Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

41–50 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#41

The easiest way to avoid this entire class of attack, is to never be willing to answer any kind of question from someone who calls you. Always hang up, Google the customer support line for the business, then call them .

We should have learned this one a long time ago from email. If something comes through from a service which may require action, then go directly to the service and stop interacting with the email.

Phones seem just as dangerous these days. I don't answer them at all. Anyone who really needs to get in touch knows multiple services that will get through to me.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#42
post #10

I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…

In Sweden we have BankID - a two-factor, two-way authentication using public/private encrypted keys that's bound to a smartphone as a signature.

The process is user-friendly while keeping security high:

- The place where you want to login has to trigger the authentication from their server on every login - and have to be certified for BankID.

- You then have to open the app, enter your fingerprint or 6-pin code before you can enter.

It's available for all state-run services including all banks and post offices.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#43
post #35
post #19

Earlier quoted context omitted.

Your bank. If someone rings you claiming to be from them, you hang up and call the phone number printed on the back of your card.

My bank has terrible call waiting lines and they even overcharge for it! And it's not just banks that are being phished

Switch to a better bank. The only way you can make change happen is by using your consumer power.

Switching accounts is easy - see https://www.currentaccountswitch.co.uk/ - all your bills are autoswitched, your pay cheque gets redirected, and it happens pretty quickly.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#44
post #37

My simple policy is I never give out any information if I'm cold-called. If they claim they're my bank, I say I'll call them back on the number printed on the card, and ask the caller which department I should be put through to. Legitimate callers have never objected to this approach, and it saves me any stress - same policy, no matter the caller, no exceptions, no need for me to try and figure out if I'm being phish…

Good idea - but here in the UK there was a scam where they called you and THEN suggested you call the number on the back of the card. They then don't hang up, but play a dialling tone down the line until you dial the number. At which time they 'answer'. This only works on home phones, not mobile, but is worth considering, and warning your family/friends about.

Fuck that's clever

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#45
post #14

I mean, if they called you why do they need to send you a pin though? Safest way is to just always call the bank back that’s what I do.

Be careful with trust if you call them back. There are possible ways to trick you into either staying on line, or just taking over your connection. GSM has pretty shitty security.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#46
post #21
post #9

This is very scary for the average person. I've taken to simply not answering any questions (not even to confirm my name) if someone calls me. If my bank calls me then I call them back on a number that's on their web site.

If my bank calls me then I call them back on a number that's on their web site. I'm always amazed at how stupid the security situation is in these cases. Banks, telecoms services, etc. do actually call up and try to 'take me through security', and when I say "tell me something you know about me first so I know you're who you say you are", the best they can usually manage is "well, uh, you bank with [Bank]". It just p…

I’ve tried getting them to give me a checksum to verify validity. For example, tell me the sum of the last four digits of my card number. They always refuse, so I always hang up and call back. Too bad they don’t understand that giving out a checksum is not insecure.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#47

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

Interesting thanks for the write-up.

One thing that I've frequently heard is that in any type of fraud call you should always hang up right at the beginning and call the bank back.

Seems like no matter how sophisticated the attackers, this defense will always foil anything along the same lines of what happened to you. The only way I can see this countermeasure failing is if the scammers can somehow manage to intercept inbound calls to the bank's customer service number.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#48
post #10

I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…

Oh it gets worse. My UK bank had a hardware token for years. They recently "upgraded" my security for online banking, and now use SMS 2FA codes for login and authorising new transfers. The hardware token is now unusable. I'd change banks, but I doubt the others are better.

They are better. One of my banks offer a hardware token which requires my card to be physically present and for a correct PIN to be entered. The other has an app with push notifications which can be used to approve or deny transactions.

Seriously, switch bank.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#49
post #37

My simple policy is I never give out any information if I'm cold-called. If they claim they're my bank, I say I'll call them back on the number printed on the card, and ask the caller which department I should be put through to. Legitimate callers have never objected to this approach, and it saves me any stress - same policy, no matter the caller, no exceptions, no need for me to try and figure out if I'm being phish…

Good idea - but here in the UK there was a scam where they called you and THEN suggested you call the number on the back of the card. They then don't hang up, but play a dialling tone down the line until you dial the number. At which time they 'answer'. This only works on home phones, not mobile, but is worth considering, and warning your family/friends about.

But, if I don't hang up the received and the counterparty hangs up, then the line tone is the one of the "busy", not the one of the "free", and I'm unable to dial anyone until I physically hang up to reset the line. Or at least that's how it works back home. Is it different in UK ? I suppose it's something that less attentive people might fall for anyways.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#50

Tldr is: they call him posing as a fraud prevention team, "we are sending you a pin to confirm its you", they trigger the password reset flow which sent him a pin, he reads out the pin, they get into the account and read some recent transactions, but needed another pin to transfer money, he wisens up. Mitigation: password reset pins should say "this is your password reset pin".

If I try to reset my password bank screams at me in every possible way, including the pope calling himself and asking if thats legit. Actually there is a 50% chance I'll lock myself out of the account when doing this, because I misstep at some point. Seriously what year is that?
Post reply on HN