Phone scammers increasingly open conversations by telling their potential victim their individual identification number (IIN), first name and surname. This creates the illusion that the call is genuinely from a bank or a government agency. However, a 12-digit identification number alone is not enough to take out a loan, obtain a banking service or register a SIM card. Kursiv investigated why fraudsters need these digits and what information is truly dangerous to share with strangers, according to infohub.kz.
An IIN by itself does not open access to government information systems or banking services, but it can become part of a social engineering scheme. For example, a fraudster cites data they already know to try to extract more important information from the person.
"An IIN alone is not enough to take out a loan, obtain banking services, register a SIM card or carry out other financial transactions. Banks, microfinance organizations and telecom operators use additional identification and authentication methods, including identity verification, biometrics, one-time SMS codes, digital signatures and other methods provided for by law," the Agency for Regulation and Development of the Financial Market told Kursiv in response to a request.
Thus, what mainly interests fraudsters is information that can confirm identity or a transaction.
The Ministry of Internal Affairs recommends not sharing SMS codes, passwords, bank card details or mobile banking logins with strangers. It also advises against following suspicious links or installing apps at the request of unknown callers.
Separately, the Ministry of Artificial Intelligence and Digital Development warns about codes from 1414.
"Never share confirmation codes from 1414, as they are intended for the account owner and can provide access to government services. Government agencies and banks never request banking details, SMS codes or other data needed to confirm transactions by phone or via messengers," the digital ministry said in response to Kursiv's request.
Consequently, if the caller already knows the IIN and other personal details, that does not mean they have gained access to accounts or government services. The danger arises the moment a person hands over login or transaction confirmation data themselves.
If a citizen has already shared personal or banking data with fraudsters, the Ministry of Internal Affairs recommends ending the conversation, contacting the bank, blocking banking access if necessary, checking account transactions and reporting to the police.
The Ministry of Digital Development also advises those who do not plan to take out loans to activate the "Stop-Credit" service in eGov Mobile. To check for a possible personal data leak, the ministry recommends NomadGuard.
In addition, compromised passwords should be changed and two-factor authentication enabled — this will also help protect accounts.
Earlier, Kursiv reported that the Ministry of Artificial Intelligence and Digital Development of the Republic of Kazakhstan responded to information about a hack of eGov and a data leak involving 15 million Kazakhstanis.


