Earlier quoted context omitted.
that they had a DB with bank ids phone numbers already.
I think OP mentioned that the member number was obtained from him.
I was just subjected to the most credible phishing attempt I’ve experienced
211–220 of 360 posts
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#212I'm sorry, I'm missing something between > Me: (that number, by itself, is useless). and > Once I gave my member number, the attacker used the password reset flow to trigger a text message from the bank. > They used this to gain access to the account. What happened here? How does an exposed useless member number trigger a password reset? Would the reset request not have come to an email account, presumably a well-pro…
But I also don't understand is: did OP give this number to the fraudster? And even if they did, I would assume the bank would send a second SMS to confirm the password reset. I don't know how it went from "useless" member number to access to the account so quickly. Maybe I'm completely wrong
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#213Re: I was just subjected to the most credible phishing attempt I’ve experienced
#214So here's a problem with banking "2FA". It's not clear what the number they send you by SMS is used for. My Gmail account has 2FA. The token is only used for login. If anyone asks me for it over the phone, there's only one reason. Banks use 2FA sometimes at login, sometimes over the phone, and sometimes to authorize transactions. That should be made transparent in the message, but it usually isn't. Imagine: "Your tem…
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#215Earlier quoted context omitted.
>It’s illegal in most countries Would love to see a citation for this.
Of course it’s illegal! All developed countries have strict rules about how you can use Telecomms networks. Of course scam artists don’t care about these rules ... Its not hard to find out further information abour this. Check with your local Telecomms regulator, google or even the Wikipedia page!
Fraud tends to be illegal. That’s as far as I’m willing to believe your “of course”.
I do not believe most countries have laws regarding caller ID spoofing.
I know that in my country IMEI spoofing is (Bizarrely!) sort-of prohibited as forgery (as in IDs, documents or “anything of evidential/testimonial(?) value”), but can’t find anything regarding phone numbers.
I know that in the US it’s only illegal to spoof your number for fraudulent purposes.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#216Earlier quoted context omitted.
I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…
My bank always says "There is an issue with your credit card/account, please call the number on the back of the card/your branch as soon as possible." and has for years. The only time they do otherwise is on very specific instances where they provide the info, "did you just buy something at store XXX for approximately $YYY" All banks and credit institutions should be required by law to do this.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#217If it really is a serious situation, they'll just have to chill until I call back to a verified number.
As far as I'm aware, this will stop all attacks like this. Unless they've hacked the phone network and can reroute my calls? :)
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#218OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
Translated: https://translate.google.com/translate?sl=pt&tl=en&u=https%3...
Original (Portuguese): https://threadreaderapp.com/thread/1179903474244444160.html
Same approach, they also pretended to be from the bank calling about an irregular transaction. In this scam, it seems they hijacked her home phone line. She tried to call from her cell phone, then they called back to her home phone and said all communication should be from it, to ensure she was at a different location.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#219Go to the police? Let us know how that works out for you. I did that once, after a highly credible phishing attempt (that, ultimately, I did not fall for). This was in Germany. Me: Here is what happened to me, I'd like to file a police report. Police: Well, with these internet scams, the fraudster is usually in another country, meaning we can't really do anything about it. Me: They used perfect German, used informati…
Thinking of this I would have continued like: Me: are you confirming that if I start a scam you will not investigate it? Police:...? Me: Ok , then thanks a lot, I know now. Police: umm, wait maybe..
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#220ninja edit: we called and froze our credit immediately