• Chozo@fedia.io
    link
    fedilink
    arrow-up
    7
    arrow-down
    23
    ·
    5 days ago

    That’s unusual, but not unheard of. Some online merchants will allow you to make payments via ACH transfers. Can be useful for things like international purchases or if you don’t have a normal credit/debit card to use. Sometimes smaller merchants will prefer this, if they don’t have an existing business partnership with a payment processor already.

    Usually these will go through a third-party system that tokenizes your login with your bank. This way the merchant can only access your routing/account numbers to do the transfer. As for why you’d need to provide your bank login instead of the routing/account numbers directly, it’s usually just a form of fraud prevention, as the login verifies that you’re actually the account owner and not trying to pay with a checkbook you found on the street.

    It’s similar to Plaid, which is a near-identical service that some merchants in the US use. From what I can tell, Ozow appears to be legitimate, so realistically it’s probably safe to enter your login details as long as you’re not getting any certificate errors on the page.

    E: Not sure why this is downvoted. I’m not saying it’s a good system, just saying that it’s not inherently a scam.

    • FuglyDuck@lemmy.world
      link
      fedilink
      English
      arrow-up
      19
      ·
      5 days ago

      You shouldn’t trust Plaid either.

      Especially if all they’re doing is looking for the routing and account number. Because that’s just as easy to give.

      • Chozo@fedia.io
        link
        fedilink
        arrow-up
        8
        arrow-down
        2
        ·
        5 days ago

        It’s also risky to give. Banks will generally approve all transactions between two accounts if one of them is a business account, because the assumption is that those are business transactions and are legitimate 99.99% of the time, so there’s very little scrutiny involved for those transfers. Giving the merchant your routing/account number gives them access to make withdraws from your account at will and at any time and can’t be revoked, and giving that access to somebody you may not fully trust the reputation of is a dangerous move.

        A trusted financial institution as a middleman can be useful for those situations, because they’ll tokenize your details to expose as little as possible to the merchant, directly. These services are typically insured, so even if something did happen to your account, you’re more likely to get your money back than if you gave a merchant direct ACH access to your bank account. It’s basically a modernized version of Western Union.

        • FuglyDuck@lemmy.world
          link
          fedilink
          English
          arrow-up
          9
          ·
          5 days ago

          You do realize that if the bank authorizes a transfer, that you did not… it’s wire fraud and they’re obligated to refund that cash, regardless if they recoup the cash or not.

          Their fuck up, their loss.

          On the other hand, if you give your credentials to a 3rd party, that’s against the ToS none of us actually read, and if something happens to your account; they’re going to deem it as your fuck up.

          As for whatever technobabble Plaid wants to use, even if they’re insured… you’re not, unless you can prove in court that they were the source of the breach. Their lawyers are probably better than yours.

          • Chozo@fedia.io
            link
            fedilink
            arrow-up
            4
            arrow-down
            3
            ·
            5 days ago

            You do realize that if the bank authorizes a transfer, that you did not… it’s wire fraud and they’re obligated to refund that cash, regardless if they recoup the cash or not.

            You do realize that not every transaction happens in countries where these protections exist, right? Not everybody can rely on something like the FDIC to protect their funds.

            On the other hand, if you give your credentials to a 3rd party, that’s against the ToS none of us actually read, and if something happens to your account; they’re going to deem it as your fuck up.

            You’re not providing your bank credentials directly to the third-party, either. They use OAuth-like systems to log you in, typically. I’m not familiar with Ozow, specifically, but from what I can tell about their company, they appear to be doing mostly the same things as Plaid.

            • FuglyDuck@lemmy.world
              link
              fedilink
              English
              arrow-up
              5
              ·
              5 days ago

              You’re not providing your bank credentials directly to the third-party, either. They use OAuth-like systems to log you in, typically. I’m not familiar with Ozow, specifically, but from what I can tell about their company, they appear to be doing mostly the same things as Plaid.

              Plaid or Ozow is the third party. You’re using their system, which they control, to provide your credentials.

              You’re trusting that a) they’re not malicious and b) they have their shit together and c) even though they do have their shit together someone doesn’t find a random exploit anyhow.

              As for the first. yeah. that’s a problem. At that point it really doesn’t matter, does it? why would you trust Ozow or anyone else in that sort of environment with your banking credentials? or even the bank with your money?

              • Chozo@fedia.io
                link
                fedilink
                arrow-up
                2
                ·
                4 days ago

                You’re trusting that a) they’re not malicious and b) they have their shit together and c) even though they do have their shit together someone doesn’t find a random exploit anyhow.

                You could say this about literally any solution short of hand-delivering cash in person.

      • OsrsNeedsF2P@lemmy.ml
        link
        fedilink
        English
        arrow-up
        17
        ·
        5 days ago

        I know someone who works in software security at Plaid. I can’t give too many details because there’s only like 20 of them - but no, you REALLY should not trust Plaid. (Allegedly) phones intercepting 2FA in their server rooms, (allegedly) bank connection issues that have led to people getting access to the wrong accounts, (allegedly) using browser bots to handle login on the backend for banks without API access, (allegedly) customer info leaks that weren’t reported… Now that I think if it, I should tell my friend about the whistleblower programs

        • Echo Dot@feddit.uk
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 days ago

          I don’t know how it works in the US but under European law if he knows about these things and isn’t reporting them he’s liable if and when it all comes to light.

          If you know that the company you work for is committing crimes, and you do not report it, you are as liable as the company.

      • bss03@infosec.pub
        link
        fedilink
        English
        arrow-up
        2
        ·
        4 days ago

        Plaid effectively admitted to stealing your transaction history and selling it to the highest bidder in the past. There was a settlement and they agreed to not to that in the future

        Just don’t ever share your password, and certainly not your banking password, and definitely not with Plaid.

    • This is fine🔥🐶☕🔥@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 days ago

      We have a variation of this system here (India)

      During checkout you can select netbanking as payment method. It asks you to select your bank and after you select it and click next/pay, it redirects you that bank’s login. You login, provide OTP, and it redirects back to the website you were shopping at, usually to orders page.

      • Trainguyrom@reddthat.com
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        4 days ago

        Sounds like a good opportunity to redirect to a fake version of the bank’s website.

        Honestly I think the best solution is a revokable token from your bank that you can give to a merchant. One token per merchant, make it easy to revoke as the user sees fit. If you see a charge on the token from one merchant by someone else it’s immediately obvious that token and possibly that merchant was compromised

          • Trainguyrom@reddthat.com
            link
            fedilink
            English
            arrow-up
            1
            ·
            4 days ago

            My thinking was in terms of a malicious website, if it does a fake redirect to a fake bank webpage it will then be able to harvest your bank login as well, which is worse than a credit/debit card being harvested

  • ravhall@discuss.online
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    12
    ·
    edit-2
    5 days ago

    Well, it is a payment processor that uses bank accounts. So, that makes sense.

    • FuglyDuck@lemmy.world
      link
      fedilink
      English
      arrow-up
      28
      ·
      5 days ago

      That’s what wire transfers are for.

      There should be no need for you to give them your credentials. Also, be aware that if you do give a third party credentials, and you get hacked, your banks going to blame you for being stupid.

      Because it is stupid.

      How stupid is it? Not even the bank support staff will ask for your credentials.

          • ravhall@discuss.online
            link
            fedilink
            English
            arrow-up
            1
            ·
            4 days ago

            All they need is your account numbers. But this is a service that appears to operate in South Africa and allows bank to bank transfers. To me that sounds like using PayPal to do bank to bank transfers which is really strange sounding.

            But regardless a username and password is an odd thing to ask for unless we are just not understanding how this app works.

  • indomara@lemmy.world
    link
    fedilink
    English
    arrow-up
    240
    ·
    5 days ago

    That is a scam, they probably send mass texts linked to tracking numbers that have a registered phone number.

    • ByteOnBikes@slrpnk.net
      link
      fedilink
      English
      arrow-up
      51
      arrow-down
      1
      ·
      5 days ago

      I remember one of the funnier scams.

      They said they were from USPS, and in order to finish shipping, they needed me to pay the tariff.

      It didn’t have anything about me. No login. No address. No tracking number. It just wanted me to hit that pay now button.

      But even then, why would I pay a tariff for something I didn’t order?

      • superkret@feddit.org
        link
        fedilink
        English
        arrow-up
        41
        ·
        5 days ago

        They didn’t send it just to you. They sent it to millions. If even one person happened to order something internationally and be stupid, it’s already worth it.

      • Hideakikarate@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        11
        ·
        5 days ago

        For a while (and still every so often), I received fake texts from delivery companies, but they always referred to me as “There”. “There, we tried to deliver your package…”, “There, your package may be returned if you don’t click this link…”. I was curious what I typed in and where that they recorded my name as “There”.

      • Viking_Hippie@lemmy.world
        link
        fedilink
        English
        arrow-up
        9
        arrow-down
        1
        ·
        5 days ago

        I get that once in a while here in Denmark too, only replace USPS with PostNord, sometimes DHL or GLS

      • Buddahriffic@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        4 days ago

        And this is one of the ways to filter random scams. If a legitimate business or public entity is reaching out to contact you about an issue you need to deal with, they will know some identifying information about you. Especially the ones claiming that there’s a warrant (or will be). If that was the case, they would definitely know your name and other specific details.

        That said, there are targeted scams, too, so don’t assume that if someone can tell you your name that they are legit. Ask them for a callback number (don’t call it, ask because they might be dumb enough to give you a number linked to them that you could pass on to investigators), then hang up and call the number you looked up online.

        • hexdream@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          4 days ago

          Be careful looking up numbers online as well. There are lots of fake numbers and sites out there. Use previous known good communication as your guide for contacting the specific entity you are trying to contact. If at all possible. Also, smammers seem to have databases of scraped and leaked data so will often pull up your data based on your caller ID or other info you may disclose to them. Be careful out there.

      • grandkaiser@lemmy.world
        link
        fedilink
        English
        arrow-up
        9
        ·
        edit-2
        4 days ago

        Banking network engineer here: Never give out your login details. Not to your mom. Not to your brother. Not to me. Not to a company. Not to a random guy in India. Don’t do it.

        • Possibly linux@lemmy.zip
          link
          fedilink
          English
          arrow-up
          2
          ·
          4 days ago

          Agreed. However, there are services that login on your behalf. It is incredibly dumb but they exist.

          Just to be entirely clear, DO NOT GIVE THEM YOUR LOGIN

          • grandkaiser@lemmy.world
            link
            fedilink
            English
            arrow-up
            6
            ·
            4 days ago

            Partners are the stupidest fuckers on the planet. I won’t name names, but I have sicced my governance team on fucking http (NO S) websites, usage of certificate pinning, public-facing databases! (Protected by a shitty 2000’s-era username+password login interface) transferring credit card numbers in CLEAR TEXT. I swear I’ve seen every possible idiotic move from partners.

  • kia@lemmy.ca
    link
    fedilink
    English
    arrow-up
    208
    ·
    5 days ago

    Ask them for their bank login details so you can deposit the money directly into their account.

  • magnetosphere@fedia.io
    link
    fedilink
    arrow-up
    128
    ·
    5 days ago

    I would be completely astonished if this was legit. If you’ve already filled out the form, change you banking password and contact your bank immediately.

  • Burn_The_Right@lemmy.world
    link
    fedilink
    English
    arrow-up
    105
    ·
    edit-2
    5 days ago

    It’s probably against your bank’s TOS to give your password to a 3rd party. No way this is legit. Run away.

    • hexdream@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      ·
      4 days ago

      My understanding is that should you disclose your credentials you would generally void any fraud protection the banks may offer.

    • Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      3
      ·
      4 days ago

      It probably is. Its for convenience reasons. They pull up your bank page in the background and automatic login and parse the page.

      It is incredibly dumb and I would strongly advise against it

      • Echo Dot@feddit.uk
        link
        fedilink
        English
        arrow-up
        2
        ·
        4 days ago

        Why would you need to give them your login details why couldn’t you just sign into your bank account yourself? You still have to provide the details either way so it’s not convenient.

      • topher@lemm.ee
        link
        fedilink
        English
        arrow-up
        24
        ·
        5 days ago

        🎶 Ooh baby don’t you know I suffer Oh baby when you phished my bank You sent me to a dodgy website Using a convincing link

        Ooooooh-ooooh You drained my bank account Ooooooh-ooooh You drained my bank account🎶

  • 1luv8008135@lemmy.world
    link
    fedilink
    English
    arrow-up
    49
    ·
    5 days ago

    Google seems to suggest they’re some sort of fintech company out of South Africa? Either way if that’s their product then I’d run a mile in the other direction, and then another just be sure.

    • topher@lemm.ee
      link
      fedilink
      English
      arrow-up
      11
      ·
      5 days ago

      Yeah no. Plaid is one thing but giving access to your bank login to pay an invoice is something quite another. If it’s legit they can accept a card payment, or send you to a PayPal invoice.

    • tourist@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      ·
      edit-2
      5 days ago

      Yep. They’ve been around for years.

      Normally you would just give them your card info like any other online pay site like PayPal etc. but I don’t know why they suddenly decided to give everyone at the company a deluxe lobotomy

      I saw this shit yesterday when I was trying to buy a weed cart online (still not sure if it’s legal or not. I still hear stories of those moron cops arresting people for “drug possession” i.e. didn’t pay a bribe)

      Noped out and just gave the clearnet grey market drug website virtual card info that’s gonna expire in a few hours anyway

    • hexdream@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      4 days ago

      As a fellow saffer, and a person who works with scam victims, I’m curious as to what services asked you to do that? Feel free to pm me.

    • barsoap@lemm.ee
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 days ago

      This kind of stuff got legalised in Germany: Banks said that e.g. Sofortüberweisung was instigating their customers to break their TOS and should be shut down, anti-trust then said “nuh-uh you can’t just shut down legitimate business” (Sofort is indeed legitimate) and instead put third-party systems under banking regulations, and required ordinary banks to have APIs allowing third parties do do sensible things.

      …which theoretically could mean that you’re sent to your actual bank to authorise and thus getting rid of the normalising phishing problem, dunno, haven’t checked I’m boycotting them out of principle for going down that route in the first place. Don’t serve any purpose now that we have real-time transfers, anyway.