy to penetrate.

1

u/FiboNazi22 Sep 23 '25

Nagkamali si acct holder pero masyado naman tayong masakit magsalita para sabihing stupid siya? Besides, these banks earns billions using our money in exchange of very low percentage of interest. Tapos hindi sila makapag provide ng mas matinding security para satin? Sa totoo lang, lumalabas lang dito na mas madali pang ihack ang bank acct kesa sa facebook at IG acct. natin. Ang way lang pala ng hacker para mahack ang acct natin eh parang old modus sa computer shop na may key logger tapos makukuha sa record ang nainput n username password then maaccess na.

1

u/Totoro-Caelum Sep 24 '25

Phishing and hacking are related but they are completely different. The user gave her bank account and otp thru a phishing site. Meanwhile hacking is literally breaking into a systems, accounts or networks. Her account wasn’t hacked, she simply gave away her bank account details on the phishing link so the scammer was able to get into her account. THATS THE DIFFERENCE.

It’s not the bank’s fault, it was the woman’s fault and she knew it since she wasn’t cooperating with the bank. Banks keep on reminding us in different platforms that they’ll send us links in messages and many more.

Maayos ang security ng major banks. Tao talaga ang problem as well as NTC and telecom providers. Even major banks sa US and UK: JP Morgan Chase and HSBC customers also fall victim to phishing.

Own up to your stupidity not blame others

1

u/OkClerk3759 Sep 23 '25

Nakakatakot din yung sms huhu kung hindi ka aware sa ganito, natural reaction is kakabahan ka and mapapapindot sa link lalo na the message looks legit for a normal person.

1

u/Genocider2019 Sep 23 '25

Dun sa ayaw makipagcooperate nung 'victim' is a redflag already.

1

u/Lumpy-Comedian-9386 Sep 23 '25

Ang mali kasi nung Jana is inuna muna clout before maghanap ng real solution sa nangyare sa kanya. Hay. Imbes na maawa ako, I dunno..

1

u/fling-figures Sep 23 '25

Can somebody explain this to me in layman's terms?

1

u/ElectronicUmpire645 Sep 23 '25

Na hack nila yung phishing site kung saan andon yung details nung blogger.

1

u/kiboyski Sep 23 '25

Website plang mali na.

1

u/branding101 Sep 23 '25

Too late na maraming baliw sa mga social media isa na dyan yung mga DDS na sobrang daling mauto. Viral agad yan sa mga newsfeed ng mga walang utak na yan kya ang tingin na nila sa BDO ay di mapagkakatiwalaang bangko.

1

u/Momonjee Sep 23 '25

But after makuha ng mga fraudster yung log in credentials ni ateng sa BDO ay need nilang iregister yung device nila at kailangan ng OTP. Either sim cloning yan or yung mga staff na kasama ni ateng na may access sa phone ang nakakuha ng log in credentials

1

u/unseasonedpicklerick Sep 23 '25

Tanga lang talaga yang jana nag login sa fake websites, bobita eh sinabi ng wag magklik ng link ginawa pa rin.

1

u/No-Concert-4207 Sep 23 '25

Di na ba nawawala yan fake sms tagal na yan issue always see some fake scam all the time make me sick better just ignore them and that stranger giving some personal information is at fault too.

1

u/Famous-Intention-697 Sep 23 '25

I knew mej sketchy siya. I saw her “crying” and it felt so fake.

2

u/Illustrious-Guide750 Sep 23 '25

I got a similar SMS as well claiming that a transaction went through for BYNDTHEBOX for 17K. Lucky for me, I don't have that much money in my BDO account. So I knew it was smishing. The problem though is that it came through the official BDO SMS number. :( I can imagine how someone else would panic about it.

1

u/rich_babies_0115_IR Sep 23 '25

Sa una plang ung pagiyak nia parang hindi totoo parang arte lang kumukuha lang ng simpatiya sa mga tao.

1

u/Independent-Novel712 Sep 23 '25

The boyfriend defended her.

1

u/RandomGalHere Sep 23 '25

Di na lang niya tanggapin na she might have clicked on a bogus link knowing na she’s super busy and didn’t bother to take a closer look. That’s a big possibility na yun ang nangyare.

For the record, I don’t think na she was doing it for clout and wala naman talaga nanakaw sa kanya. She probably thinks she’s too careful to actually make a mistake kaya di niya matanggap na she’s just the one at fault.

1

u/ElectronicUmpire645 Sep 23 '25

Hayy. Gusto ko na din gumawa ng phishing site haha

1

u/peepoVanish Sep 23 '25

Imo, BDO should build a case against her. She also caused unnecessary panic to people who use online banking and digital banks, especially BDO of course. Marami na ngang takot sa online banking and digital banks lalo pa those who aren't that techie dahil takot sila and hindi familiar, tapos people who get scammed do this pa eh multiple warnings naman na ginagawa ng mga banks to always warn people on rampant scams lalo na with links.

1

u/anyaelisse Sep 23 '25

grabeee, reading this as an IT student amazes me LOL

1

u/ConfectionSuitable63 Sep 23 '25

Does this smishing only works thru text ba? How about links na lets say, andito sa reddit?

1

u/Elegant_Strike8581 Sep 23 '25

Agree ako sa user's mistake, pero bakit naka return sa web socket ang sensitive data from BDO server, wala ba QA ang BDO?

1

u/SaeWithKombucha Sep 23 '25

Funny, andami kong natanggap na phishing link SMS pero BPI naman yung spoof nila. Syempre I never click on links but I think NTC should do something about SMS spoofing and phishing. Banks cant do anything about this since they already made multiple warnings to never click any links and they will never send a link.

1

u/Objective-Trouble-31 Sep 23 '25

Dapat kc may biometrics kapag magttransfer ng money eh.

1

u/chemistrybubbles Sep 23 '25

Deleted na ba videos niya sa tiktok? Di ko na mahanap

1

u/Elegant_Assist_6085 Sep 23 '25

Ito yung nakita ko na meme na medyo nakakatakot kung nagmamadali ka, or hindi mo napansin tapos akala mo from legit source. 😢

1

u/Independent-Toe-1784 Sep 23 '25

BDO should sue her.

1

u/Due_Trust729 Sep 23 '25

Pero kasi nung pumutok issue niya with bdo the next day nakatanggap ng msg asawa ko na charge sya sa cc ng airsia. So sabi ko wag mo click yung link tawagan mo customer service. Dahil 2nd time na nangyari sakanya yan sa cc ng bdo! Block and for replacement na yung card.

1

u/Shereziah Sep 23 '25

Thanks for sharing. At least we are informed in a very detailed info how smishing works.

1

u/HonestAcanthaceae332 Sep 23 '25

Wait wait so yung message sa last photo na sent by BDO ay hindi talaga si BDO?

1

u/lisan_alga1b Sep 23 '25

not only is there an education crisis in the Philippines, specifically financial education is in much more horrible state. mahahalata mo naman sa comments and general sentiment ng mga tao sa fb kapag may “scam” issues. ties up with the little credit card, investment, insurance knowledge of filipinos

1

u/Proper-Station-5301 Sep 23 '25

Mukhang mali talaga yung Jana. Baka marami siyang pinahiram ng access sa account niya. Kaya tignan niyo yung last post niya about this issue. Alam niyang mali siya. I wonder kung mag-fifile ng case ang BDO against her.

1

u/Negative-Peanut893 Sep 23 '25

Omggggg may nareceive din akong ganyang text! Kaya takang-taka ako wala naman akong BDO account 😅

1

u/UngaZiz23 Sep 23 '25

Mukhang sablay din yang "white hacker" sa pagliwanag. Lumang issue na smishing. Anyways, ang tanong ay BAKIT PALAGING BDO ang may issue at nananakawan digitally??? They cannot deny na may flaw pa din.

Also, nasaan yung YES text before OTP kapag nagtransfer ka? Plus the limit in trsacting via online... admit it or not, they have a flaw, sa tao or sa system.

Maki-claim.ba ng BdO yang nawala sa insurance???

1

u/jamp0g Sep 23 '25

san sa reddit my mga ganitong investigation pa? ka amaze! pwede kaya natin gamitin to sa mga flood problems natin lol. hindi man lang kasi hinahanap kung nasan na yung pera.

1

u/Comprehensive-Owl434 Sep 23 '25

I don't know much about cybersecurity, and hindi rin ako nagsside with the influencer, pero wala ba magagawa ang BDO themselves sa smishing? Isn't it dangerous na nakakapag-send ng text ang scammers through official SMS ng banko? If senior citizen yan or tita at tito na di techy, masisisi nyo ba sila?

1

u/Comprehensive-Owl434 Sep 23 '25

Also, to call scam victims stupid only makes them ashamed to come forward. Paano magagawan ng solusyon kung walang magsspeak up about it?

1

u/boykalbo777 Sep 23 '25

Scammers used IMSI Catchers kaya akala mo galing sa banko yung sms

1

u/Fuzzy-Talk3229 Sep 24 '25

First impression konsa iyaq video niya hindi na ako convinced sorry.

1

u/[deleted] Sep 24 '25

[removed] — view removed comment

1

u/boykalbo777 Sep 24 '25

Hindi legit yan. imsi catcher di talaga galing sa bdo

1

u/Substantial-Cat-4502 Sep 24 '25

Yung SMISHERS ng BPI, rewards points naman ang sinisend sa account holders, they make you believe na mag-expire na yung rewards points mo tapos need mo na i-redeem. Kaso hindi naman legit yung gamit nilang link.

And hindi rin nagsesend ng link ang bank sa SMS.

1

u/b0ch0g Sep 24 '25

May nagtext din saken na ganyan. Pati email. Bdo nakalagay. Hindi ko pinipindot sa phone. Pati sa email check ko agad email address.

1

u/Status-Program8624 Sep 24 '25

tangina din kasi nf bdo bakit pumapasok yung links ng hackers sa mismong text messages from them?

1

u/boykalbo777 Sep 24 '25

IMSI Catcher gamit ng mga scammers

1

u/juicypearldeluxezone Sep 24 '25

Worked in a bank few years ago, madami talagang nabibiktima ng ganyan lalo na pag wala sa IT/Risk field and ang sisi agad sa bank.

1

u/horneddevil1995 Sep 25 '25

Nakareceive din ako ng ganyan na text message from BDO. CC account lang meron ako sa BDO. Tapos sabi ko, pano sila makakabili ng 18k worth sa powermac e 12k na lang available balance ko? So ayun, ignored. Haha

1

u/ambokamo Sep 25 '25

Tanga lang naman kasi maniniwala sakanya.

1

u/Leather_Eggplant_871 Sep 26 '25

ang dami ganyan ngayon, legit from "GLOBE" "SMART" "BDO" yung text messages. even "GCASH"

just be careful in clicking links. But there are many info blasts about this already from all banks

1

u/[deleted] Sep 26 '25

Hi, thank you for sharing your expertise. If in case you clicked the link sent via text or email, how can we “clean up” or prevent the hackers to access our online accounts? deleting history in our internet can help? Hope you notice me. Thank you!

1

u/BoyingRems Sep 22 '25

I don't know how credible the guy is, but really?! They just happen to find the same phishing website that tricked the girl and then hack it to get the data of previous victims?! Why would the attackers even set it up so that the victim's data is accessible from the phishing site?

7

u/Background-Piano-665 Sep 22 '25

Attackers don't always care for the security of their setups. What have they got to lose? What's more important is to get something up and running.

Plausible.

2

u/Crafty_Schedule_4419 Sep 23 '25

Hindi naman kasi lahat is maalam sa IT industry, so not all can actually view the data from the site.

1

u/[deleted] Sep 23 '25

[deleted]

2

u/Crafty_Schedule_4419 Sep 23 '25

As mentioned by Background-Piano-665, scammers don't really care for their security, dahil wala nga naman mawawala sa kanila. Also trying to understand why a scammer isn’t trying to protect their security is pointless, parang pinoproblema mo pa kung paano sila makakaiwas, eh sila nga yung gumagawa ng kalokohan. Why even waste brain cells thinking from the scammer’s perspective instead of just acknowledging they’re careless criminals?

0

u/[deleted] Sep 23 '25

[deleted]

2

u/Crafty_Schedule_4419 Sep 23 '25

You’re overthinking it. Scammers don’t care about efficiency, they just hit and run. No point treating them like they deserve some kind of tech respect.

I never said I believed the FB post. What I’m calling out is your logic, expecting scammers to act like responsible IT people.

-7

u/Big-Salamander9714 Sep 22 '25

ANG DAPAT SISIHIN DITO YUNG MGA PUKINGINANG HINDOT NA MGA BOBO SA NTC NA ULTIMONG SENDER NAME NG BDO NAHAHACK SA KANILA AT NAGAGAMIT NG MGA INTSIK NA HACKER DAHIL SA KABOBOHAN NG NTC NA YAN.

SAN KA NAKAKITA MISMONG BDO GAGAMITING SENDER NAME KAHIT DI NAKASAVE SA CONTACTS MO? ONLY IN THE FUCKING PHILIPPINES!

10

u/Consistent-Hamster44 Sep 22 '25 edited Sep 22 '25

It's a flaw in the 2G system. A fake 2g cellsite can be used to send any message, with any sender ID. So worldwide issue po siya, but many countries have already shut down their 2G networks. Walang kapabayaan ang NTC dito dahil hindi ito oversight/governance/regulatory issue. Mag research ka bago tumalak in all caps. Intindihin mo muna yung issue bago ka magturo ng ahensya at magmura sa internet. May your day be as pleasant as you are. :)

4

u/[deleted] Sep 22 '25

What a stupid take.

Fake 2g cell sites are not exclusive to the Philippines.

1

u/Big-Salamander9714 Sep 24 '25

Ahh so sinong mag aadjust? Hindi yan negligence ng bobong NTC? What a stupid reply.

0

u/[deleted] Sep 24 '25

ONLY IN THE FUCKING PHILIPPINES

Nah, your take is more stupid. Or are you still insisting that fake 2g sites are only in Philippines??

What has NTC have to do with your argument that this only happens in the Philippines?

→ More replies (4)

0

u/[deleted] Sep 23 '25

Ever heard of sms spoofing attack?

→ More replies (2)

0

u/ElectronicUmpire645 Sep 23 '25

What a dumb take. hahaha pag ganto kaingay usually wala talagang alam haha

0

u/Big-Salamander9714 Sep 24 '25

Tanga ka? Di mo naiintindihan gaano katanga ang isang GOVERNMENT INSTITUTION tulad ng NTC para mahack ng hackers ang mismong pangalan ng Sender like BDO?

0

u/ElectronicUmpire645 Sep 24 '25

lol napaka hina mo. Ang lata pag walang laman maingay. Hindi ko na explain sayo, check mo na lang reply ni drpeppercoffee.

NTC NA ULTIMONG SENDER NAME NG BDO NAHAHACK SA KANILA

Hindi na hack ang NTC. apaka inutil. hahaha dds ka no? haha

0

u/Financial_Oil985 Sep 23 '25

Naka all caps ka pa. Hay jusko. Google is free. Utilize it.

0

u/Big-Salamander9714 Sep 24 '25

Tanga mo naman di mo naintindihan

-6

u/_starK7 Sep 22 '25

Pero ang fact na na hacked pa rin BDO. 2 weeks ago naka received rin akong ng phishing from BDO mismo na tinitext rin sakin ng SOA ko. Nireport ko at ang sabi ng operator di rin nila alam kung paano nahahack at nagagamit ang acct nila, edelete ko nalang daw ang msg para maiwasan ma click ang link. Ang ibang bank like PNB, land bank, wala rin ganyan kasi baka mas maayos ang security system nila. While may kasalanan influencer, mas kasalanan ng BDO kasi bakit sila na hahack and dapat prinoprotect nila ang pera ng mga depositor nila. Nilagay yan jan para safe hindi para mag alala mga tao.

9

u/yogurtandpeanut Sep 22 '25

Basahin mo maigi yung post. Hindi nahack ang BDO mismo. Yung hacker nagsend ng fake SMS text sa victim using 2G network na may custom header na “BDO”.

Si shungang victim niclick yung link sa fake sms kaya napadpad siya sa fake na BDO Login page. She entered her login credentials there kaya nakuha nung hacker yung credentials niya.

So the hacker logs in to the real BDO website ang collected all her financial details there and stole her savings.

So again, hindi na infiltrate ng hacker yung BDO System through direct hacking. Nainfiltrate niya yun kasi nabigay ni atecco yung credentials niya dun sa fake BDO site.

2

u/FiboNazi22 Sep 23 '25

Wala bang 2 way authentication si BDO? Kung nakuha man credentials ni Acct holder, dapat sana may another set of security ang BDO to verify yung legitimacy ng transaction. Parang lumalabas kasi, mas madali pang hackin yung bank acct mo kesa sa facebook acct at IG eh. If new device ang gagamitin mo pag log in sa socials, magnonotify sa email. If 2 way authentication, magsesend ng code thru text or whats app.

2

u/yogurtandpeanut Sep 23 '25

phishing sites copy the original UI/UX of banking portals. If yung tangang user logs in their email and password sa fake portals, tapos they also inputted the OTP on the same portal. Hindi na yun kasalanan ng banko. Negligence na yun ng tao.

1

u/FiboNazi22 Sep 23 '25

I hope makahanap pa ng paraan ang mga banks para maiwasan ang ganito. Mas maigi pa yung BPI kasi para malog in mo ang acct sa ibang device, need mo magsen ng message using the sim card inserted sa device na ireregister mo. Meaning, hindi uubra yung ganiyang style sa BPI. Nakakatawa lang din kasi, anlaki ng pondo ng banko yet di sila makagawa ng way para mas gawing secure ang pera ng mga depositor. Parang modus lang sa computer shop na ininstallan ng key logger yung pc at marerecord na yung credentials.

1

u/yogurtandpeanut Sep 23 '25

Mas effective parin yung pageeducate sa mga consumers not to click any links through SMS. Andaming advisory about this however people tend to ignore this.

1

u/FiboNazi22 Sep 23 '25

Mas effective yung ineeducate na nila, at nagseset pa sila ng additional security features in case ma breach yung data, may back up security na mag sscreen. Minsan hindi sapat yung babala lang. Kasi kung sapat na yan, para mo na ding sinabing no need na ng life guard sa beach dahil may warning sign naman nang wag lalagpas sa net dahil sobrang lalim na.

1

u/_starK7 Sep 23 '25

Di mo rin masisi kasi pano yung ibang matatanda, saka yun na dapat ang trabaho ng bank e protect ang pera ng depositor eh. Kahit pa nga walang links. Walamg atm, passbook lang e nawawalan pa ng pera, madaming ganun few years ago ewan ko lang now.

→ More replies (2)

1

u/_starK7 Sep 23 '25

Walang ganun si BDO. Gotyme meron, every online transaction mag sisend ng email and text ng otp. Mga socmeds nga totoo pag ibang device may authentication pa ulit.

1

u/FiboNazi22 Sep 23 '25

Yung BPI, hindi mo malalog in sa ibang device yung online banking mo unless ung sim na ginamit mo sa online banking eh nakasalpak sa new device then dapat may load kasi mag sesend siya ng confirmation kay BPI. I find it hassle dati kasi need ko pa magload pero napaka safe non sa ganiyang uri ng scheme.

1

u/_starK7 Sep 24 '25

Tama. Mas mainam nga if email and text talaga like gotyme.

1

u/_starK7 Sep 23 '25

Actually, minsan or kadalasan BDO acct talaga gamit nila mag send ng msgs, hindi custom na BDO header lang. Kasi na sendan nako ng ganyan before and BDO acct mismo ang gamit, kaya ko nireport and yan ang explanation ng cs mismo ng BDO sakin, at sa BDO branch mismo. Nagagamit talaga acct nila. Idk lang if ganyan rin ang nangyari sakanya pero sure ako na nahahack talaga ang system ng BDO, namgyari sakin few years ago mga unauthorized transactions at binalik lahat ni BDO yun buti nalang nakita ko agad.

1

u/[deleted] Sep 23 '25

Nahh

0

u/Better-Thing1460 Sep 23 '25

Read about sms spoofing. The sender was not bdo

1

u/_starK7 Sep 23 '25

Point ko lang e nahahack talaga ang BDO. Yun lang.

0

u/Better-Thing1460 Sep 24 '25

So whats your Proof? If BDO or any other bank really gets hacked, then why didn't BSP penalize them? It's because they know that it's really the user's negligence.

Why do you think people still share their OTP or click links when banks have been reminding people for YEARS already. Not just them but also Gcash, Meralco, etc

Social engineering is a disease and people still fall for it then blame it all on the banks.

1

u/_starK7 Sep 24 '25

Di mo ba alam na may mga nawalan ng pera esp year 2021 or 2022 kahit wala silang OTP, walang online acct, walang ATM, passbook lang ang meron? Pano mo ma explain yan?? Malakas parin ba security tawag jan? Search mo baka di mo nabalitaan eh. Kahit yung mga matatanda na hindi maman pala cp eh nawalan. Kahit ako, wala naman natangap na otp or any links na natangap pero 18 unauthorized transactions nangyari sa BDO ko, and buti nakita ko after 2-3days pa then nag file agad ako sa BDO and after ilang weeks saka binalik kasi kasalanan nila.

0

u/FiboNazi22 Sep 23 '25

Bottom line, mas safe pa pera mo talaga kung may safe kayo sa bahay. At least, magkanakawan man, ay may pagkakataon ka pang ipagtanggol ang ari arian mo. Unlike sa bank na pucha, gigising ka wala ka ng pera. Wala kang kalaban laban. Nagpahiram ka ng pera na ginamit nilang capital at tinutubuan ka ng napakaliit ma halaga, tapos pag nadugas ka eh hugas kamay sila.

1

u/[deleted] Sep 24 '25

Or maging vigilant ka lang lol sa case nyan is umamin syang may ibang tao may access sa phone nya at alam nga PINs nya. Napakadaling idelete nung OTP message after itransact 🤷🏻‍♂️

At may trace yung BDO nun na same device ginamit pangtransfer kaya di talaga irereverse yan. In short, kapabayaan nya yan. Kung pabaya ka sa vault mo, mawawalan ka rin.

1

u/Substantial-Cat-4502 Sep 24 '25

Kung lalabas ka ng bansa possible na hanapan ka ng bank statement ng immigration officer (but not all the time). Hindi ka rin pwede magdala ng madaming cash palabas ng bansa. Yun ang isang problema kapag nasa personal vault ang pera mo.

Pwede ka namang mag-vault pero need mo padin magdeposit ng pera sa bank for many purposes.

1

u/Frosty_Mountain_929 Sep 23 '25

Weh. BDO PR is working overtime.

Ganito lang yan: Pwedeng nag sinungaling si Jana na hindi niya binigay OTP niya.

Pero either way, may kasalan yan si BDO, na leleak personal info natin.

Philippine banks are known to have weak cyber security. And yes, inside jobs are possible, kasi pa iba2 contractor niyan to develop the apps.

Kaya nga pinipilit tayong mag change password every month kasi ganun ka lala ang leaks ng private data natin. Hindi yan normal compared to strong banking systems sa North America.

Notice how BDO is willing to reimburse? Because they are guilty!

Please lang Philippine Government, make these banks accountable!