Even if you don’t fall for this trick sms is not secure and most providers don’t even bat an eye if a fraudster walks into one of their stores and requests a sim registered to your phone number.
Password reset is a difficult problem.
121–130 of 360 posts
Even if you don’t fall for this trick sms is not secure and most providers don’t even bat an eye if a fraudster walks into one of their stores and requests a sim registered to your phone number.
Password reset is a difficult problem.
I mean, if they called you why do they need to send you a pin though? Safest way is to just always call the bank back that’s what I do.
Be careful with trust if you call them back. There are possible ways to trick you into either staying on line, or just taking over your connection. GSM has pretty shitty security.
I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…
Oh it gets worse. My UK bank had a hardware token for years. They recently "upgraded" my security for online banking, and now use SMS 2FA codes for login and authorising new transfers. The hardware token is now unusable. I'd change banks, but I doubt the others are better.
OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
A scam phone call seems like a clumsy way of doing it. It also risks alerting the victim to what's going on.
It surprises me that it is legal to conduct banking operations to the general public in this way. In many countries (including all of EU since SCA) that is not the case.
Earlier quoted context omitted.
Interesting thanks for the write-up. One thing that I've frequently heard is that in any type of fraud call you should always hang up right at the beginning and call the bank back. Seems like no matter how sophisticated the attackers, this defense will always foil anything along the same lines of what happened to you. The only way I can see this countermeasure failing is if the scammers can somehow manage to intercep…
IMHO this should be the law for financial and medical institutions tc. They should not be allowed to call and ask the receiver to provide verification information.
I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…
I have read about similar type of fraud. The scammers say that they are from the bank and they saw suspicious transaction and want to verify whether it was you, and try to get your card information and code from SMS.
Earlier quoted context omitted.
> Last time I needed a new token issuer dongle, I had to actually visit the bank and sign stuff. I'm glad UK banks try to avoid physical dongles because having to go to the bank and sign stuff to get one is not always convenient, not to mention you need to carry around the dongle everywhere, and if you lose it while you're in vacation it's yet more troubles. Phone 2FA would be good but a bit pointless because the 2FA…
> Phone 2FA would be good but a bit pointless because the 2FA app is on the phone, and so is the banking app. This is exactly like having a physical token with you. If it gets stolen, they have the tokens. But, at least, having token on the phone app is waymore convenient for customers and also has another layer of protection (think of the fingerprint/passcode ecc you need to access your phone)
You need my phone unlocked and my six digit pin in order to identify as me.
There are still possible social engineering attacks, though.
Saw this on Twitter this morning. Sounds like they must have engineered it and set things up beforehand because they (a) knew which bank he was with and (b) had everything set up ready to log in when they got his ID number and received the password reset code from his text message. I guess one thing that could have mitigated this quicker is if the text from the bank had said "Here is the code you requested to reset y…
Which bank you have is not very secret information. Any payment exposes that information. It's a very clever scam, but it's also a very insecure bank if this is enough to authorise payment. Get a different bank that uses 2FA, makes it clear what an authorisation code is for, and doesn't call you for this kind of sensitive information. If they really do need to reach you quickly to stop a fraudulent transaction, a sim…
Still, it means they had to spend some time to prepare for this specific person.
Aside - here in Europe, the account numbers including bank code is pretty much public information. Something like e-mail address. After all, you can only send something in there. To withdraw, you need login credentials.