OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
I was just subjected to the most credible phishing attempt I’ve experienced
111–120 of 360 posts
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#112Quick question: What would an attacker gain from getting into your bank account? From mine (french big bank), they could be annoying (asking the bank to close accounts, ordering new checkbooks, getting all kind of information on past transactions, wire money between my accounts), but I can't see how one would effectively leverage that. I mean, an attacker goal would be to draw money in some way; all money wirings to…
I'm in the UK and have a personal account with HSBC and a business account with Lloyds. In both cases I need to generate a code to setup a new recipient - using the app (HSBC) or a physical card reader (Lloyds). I also get an SMS in both cases asking me to contact them if I didn't submit the request. So anyone gaining access to my accounts wouldn't be able to transfer money out.
I suppose they could do other things - contact the bank's support staff using their realtime chat thing maybe and social engineer something that way? Perhaps they don't ask for further confirmation in that case but I haven't checked.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#113Earlier quoted context omitted.
> Last time I needed a new token issuer dongle, I had to actually visit the bank and sign stuff. I'm glad UK banks try to avoid physical dongles because having to go to the bank and sign stuff to get one is not always convenient, not to mention you need to carry around the dongle everywhere, and if you lose it while you're in vacation it's yet more troubles. Phone 2FA would be good but a bit pointless because the 2FA…
I don't think having 2FA in phone app is pointless. It's still second factor, if someone got to your bank account. They need to get access to that 2FA app as well. And of course you protect that app with password/ping. Do you know of cases when 2FA app was defeated when someone stole money from bank account?
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#114OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#115OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
So how are they going to verify it’s you who is calling them?
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#116And as always: The best defense is minimizing data other people have about you. None of my banks needs my phone number, so none of my banks has my phone number, so if someone called and claimed they were my bank, that would obviously be bullshit. It's not just the obvious "people can't abuse or lose data they don't have" why keeping your info to yourself protects you against abuse.
Wow, I am pretty sure most banks require a phone number when you open an account. Or do you give them a random number?
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#117OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
It should be noted that Caller ID spoofing is possible with pretty basic equipment. It's illegal in most countries but there's nothing technically preventing you from doing it. Which is crazy IMO.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#118OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
It should be noted that Caller ID spoofing is possible with pretty basic equipment. It's illegal in most countries but there's nothing technically preventing you from doing it. Which is crazy IMO.
Would love to see a citation for this.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#119OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
Interesting thanks for the write-up. One thing that I've frequently heard is that in any type of fraud call you should always hang up right at the beginning and call the bank back. Seems like no matter how sophisticated the attackers, this defense will always foil anything along the same lines of what happened to you. The only way I can see this countermeasure failing is if the scammers can somehow manage to intercep…