Live data from Hacker News

Voice Phishing Scams Are Getting More Clever

krebsonsecurity.com

31–40 of 226 posts

Re: Voice Phishing Scams Are Getting More Clever

#31
post #21

Earlier quoted context omitted.

It makes me laugh when my banks fraud department calls me and then asks me to verify myself to them by giving personal information before asking me questions. I usually laugh at them and tell them they they are the unverified party in this phone call, not me. I always pull up the website and confirm before telling them anything.

IMO even that's not sufficient. I've had calls claiming to be my bank that new dollar amounts and dates of 2 charges I had recently disputed. But I've been fooled once before, so I went into my local branch and spoke to the manager face to face. No one from the bank had placed a call regarding my account and there was no issue with my dispute. The phone number was not owned by the bank and after 2 voice mails they st…

To be honest even after I had seen that the charges being described to me on the phone were indeed on my account I was still running through scenarios where this could be a fraudulent call. However, I eventually came up with the logic that somebody had already managed to put the charge on my account, and once they'd gotten that far, I couldn't think of any reason for the scammer to call me. Basically, scammers had visibly already won prior to the call, so the odds of the call being fraudulent were low.

Re: Voice Phishing Scams Are Getting More Clever

#32
post #21
post #7

I'll give you the flip side of the scammer's deterioration of trust in the phone... a few months back I got a phone call from what appeared to be my bank, and they were asking me about a fraudulent charge that I didn't recognize. Worried that this was the beginning of a scam, I delayed a bit on the phone while I logged in independently to my bank account... and lo, yes, indeed, there was a fraudulent charge to my acc…

It makes me laugh when my banks fraud department calls me and then asks me to verify myself to them by giving personal information before asking me questions. I usually laugh at them and tell them they they are the unverified party in this phone call, not me. I always pull up the website and confirm before telling them anything.

> I usually laugh at them and tell them they they are the unverified party in this phone call, not me.

This is one of the related reasons why I finally got my ducks in a row and switched away from Chase three years ago. Their potential-fraud-has-happened outreach department was, in my experience, terrible about this. It didn't help that their potential-fraud-detection department was similarly bad. ("You used your debit card at an AM/PM in Washington State!!!!" Yes, I know, it is about 900 feet from my house; I go there regularly.)

Point being, I got quite a few calls from their (real) fraud prevention department about (supposed) fraud. Each time, the rep who called me would get mad at me for not handing over the last four of my SSN and my complete address to the calling party. I pointed out, each time, that they were the ones who called me so I should be verifying them. "But, sir, WE are the bank and you could be anyone who just answered your phone."

The credit union I now use just presents a message with their name and a request to call back. "We may have detected a fraudulent purchase; please give us a call at the number on the back of your card and reference case number [digits]." Fortunately, their system is much better; I've only heard this message once.

Re: Voice Phishing Scams Are Getting More Clever

#36
post #7

I'll give you the flip side of the scammer's deterioration of trust in the phone... a few months back I got a phone call from what appeared to be my bank, and they were asking me about a fraudulent charge that I didn't recognize. Worried that this was the beginning of a scam, I delayed a bit on the phone while I logged in independently to my bank account... and lo, yes, indeed, there was a fraudulent charge to my acc…

For those worried about a situation like this, I set up automated purchase alerts on my credit cards and withdrawal alerts on my bank accounts. I see it all in close-enough-to-real-time, and it's helped me catch fraud before the banks did at least twice in the past few years.

Also, for anyone that doesn't know: you can request an old school ATM card (not a debit card, i.e. no MC/Visa logo) from your bank and use a credit card for purchases instead.

This reduces the exposure of a critical account. And if you do become a victim of fraudulent charges, you don't have to worry about your bank account being drained immediately (possibly resulting in overdrafts, etc).

Re: Voice Phishing Scams Are Getting More Clever

#37
The issue, as I understand it, is that the SS7 telephone network is completely insecure assuming that you have the ability to connect to it. Shady gateway providers will allow you the privilege, and once you're in, you can do just about anything.

There is precious little within SS7 to prevent or respond to spoofing. It's a major nightmare for telephone companies.

Re: Voice Phishing Scams Are Getting More Clever

#38
post #16

How come in 2018 we can't get a reliable CallerID. Surely this is something that could be simply regulated. Perhaps there should be a few types of CallerID - verified, physical and nominated. Eg a company calls you with a verified ID (like TLS), a local number from a single line is physically authenticated and anything else is just a best guess. That way we can filter more reliably.

No options. Make it mandatory and make it unable to be faked.

It wouldn't really need to be mandatory, just something that cell providers and reputable businesses provided. Then phone companies could start rejecting anything that didn't provide it.

Re: Voice Phishing Scams Are Getting More Clever

#39
post #21

Earlier quoted context omitted.

It makes me laugh when my banks fraud department calls me and then asks me to verify myself to them by giving personal information before asking me questions. I usually laugh at them and tell them they they are the unverified party in this phone call, not me. I always pull up the website and confirm before telling them anything.

> I usually laugh at them and tell them they they are the unverified party in this phone call, not me. This is one of the related reasons why I finally got my ducks in a row and switched away from Chase three years ago. Their potential-fraud-has-happened outreach department was, in my experience, terrible about this. It didn't help that their potential-fraud-detection department was similarly bad. ("You used your deb…

their potential-fraud-detection department was similarly bad. ("You used your debit card at an AM/PM in Washington State!!!!" Yes, I know, it is about 900 feet from my house; I go there regularly.)

A year ago I had an awful experience with this.

We were on vacation at Big Bend National Park, which is hours away from everything in southwest Texas. When trying to pay for breakfast, our card was denied. I tried to call the card company to tell them that it was OK, but couldn't get through - there was no cell service. Outside the restaurant was a pay phone (remember them?) that I was able to use to call their 800 number.

I learned then that they'd actually flagged my card as stolen, so I could no longer use it at all, and to get it turned back on I needed to receive the code they were sending by SMS and read it back to them. The thing was, we were in a dead cell area, we couldn't get the SMS. And Big Bend is mind-bogglingly huge - 1,252 of square miles of mostly desert (there's a whole mountain ranged entirely contained within the park). As far as I could tell, I didn't have enough gas to drive out of the park to get to cell service to achieve this (the park is so big that it's got its own gas station in the middle, and I'd intended to use this - but without my card, how can I?).

It seemed a perfect trap, there was no way we were going to be able to get out. What eventually saved us was that the hotel manager overheard me shouting at the card people, and came out to give me a map, with the places inside the park that can get SMS text highlighted. Using that I was able to fulfill their requirement.

They never were able to tell me why they flagged the card in the first place. They told me that they advise all card holders to warn them when they plan to go out of state. But I live in Texas, and I was in Texas when the charge triggered. They just shrugged that off.

Re: Voice Phishing Scams Are Getting More Clever

#40
post #21
post #7

I'll give you the flip side of the scammer's deterioration of trust in the phone... a few months back I got a phone call from what appeared to be my bank, and they were asking me about a fraudulent charge that I didn't recognize. Worried that this was the beginning of a scam, I delayed a bit on the phone while I logged in independently to my bank account... and lo, yes, indeed, there was a fraudulent charge to my acc…

It makes me laugh when my banks fraud department calls me and then asks me to verify myself to them by giving personal information before asking me questions. I usually laugh at them and tell them they they are the unverified party in this phone call, not me. I always pull up the website and confirm before telling them anything.

This works as long as you're not talking to the scammers who themselves made the fraudulent transactions (which would be why they knew the times, locations and amounts involved).

A bit of a stretch perhaps :)

Post reply on HN