I was just subjected to the most credible phishing attempt I’ve experienced
231–240 of 360 posts
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#232"This is a verification code from [bank]. Enter online at prompt or in password field w/in 30 minutes."
Nowhere does it mention the purpose, or to NOT read the code over the phone under any circumstances.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#233OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
Unfortunately, some banks do this. (I'm looking at you, U.S. Bank.)
It's like someone calling me and then asking me who they're speaking to. Really? You called me! (Assuming they're not returning a missed call, of course.)
If (someone claiming to be) a bank calls/texts you, (and it's not immediately after a declined transaction) you always hang up and call the number you already have for the bank.
Even if it is after a declined transaction, you still don't provide any info. If they ask if you attempted a $101.89 purchase at "big box store," you should simply respond yes/no, and provide no other info.
If you didn't attempt that transaction, they especially don't need to confirm any other info.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#234The bank I'm currently at has this "obnoxious" text around verification numbers: Don't EVER communicate the following verification number to anyone, including collaborators: 123456 SMS OTP should always have that or similar text.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#235Re: I was just subjected to the most credible phishing attempt I’ve experienced
#236Earlier quoted context omitted.
My bank always says "There is an issue with your credit card/account, please call the number on the back of the card/your branch as soon as possible." and has for years. The only time they do otherwise is on very specific instances where they provide the info, "did you just buy something at store XXX for approximately $YYY" All banks and credit institutions should be required by law to do this.
Capital One has an app, every time my card is used I get a push notification. This is the best solution in my mind. I can actively monitor my card usage and call if I see something suspicious.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#237Earlier quoted context omitted.
The security part of PSD2 is starting to look like another cookie law. Banks of course didn't implement any proper 2FA like U2F but rather send you scrounging for the phone with their app every time you want to look up a transaction or an account number, something that didn't require second factor until the directive. In fact, because it makes checking recent transactions that much less convenient, it probably made m…
TOTP is in terms of usability not very different from PhotoTAN or ChipTAN, so I don't see how these methods aren't "proper 2FA". U2F is a useful method, but it's not common at all (even in IT most companies don't provide it, not even the website we're on right now, nor PayPal), and it's not understandable how this isn't "proper 2FA". In addition, the directive requiring the purpose of the code to be fixed and shown a…
Other solutions are either or. There is a benefit to confirming particular actions (with the info about the action) in the app but it's unnecessarily inconvenient for mere login.
U2F isn't widely supported but I managed to secure virtually my entire high-value Internet presence with it. Google, OVH, Coinbase, and Stripe all support it. Let's be honest, for HN I wouldn't bother with any second factor. I have the password saved in the browser and that's more than enough.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#238OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
>When I read the thread now, it's obviously full of red flags. I was successfully manipulated, and whilst I'm certainly not as clever as all the people pointing out they would have caught this from sentence one, I believe I'm also not the lowest hanging fruit in terms of a target :-) Makes you wonder what this will look like when these scams evolve another couple of generations in terms of complexity ... I think this…
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#239Earlier quoted context omitted.
> it’s only illegal to spoof your number for fraudulent purposes Seems like you’re gettig bogged down in semantics sir
How is that semantics? Fraud is already illegal literally everywhere, so spoofing your number for fraudulent purposes will obviously be a part of that crime. If this is intended to defend your original claim, you’re being utterly ridiculous. You made a specific claim about caller id spoofing, not fraud. For example, If you’re spoofing a random number for telemarketing calls that’s just not fraud.
It absolutely is, and in most civilised countries is illegal.
Like, I can totally believe that in the USA where any old lunatic can own an automatic weapon amd nobody gets concerned until he shoots up a school thats the case ye
There’s probably some constitutional argument that you can spoof your number based on something ridiculous like free speech
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#240OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
>When I read the thread now, it's obviously full of red flags. I was successfully manipulated, and whilst I'm certainly not as clever as all the people pointing out they would have caught this from sentence one, I believe I'm also not the lowest hanging fruit in terms of a target :-) Makes you wonder what this will look like when these scams evolve another couple of generations in terms of complexity ... I think this…