Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

201–210 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#201

Earlier quoted context omitted.

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…

While spoofing numbers on incoming calls is far easier, it is also possible for an attacker to redirect your outgoing calls from the right place in the phone network. You just shouldn't consider any aspect of the phone network to provide authenticity or confidentiality.

I had an experience indistinguishable from the phishing attack being discussed - with the only difference that I initiated the phone call. A transaction I had initiated had triggered some fraud warnings and my account was locked.

They asked for my account number, name, and address for verification. When they got to the point that they sent me a code over SMS and wanted me to tell it to them over the phone, I stopped them and explained that this is also the exact set of steps required to reset my account and that I wouldn’t do it.

I went to a branch in person to unlock my account and the person helping me asked me to enter my password on their terminal so that they could “see the error message”.

I’m still not sure if some parts of this were a more advanced phishing scheme than I had thought was possible, even though it does just seem like a set of confusing practices by the bank.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#202

Earlier quoted context omitted.

Banks have this in place already - EMV cards have powerful cryptoprocessors. In Germany we can use chipTAN, it's a small cheap reader for your card where you scan a six-binary-blinking screen that transmits the transaction data, then the card signs it and you get a six-digit TAN back. You can also manually enter the hash to be signed ("start code" is the technical term) and you get the TAN. Customer support could ask…

Would you happen to know what kind of signature scheme they use?

My bank seems to use a similar scheme. It appears akin to TOTP with 8 numbers. But the secret is inside the black box. They also have something like a QR code but with RGB colors (does not work with blue light reducing features).

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#203

Earlier quoted context omitted.

Would you happen to know what kind of signature scheme they use?

IIRC the German system is proprietary, the specs are available only after payment of a couple hundred euros.

I am grossed out by proprietary protocols but proprietary encryption algorithms just make me laugh. Who even though that this would be a good idea? Are they seriously trusting their money with this?

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#204

Go to the police? Let us know how that works out for you. I did that once, after a highly credible phishing attempt (that, ultimately, I did not fall for). This was in Germany. Me: Here is what happened to me, I'd like to file a police report. Police: Well, with these internet scams, the fraudster is usually in another country, meaning we can't really do anything about it. Me: They used perfect German, used informati…

[deleted]

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#205

Earlier quoted context omitted.

While spoofing numbers on incoming calls is far easier, it is also possible for an attacker to redirect your outgoing calls from the right place in the phone network. You just shouldn't consider any aspect of the phone network to provide authenticity or confidentiality.

I had an experience indistinguishable from the phishing attack being discussed - with the only difference that I initiated the phone call. A transaction I had initiated had triggered some fraud warnings and my account was locked. They asked for my account number, name, and address for verification. When they got to the point that they sent me a code over SMS and wanted me to tell it to them over the phone, I stopped…

I wonder if bank staff are in on it sometimes. I once was at a bank branch and had the teller pick up the phone, call another teller and tell her my balance in a foreign language that I happen to speak fluently (but don’t look like I should).

I wanted to ask her why she would be doing that, but I was a bit more meek in my younger days.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#206
post #200

Earlier quoted context omitted.

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…

>my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" Amex got quite offended when I did this, and almost chastised me when I got through to an agent after making the outbound call myself. They argued that because they only asked for limited personal information (DOB) it was fine... I would still do it again!

I had that same issue with Amex, they phoned, said there was a concern with my card and then wanted me to go through identity checks before saying more. They also got quite stroppy when I refused and asked them to prove their own identity first!

Eventually they did suggest I call the number on the back of my card, but I was annoyed by their lack of professionalism by this point (I mean, they are asking me to do stuff - giving out information to unknown callers - which they themselves always tell customers never to do!) I said I wasn't going to phone a general number and get stuck on hold for hours over an unknown issue - either give me some reference to get through quickly to the right person, tell me what the problem is now, or send me a letter. But they kept claiming that they couldn't send out letters in the post :-(

In the end, I finally received a letter by mail telling me that there were problems with my direct debit payments. So it was a genuine call but their inability to securely make these calls is frustrating.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#207

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

Step one for me when I am giving sensitive information is always "let's end this call and let me call you". I had gotten an e-mail from my bank and I called the number in the e-mail without thinking to lookup the support number on my own first. The number was legit and it gave the fraud dept a chuckle but it very well could've been a fake number

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#209
post #135

Earlier quoted context omitted.

In Sweden we have BankID - a two-factor, two-way authentication using public/private encrypted keys that's bound to a smartphone as a signature. The process is user-friendly while keeping security high: - The place where you want to login has to trigger the authentication from their server on every login - and have to be certified for BankID. - You then have to open the app, enter your fingerprint or 6-pin code befor…

That's the Mobile BankID, and it gets scammed a lot. The smart-card based BankID is the only acceptable choice IMO

How is that different, since social engineering works there too?

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#210

Earlier quoted context omitted.

In Sweden we have BankID - a two-factor, two-way authentication using public/private encrypted keys that's bound to a smartphone as a signature. The process is user-friendly while keeping security high: - The place where you want to login has to trigger the authentication from their server on every login - and have to be certified for BankID. - You then have to open the app, enter your fingerprint or 6-pin code befor…

Unfortunately the BankID has been scammed a lot, where fraudsters have simple asked people on the phone to sign BankID stuff for them. It is far from perfect and in fact the scam here would be possible to do with BankID as well. https://www.expressen.se/dinapengar/sparande/bedragerier-med...

Sure, I'd assume that social engineering will always work as long as a person has no way to validate who's on the other end.
Post reply on HN