Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

121–130 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#121
Unfortunately it seems we went from one ineffective solution, knowledge of a social security number and some useless ‘security questions’, to the next ineffective solution.

Even if you don’t fall for this trick sms is not secure and most providers don’t even bat an eye if a fraudster walks into one of their stores and requests a sim registered to your phone number.

Password reset is a difficult problem.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#122
post #14

I mean, if they called you why do they need to send you a pin though? Safest way is to just always call the bank back that’s what I do.

Be careful with trust if you call them back. There are possible ways to trick you into either staying on line, or just taking over your connection. GSM has pretty shitty security.

The "staying on the line trick" is just fear mongering. On any digital phone line (including landlines, which are just SIP with a SIP-to-analog converted) the call is disconnected (as in a call clearing message is sent by the phone or converter) as soon as you hangup (which will make it all the way to the scammer's phone and disconnect the call on his end too). Re-initiating a call after this would involve a call setup message, followed by a ringtone and you'd have to explicitly pick up the phone for it to be reconnected. There's just no way for this to happen on modern phone infrastructures.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#123
post #10

I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…

Oh it gets worse. My UK bank had a hardware token for years. They recently "upgraded" my security for online banking, and now use SMS 2FA codes for login and authorising new transfers. The hardware token is now unusable. I'd change banks, but I doubt the others are better.

I hate hardware tokens. Recently got one from my bank. I'm switching banks. I just don't see any advantage over a phone app (plus a phone app can offer better notifications).

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#124

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

If the password reset procedure is over SMS, wouldn't any interception of that token have allowed the attackers to access your account and even initiate outgoing transfers?

A scam phone call seems like a clumsy way of doing it. It also risks alerting the victim to what's going on.

It surprises me that it is legal to conduct banking operations to the general public in this way. In many countries (including all of EU since SCA) that is not the case.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#125

Earlier quoted context omitted.

Interesting thanks for the write-up. One thing that I've frequently heard is that in any type of fraud call you should always hang up right at the beginning and call the bank back. Seems like no matter how sophisticated the attackers, this defense will always foil anything along the same lines of what happened to you. The only way I can see this countermeasure failing is if the scammers can somehow manage to intercep…

IMHO this should be the law for financial and medical institutions tc. They should not be allowed to call and ask the receiver to provide verification information.

It doesn't need to be the law: I never provide any information to someone who calls me, unless I have a way of authenticating them.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#126
post #10

I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…

[deleted]

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#127
In Russia when a bank sends a code via SMS, there usually is a comment like "don't tell this code to anyone, even to bank employees".

I have read about similar type of fraud. The scammers say that they are from the bank and they saw suspicious transaction and want to verify whether it was you, and try to get your card information and code from SMS.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#128

Earlier quoted context omitted.

> Last time I needed a new token issuer dongle, I had to actually visit the bank and sign stuff. I'm glad UK banks try to avoid physical dongles because having to go to the bank and sign stuff to get one is not always convenient, not to mention you need to carry around the dongle everywhere, and if you lose it while you're in vacation it's yet more troubles. Phone 2FA would be good but a bit pointless because the 2FA…

> Phone 2FA would be good but a bit pointless because the 2FA app is on the phone, and so is the banking app. This is exactly like having a physical token with you. If it gets stolen, they have the tokens. But, at least, having token on the phone app is waymore convenient for customers and also has another layer of protection (think of the fingerprint/passcode ecc you need to access your phone)

Over here in EU land the mobile identifier app is pin protected. Think Google Authenticator but with a pin to access the tokens.

You need my phone unlocked and my six digit pin in order to identify as me.

There are still possible social engineering attacks, though.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#129
post #26

Saw this on Twitter this morning. Sounds like they must have engineered it and set things up beforehand because they (a) knew which bank he was with and (b) had everything set up ready to log in when they got his ID number and received the password reset code from his text message. I guess one thing that could have mitigated this quicker is if the text from the bank had said "Here is the code you requested to reset y…

Which bank you have is not very secret information. Any payment exposes that information. It's a very clever scam, but it's also a very insecure bank if this is enough to authorise payment. Get a different bank that uses 2FA, makes it clear what an authorisation code is for, and doesn't call you for this kind of sensitive information. If they really do need to reach you quickly to stop a fraudulent transaction, a sim…

> Which bank you have is not very secret information. Any payment exposes that information.

Still, it means they had to spend some time to prepare for this specific person.

Aside - here in Europe, the account numbers including bank code is pretty much public information. Something like e-mail address. After all, you can only send something in there. To withdraw, you need login credentials.

Post reply on HN