The most surprising part is that they were able to gain access to your account using just the code texted to you. It's called second factor for a reason. The bank should still have sent you a password reset email.
I was just subjected to the most credible phishing attempt I’ve experienced
151–160 of 360 posts
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#152Earlier quoted context omitted.
There seems to be broad consensus amongst the commenters that this is the most reliable defense against this kind of attack. Makes sense. If they are able to intercept my outbound calls, it's probably an entirely different level of sophistication and targeting.
I read about a landline attack that would keep the line open when you put the receiver down, play a dial tone, and then wait until you’d entered a number before putting you back on with the scammer
I experienced this once, but not as a scam, I think there must have been some kind of fault at the exchange... the other end was a mobile phone and they didn't end the call, just putting the phone back in their pocket - the landline wouldn't disconnect, whatever signal was send, even disconnecting the phone entirely and plunging it back in. I didn't understand how exactly, but it made it pretty clear the (landline) telephone is not in control of the connection.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#153Earlier quoted context omitted.
> Phone 2FA would be good but a bit pointless because the 2FA app is on the phone, and so is the banking app. This is exactly like having a physical token with you. If it gets stolen, they have the tokens. But, at least, having token on the phone app is waymore convenient for customers and also has another layer of protection (think of the fingerprint/passcode ecc you need to access your phone)
Over here in EU land the mobile identifier app is pin protected. Think Google Authenticator but with a pin to access the tokens. You need my phone unlocked and my six digit pin in order to identify as me. There are still possible social engineering attacks, though.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#154Go to the police? Let us know how that works out for you. I did that once, after a highly credible phishing attempt (that, ultimately, I did not fall for). This was in Germany. Me: Here is what happened to me, I'd like to file a police report. Police: Well, with these internet scams, the fraudster is usually in another country, meaning we can't really do anything about it. Me: They used perfect German, used informati…
Me: are you confirming that if I start a scam you will not investigate it?
Police:...?
Me: Ok , then thanks a lot, I know now.
Police: umm, wait maybe..
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#155- when you answer the call, stay completely silent: some systems will automatically hang up after a few seconds
- I never say the word "Yes" if I don't know the caller, so that they can't record it and use it in some scam contracts. Yes, vocal consent is a thing in some countries.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#156Re: I was just subjected to the most credible phishing attempt I’ve experienced
#157OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
>It is better if banks include a security warning / specific reason the code is sent with the password reset pins and similar credentials. My bank did not. Another twitter user noted being subject to the scam, and just glancing over the warning copy. So it helps, but it is not perfect. Especially pre-coffee. I'm seriously surprised there are banks that send SMS codes without a reason for the code. All banks I deal wi…
You can make 2FA really easy if you want to, now that EU req. 2FA there will probably be more banks with reasonable solutions.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#158This is very scary for the average person. I've taken to simply not answering any questions (not even to confirm my name) if someone calls me. If my bank calls me then I call them back on a number that's on their web site.
If my bank calls me then I call them back on a number that's on their web site. I'm always amazed at how stupid the security situation is in these cases. Banks, telecoms services, etc. do actually call up and try to 'take me through security', and when I say "tell me something you know about me first so I know you're who you say you are", the best they can usually manage is "well, uh, you bank with [Bank]". It just p…
So given banks have nothing to lose by scams, I suppose that explains why they just don't care about the fact they're training users to ignore them. The bank just does whatever's easiest for it, which in this case is just to call the customer.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#159Earlier quoted context omitted.
I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…
I always say to them: I can not identify myself to you because I cannot authentic who you are . And explain to them that we, as a society, need to come up a way of authenticating inbound and outbound calls to ensure we are connect with who the other party claims to be because when you do this it conditions society in to responding and that’s how phishing attacks occur .
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#160My simple policy is I never give out any information if I'm cold-called. If they claim they're my bank, I say I'll call them back on the number printed on the card, and ask the caller which department I should be put through to. Legitimate callers have never objected to this approach, and it saves me any stress - same policy, no matter the caller, no exceptions, no need for me to try and figure out if I'm being phish…
Good idea - but here in the UK there was a scam where they called you and THEN suggested you call the number on the back of the card. They then don't hang up, but play a dialling tone down the line until you dial the number. At which time they 'answer'. This only works on home phones, not mobile, but is worth considering, and warning your family/friends about.
It's such an old story that you'd have thought there would be an explanation online by now of exactly which telephone exchanges had this problem and when those telephone exchanges were in use.
For what it's worth, it didn't work when I tried it, probably in the 1980s. Perhaps it worked in the 1970s in some places?