Live data from Hacker News

I Dialed a Wrong Number and Stumbled into International Phone Fraud

theatlantic.com

31–40 of 113 posts

Re: I Dialed a Wrong Number and Stumbled into International Phone Fraud

#31
post #27

I still don't understand, how do the scammers actually get paid?

"My phone call never actually made it to Cuba. The fraudsters make money because the last carrier simply pretends that it connected to Cuba when it actually connected me to the audiobook recording. So it charges Cuban rates to the previous carrier, which charges the preceding carrier, which charges the preceding carrier, and the costs flow upstream to my telecom carrier."

Re: I Dialed a Wrong Number and Stumbled into International Phone Fraud

#32
tl;dr This summarizes it perfectly.

  My phone call [to a disconnected number] never actually made it to Cuba. The fraudsters make money because the last carrier simply pretends that it connected to Cuba when it actually connected me to the audiobook recording. So it charges Cuban rates to the previous carrier, which charges the preceding carrier, which charges the preceding carrier, and the costs flow upstream to my telecom carrier. The fraudsters siphoning money from the telecommunications system could be anywhere in the world.

Re: I Dialed a Wrong Number and Stumbled into International Phone Fraud

#33
post #3

Long ago I did some contract coding for a company that processed donations via credit card. To my amazement, we had to watch out for people trying to donate small amounts to the Red Cross. Why? Because people with a list of possibly-valid credit card numbers would use small donations to brand-name charities as a way of validating credit cards. It made me long for some sort of professional association that kept track…

I'm surprised this surprises anyone. This is common in brick and mortar stores as well.

If you're processing credit cards online, you should be using some sort of fraud detection, like Maxminds MinFraud or something like it.

Re: I Dialed a Wrong Number and Stumbled into International Phone Fraud

#36
post #4

Earlier quoted context omitted.

After launching several SaaS with a $1 trial and such, this also happens there.

I think the candy japan guy from around here talks about it a lot.. people using candy to validate stolen CCs...

Relevant post: https://www.candyjapan.com/behind-the-scenes/how-i-got-credi...

Re: I Dialed a Wrong Number and Stumbled into International Phone Fraud

#37

I have a related story. I was in North America, looking for an apartment in Australia. At the time I'd buy phone cards for long distance calls, and they'd always work fine. So, I used the phone card, and tried to call someone about an apartment that looked great. According to the advertisement, it was a woman that owned the apartment and she had an extra bedroom she was renting. I called, and a man answered. It went…

I wonder if they've done any research on what sort of recording keeps people on the line the longest.

I'd like to offer you a job in our marketing org

Re: I Dialed a Wrong Number and Stumbled into International Phone Fraud

#38

I have a related story. I was in North America, looking for an apartment in Australia. At the time I'd buy phone cards for long distance calls, and they'd always work fine. So, I used the phone card, and tried to call someone about an apartment that looked great. According to the advertisement, it was a woman that owned the apartment and she had an extra bedroom she was renting. I called, and a man answered. It went…

I'm surprised they bother when the scams cheap cards pull are often waaaaay easier.

The cheekiest example I've seen was great in its own way: it defined an advertised minute as being 55 seconds long.

Re: I Dialed a Wrong Number and Stumbled into International Phone Fraud

#39

Interesting to note that Phreaking is still very much alive and kicking. Most of the hackers I know gave up on Phreaking once hacking became popular in their circles. To me, there will always be something more fascinating about the telephone infrastructure.

I think of phreaking as a byproduct of an era where signal controls were integrated in bearer traffic.

It feels magical to know that the same transport that delivers the sound of your voice was susceptible to tampering and rerouting by other sounds.

This is something other than phreaking, imo. It's straight forward service fraud and hacking. Bearer and Signal have been divorced. The attacker has to get privileged access to a network that is generally not accessible to the public. Phreaking was neat because literally anyone could do it if they knew about the methods.

Knowing the methods used here isn't enough. You need to get on the trusted SS7 network and have a roaming/interconnect agreement to start doing really interesting things.

Re: I Dialed a Wrong Number and Stumbled into International Phone Fraud

#40
post #6

The problem with stopping fraud is that people generally do not fight fraud as hard as fraudsters fight to keep their income.

Definitely. There's also the same sort of issue with gazelles and cheetahs. Both are fast, but for the cheetah to get its dinner, it only has to be faster than the slowest gazelle. I'm sure some of the phone companies are reasonably fraud-resistant, but securing a whole industry is harder.

Well, in that case the companies just have to not be the slowest gazelle, right? That doesn't seem like much effort involved, so the problem is probably in knowing what the other companies are doing so you're not the mark.
Post reply on HN