Partners

Partner Acquisition

Partner Directory

How to open a
World Account

Europe

Asia

Oceania

North America

México

Español

Related content

Legal

Understanding and Preventing Account Takeovers (ATO)

What is ATO?

Account Takeover (ATO) is a type of cyber crime whereby a third party gains unauthorized access to your account without your permission or awareness. This can lead to serious financial loss, unauthorized transactions, unauthorised changes to your account details, identity theft, and other harmful consequences.

How Does ATO Happen?

  1. Data Leak via Phishing Attack:
    • Phishing is a common deceptive tactic that tricks you into revealing sensitive information, such as your login credentials. This is often done through fraudulent emails and text messages, or through fake websites that look like legitimate sources.
    • Example: John receives an email which looks like it is sent by his bank, requesting him to verify his account details. The link in the email leads to a fake website which prompts him to enter his username and password, and thereby unknowingly granting the attacker access to his account.
  1. OTP Bots:
    • One-Time Password (OTP) bots are malicious software designed to intercept and steal OTPs used for two-factor authentication. To achieve this, the attacker might send your personal information such as your phone number to the bot, which then pretends to be a legitimate company and requests for the OTP.
    • Example: The attacker logs into Susan’s bank account and triggers an OTP. The OTP bot then sends Susan a message saying We’ve detected suspicious activity in your bank account. Reply with the OTP sent to secure your account.” If Susan replies to the message and shares her OTP, the attacker can then use the OTP to log in Susan’s bank account and steal her money.
  1. Obtaining Phone Control:
    • Attackers can gain unauthorized access to your device’s operating system via malware. This can happen if you download a malicious app or click on a malicious link.
    • Example: Celine saw an advertisement on Facebook on a flash deal, which prompted her to download an application to complete the purchase. Celine then downloaded the application, which was in reality a malicious app. After the application has been downloaded, Celine realised her banking app was opened automatically and an unauthorised transaction was executed as the attacker was able to control her phone remotely.

How to Protect Yourself

  1. Exercise Caution with Attachments and Links:
    • Be cautious with email attachments and links, especially from unknown sources. Malware can be hidden in these files.
    • Tip: Do not click on links or download attachments from unknown email addresses or mobile numbers. Even if the link looks legitimate, it could lead to a fake website.
  1. Update Your Credentials:
    • Regularly update your passwords and use strong, unique passwords for each account.
    • Tip: Use a password manager to generate and store complex passwords securely.
  1. Never Disclose Your OTP:
    • Never share your OTP with anyone, even if they claim to be from a legitimate company.
    • Tip: WorldFirst employees will never request you to share your OTP. Be cautious of calls or messages asking for your OTP, especially if the voice sounds artificial.
  1. Check Before Downloading Apps:
    • Verify the legitimacy of an app before downloading. Check the number of downloads and check the app reviews.
    • Tip: If a well-known payment platform has very few downloads, it might be a red flag. Also, pay attention to any warning messages before downloading an app from the Google Play Store or Apple App Store.
  1. Treat Warning Signs Seriously:
    • Pay attention to any warnings or alerts from your device or apps. These can indicate potential security threats.
    • Tip: Read warning messages carefully and do not proceed if something seems off.
  1. Avoid Fake Websites:
    • Fake websites often look legitimate but are designed to steal your login credentials or sensitive information. Verify through the company’s official website to avoid accidentally visiting malicious websites. Examples of official WorldFirst sites: worldfirst.com/my/, worldfirst.com/ph/, worlfirst.com.cn
    • Tip: Bookmark https://portal.worldfirst.com/dashboard to avoid accidentally visiting malicious websites. Always verify the URL before logging in.

Potential Consequences of ATO

  • Financial Loss: Attackers can steal money from your account through unauthorized transactions.
  • Legal Implications: Your personal information may be used to commit fraud, thereby causing you to unintentionally become involved in illegal activities.
  • Reputational Damage: For businesses, ATO can harm your reputation and customer trust.

What to Do If You Suspect ATO

  • Contact Us Immediately: Reach out to the Merchant Services team at https://www.worldfirst.com.cn/static/help/contact-info/ for immediate support. We can help you to suspend your account and initiate an investigation.
  • Change Your Passwords: Update your passwords for all affected accounts.
  • Report the Incident: Inform the relevant authorities about the incident.

By staying vigilant and following these protective measures, you can significantly reduce the risk of falling victim to an account takeover.

Logistics

DHL

DHL offers a comprehensive range of parcel, express, freight transport, and supply chain management services as well as e-commerce logistics solutions.

China product sourcing marketplace

1688.com

China's leading wholesale marketplace. Source high-quality products directly from manufacturers.

Accounting Saas

Netsuite

Run your business on one platform. Cloud ERP for growth-focused companies.

Return logistics

Return Helper

Offers one-stop logistics for cross-border sellers, including first-mile and last-mile delivery, fulfillment, and returns management solutions.

SGD150 Credits In Wallet

How to redeem:

· Sign up through the above link
· Write to [email protected] quoting [WorldFirst150]
· Only new users of Return Helper enjoys this promotion

Digital marketing service

VERZ DESIGN

Offers full-suite e-commerce web development & digital marketing services, driving client success and growth for DTC, B2C, and B2B businesses. With a strong presence across SEA, Verz Design has been entrusted as one of the region's few Shopify Plus partner agencies.

· Complimentary Website & Digital Marketing Audit for Supercharged Business Growth
· Please reach out via email to [email protected] and [email protected] for further information.

Digital marketing service

AnyMind Group

Marketing automation redefined. AI-powered solutions for brands to scale.

Digital marketing service

Eber

Leading provider in the realm of loyalty solutions across multiple channels, including online, in-store, and mobile platforms.

US Marketplace

Amazon Global Selling

Reach millions of customers worldwide.Sell internationally on Amazon's trusted platform.

China product sourcing marketplace

TaoWorld

Effortless China sourcing. Simplified fulfillment and global shipping.

US Furniture and Home living Marketplace

Wayfair

Your one-stop shop for home. Discover millions of furniture and décor items online.

Online payment gateway

2C2P

Seamless online payments across Asia. Trusted payment processing for your global business.

Accounting Saas

Xero

Beautiful, cloud-based accounting software designed for small businesses.

HR services Saas

Talenox

A cloud-based HR software that simplifies payroll, leave, and employee management, tailored to meet local compliance needs in Singapore, Malaysia and Hong Kong.

80% off on the first 3 months for Talenox’s Paid Plans.

How to redeem:

· Click on link above
· Input [WFCTAL80] to redeem this deal on Talenox’s website

Loan financing

CHOCO UP

Provides fast, flexible, and zero-equity working capital solutions to empower businesses. Every business should have the chance to grow, which is why Choco-Up offers a range of solutions beyond just financing.

Up to 10% cashback of fees.

How to redeem:

· Upon successful closure of adopting Revenue based financing/Invoice financing + complete repayment
· Up to 10% cashback of fees charged by Choco Up on funding amount
· Simply sign up via link, Choco Up will initiate agreement specifically for the promo signups thereafter

Send money in 100+ currencies

You can send money in your WorldFirst account to any of the currencies we support.

Collect money in 20+ currencies

You can collect money in 20+ currencies. It only takes a few minutes to open an account in the currency you need.

Get Paid by 130+ marketplaces

Seamlessly get paid by 130+ marketplaces and pay your suppliers anywhere.

Pay in 15 currencies with World Card, no FX fees

Enjoy zero FX fees when paying in the following 15 currencies with World Card.