Earlier quoted context omitted.
Good idea - but here in the UK there was a scam where they called you and THEN suggested you call the number on the back of the card. They then don't hang up, but play a dialling tone down the line until you dial the number. At which time they 'answer'. This only works on home phones, not mobile, but is worth considering, and warning your family/friends about.
Have you any idea when this worked in the UK? It's such an old story that you'd have thought there would be an explanation online by now of exactly which telephone exchanges had this problem and when those telephone exchanges were in use. For what it's worth, it didn't work when I tried it, probably in the 1980s. Perhaps it worked in the 1970s in some places?
I was just subjected to the most credible phishing attempt I’ve experienced
171–180 of 360 posts
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#172OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#173When I first started using web based communication platforms like Twitter and Nexmo I was really surprised to learn that I could put anything in the from field when sending a text message. All I could think was that it was a weakness that was ripe for abuse.
I believe there was a case in Germany a few years back where a group of phishers had online banking login details for several hundred users but couldn't initiate transfers without entering a PIN sent to the account holders phone via SMS. So the phishers set up a fake telephone company so that they could issue SS7 commands and have the account holders phone's temporarily redirected to another number where the PIN could be intercepted.
I think there is a false assumption amongst many people that the telephone system is inherently secure. Stuff like the above and all the robo calls coming from false numbers should warn otherwise.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#174OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
I think this is a social skills moment. For those that claim it's "easy" to spot: This is not the right time for people to brag about how they would have totally spotted it. This is mostly for protecting people who (as most people in this world) don't have time to build up a solid understanding of all aspects of internet security. If you don't care about these people, as some sort of Darwinian schadenfreude, stfu. If you do, focus on their perspective, not your brilliant detective skills.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#175Re: I was just subjected to the most credible phishing attempt I’ve experienced
#176OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…
You just shouldn't consider any aspect of the phone network to provide authenticity or confidentiality.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#177OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
Just realizing that a phishing-attack like this is nowadays impossible in the EU: proper two-factor authentication is mandatory now (Revised Directive on Payment Services, PSD2), even just for login. TAN-codes generated for transactions need to incorporate the data of the transaction (recipient and amount), so that a phished TAN cannot be used to authorize a different transaction. I think even a simple SMS TAN may no…
In fact, because it makes checking recent transactions that much less convenient, it probably made me less safe because I do it much less often.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#178The easiest way to avoid this entire class of attack, is to never be willing to answer any kind of question from someone who calls you. Always hang up, Google the customer support line for the business, then call them .
How easy would it be for an attacker to (at least temporarily) outrank the bank in SEO so that when people google the bank's number they find the top result being the attacker's number?
https://www.forbes.com/sites/leemathews/2018/11/26/fraudster...
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#179Re: I was just subjected to the most credible phishing attempt I’ve experienced
#180"Never answer your phone. Seriously. Only use it to make outbound calls. You cannot trust caller ID, and you should never answer unscheduled inbound calls."
Makes sense. Phone calls as they are can no longer be used for security verification. Just can't.