Don't EVER communicate the following verification number to anyone, including collaborators: 123456
SMS OTP should always have that or similar text.I was just subjected to the most credible phishing attempt I’ve experienced
31–40 of 360 posts
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#32If someone is asking you the PIN so they can confirm it is you, you can ask them to give you the PIN so that you can tell if it matches or not.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#33The banks here in the Netherland all have (well, except for one maybe) hardware authentication devices. They are portable smartcard readers, you insert your card, enter your PIN on the device itself (not your computer or phone) and transfer a digest from your PC to the reader by typing or scanning a QR code (some readers have a little camera). You then type the signature into your computer or phone.
The readers for my bank even have a screen, that tells you what you are signing, like a login, or transfer of which amount to which bank account. Photo here [0].
The banks are very clear that they will never ask you to use the device over the phone. And that double confirmation by showing the sign action on the screen of the reader makes any form of phishing really hard.
IMO these smart card readers are the best compromise between convenience and security for banking.
[0] https://4.bp.blogspot.com/-6c1NGHew1P8/VBqvTeqDQdI/AAAAAAAAf...
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#34It sounded sketchy from the moment they asked for a pin code that they sent to your phone. It's easier to talk from the outside, but that should always be a red flag. What exactly would they be confirming by sending a PIN to the same number they were already contacting? But that's a great heads up. Phishing is not just about obviously fake e-mails to hotmail accounts.
Like you said, spam and phising used to be obviously bad but I'm afraid I'm going to fall for it some day now.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#35Who does "Phishing protection as a Service"? Like, a line you can call and ask "Is this legit?" .
Your bank. If someone rings you claiming to be from them, you hang up and call the phone number printed on the back of your card.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#36I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…
Meanwhile, banking security in the US is stuck in the Stone Age. Last I checked Wells Fargo, one of the largest US banks, still does not allow passwords greater than 14 characters in length and passwords are not case sensitive.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#37My simple policy is I never give out any information if I'm cold-called. If they claim they're my bank, I say I'll call them back on the number printed on the card, and ask the caller which department I should be put through to. Legitimate callers have never objected to this approach, and it saves me any stress - same policy, no matter the caller, no exceptions, no need for me to try and figure out if I'm being phish…
They then don't hang up, but play a dialling tone down the line until you dial the number. At which time they 'answer'. This only works on home phones, not mobile, but is worth considering, and warning your family/friends about.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#38The easiest way to avoid this entire class of attack, is to never be willing to answer any kind of question from someone who calls you. Always hang up, Google the customer support line for the business, then call them .
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#39It's even worse in Russia - fake caller ID makes you think you are talking with the bank, mobile phone operators don't seem to be doing much, or at least didn't a couple of months ago. That said, all the banks I used send you along with the confirmation code a description of what you are actually confirming.
It is in the protocol. Operators are not the only problem here.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#40The easiest way to avoid this entire class of attack, is to never be willing to answer any kind of question from someone who calls you. Always hang up, Google the customer support line for the business, then call them .
On UK landlines the call is not terminated until the person who made the call hangs up. That is to say if I call you, you answered and then hung up, then waited a minute and picked up the phone again, I'd still be there and the connection still made.
Scammers phoned people, told them there is an account issue and to phone the number on the reverse of their credit or debit card. The scammers keep the line open and play a recording of a dial tone to the target phoning back and then go through garnering all the details needed to rinse the accounts.
I believe in response UK phone networks are implementing time limits on one sided terminations