Recommendations on Fraud Prevention

Fraudsters do not hack the bank. They work with the individual: they create fear, a sense of urgency, and an illusion of official authority. Their sole objective is to induce you yourself to disclose a code, install a program, or transfer funds. The following rules are effective.

1.    The bank never requests confidential data.

An employee of the bank, the security service, the Prosecutor’s Office, MIB, the tax authority, the Central Bank, or any other government agency will never request the following by telephone, messenger, or link:

-       a code from an SMS or push notification;

-       CVV/CVC (the three digits on the reverse of the card);

-       PIN code;

-       login and password for the application;

-       code word (except in cases where you yourself initiated the call to the bank).

If you are asked for any of the above - terminate the conversation immediately. This is a fraudster.

A genuine bank employee can see your transactions independently and has no need for codes.

Rule: Terminate the conversation.

2. Do not trust a call even if the number appears to belong to the bank.

Question any incoming call and any information received. Fraudsters spoof phone numbers. A phone call may appear to originate “from the bank’s number,” from abroad, or via Telegram/WhatsApp.

Government authorities (the Central Bank, the Ministry of Internal Affairs, the Enforcement Agency, the Prosecutor’s Office) do not contact citizens by telephone regarding bank accounts or loans.

Rule: Terminate the conversation.

3. Do not install programs and do not follow links.

You may be asked to install a “security application,” a “bank antivirus”, or remote-access software (AnyDesk, TeamViewer, and similar). Do not do that. Such programs intercept SMS codes and grant complete control over your phone software.

Never follow suspicious links received in SMS messages, Telegram, WhatsApp, or similar channels.

How to recognize that a link may be a trap:

    The link ends with .apk (or .pdf or .xyz) — do not open it! Examples: bank_xavfsizlik.apk, SudgaChaqiruv.apk, CBU.apk, bu_sizning_suratingiz.apk;

    The link contains words such as: bonus, update, secure, support, download;

    The link uses shorteners such as: bit.ly, t.me/…;

    The link appears to be an ordinary website address beginning with “//…”.

Example: //mygov-uz.net/sud.pdf (in reality, a fake application may begin downloading instead of a PDF file).

Rule: Install applications only from official stores (Google Play, App Store).

4. Do not transfer funds “to a safe account” and do not take out a loan “for protection.”

Classic scheme: “Your money is at risk; transfer it immediately to a special (safe) account” / “Take out a loan and repay it at once”. No such accounts exist.

If you are offered to “cancel someone else’s loan issued in your name” - these are fraudsters.

Rule: Terminate the conversation.

Daily Checklist:

·      Question any incoming calls and any information received.

·      If in doubt — hang up.

·      Never disclose an SMS code to anyone.

·      Do not open links from unknown messages.

·      Do not install “verification” programs.

·      Urgency and threats are the principal indicators of fraud.

Financial security is the habit of verifying the source and of not making decisions while in a state of fear.