Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

141–150 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#141
post #55

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

> It is better if [...anyone...] include a security warning / specific reason the code is sent with the password reset pins and similar credentials. I think anyone building such systems (either via e-mail or SMS or whatever) should at least remember THIS. Send something like this via SMS: > The password reset code you requested via our website is 12345. We will never ask you for this code except when you requested a…

BofA gives a disclaimer when you have a 2FA code texted to you (still wish they supported TOTP, but whatever).

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#142
post #9

This is very scary for the average person. I've taken to simply not answering any questions (not even to confirm my name) if someone calls me. If my bank calls me then I call them back on a number that's on their web site.

Being on HN I don't think I'm the average person, but I wouldn't rule out falling for this at some point in the future as well. But doubly so for my non-technical parent or partner, I guess.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#143
post #95
post #72

In EU, there is the (recent) implementation of a (new) directive, PSD2: https://en.wikipedia.org/wiki/Payment_Services_Directive#Rev... That carries with it the requirement of SCA: https://en.wikipedia.org/wiki/Strong_customer_authentication In practice (here in Italy) you have a client number (secret) a password/PIN (also secret) AND either a SMS to your mobile with a one time code or a Smartphone app (yikes!), ther…

Also, when you're wiring money to someone, my bank is now requesting to input certain digits of the amount and destination account into the app. Those digits are then factored into the 2FA algorithm. I am not sure if this adds substantially to the security though.

The idea is, it defeats attacks not so different from the one the Tweet is about, where you are misled about what will happen when you take an action.

If you only need "a code" whether it's to send $40 to a close friend or your entire account balance to an account you've never heard of that was created yesterday in a foreign country - then the scammers only have to trick you into trying to do the former, even though what they want to achieve is the latter, so that you'll give them a code which is what they need.

The bank can do a good or bad job of communicating what's going on and actually preventing the fraud, depending on whether the understanding of what they're trying to achieve was pushed down all the way from regulators to the engineers building the system.

The best systems here don't give you (and thus the attackers manipulating you) a lot of opportunity to manipulate things, but they do present you with information that should be raising red flags if you're being tricked. For example if the app says "Enter the six digits shown on the web page" and you just mindlessly copy those digits, an ordinary customer may not know why it's those six digits, bad guys with a fake web page can tell them to put whatever they want. Whereas if the _app_ says "Enter the whole dollar amount to send" then bad guys may struggle to explain why they want you to type 5839, your entire account balance, when you wanted to send $40 to the supposed friend in need and your suspicions might be raised enough for the scam to fail.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#144
Go to the police? Let us know how that works out for you. I did that once, after a highly credible phishing attempt (that, ultimately, I did not fall for). This was in Germany.

Me: Here is what happened to me, I'd like to file a police report.

Police: Well, with these internet scams, the fraudster is usually in another country, meaning we can't really do anything about it.

Me: They used perfect German, used information that I only ever provided into a non-public database of a German-based business that must have had a breach of some sort. The fraudster also used pictures of apartments in Germany that must have been taken here.

Police: Well, still. The person actually doing all of that could have been doing all of that from another country. Usually Russia or China or something.

Me [thinking to myself]: Yeah, Russia, or China, or some country where law enforcement generally presumes, even against all evidence, that any and all cybercrime is happening outside their jurisdiction and therefore not doing any law enforcement at all when it comes to cybercrime. Like what is happening right here right now.

Me: Well, I realize that nobody is going to start an investigation into this specific thing that happened here, but still: Isn't anyone at least compiling a database so that, once patterns become bigger and more apparent, an investigation of sorts may become warranted, etc?

Police: Nope. Nobody doing that. You can file a report. But I can tell you right now that nobody is going to look at it or do anything with it. Also, we kind of have more important things to do, here at the station. I mean: It's your choice. I can't stop you. Just telling you how it is.

Me: Okay, thank you, goodbye.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#145

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

In your tweets you mention "And now... joyfully resetting all my passwords, filing a police report, getting additional fraud detection in place". What passwords are you talking about and why do you need to reset them? As far as I can tell no passwords have been compromised in the attack as you describe it.

Or do you suspect that there's been an other, undisclosed breach that the scammer used to get your name and phone number? I suppose it's plausible but it seems like it wouldn't be too difficult to get that info.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#146
post #23

It's even worse in Russia - fake caller ID makes you think you are talking with the bank, mobile phone operators don't seem to be doing much, or at least didn't a couple of months ago. That said, all the banks I used send you along with the confirmation code a description of what you are actually confirming.

>> mobile phone operators don't seem to be doing much It is in the protocol. Operators are not the only problem here. https://en.wikipedia.org/wiki/Caller_ID_spoofing

Thanks for the link

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#147

My simple policy is I never give out any information if I'm cold-called. If they claim they're my bank, I say I'll call them back on the number printed on the card, and ask the caller which department I should be put through to. Legitimate callers have never objected to this approach, and it saves me any stress - same policy, no matter the caller, no exceptions, no need for me to try and figure out if I'm being phish…

I usually receive soft objections to this. They don't even seem to understand the problem most of the time. In fact, they speak rather like I would expect a scammer to: "but we just need to verify who you are, and you will still have to do this if you call the number on your card, so it's easier if I do it now".

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#148

Earlier quoted context omitted.

> My simple policy is I never give out any information if I'm cold-called. That's what I do. When someone calls me and then proceeds to ask me security question to allegedly assert my identity I reply "well, you called me so how do you prove to me who you are first?" I usually get a "err..." but on one occasion the guy was rather rude and hanged up. The worst thing is that most of the time these calls are genuine. Th…

My bank did this once - called me out of the blue and started asking for answers to security questions. I asked them how I could be sure it was definitely them and they said to call the number on my card and ask for a particular department, which I did, and it turned out it was indeed genuine. The fact that they had an immediate answer to the question obviously means that they were asked this question all the time. I…

Makes me wonder, what if a bank just started all phone calls like that with: "Hi this is Bank, we need to get in contact with you, for security reasons could you please hang up and call the number on the back of your card?"

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#149

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…

I always say to them: I can not identify myself to you because I cannot authentic who you are.

And explain to them that we, as a society, need to come up a way of authenticating inbound and outbound calls to ensure we are connect with who the other party claims to be because when you do this it conditions society in to responding and that’s how phishing attacks occur.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#150
post #125

Earlier quoted context omitted.

IMHO this should be the law for financial and medical institutions tc. They should not be allowed to call and ask the receiver to provide verification information.

It doesn't need to be the law: I never provide any information to someone who calls me, unless I have a way of authenticating them.

You're set, then. But the reason a law would be beneficial is it would condition everyone's parents and people who aren't as awesome as you to stop trusting callers and start calling a known-good number.
Post reply on HN