Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

161–170 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#161
I'm sorry, I'm missing something between

> Me: (that number, by itself, is useless).

and

> Once I gave my member number, the attacker used the password reset flow to trigger a text message from the bank. > They used this to gain access to the account.

What happened here? How does an exposed useless member number trigger a password reset? Would the reset request not have come to an email account, presumably a well-protected one?

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#162
post #145

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

In your tweets you mention "And now... joyfully resetting all my passwords, filing a police report, getting additional fraud detection in place". What passwords are you talking about and why do you need to reset them? As far as I can tell no passwords have been compromised in the attack as you describe it. Or do you suspect that there's been an other, undisclosed breach that the scammer used to get your name and phon…

Should have written that more clearly. More accurate verbiage would have been "changing all my banking credentials, and enabling all possible notifications". I have no reason to believe other credentials were compromised, and have unique pw in place for nearly everything.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#163
So here's a problem with banking "2FA". It's not clear what the number they send you by SMS is used for.

My Gmail account has 2FA. The token is only used for login. If anyone asks me for it over the phone, there's only one reason.

Banks use 2FA sometimes at login, sometimes over the phone, and sometimes to authorize transactions. That should be made transparent in the message, but it usually isn't.

Imagine: "Your temporary pin for identity verification is 373123, and expires in 5 minutes."

"Your temporary pin to authorize a transfer for an amount ending in $xxx4.23 is 522185 and expires in 5 minutes."

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#164

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

>It is better if banks include a security warning / specific reason the code is sent with the password reset pins and similar credentials. My bank did not. Another twitter user noted being subject to the scam, and just glancing over the warning copy. So it helps, but it is not perfect. Especially pre-coffee. I'm seriously surprised there are banks that send SMS codes without a reason for the code. All banks I deal wi…

Elderly are the most common subject of these attacks. So it is especially important to set strong protection for them. The inconvenience is regrettable but necessary.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#165

Go to the police? Let us know how that works out for you. I did that once, after a highly credible phishing attempt (that, ultimately, I did not fall for). This was in Germany. Me: Here is what happened to me, I'd like to file a police report. Police: Well, with these internet scams, the fraudster is usually in another country, meaning we can't really do anything about it. Me: They used perfect German, used informati…

This is an uninsightful comment. You go to the police to get the report.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#166
post #159

Earlier quoted context omitted.

I always say to them: I can not identify myself to you because I cannot authentic who you are . And explain to them that we, as a society, need to come up a way of authenticating inbound and outbound calls to ensure we are connect with who the other party claims to be because when you do this it conditions society in to responding and that’s how phishing attacks occur .

society could fix all sorts of problems if we had a public key infrastructure...

Banks have this in place already - EMV cards have powerful cryptoprocessors. In Germany we can use chipTAN, it's a small cheap reader for your card where you scan a six-binary-blinking screen that transmits the transaction data, then the card signs it and you get a six-digit TAN back. You can also manually enter the hash to be signed ("start code" is the technical term) and you get the TAN.

Customer support could ask you to authenticate using the TAN already, the hurdle is that you would need to carry the reader at all times.

Unrelated to banks, I believe it could be possible to extend SS7 signalling to not just transmit the caller ID but also a crypto signature/public key which the phone then can verify - or your phone provider could. Think of something like HSTS with a global database, if there is no match for the phone number the provider patches the call through, but if there is an entry, all providers can check for the public key transmitted by the caller and refuse to patch the call if it's missing or faked.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#167

Go to the police? Let us know how that works out for you. I did that once, after a highly credible phishing attempt (that, ultimately, I did not fall for). This was in Germany. Me: Here is what happened to me, I'd like to file a police report. Police: Well, with these internet scams, the fraudster is usually in another country, meaning we can't really do anything about it. Me: They used perfect German, used informati…

File a written criminal complaint directly with the Staatsanwaltschaft, bypass the incompetent morons at the police.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#168
post #159

Earlier quoted context omitted.

I always say to them: I can not identify myself to you because I cannot authentic who you are . And explain to them that we, as a society, need to come up a way of authenticating inbound and outbound calls to ensure we are connect with who the other party claims to be because when you do this it conditions society in to responding and that’s how phishing attacks occur .

society could fix all sorts of problems if we had a public key infrastructure...

Or maybe some sort of interconnected web of people who trust each other...

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#169

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

thanks for sharing and sorry it happened to you. sad to say but, i would be suspicious with if any interaction with a bank is going this easy and is this convenient...
Post reply on HN