Online Games Drain Players’ Accounts Through Small, Repeated Thefts

Investigation by Mena Ghali
Some websites that online gamers use to pay for their games or buy some of their tools, what you get from data, to steal money from the cards they use to sign up.
These sites are commonly referred to as "third parties". They get amounts that may not be visible to many bank account holders, because of their small size. However, it does not stop there, but continues to "stretch out its hand" into the players' pockets, secretly, with many victims considering that the amounts it seizes are so small that it is not worth filing a complaint with the relevant agencies, and that they – at best – take the necessary measures to secure the bank account.
Their parents confirmed that they were victims of "small scams", after their sons bought virtual tools for some online games, before they realized that scams never stop.
And a study from the University of Maryland showed that hackers attack a user's computer every 39 seconds, because most often the victim has a credit or debit card, especially his own, attached to the account from which he logged into the game.
An online game user, Joseph Noble, said he participated in one of the fighting and strategy games, and needed to buy tools and weapons inside the game, equivalent to 40 dirhams at a time. But he was surprised to see a dollar withdrawal via the game's payment server automatically, without his knowledge.
He added that there are payment platforms based on so-called "black sites" which in turn rely on recording bank card data, then selling them, or withdrawing them periodically, which prompted him to stop playing the game, as he says, to avoid running out of money.
Mohammed Abdul-Qadir said his son used to go into a strategy game, which is basically free online stores. But they rely on their practice to buy guns, weapons and tools for large sums of money to reach higher levels.
He added: "Whenever a student came to me to buy tools within the game, I was surprised by messages that sent me withdrawals of between 10 and 30 dirhams continuously, without knowing a reason for it, and when I looked up the name of the entity that used to withdraw money from me, I was surprised that it was a payment intermediary, which made me quicker to change my bank card to avoid withdrawing more money".
Noraldine Khaled, a child's father, said he was surprised by the amount withdrawn from his bank card for no apparent reason, and when the bank asked, it knew it belonged to one of the companies authorized to pay for the online game.
He continued, "I went back to my son and asked him if he was using it unknowingly, and he assured me that he had only used it once, but that side kept withdrawing money all the time, starting with small amounts".
Professor of sociology at Sharjah University, Dr. Ahmed Al-Amosh, said that online games cause many negative aspects; before talking about physical risks, they lead to the spread of violence and aggressive manifestations towards oneself or another, especially that a child tries to imitate games by harming others, as well as that these games follow the policy of graduating to addiction afterwards.
He pointed out that when a man gets to this point, he can't give it up. Studies suggest that people sometimes resort to theft in order to buy virtual instruments, may use their family's credit card without knowing it, and then become addicted. He explained that it starts gradually, represented by a small amount, and then comes to thinking about money and collecting it in any way to buy what he sees fit, pointing out that e-games are routine activity that a person is used to, and so it must be tried to change, which is up to the family, school, media and cultural clubs, with legal programs to protect young people from the dangers of e-games.
For his part, cybersecurity expert Sami A Nour said that the origin of the application's popularity is to launch it through official app stores such as the App Store or Google Play, and these stores are the secure and authoritative intermediary, allowing in-game purchases through them.
He added that "most games are free, but the purchase process takes place inside them", explaining that "the player or user buys through payment to the store, which deposits the income to the company that owns the app; they in turn receive a commission as such. It is important for its continuity, providing revenue, developing its digital infrastructure, helping to maintain security and user information, and preventing refused or fraudulent purchases".
He said that some gaming companies offered off-the-shelf payments, like Biggie and Fortnite.
He said that "the latter in particular tried to circumvent and access payment through the app directly, which resulted in them being denied stores, because this methodology poses a risk to individual data, and can harm the profits of the companies that own the stores. In terms of security, companies like Google or Apple protect users from unsecured purchases, store payment cards, as well as protection from unplanned payments. He points out that "recourse by some gaming companies to payment scams outside these stores is a type of fraud, and this is reflected in me as an individual where I have difficulty recovering my money, because the user can't distinguish between an accredited and an accredited store. And the gaming companies are the main reason for that".
He added: "The second aim of this is to sell cards for profit, which causes users to automatically withdraw money unwittingly".
He stressed the need to cancel the process of card registration in games, because users make purchases from unsafe stores, called "third parties", and it has become a cause for fraud; it creates a kind of mal-service and fraud, exposing children to online blackmail, or various forms of exploitation, and many users sell pornography, taking from these cards a price for that material. This creates a behavioral and ethical decline, stressing that "paying outside of official app stores creates huge and divisive digital risks, one reason for which is to make payments available in an unregulated and uncontrollable way".
In turn, legal scholar Dr. Mohsen Mohammad al-Khabani said that the UAE's legislator's eagerness to update laws and legislation to combat cyber-payment in this regard is evident, even though criminal gangs have invented methods of cyber-hacking and cybercrime; however, the law remains barred by severe penalties in this regard.
For information-technology offences, Article 15 of Federal Decree-Law No. 34 of 2021 on Combating Rumours and Cybercrime sets deterrent penalties for attacks on electronic payment methods: imprisonment and a fine of between AED 200,000 and AED 2 million, or either penalty. Any person who falsifies, copies or copies a credit card, a debit card or any other electronic means of payment or takes possession of its data or information using information technology or an information system shall be punished with the same penalty if he: creates or designs any information technology means or software with the intention of facilitating any of the acts provided for in the first paragraph of this Article, or use without authorization a credit card, electronic or debit card or any electronic means of payment or any of its data or information, for the purpose of obtaining for himself or others money or property of others or to take advantage of services provided by others, or before dealing with such counterfeit, counterfeit, duplicate or other electronic means of payment or with the data of electronic means of payment seized in an unlawful manner with the knowledge that they are not lawful".
Al Khabani added that Article 40 of the same decree-law on electronic fraud provides that anyone who unlawfully obtains movable property, a benefit, a document or a signature on such a document for themselves or another person faces at least one year in prison and a fine of between AED 250,000 and AED 1 million, or either penalty, By using any means of fraud, taking a false name or impersonating a false identity through an information network, an electronic information system or one of the means of information technology".
He stressed that, with such legislation deciding deterrent penalties by the UAE legislature to ensure a secure cyber environment to ensure the positive use of these technologies, the parties to the relationship need to play a significant role in ensuring the safe and efficient use of electronic payment methods. Cybercriminals are usually vigilant and error-prone for the parties to the relationship in the process of purchasing credit cards online. Note that most of these errors are the responsibility of the normal user, causing him to neglect and neglect to use his credit card in an unsafe manner, which could be exposed to hacking and money theft without his knowledge.
For example, if a bank or credit card company does not provide adequate card insurance, the third party that could be a factor in the commission of this crime is the website or the person who was hacked, due to a weakness in the electronic means of protection that are supposed to be strong against hackers.
To find out who is responsible for the breach of the duty to control, control and exercise due diligence it is understood that the general rule of responsibility is the availability of error and damage and combines them with a causal link, and therefore whenever the fault is on the user, the responsibility lies on him to patronize and neglect the use between his hands of accounts, who should be careful to shop from sites that ensure secure shopping, And to ensure that the merchant's only information needed in the e-space to complete purchases is the name on the card, credit card number and expiration date, if he finds himself committed to due diligence he must prove that the mistake was made by the other parties to the relationship to ensure fair compensation for the damage.
• "black sites" are based on the periodic recording of bank card data and the sale or withdrawal of funds from them.
• The origin of the popularity of apps is to launch them through official stores such as the App Store or Google Play.
Mechanisms of protection
Cybersecurity experts have identified mechanisms by which users can protect their devices and accounts, play safely, and most notably:
■ Run binary authentication on the user's own gaming machines to avoid being hacked.
■ If the user applies his or her credit card, he or she must monitor purchases from the account.
■ The user should check to see if the game companies are providing "cleaning" for the chat function, allowing the game companies to impose control on a specific language and prevent the publication of links.
■ An active anti-virus software must be installed to deal with any threat.
■ Users must inform the company of any unusual activity, especially if there is something that appears to be a scam.
■ Parents should check assessments to see if games are appropriate for their children's age group, as well as read safety controls, while educating children about the importance of paying attention to privacy policy and safety in games.
■ Run all security protocols on devices.
Warning .
Abu Dhabi police warned against clicking on anonymous online links and dealing with fake and untrustworthy e-shops, pointing out that they may engage in fraud by stealing money through their bank cards or bank accounts.
She warned of fake online gaming platforms, urging parents to be vigilant in dealing with them so they don't run out of money.
She warned of the dangers of signing up for or buying e-games online or disclosing credit card details to keep them confidential, buying through trusted websites that apply secure controls, and using a credit card with limited balance so they are not vulnerable to fraud and piracy, leading to a reduction in monthly amounts from the credit card.
Potential risks .
Although online gaming is a way of communicating and interacting with others, it's still fraught with risks, so if you try to find cheaper or free versions of your favorite games, for example, you risk downloading viruses and malware.
This is the case when you access cheat codes or buy items from outside vendors.
And even if you download a game legally, the security flaw could put you at risk. Once malicious software reaches your device, hackers can steal your personal information.
Cybercriminals collect personally identifiable information to build profiles of their potential victims.
The potential risk of playing online with strangers is that chatting allows for the collection of sensitive information, such as name, phone number and home address.
And if you use a username and password for all of your favorite gaming platforms — which is not recommended — then if hackers get your credentials, hackers will be able to access all of your accounts and possibly seize them.
Legal proceedings
Lawyer and legal expert, Mohamed Ibrahim Bastiki, said that continuing to deduct online gaming fees from players' bank card accounts, without their consent, is a crime. He went on to say that the affected person should contact the bank to suspend the card, as a first step, with a search for the possibility of recovering the amount withdrawn from the account.
The second step, according to Pesticky, is for the victim to report the incident as soon as they are exposed.
In this case, he can apply to the Dubai Police or the Ministry of Interior. He stressed that there is no minimum amount that can be reported, "it is ultimately called theft, and that the site or server for which the withdrawal is being carried out can finance terrorism or any other crime".
Pesticky warned the account holder against the crime, pointing out that "he may fall under the law if he does not take appropriate legal action, i.e. he must act legally to secure himself".
Source: Emarat Al Youm