Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

221–230 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#221

I'm sorry, I'm missing something between > Me: (that number, by itself, is useless). and > Once I gave my member number, the attacker used the password reset flow to trigger a text message from the bank. > They used this to gain access to the account. What happened here? How does an exposed useless member number trigger a password reset? Would the reset request not have come to an email account, presumably a well-pro…

I might be wrong, but I think the fraudster used the member number (which is basically the online banking login username) to perform a password reset on the banks website. The website sends a confirmation code via SMS, which would be used for 2 factor auth to reset the password. But I also don't understand is: did OP give this number to the fraudster? And even if they did, I would assume the bank would send a second…

Yes, OP gave this number to the fraudster, not realizing it was a password reset authorization code. OP thought it was a code that established that the person they were speaking with was a legitimate representative of the bank, since they had the power to generate a code that came from the bank.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#222
post #132
post #33

I don't understand why there are still banks that do SMS verification. It has been proven so many times now that that it is vulnerable to both phishing (proven here), sim swapping attacks, etc. The banks here in the Netherland all have (well, except for one maybe) hardware authentication devices. They are portable smartcard readers, you insert your card, enter your PIN on the device itself (not your computer or phone…

IMO smart card readers are the worst solution for everything. They are invariable less capable and less secure than my phone. Why would I carry 2 devices (one of these quite primitive) if I could only carry one?

Can you elaborate why you believe smartcards are less secure than your mobile phone?

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#223
post #159

Earlier quoted context omitted.

I always say to them: I can not identify myself to you because I cannot authentic who you are . And explain to them that we, as a society, need to come up a way of authenticating inbound and outbound calls to ensure we are connect with who the other party claims to be because when you do this it conditions society in to responding and that’s how phishing attacks occur .

society could fix all sorts of problems if we had a public key infrastructure...

We are in some kind of Stone Age of The digital age...

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#224
post #193

Earlier quoted context omitted.

Of course it’s illegal! All developed countries have strict rules about how you can use Telecomms networks. Of course scam artists don’t care about these rules ... Its not hard to find out further information abour this. Check with your local Telecomms regulator, google or even the Wikipedia page!

>Of course it’s illegal? Fraud tends to be illegal. That’s as far as I’m willing to believe your “of course”. I do not believe most countries have laws regarding caller ID spoofing. I know that in my country IMEI spoofing is (Bizarrely!) sort-of prohibited as forgery (as in IDs, documents or “anything of evidential/testimonial(?) value”), but can’t find anything regarding phone numbers. I know that in the US it’s onl…

> it’s only illegal to spoof your number for fraudulent purposes

Seems like you’re gettig bogged down in semantics sir

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#225
post #135

Earlier quoted context omitted.

That's the Mobile BankID, and it gets scammed a lot. The smart-card based BankID is the only acceptable choice IMO

How is that different, since social engineering works there too?

Not as easily. As I understand it, with Mobile BankID, the attacker goes to the bank web site and then asks the victim to authenticate with their BankID app.

With the real BankID, the computer accessing the bank web site needs access to the smart card. Exploitation is still possible of course, but the bar seems higher.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#226

Go to the police? Let us know how that works out for you. I did that once, after a highly credible phishing attempt (that, ultimately, I did not fall for). This was in Germany. Me: Here is what happened to me, I'd like to file a police report. Police: Well, with these internet scams, the fraudster is usually in another country, meaning we can't really do anything about it. Me: They used perfect German, used informati…

Yeah, that's kind of what I've expected. However, having the police report often helps when dealing with the bank if there is any real fraudulent activity. It shows them you're serious.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#227

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

> When I read the thread now, it's obviously full of red flags. I was successfully manipulated, and whilst I'm certainly not as clever as all the people pointing out they would have caught this from sentence one, I believe I'm also not the lowest hanging fruit in terms of a target :-)

I think it's soo easy to spot scams because 99% of them are so shit, poor spelling, talking nonsense.

If scammers simply spell checked their scams I would fall for them all.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#228
post #224

Earlier quoted context omitted.

>Of course it’s illegal? Fraud tends to be illegal. That’s as far as I’m willing to believe your “of course”. I do not believe most countries have laws regarding caller ID spoofing. I know that in my country IMEI spoofing is (Bizarrely!) sort-of prohibited as forgery (as in IDs, documents or “anything of evidential/testimonial(?) value”), but can’t find anything regarding phone numbers. I know that in the US it’s onl…

> it’s only illegal to spoof your number for fraudulent purposes Seems like you’re gettig bogged down in semantics sir

How is that semantics? Fraud is already illegal literally everywhere, so spoofing your number for fraudulent purposes will obviously be a part of that crime.

If this is intended to defend your original claim, you’re being utterly ridiculous. You made a specific claim about caller id spoofing, not fraud.

For example, If you’re spoofing a random number for telemarketing calls that’s just not fraud.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#229
post #200

Earlier quoted context omitted.

>my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" Amex got quite offended when I did this, and almost chastised me when I got through to an agent after making the outbound call myself. They argued that because they only asked for limited personal information (DOB) it was fine... I would still do it again!

I had that same issue with Amex, they phoned, said there was a concern with my card and then wanted me to go through identity checks before saying more. They also got quite stroppy when I refused and asked them to prove their own identity first! Eventually they did suggest I call the number on the back of my card, but I was annoyed by their lack of professionalism by this point (I mean, they are asking me to do stuff…

I think if they gave you a number to bypass the general queue that you’re still vulnerable to an attack, right?

The only way to ensure you’re calling amex is to call the number you know, otherwise the scammer will have you call another one.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#230
post #200

Earlier quoted context omitted.

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…

>my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" Amex got quite offended when I did this, and almost chastised me when I got through to an agent after making the outbound call myself. They argued that because they only asked for limited personal information (DOB) it was fine... I would still do it again!

At least with an email you can hopefully verify the headers. A phone number is too easily spoofed these days and the end user has no real means of verification.
Post reply on HN