Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

241–250 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#241
A few bits about me: Wells Fargo is the bank I use, I post things on Craigslist and list my phone number, and T-Mobile is my mobile phone provider.

I almost always get text messages from numbers trying to scam me into receiving their check or giving them my G-Voice verification code.

I looked into the phone numbers that contacted me and it's difficult to find exactly who is trying to reach me.

A few things I learned:

- Apparently phone number spoofing has legitimate use cases so it is a "feature" that is do-able. I was asking different companies and they said for example: checking for domestic violence or checking on someone if they have a second spouse somehow.

- It is difficult to look-up online who is the caller and what mobile provider do they use.

- Some private companies have an internal database that contains the information. I asked one company and they told me what was the provider of the phone number.

- Spoofing makes it difficult to know where the actual call is coming from. Someone can use my mom's number to call me. It might be difficult for my phone provider to inspect the call further than what I would see on my phone already.

What I'd like:

- For T-Mobile not to forward to me calls that are known to be from fraudulous callers or thought to be from fraudulous callers.

- Know if T-Mobile can provide me with information on where the call is coming from.

- After I identify what company XYZ issued the phone number, or what company provided the telephone service to the fraudsters, ask them more information on the caller.

- Ask such company XYZ to stop routing these calls to me.

- Create a resource such that whenever there is a scam call coming in, we could send the number to such a resource, and discover what company BCD issued them a phone number and routed their call. I believe that once this company BCD knows about their fraudulent customers, it is supposed to not do business with them.

Hopefully with such steps, the situation should clear up over time.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#242
post #229

Earlier quoted context omitted.

I had that same issue with Amex, they phoned, said there was a concern with my card and then wanted me to go through identity checks before saying more. They also got quite stroppy when I refused and asked them to prove their own identity first! Eventually they did suggest I call the number on the back of my card, but I was annoyed by their lack of professionalism by this point (I mean, they are asking me to do stuff…

I think if they gave you a number to bypass the general queue that you’re still vulnerable to an attack, right? The only way to ensure you’re calling amex is to call the number you know, otherwise the scammer will have you call another one.

Not a different number to call, but instead a shortcut through the usual automated phone menus - e.g. I've had a bank tell me to phone their number and then enter an extension to take me straight through to the right person.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#243
post #200

Earlier quoted context omitted.

>my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" Amex got quite offended when I did this, and almost chastised me when I got through to an agent after making the outbound call myself. They argued that because they only asked for limited personal information (DOB) it was fine... I would still do it again!

I had that same issue with Amex, they phoned, said there was a concern with my card and then wanted me to go through identity checks before saying more. They also got quite stroppy when I refused and asked them to prove their own identity first! Eventually they did suggest I call the number on the back of my card, but I was annoyed by their lack of professionalism by this point (I mean, they are asking me to do stuff…

Why would a letter be genuine? That seems easier to spoof then phone or email?

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#244
post #229

Earlier quoted context omitted.

I had that same issue with Amex, they phoned, said there was a concern with my card and then wanted me to go through identity checks before saying more. They also got quite stroppy when I refused and asked them to prove their own identity first! Eventually they did suggest I call the number on the back of my card, but I was annoyed by their lack of professionalism by this point (I mean, they are asking me to do stuff…

I think if they gave you a number to bypass the general queue that you’re still vulnerable to an attack, right? The only way to ensure you’re calling amex is to call the number you know, otherwise the scammer will have you call another one.

Call the number of the back of the card - "Press X if you have been given a code by us". Effectively, you're calling + .

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#245

I'm sorry, I'm missing something between > Me: (that number, by itself, is useless). and > Once I gave my member number, the attacker used the password reset flow to trigger a text message from the bank. > They used this to gain access to the account. What happened here? How does an exposed useless member number trigger a password reset? Would the reset request not have come to an email account, presumably a well-pro…

I might be wrong, but I think the fraudster used the member number (which is basically the online banking login username) to perform a password reset on the banks website. The website sends a confirmation code via SMS, which would be used for 2 factor auth to reset the password. But I also don't understand is: did OP give this number to the fraudster? And even if they did, I would assume the bank would send a second…

I've often seen that a password reset completion will trigger an email notification, but not a second 2FA verification to confirm.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#246

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

How do we know you are the OP?

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#247
post #229

Earlier quoted context omitted.

I had that same issue with Amex, they phoned, said there was a concern with my card and then wanted me to go through identity checks before saying more. They also got quite stroppy when I refused and asked them to prove their own identity first! Eventually they did suggest I call the number on the back of my card, but I was annoyed by their lack of professionalism by this point (I mean, they are asking me to do stuff…

I think if they gave you a number to bypass the general queue that you’re still vulnerable to an attack, right? The only way to ensure you’re calling amex is to call the number you know, otherwise the scammer will have you call another one.

It would be reasonably trivial to build a phone system that lets the agent generate a OTP of sorts.

"Hey, we need to talk about your account. Call our general enquiries number on our website, press 9 and enter 'XXXXXX' to be reconnected to me."

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#248
post #68

Earlier quoted context omitted.

Wow, this really is something if done right. I don't use a landline now, but if I remember, the caller needs to disconnect for the line to actually be disconnected. So even if the callee tries to disconnect by hanging up, the caller is still actually connected. If the callee picks up the receiver again and hears a dial tone, they'd be none the wiser. But I guess the scammer would also need to detect a key-press tone…

Never heard of the systems with this flaw. It was always "if you hang up then it's completely cut".

Perhaps it worked on Strowger exchanges when the call is local? I definitely remember this being "a thing" back in the 1970s but I don't remember ever succeeding in reproducing it. Obviously there must have been some time out because otherwise you could DoS anyone's phone by just calling them then not hanging up.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#249

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

Interesting thanks for the write-up. One thing that I've frequently heard is that in any type of fraud call you should always hang up right at the beginning and call the bank back. Seems like no matter how sophisticated the attackers, this defense will always foil anything along the same lines of what happened to you. The only way I can see this countermeasure failing is if the scammers can somehow manage to intercep…

It is a pretty good idea, but only sufficient if you don't have much money. For large balances it might be worth someone's time to bribe your local telco worker or subvert your SS7/Diameter routing so that your calls route via an intermediary (i.e. make your phone a roaming number, route it's calls to an attacker controlled exchange in e.g. India). It is even simpler to listen in to your legitimate call and hear your phone banking password and secret Q&As.

Calling via a landline or via an operator assisted call would make such tricks much more difficult.

Some great papers on Diameter and telco security here: https://www.bell-labs.com/usr/silke.holtmanns

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#250

Earlier quoted context omitted.

While spoofing numbers on incoming calls is far easier, it is also possible for an attacker to redirect your outgoing calls from the right place in the phone network. You just shouldn't consider any aspect of the phone network to provide authenticity or confidentiality.

I had an experience indistinguishable from the phishing attack being discussed - with the only difference that I initiated the phone call. A transaction I had initiated had triggered some fraud warnings and my account was locked. They asked for my account number, name, and address for verification. When they got to the point that they sent me a code over SMS and wanted me to tell it to them over the phone, I stopped…

You initiated the call to what number? The number on your card? If so, that's ridiculous.

(Obviously, initiating a call to a number provided by a potential scammer offers no protection. If someone is intercepting and redirecting your outgoing calls via the phone network, I'd say you probably have a bigger problem than a declined transaction.)

Post reply on HN