Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

111–120 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#111

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

The best defense against a scam is familiarity. Thanks for sharing this, hopefully it protects someone else.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#112

Quick question: What would an attacker gain from getting into your bank account? From mine (french big bank), they could be annoying (asking the bank to close accounts, ordering new checkbooks, getting all kind of information on past transactions, wire money between my accounts), but I can't see how one would effectively leverage that. I mean, an attacker goal would be to draw money in some way; all money wirings to…

I'm not sure why you've been downvoted for this - it's a perfectly legitimate question.

I'm in the UK and have a personal account with HSBC and a business account with Lloyds. In both cases I need to generate a code to setup a new recipient - using the app (HSBC) or a physical card reader (Lloyds). I also get an SMS in both cases asking me to contact them if I didn't submit the request. So anyone gaining access to my accounts wouldn't be able to transfer money out.

I suppose they could do other things - contact the bank's support staff using their realtime chat thing maybe and social engineer something that way? Perhaps they don't ask for further confirmation in that case but I haven't checked.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#113

Earlier quoted context omitted.

> Last time I needed a new token issuer dongle, I had to actually visit the bank and sign stuff. I'm glad UK banks try to avoid physical dongles because having to go to the bank and sign stuff to get one is not always convenient, not to mention you need to carry around the dongle everywhere, and if you lose it while you're in vacation it's yet more troubles. Phone 2FA would be good but a bit pointless because the 2FA…

I don't think having 2FA in phone app is pointless. It's still second factor, if someone got to your bank account. They need to get access to that 2FA app as well. And of course you protect that app with password/ping. Do you know of cases when 2FA app was defeated when someone stole money from bank account?

What I mean is that if a user has access to my bank mobile app on my phone, they also have access to the Google Authenticator app. With Lloyds, the app is locked by finger print or password which in this particular scenario is actually more secure.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#114

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiate a call (usually they launch straight away into verifying who I am, asking me a ton of personal details before I even know that they're legit... sigh) and would just ask me to call them back on an official number (not one they give me over the phone, obviously) instead. If that were standard practice, I think these kind of scams would be a lot easier to detect.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#115

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

> My bank no longer allows me to reset my password without calling them (thanks bank).

So how are they going to verify it’s you who is calling them?

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#116

And as always: The best defense is minimizing data other people have about you. None of my banks needs my phone number, so none of my banks has my phone number, so if someone called and claimed they were my bank, that would obviously be bullshit. It's not just the obvious "people can't abuse or lose data they don't have" why keeping your info to yourself protects you against abuse.

Wow, I am pretty sure most banks require a phone number when you open an account. Or do you give them a random number?

Well, many require that you fill the phone number field, but just entering zeros does the job. If anyone (not just banks) does extended validation, I enter some syntactically valid but unallocatable number, that has always done the job so far.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#117
post #99

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

It should be noted that Caller ID spoofing is possible with pretty basic equipment. It's illegal in most countries but there's nothing technically preventing you from doing it. Which is crazy IMO.

SMS number spoofing is even easier, and available via almost all programatic SMS services. Usually used to set the sender name.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#118
post #99

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

It should be noted that Caller ID spoofing is possible with pretty basic equipment. It's illegal in most countries but there's nothing technically preventing you from doing it. Which is crazy IMO.

>It’s illegal in most countries

Would love to see a citation for this.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#119

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

Interesting thanks for the write-up. One thing that I've frequently heard is that in any type of fraud call you should always hang up right at the beginning and call the bank back. Seems like no matter how sophisticated the attackers, this defense will always foil anything along the same lines of what happened to you. The only way I can see this countermeasure failing is if the scammers can somehow manage to intercep…

IMHO this should be the law for financial and medical institutions tc. They should not be allowed to call and ask the receiver to provide verification information.
Post reply on HN