Victims should not be ridiculed, says Branko Džakula, adding that shame often leads people to report fraud late, which reduces the possibility of limiting the damage.
No one is completely immune to a well-prepared scam, say interviewees (Illustration), Photo: Shutterstock
Disclaimer: The translations are mostly done through AI translator and might not be 100% accurate.
Although the number of people who use mobile phones, applications, and social networks every day is large, the way they use all these services is questionable - whether they know how to check a website address, recognize a fake ad, or determine who is behind an investment offer.
It is noticeable, however, as the Police Directorate told "Vijesti", that not all users "do not have enough knowledge to adequately protect their data, recognize fraud, assess the credibility of information, or understand why certain content appears on their screen."
"Montenegro is digitally connected, but it is not yet digitally resilient enough," he tells "Vijesti" Branko Džakula, cybersecurity expert.
From the Ministry of Public Administration (MPA), headed by Marash Dukaj, have a similar view and support it with statistics: more than 88 percent of citizens, they point out, have access to the internet and use digital devices on a daily basis, but this, they point out, does not necessarily mean a high level of digital literacy.
"Frequent use of smartphones, social networks, electronic banking or online shopping does not automatically mean the user's ability to critically assess the authenticity of digital content, the identity of the interlocutor, the credibility of a financial offer, the method of processing personal data or the security consequences of a certain action," he says. Andreja Mihailović, Manager of the Innovation Hub for Cybersecurity at the University of Montenegro (UCG).
According to her, digital literacy encompasses much more than the operational ability to use devices and applications: 'It includes information and data literacy, source evaluation, problem solving, and digital security.'
Some are more exposed, but no one is completely immune
According to data released at the end of March, 62 criminal reports for cybercrime, including phishing, smishing, online financial fraud and identity theft, have been filed with the Police Directorate in the last three years.
"No one is completely immune to a well-prepared scam," says Džakula.
Interlocutors of "Vijesti" indicate that senior citizens and people with less developed digital skills may be particularly vulnerable. However, children and young people are not exempt from the risk either.
UP says that older people do not have enough technical knowledge to use technology safely, and young people do not have enough knowledge to critically understand the content they are served.
They add that older generations are particularly vulnerable when they receive a fake message from a bank, post office, government institution, or other authority, while young people, although they are excellent at using technology, largely fail to recognize disinformation, manipulative content, deepfake records, hidden advertisements, and similar phenomena.
Džakula says that young people are a risky group because they make decisions quickly, are influenced by influencers, and are also convinced that they know the internet well.
According to him, people under financial pressure, people entering the world of cryptocurrencies for the first time, and those who receive an offer from a friend or acquaintance are also at risk.
The public administration sector also points out that victims of online fraud are not necessarily those who lack IT skills.
"Scams are increasingly sophisticated today and often very convincingly imitate banks, government institutions, companies or people that users trust. They most often rely on inducing fear, a sense of urgency, curiosity or trust," they said, adding that the development of artificial intelligence further increases this challenge.
That is why, they add, in addition to technical knowledge, it is increasingly important to develop critical thinking and the habit of checking information.
"Scammers exploit trust, emotions and pressure. They misuse media logos, names of government officials, photos of famous people and the appearance of legitimate portals. They then offer easy money and demand that a decision be made immediately."
The UP believes that the key problem is that citizens massively use electronic banking and online shopping, "but they do not yet have sufficiently developed habits in the field of cybersecurity."
"This is precisely what makes citizens an extremely attractive target for criminals, because the fraudster no longer needs a complex technical penetration into the system, but rather simply sends the user a convincing message, or a phishing link," they say.
Misuse of brands, creating a false image
The editorial staff of "Vijesti" has repeatedly informed the public about a sponsored post on social networks, which uses the brand's name and logo, with claims about alleged new laws, financial benefits and an invitation to click on a link. In one of such posts, the name of the Prime Minister is also used. Milojko Spajić, and retirees are encouraged to invest in order to receive certain income later...
In recent months, 'Vijesti' has also published several articles about the 'DistributeX' platform, against whose founders several criminal charges have been filed on suspicion of crypto and financial fraud… The injured parties told the editorial staff that, among other things, they were misled because a non-governmental organization was used for the scheme, whose registration was approved by the Ministry of Regional Investment Development and Cooperation with NGOs. The scheme operated through groups on WhatsApp, a regular application that is used globally for communication. 'DistributeX' also had offices in several cities in Montenegro, one of which is in the Preko Morača district of Podgorica.
"The 'DistributeX' case showed that even an office, promotional events, WhatsApp groups, and a large number of members are not proof that the business model is legitimate," says Branko Džakula.
The UP also reminds us of other types of fraud that are present in the online space of Montenegro, including phishing messages distributed via SMS, Viber and WhatsApp, where, they explain, the ultimate goal of the fraudsters was to trick the victim into opening a link and providing personal data, passwords, card numbers or security codes...
What helps scammers get by?
The Internet has been commercially used and expanded in Montenegro since the establishment of the Internet Montenegro company in May 1997. However, citizens continue to fall prey to various online content.
Mihailović says this is because modern digital fraud is based less and less on the technical unsophistication of the victim, and more and more on professionalized manipulation of the user.
"Today's campaigns use visually almost identical copies of legitimate media and institutions, internet addresses that differ minimally from the originals, stolen logos and identities, compromised accounts, sponsored ads, fake comments and reviews, fake profiles of experts, banks or public officials, and increasingly synthetically generated audio-visual content," she said.
Generative artificial intelligence, according to her, is further changing the way fraud is prepared and carried out.
'It is now much easier for a fraudster to produce grammatically flawless text, a personalized message, a convincing visual identity, a voice imitation, or a convincingly altered video. This reduces the number of indicators that users have traditionally relied on to recognize fraud.'
He also points to examples such as the one in which the identity of "Vijesti" and the name of the Prime Minister are used. Milojko Spajić, and citizens are encouraged to invest.
'The example represents a combination of several highly effective techniques: misrepresentation, abuse of the media's reputational authority, the psychological tendency to trust authorities more, and a financial incentive based on the expectation of profit.'
It is particularly problematic, he explains, when fraud passes through legitimate digital infrastructure: a social network, advertising system, search engine, or communication application.
"Presence on a well-known platform creates an additional illusion of credibility for the average user. That's why it's no longer enough to tell users to 'not click on suspicious links'. The problem is that a link, ad or portal often no longer looks suspicious, and the key competency of a modern user is not intuitive recognition of fraud, but verification of authenticity through an independent channel."
The most important lessons
Before any lesson, Džakula says that victims should not be ridiculed: "Shame often leads people to report fraud late, which reduces the possibility of limiting the damage."
When it comes to lessons that every internet user should know, one of the most important, as stated by the public administration department, is that one should not automatically trust content on the internet just because it looks convincing or comes from a seemingly familiar source.
That is why they say that before opening a link, submitting data, or sharing information, it is necessary to check the source, sender, and credibility of the content.
"The appearance of a page is not proof of its authenticity. Any important information should be verified through another, independent channel. When an ad looks like a text from a media outlet, the user should independently open the official website of that media outlet and search for the publication," says Džakula.
The University of Pristina recommends special caution when opening links that arrive via SMS messages, e-mail, platforms such as Viber, WhatsApp, social networks, or other communication applications.
"Banks, government institutions, and serious companies will never ask citizens to provide sensitive data via messages," they say.
This means, Džakula explains, that legitimate institutions never ask users for a password, PIN, number from the back of the card, or one-time code.
If a user receives an alleged message from a bank, according to Mihailović, they should not check via the link in the same message.
"It is necessary to independently open the official application or contact the bank via a previously known number. The same applies to the media, government bodies and other institutions."
The MPA also reminds of the basic rules of digital security: do not share passwords, PIN codes and other sensitive data, use strong and different passwords, and enable multi-factor authentication wherever available.
They emphasize that special caution should be exercised when users are asked to respond urgently or provide personal and financial information.
"A legitimate business will not ask you to deposit money first in order to make money. The promise of safe and quick profits is almost always a red flag," says Džakula.
Mihailović recalls cases such as the 'DistributeX' scheme and says that in similar models, one of the central elements of the analysis must be the source of economic return.
"It is not enough to ask whether the platform is paying users. It is necessary to ask what real market activity generates the income from which these payments are financed. If the financial sustainability of the system is dominantly tied to the continuous influx of new members and their payments, rather than to an identified market activity that creates value, this is a very serious indicator of a fraudulent or pyramid scheme," she said.
A particularly dangerous indicator, he adds, is the request that the victim, after having already invested money, pay an additional amount in order to withdraw the allegedly earned profit:
"It's a typical advance payment fraud mechanism."
Džakula says there is a simple rule:
'Stop, check and research through trusted sources, ask another person before you deposit money or send personal information. Often if you also use an AI tool like ChatGPT, Gemini, Claude, Grok, and provide a query to verify a site or request, they can quickly analyze and identify online fraud.'
Stop, check and explore: Branko Džakula
foto: IT Cortex
Education since elementary school
Digital literacy, according to the MPA, cannot be acquired once and considered a completed process.
"Technology, and therefore risks, are changing very quickly. That is why continuous education is needed through the formal education system, but also through practical training, public campaigns, media content and programs intended for different age and social groups," they say.
They believe that digital literacy is a shared responsibility.
For Džakula, digital security, media and financial literacy should be part of education from primary school onwards, and children should work on real examples of fake messages, advertisements, investment offers and content created with the help of artificial intelligence... He does not leave out the role of the media and institutions:
"The media should publish brief instructions for recognizing and reporting similar cases along with reports on fraud. Institutions should provide a clear place to report online fraud. Banks and telecommunications companies can send alerts when they recognize mass campaigns or unusual transactions."
Džakula also recommends that experts, schools, libraries, and pensioner associations organize short, free training sessions, and as he said, family is also important.
"Senior members should not be criticized, but encouraged to call someone they trust before making an unusual payment or sending documents."
The MPA points out the importance of each individual, saying that older family members should be helped to protect their accounts, and children should be talked about safe behavior on the internet, and others should be warned about attempted fraud...
"These are simple examples of how we can contribute to a safer digital environment."
Džakula says the goal is not for every citizen to become a cybersecurity expert: "The goal is for them to know when to stop, how to verify information, and who to report a problem to."
The MPA adds that the goal of digital literacy is to empower citizens to use technology independently, responsibly, critically, and safely.
UP said that digital literacy should become part of basic life literacy:
"Because by developing such habits in children, parents, teachers, journalists, civil servants, entrepreneurs and all other citizens, we will create a society that is more resistant to fraud, manipulation and misuse of technology."
Who to report fraud to
If the fraud has already occurred, says Džakula, it is necessary to immediately contact the bank, change passwords, save messages and payment receipts, and report the case to the police and CIRT.
CIRT is a government body responsible for responding to computer security incidents in the cyberspace of Montenegro, and its address on the Internet is: https://cirt.gov.me/
Reports to the Police Directorate can be submitted via the Police of Montenegro, the official citizen application, which is available for both iOS and Android devices.
See more:
Download the app and follow the news FOLLOW US ON
(0)Comments