Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

191–200 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#191

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…

My bank always says "There is an issue with your credit card/account, please call the number on the back of the card/your branch as soon as possible." and has for years.

The only time they do otherwise is on very specific instances where they provide the info, "did you just buy something at store XXX for approximately $YYY"

All banks and credit institutions should be required by law to do this.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#192

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…

I don't do that. I say "are you crazy, you are a bank and asking me to prove who I am? You called me. You prove who you are first."

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#193
post #99

Earlier quoted context omitted.

It should be noted that Caller ID spoofing is possible with pretty basic equipment. It's illegal in most countries but there's nothing technically preventing you from doing it. Which is crazy IMO.

>It’s illegal in most countries Would love to see a citation for this.

Of course it’s illegal! All developed countries have strict rules about how you can use Telecomms networks. Of course scam artists don’t care about these rules ... Its not hard to find out further information abour this. Check with your local Telecomms regulator, google or even the Wikipedia page!

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#194

So here's a problem with banking "2FA". It's not clear what the number they send you by SMS is used for. My Gmail account has 2FA. The token is only used for login. If anyone asks me for it over the phone, there's only one reason. Banks use 2FA sometimes at login, sometimes over the phone, and sometimes to authorize transactions. That should be made transparent in the message, but it usually isn't. Imagine: "Your tem…

My bank here in Germany does exactly this. The message I get is something along the lines of "Here is your authorization code for transaction number XXX for 5€ to RECIPIENT issued at 14:23: 12345"

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#195

Go to the police? Let us know how that works out for you. I did that once, after a highly credible phishing attempt (that, ultimately, I did not fall for). This was in Germany. Me: Here is what happened to me, I'd like to file a police report. Police: Well, with these internet scams, the fraudster is usually in another country, meaning we can't really do anything about it. Me: They used perfect German, used informati…

The police is more busy trying to catch victimless crimes instead of going after scams which have real victims. If you search for "fake dna test online" for example you will find a lot of relevant results even in the first page of google.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#196

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

> The caller called me twice in rapid succession (First ignore the call from a number you do not know. Then they call back again immediately: "maybe this is urgent / important").

This also gets past some Do Not Disturb modes.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#197
post #160
post #37

Earlier quoted context omitted.

Good idea - but here in the UK there was a scam where they called you and THEN suggested you call the number on the back of the card. They then don't hang up, but play a dialling tone down the line until you dial the number. At which time they 'answer'. This only works on home phones, not mobile, but is worth considering, and warning your family/friends about.

Have you any idea when this worked in the UK? It's such an old story that you'd have thought there would be an explanation online by now of exactly which telephone exchanges had this problem and when those telephone exchanges were in use. For what it's worth, it didn't work when I tried it, probably in the 1980s. Perhaps it worked in the 1970s in some places?

On POTS lines, the call doesn't drop until the initiator hangs up so even if you put down the phone the connection is still there, pick up the phone again and you resume the same call. I used to use this to move to the upstairs phone to continue a call (back then we had two wired handsets on the same line). The last time I can personally cite it working that way is the late 90s, but I'm sure it has more recently than that, possible even still now for some lines.

I can't test as I've not had a voice capable land-line for some time. It may not work on newer exchange equipment. It won't work if you have a service whereby calls are directed over a digital connection. It has never worked for mobile phone services. It doesn't work on some (most? all?) office PBX arrangements, either.

As well as allowing this sort of scam to operate, the "feature" can also be used as a DoS attack, blocking calls to and from a line for a time.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#198

Since we also discussing personal strategies: - when you answer the call, stay completely silent: some systems will automatically hang up after a few seconds - I never say the word "Yes" if I don't know the caller, so that they can't record it and use it in some scam contracts. Yes, vocal consent is a thing in some countries.

I don’t stay silent, I will either make caveman grunting noises, push some random digits, or ask for ‘Mom?’ in a fake accent.

And then they hang up.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#199

Earlier quoted context omitted.

Or maybe some sort of interconnected web of people who trust each other...

Like the web of trust from GPG?

The WoT originated with PGP (though obviously GPG implemented it as well), but yes, that was the joke.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#200

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…

>my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are"

Amex got quite offended when I did this, and almost chastised me when I got through to an agent after making the outbound call myself. They argued that because they only asked for limited personal information (DOB) it was fine...

I would still do it again!

Post reply on HN