Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

211–220 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#211
post #130
post #12

Earlier quoted context omitted.

that they had a DB with bank ids phone numbers already.

I think OP mentioned that the member number was obtained from him.

yeah, they had the phone number to match, which made it believable

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#212

I'm sorry, I'm missing something between > Me: (that number, by itself, is useless). and > Once I gave my member number, the attacker used the password reset flow to trigger a text message from the bank. > They used this to gain access to the account. What happened here? How does an exposed useless member number trigger a password reset? Would the reset request not have come to an email account, presumably a well-pro…

I might be wrong, but I think the fraudster used the member number (which is basically the online banking login username) to perform a password reset on the banks website. The website sends a confirmation code via SMS, which would be used for 2 factor auth to reset the password.

But I also don't understand is: did OP give this number to the fraudster? And even if they did, I would assume the bank would send a second SMS to confirm the password reset. I don't know how it went from "useless" member number to access to the account so quickly. Maybe I'm completely wrong

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#214

So here's a problem with banking "2FA". It's not clear what the number they send you by SMS is used for. My Gmail account has 2FA. The token is only used for login. If anyone asks me for it over the phone, there's only one reason. Banks use 2FA sometimes at login, sometimes over the phone, and sometimes to authorize transactions. That should be made transparent in the message, but it usually isn't. Imagine: "Your tem…

2FA is now mandatory in the EU with recent banking regulations (PSD2)

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#215
post #193

Earlier quoted context omitted.

>It’s illegal in most countries Would love to see a citation for this.

Of course it’s illegal! All developed countries have strict rules about how you can use Telecomms networks. Of course scam artists don’t care about these rules ... Its not hard to find out further information abour this. Check with your local Telecomms regulator, google or even the Wikipedia page!

>Of course it’s illegal?

Fraud tends to be illegal. That’s as far as I’m willing to believe your “of course”.

I do not believe most countries have laws regarding caller ID spoofing.

I know that in my country IMEI spoofing is (Bizarrely!) sort-of prohibited as forgery (as in IDs, documents or “anything of evidential/testimonial(?) value”), but can’t find anything regarding phone numbers.

I know that in the US it’s only illegal to spoof your number for fraudulent purposes.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#216

Earlier quoted context omitted.

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…

My bank always says "There is an issue with your credit card/account, please call the number on the back of the card/your branch as soon as possible." and has for years. The only time they do otherwise is on very specific instances where they provide the info, "did you just buy something at store XXX for approximately $YYY" All banks and credit institutions should be required by law to do this.

Capital One has an app, every time my card is used I get a push notification. This is the best solution in my mind. I can actively monitor my card usage and call if I see something suspicious.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#217
Nice trick. I commend it. However my hard rule is to simply never continue incoming calls.

If it really is a serious situation, they'll just have to chill until I call back to a verified number.

As far as I'm aware, this will stop all attacks like this. Unless they've hacked the phone network and can reroute my calls? :)

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#218

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

I've recently read about a similar attack, but in Brazil.

Translated: https://translate.google.com/translate?sl=pt&tl=en&u=https%3...

Original (Portuguese): https://threadreaderapp.com/thread/1179903474244444160.html

Same approach, they also pretended to be from the bank calling about an irregular transaction. In this scam, it seems they hijacked her home phone line. She tried to call from her cell phone, then they called back to her home phone and said all communication should be from it, to ensure she was at a different location.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#219
post #154

Go to the police? Let us know how that works out for you. I did that once, after a highly credible phishing attempt (that, ultimately, I did not fall for). This was in Germany. Me: Here is what happened to me, I'd like to file a police report. Police: Well, with these internet scams, the fraudster is usually in another country, meaning we can't really do anything about it. Me: They used perfect German, used informati…

Thinking of this I would have continued like: Me: are you confirming that if I start a scam you will not investigate it? Police:...? Me: Ok , then thanks a lot, I know now. Police: umm, wait maybe..

Exactly

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#220
This happened to my wife a few months ago. I heard her part of the conversation. We thought something was wrong. I logged in to my bank account and watched the money drain out of our join account. My wife couldn't login to her account (the phisher changed the password) but they drained all her accounts. I called our bank within the hour. They were very reasonable with resolving the issue and returning our money. The phisher was attempting to purchase gift cards from a Walmart 500 miles away. It was easy to prove to the bank that we were scammed. I hope others are just as lucky and can report it in time.

ninja edit: we called and froze our credit immediately

Post reply on HN