NAB Fraud Prevention 2 — Questions and Answers
Question 1: A customer receives a text message claiming to be from NAB asking them to click a link to verify a suspicious transaction. This is an example of what type of fraud?
- Vishing
- Smishing (Correct answer)
- Phishing
- Skimming
Correct answer: Smishing
Smishing is SMS-based phishing where fraudsters send fake text messages impersonating legitimate organisations like banks.
Question 2: What is 'card-not-present' (CNP) fraud?
- Fraud committed using a stolen physical card at an ATM
- Fraud where card details are used to make transactions without the physical card (Correct answer)
- Fraud involving counterfeit cards embedded with skimming devices
- Fraud where a card is intercepted in the mail before reaching the customer
Correct answer: Fraud where card details are used to make transactions without the physical card
CNP fraud occurs when a fraudster uses stolen card details (number, expiry, CVV) to make online or phone transactions without needing the physical card.
Question 3: A NAB employee notices a colleague accessing customer account records for clients outside their normal portfolio without a clear business reason. What should they do first?
- Confront the colleague directly
- Ignore it as it is likely a routine check
- Report it through NAB's internal fraud or whistleblower channel (Correct answer)
- Delete the access logs to protect the colleague
Correct answer: Report it through NAB's internal fraud or whistleblower channel
Unexplained access to customer accounts by employees may indicate insider fraud and should be reported through NAB's designated whistleblower or fraud reporting channel.
Question 4: Which of the following best describes 'account takeover' fraud?
- A fraudster opens a new account using a stolen identity
- A fraudster gains unauthorised access to an existing customer account and makes changes or withdrawals (Correct answer)
- A fraudster deposits counterfeit cheques into an account
- A fraudster intercepts a customer's debit card in the mail
Correct answer: A fraudster gains unauthorised access to an existing customer account and makes changes or withdrawals
Account takeover fraud involves a fraudster using stolen credentials to access and control an existing customer's account.
Question 5: NAB's fraud monitoring systems flag a customer's account for a large overseas transaction that doesn't match their usual spending patterns. What is this process called?
- Credit scoring
- Behavioural analytics / anomaly detection (Correct answer)
- Know Your Customer (KYC)
- Anti-money laundering (AML) screening
Correct answer: Behavioural analytics / anomaly detection
Behavioural analytics compares current transactions against a customer's historical patterns to flag unusual activity as potentially fraudulent.
Question 6: A customer is tricked into purchasing gift cards and sharing the codes with someone posing as a NAB fraud officer. What type of social engineering scam is this?
- Skimming scam
- Impersonation / authority scam (Correct answer)
- Malware injection
- Counterfeit currency scam
Correct answer: Impersonation / authority scam
Impersonation scams involve fraudsters posing as trusted authorities (like bank staff or police) to pressure victims into transferring money or sharing gift card codes.
Question 7: What does the term 'mule account' refer to in the context of fraud?
- An account used exclusively for business transactions
- A dormant account reactivated after more than 5 years
- A bank account used to receive and forward fraudulently obtained funds (Correct answer)
- An offshore account used for tax minimisation
Correct answer: A bank account used to receive and forward fraudulently obtained funds
A mule account is used by fraudsters (often through unwitting recruits) to receive stolen funds and quickly transfer them, making the money harder to trace.
A customer receives a text message claiming to be from NAB asking them to click a link to verify a suspicious transaction.
This is an example of what type of fraud?