Internet fraud seriously endangers the security of property and information of companies, so it is everyone’s duty to prevent fraud.
Recently, WeCom team has discovered some new frauds, and has enhanced its approaches to fight with them. A number of accounts with fraudulent behaviors were restricted or banned in a tiered manner.
WeCom has strict security protection strategies, but fraudsters may still take advantage of various security vulnerabilities, such as bribing employees and compromising employee accounts.
We hope that our users pay attention to the following:
1. Be on high alert to the following new fraud methods and learn the preventive measures.
2. Strengthen security awareness to avoid fraudsters taking advantage of negligence or temptation.
The information and property security of companies shall be jointly safeguarded by us.
The following are the new fraud methods we have discovered:
1. Compromising employee accounts
Fraudsters wearing work clothes visit the company’s office and borrow users’ mobile phones under the pretext of performing offline marketing for a certain company or data labeling for a certain map app. However, in fact, fraudsters are hacking the users’ mobile number and verification code to log in to WeCom.
Criminals will also ask users to scan unknown QR codes to compromise their accounts under the guise of tasks or gifts in crowded places such as universities, companies, and subways. Once the user scans the QR code, criminals will be authorized to log in.
After compromising the account, criminals may carry out fraud within the company, and may also leak confidential information such as the corporate directory and chat history, resulting in serious consequences.
2. Renting or buying accounts from users or join the corporate directory by being invited by employees
Some users with weak security awareness and who are greedy for petty advantages rented or sold their WeCom accounts to network attackers. Then, the network attackers used the rented employee account to swindle. Once the criminals are caught, the users should also bear legal responsibility.
Some companies have set up in the admin console to allow employees to invite users to join the corporate directory, but users who are deceived or bribed by criminals may invite unknown users, which may cause security hazards.
The WeCom security team has been closely monitoring and cracking down on the above frauds, assisting companies to achieve the best information security practices.
We recommend that users take the following preventive measures:
● Do not lend your mobile phone with WeCom to strangers or scan unknown QR codes, preventing the account from being compromised by criminals.
● Do not invite external personnel into the company, and do not sell or rent your account to external personnel. Employees who endanger the collective interests of the company because they are greedy for small gains may be subject to internal penalties and even legal sanctions.
● Do not install unknown software. Virus-infected software may hijack WeCom to send messages that cause harassment or frauds.
The property and data security of a company requires the efforts of all members. We hope to remind users to put more emphasis on account security and obedience of the law., so that criminals cannot take advantage of the vulnerability.
For illegal and criminal acts that endanger the security of platforms and companies, the WeCom security team will handle them in strict accordance with
WeCom User Account Usage Rules and relevant national laws and regulations, and continue to protect the security of companies.