The Agency of the Republic of Kazakhstan for Regulation and Development of the Financial Market (ARDFM) has warned citizens about mobile applications that can access users' personal data, reports infohub.kz.
As noted in the agency's statement, when installing programs, many users automatically agree to requested permissions without considering how necessary they are for the service to function. As a result, dozens of installed apps may gain access to the camera, microphone, contacts, geolocation, files, and other data.
"Excessive permissions increase the risk of personal information leakage, its misuse, and fraudulent attacks," the ARDFM emphasized.
Depending on the app's functionality, it may request access to geolocation to determine the device's location, camera and photo gallery for creating photos and videos or accessing saved files, microphone for recording and transmitting audio, contacts for accessing the phone book, files and device memory for working with documents, calls and SMS, including reading messages with confirmation codes, as well as notifications for sending messages that may contain personal information.
"The necessity of granting each permission should correspond to the app's functionality. For example, a calculator or flashlight in most cases does not require access to contacts, SMS, or geolocation," the agency added.
Kazakhstanis were reminded that if an app or its developer's infrastructure is subjected to a cyberattack, the data obtained could be compromised and used by malicious actors. In particular, the information could be used to prepare personalized phishing attacks, social engineering and fraud, gaining access to other accounts, creating a detailed digital profile of the user, and unlawful distribution or commercial use of personal data.
Special attention should be paid to apps that request permissions unrelated to their core functions. First of all, the Agency's experts recommend limiting access to geolocation: for apps that do not require constant location tracking, it is recommended to choose the "while using the app" mode or completely disable access. Also, access to the camera and microphone should be restricted, granting it only to those apps that truly need it for operation. Additionally, it is better to limit access to contacts and files if the app's functionality does not involve working with the phone book or documents.
It is necessary to reconsider the need to use an app if it requests a large number of permissions unrelated to its functionality; there is no reliable information about the developer; the app is downloaded from an unknown or unofficial source; the service contains an excessive amount of intrusive advertising or pop-ups; or the app requires access to SMS, contacts, payment, or other confidential data without obvious necessity.
"Personal data is valuable information that can be used by malicious actors to prepare targeted fraudulent attacks. Do not give an app more access than necessary for its operation. Regularly checking permissions is a simple habit that helps protect personal data and increase the level of digital security," the ARDFM reminded.


