I was just subjected to the most credible phishing attempt I’ve experienced
1–10 of 360 posts
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#2Mitigation: password reset pins should say "this is your password reset pin".
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#3Re: I was just subjected to the most credible phishing attempt I’ve experienced
#4I guess one thing that could have mitigated this quicker is if the text from the bank had said "Here is the code you requested to reset your online password" instead of a generic "Your authorisation code is..."
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#5But that's a great heads up. Phishing is not just about obviously fake e-mails to hotmail accounts.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#6Re: I was just subjected to the most credible phishing attempt I’ve experienced
#7Re: I was just subjected to the most credible phishing attempt I’ve experienced
#8Saw this on Twitter this morning. Sounds like they must have engineered it and set things up beforehand because they (a) knew which bank he was with and (b) had everything set up ready to log in when they got his ID number and received the password reset code from his text message. I guess one thing that could have mitigated this quicker is if the text from the bank had said "Here is the code you requested to reset y…
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#9Re: I was just subjected to the most credible phishing attempt I’ve experienced
#10Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset.
Last time I needed a new token issuer dongle, I had to actually visit the bank and sign stuff.