Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

1–10 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#2
Tldr is: they call him posing as a fraud prevention team, "we are sending you a pin to confirm its you", they trigger the password reset flow which sent him a pin, he reads out the pin, they get into the account and read some recent transactions, but needed another pin to transfer money, he wisens up.

Mitigation: password reset pins should say "this is your password reset pin".

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#3
Seems to me the bank should take more care for resetting a user's internet banking password. For example as far as I know, all banks in the UK need you to call them up and answer a couple of verification questions before reseting any login details.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#4
Saw this on Twitter this morning. Sounds like they must have engineered it and set things up beforehand because they (a) knew which bank he was with and (b) had everything set up ready to log in when they got his ID number and received the password reset code from his text message.

I guess one thing that could have mitigated this quicker is if the text from the bank had said "Here is the code you requested to reset your online password" instead of a generic "Your authorisation code is..."

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#5
It sounded sketchy from the moment they asked for a pin code that they sent to your phone. It's easier to talk from the outside, but that should always be a red flag. What exactly would they be confirming by sending a PIN to the same number they were already contacting?

But that's a great heads up. Phishing is not just about obviously fake e-mails to hotmail accounts.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#8

Saw this on Twitter this morning. Sounds like they must have engineered it and set things up beforehand because they (a) knew which bank he was with and (b) had everything set up ready to log in when they got his ID number and received the password reset code from his text message. I guess one thing that could have mitigated this quicker is if the text from the bank had said "Here is the code you requested to reset y…

[deleted]

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#10
I keep getting astonished by how bad online banking security is in the UK and US.

Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset.

Last time I needed a new token issuer dongle, I had to actually visit the bank and sign stuff.

Post reply on HN