I'm sorry, I'm missing something between > Me: (that number, by itself, is useless). and > Once I gave my member number, the attacker used the password reset flow to trigger a text message from the bank. > They used this to gain access to the account. What happened here? How does an exposed useless member number trigger a password reset? Would the reset request not have come to an email account, presumably a well-pro…
I might be wrong, but I think the fraudster used the member number (which is basically the online banking login username) to perform a password reset on the banks website. The website sends a confirmation code via SMS, which would be used for 2 factor auth to reset the password. But I also don't understand is: did OP give this number to the fraudster? And even if they did, I would assume the bank would send a second…
I was just subjected to the most credible phishing attempt I’ve experienced
221–230 of 360 posts
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#222I don't understand why there are still banks that do SMS verification. It has been proven so many times now that that it is vulnerable to both phishing (proven here), sim swapping attacks, etc. The banks here in the Netherland all have (well, except for one maybe) hardware authentication devices. They are portable smartcard readers, you insert your card, enter your PIN on the device itself (not your computer or phone…
IMO smart card readers are the worst solution for everything. They are invariable less capable and less secure than my phone. Why would I carry 2 devices (one of these quite primitive) if I could only carry one?
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#223Earlier quoted context omitted.
I always say to them: I can not identify myself to you because I cannot authentic who you are . And explain to them that we, as a society, need to come up a way of authenticating inbound and outbound calls to ensure we are connect with who the other party claims to be because when you do this it conditions society in to responding and that’s how phishing attacks occur .
society could fix all sorts of problems if we had a public key infrastructure...
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#224Earlier quoted context omitted.
Of course it’s illegal! All developed countries have strict rules about how you can use Telecomms networks. Of course scam artists don’t care about these rules ... Its not hard to find out further information abour this. Check with your local Telecomms regulator, google or even the Wikipedia page!
>Of course it’s illegal? Fraud tends to be illegal. That’s as far as I’m willing to believe your “of course”. I do not believe most countries have laws regarding caller ID spoofing. I know that in my country IMEI spoofing is (Bizarrely!) sort-of prohibited as forgery (as in IDs, documents or “anything of evidential/testimonial(?) value”), but can’t find anything regarding phone numbers. I know that in the US it’s onl…
Seems like you’re gettig bogged down in semantics sir
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#225Earlier quoted context omitted.
That's the Mobile BankID, and it gets scammed a lot. The smart-card based BankID is the only acceptable choice IMO
How is that different, since social engineering works there too?
With the real BankID, the computer accessing the bank web site needs access to the smart card. Exploitation is still possible of course, but the bar seems higher.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#226Go to the police? Let us know how that works out for you. I did that once, after a highly credible phishing attempt (that, ultimately, I did not fall for). This was in Germany. Me: Here is what happened to me, I'd like to file a police report. Police: Well, with these internet scams, the fraudster is usually in another country, meaning we can't really do anything about it. Me: They used perfect German, used informati…
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#227OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
I think it's soo easy to spot scams because 99% of them are so shit, poor spelling, talking nonsense.
If scammers simply spell checked their scams I would fall for them all.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#228Earlier quoted context omitted.
>Of course it’s illegal? Fraud tends to be illegal. That’s as far as I’m willing to believe your “of course”. I do not believe most countries have laws regarding caller ID spoofing. I know that in my country IMEI spoofing is (Bizarrely!) sort-of prohibited as forgery (as in IDs, documents or “anything of evidential/testimonial(?) value”), but can’t find anything regarding phone numbers. I know that in the US it’s onl…
> it’s only illegal to spoof your number for fraudulent purposes Seems like you’re gettig bogged down in semantics sir
If this is intended to defend your original claim, you’re being utterly ridiculous. You made a specific claim about caller id spoofing, not fraud.
For example, If you’re spoofing a random number for telemarketing calls that’s just not fraud.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#229Earlier quoted context omitted.
>my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" Amex got quite offended when I did this, and almost chastised me when I got through to an agent after making the outbound call myself. They argued that because they only asked for limited personal information (DOB) it was fine... I would still do it again!
I had that same issue with Amex, they phoned, said there was a concern with my card and then wanted me to go through identity checks before saying more. They also got quite stroppy when I refused and asked them to prove their own identity first! Eventually they did suggest I call the number on the back of my card, but I was annoyed by their lack of professionalism by this point (I mean, they are asking me to do stuff…
The only way to ensure you’re calling amex is to call the number you know, otherwise the scammer will have you call another one.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#230Earlier quoted context omitted.
I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…
>my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" Amex got quite offended when I did this, and almost chastised me when I got through to an agent after making the outbound call myself. They argued that because they only asked for limited personal information (DOB) it was fine... I would still do it again!