Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

251–260 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#251
post #222
post #132

Earlier quoted context omitted.

IMO smart card readers are the worst solution for everything. They are invariable less capable and less secure than my phone. Why would I carry 2 devices (one of these quite primitive) if I could only carry one?

Can you elaborate why you believe smartcards are less secure than your mobile phone?

All the ones I've seen have no security, either it's just a changing password (e.g. RSA key), or you input your card (optionally entering your PIN which you share with every POS terminal / shop) and get a password.

My phone requires a password (which I can set to be arbitrarily secure, not 4-digit PIN (LOL)) or a fingerprint (which is something noone can steal, unlike a credit card... or at least I'd notice it's missing much sooner!)

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#252

Earlier quoted context omitted.

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…

My bank always says "There is an issue with your credit card/account, please call the number on the back of the card/your branch as soon as possible." and has for years. The only time they do otherwise is on very specific instances where they provide the info, "did you just buy something at store XXX for approximately $YYY" All banks and credit institutions should be required by law to do this.

My bank does this. Two texts:

1: "We need you to verify some transactions. You will receive a text from with the transaction details"

2: "Do you recognise these transactions? Reply Y if yes, N if no"

Y -> "Thank you for verifying the transactions. If any transactions have been declined, you may been to repeat them"

N -> "Your card has been blocked and a new one ordered. Please contact us if you need any further advice"

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#253
post #239

Earlier quoted context omitted.

How is that semantics? Fraud is already illegal literally everywhere, so spoofing your number for fraudulent purposes will obviously be a part of that crime. If this is intended to defend your original claim, you’re being utterly ridiculous. You made a specific claim about caller id spoofing, not fraud. For example, If you’re spoofing a random number for telemarketing calls that’s just not fraud.

> If you’re spoofing a random number for telemarketing calls that’s just not fraud. It absolutely is, and in most civilised countries is illegal. Like, I can totally believe that in the USA where any old lunatic can own an automatic weapon amd nobody gets concerned until he shoots up a school thats the case ye There’s probably some constitutional argument that you can spoof your number based on something ridiculous l…

>in most civilised countries is illegal.

I feel like we’re moving goalposts here and “civilised countries” will sooner than later become “English-speaking countries”, in which case I’m totally willing to concede that you’re probably right.

Very few countries have found it necessary to prohibit CID spoofing.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#254
post #232

This seems like a big problem, since my bank's SMS codes don't specify why they are sending it: "This is a verification code from [bank]. Enter online at prompt or in password field w/in 30 minutes." Nowhere does it mention the purpose, or to NOT read the code over the phone under any circumstances.

My bank starts with "SECURITY ALERT: NEVER REVEAL THIS CODE TO ANYONE" and ends with "Contact us if you didn't request it".

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#255

Earlier quoted context omitted.

My bank always says "There is an issue with your credit card/account, please call the number on the back of the card/your branch as soon as possible." and has for years. The only time they do otherwise is on very specific instances where they provide the info, "did you just buy something at store XXX for approximately $YYY" All banks and credit institutions should be required by law to do this.

Capital One has an app, every time my card is used I get a push notification. This is the best solution in my mind. I can actively monitor my card usage and call if I see something suspicious.

My AmEx does that too. I really like that feature.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#256
post #243

Earlier quoted context omitted.

I had that same issue with Amex, they phoned, said there was a concern with my card and then wanted me to go through identity checks before saying more. They also got quite stroppy when I refused and asked them to prove their own identity first! Eventually they did suggest I call the number on the back of my card, but I was annoyed by their lack of professionalism by this point (I mean, they are asking me to do stuff…

Why would a letter be genuine? That seems easier to spoof then phone or email?

It might not be genuine. But what one should do to resolve the problem described in the letter is to go to the regular amex website, log in, and update your debit information.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#257

Earlier quoted context omitted.

I had an experience indistinguishable from the phishing attack being discussed - with the only difference that I initiated the phone call. A transaction I had initiated had triggered some fraud warnings and my account was locked. They asked for my account number, name, and address for verification. When they got to the point that they sent me a code over SMS and wanted me to tell it to them over the phone, I stopped…

I wonder if bank staff are in on it sometimes. I once was at a bank branch and had the teller pick up the phone, call another teller and tell her my balance in a foreign language that I happen to speak fluently (but don’t look like I should). I wanted to ask her why she would be doing that, but I was a bit more meek in my younger days.

At least if you're at the bank, the typical separation of powers would at least ensure they're caught promptly, should something go wrong.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#258

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

> When I read the thread now, it's obviously full of red flags. I was successfully manipulated, and whilst I'm certainly not as clever as all the people pointing out they would have caught this from sentence one, I believe I'm also not the lowest hanging fruit in terms of a target :-) I think it's soo easy to spot scams because 99% of them are so shit, poor spelling, talking nonsense. If scammers simply spell checked…

Not sure if still the case, but this used to be done specifically to weed out people who weren't quite gullible enough.

https://www.telegraph.co.uk/technology/microsoft/9346371/Nig...

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#259
Reading this thread reminds me of when I was subject to a social engineering attack by people who claimed to be the FBI. The voice messages they left sounded unconvincing so I ignored them on the basis the real FBI would have better ways to contact me.

Couple days later two FBI agents show up in my driveway asking why I didn't respond to their voicemail..

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#260
post #68

Earlier quoted context omitted.

Wow, this really is something if done right. I don't use a landline now, but if I remember, the caller needs to disconnect for the line to actually be disconnected. So even if the callee tries to disconnect by hanging up, the caller is still actually connected. If the callee picks up the receiver again and hears a dial tone, they'd be none the wiser. But I guess the scammer would also need to detect a key-press tone…

That's not how it works with digital lines. Disconnect on any side breaks the whole circuit presuming they conform to even ancient PDH, much less SONET or SDH. Oh and this includes even more ancient ISDN. The trunk will immediately tear down the DS0 slot and circuit. GSM and VoIP also do not allow this behavior without engaging call waiting on subscriber side. This only happens with old fully analog connections. Not…

I haven't heard of this working since the 80's, with rotary pulse dial phones.
Post reply on HN