Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

261–270 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#262
post #200

Earlier quoted context omitted.

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…

>my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" Amex got quite offended when I did this, and almost chastised me when I got through to an agent after making the outbound call myself. They argued that because they only asked for limited personal information (DOB) it was fine... I would still do it again!

I also do this every time when my doctor's office or insurance calls. They have to verify your identity to give you medical information. I need to verify their identity to give them my personally identifiable information.

I think eventually they got the point because now they have a secure online email system and just leave a message asking me to call back. They still leave a return phone number, but it's getting better.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#263
post #243

Earlier quoted context omitted.

I had that same issue with Amex, they phoned, said there was a concern with my card and then wanted me to go through identity checks before saying more. They also got quite stroppy when I refused and asked them to prove their own identity first! Eventually they did suggest I call the number on the back of my card, but I was annoyed by their lack of professionalism by this point (I mean, they are asking me to do stuff…

Why would a letter be genuine? That seems easier to spoof then phone or email?

My preference is to have multiple points of contact. Email+phone and the alert is sent simultaneously both ways. This happened recently when a purchase I made was flagged. I got a text asking to approve the charge. Not trusting SMS I checked my email and saw the same message as the text and a link to take further action.

I was disappointed that no alert was sent through the banking app. That would be the most secure option but is explicitly disallowed in the notification settings.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#264

Earlier quoted context omitted.

My bank always says "There is an issue with your credit card/account, please call the number on the back of the card/your branch as soon as possible." and has for years. The only time they do otherwise is on very specific instances where they provide the info, "did you just buy something at store XXX for approximately $YYY" All banks and credit institutions should be required by law to do this.

My bank does this. Two texts: 1: "We need you to verify some transactions. You will receive a text from with the transaction details" 2: "Do you recognise these transactions? Reply Y if yes, N if no" Y -> "Thank you for verifying the transactions. If any transactions have been declined, you may been to repeat them" N -> "Your card has been blocked and a new one ordered. Please contact us if you need any further advic…

These are what I usually see, or else an automated call with the same approximate script. Is there anything insecure about doing this one? The only thing I can think of is a MiTM where your account credentials are already compromised and they are using your answers to reset your password.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#265
post #177

Earlier quoted context omitted.

Just realizing that a phishing-attack like this is nowadays impossible in the EU: proper two-factor authentication is mandatory now (Revised Directive on Payment Services, PSD2), even just for login. TAN-codes generated for transactions need to incorporate the data of the transaction (recipient and amount), so that a phished TAN cannot be used to authorize a different transaction. I think even a simple SMS TAN may no…

The security part of PSD2 is starting to look like another cookie law. Banks of course didn't implement any proper 2FA like U2F but rather send you scrounging for the phone with their app every time you want to look up a transaction or an account number, something that didn't require second factor until the directive. In fact, because it makes checking recent transactions that much less convenient, it probably made m…

Here we have ChipTAN - I put my card into a special reader (some photodiodes plus keypad and display), hold the diode-end of the reader onto my PC display and a flickering image on the website transfers some info to the reader. On the reader I then see some info on the transaction (IBAN and amount), plus a TAN. I then enter that TAN on the banks website.

So an attacker would need to alter the image (simple) and cause a collision (hopefully difficult) or somehow abuse an error in the reader firmware.

It seems there is now a QR variant of that (which increases the attack surface since now it has to understand a more complex data format).

If my bank would have had me install an App or use SMS 2FA I would have kindly asked them to .... off (or, if they think their "2FA" is safe, just connect their mobile phones to this totally unsuspicious looking USB device).

ChipTAN on wikipedia: https://en.wikipedia.org/wiki/Transaction_authentication_num...

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#266

Reading this thread reminds me of when I was subject to a social engineering attack by people who claimed to be the FBI. The voice messages they left sounded unconvincing so I ignored them on the basis the real FBI would have better ways to contact me. Couple days later two FBI agents show up in my driveway asking why I didn't respond to their voicemail..

Well, you weren't wrong.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#267

Earlier quoted context omitted.

Capital One has an app, every time my card is used I get a push notification. This is the best solution in my mind. I can actively monitor my card usage and call if I see something suspicious.

I wish all banks and CCs offered this feature.

It's worth searching on their site / calling them, since in my experience every time over the last couple years I have dug, I have found it offered.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#268

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

I got a similar call a few months back. They didn't ask for my PIN, but did ask for some other sensitive information. Fortunately I was able to verify afterward that it was legitimate by initiating a call to the bank using the number on their website (in case the original was spoofed), and they confirmed a record of the call in their system. But this was after I'd given them some information.

Phone number spoofing has to stop. There is no excuse anymore.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#269
post #174

Earlier quoted context omitted.

>When I read the thread now, it's obviously full of red flags. I was successfully manipulated, and whilst I'm certainly not as clever as all the people pointing out they would have caught this from sentence one, I believe I'm also not the lowest hanging fruit in terms of a target :-) Makes you wonder what this will look like when these scams evolve another couple of generations in terms of complexity ... I think this…

I'd wager >50% of those that claim "Ah ha! I'd spot it here!" would fail in real life. Arm-chair quarterbacking is easy. Spotting the scam in real life, when you're walking down the street or otherwise distracted with life? Much harder.

I don’t know... this is not a “social skills” thing. It’s a very simple rule that should be easy for anyone to follow: never talk to any business who calls you. Ask who they are, hang up, and call the official customer support number. That’s it. No wizardry, charisma, or smooth talking ability needed. Get who they are and hang up.

Personally, I don’t even answer the phone anymore unless the number is one of my contacts. Looking at the last 30 days of call history, a good 95% of my incoming calls were spammers who didn’t leave a message or spammers who did.

The last time a legitimate number called me I didn’t recognize was probably a year ago. It was my daughter’s school. They left a message and I called them back immediately. That’s probably the safest way of dealing with the security trash fire called the phone system.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#270

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…

I get these calls from time to time, and any bank with proper training should be 100% okay with you questioning their authenticity. There are some replies which indicate that the agent is annoyed... That's just poor training.

As for them initiating a phone call, it still does remain the best way to contact someone urgently, usually falling back to SMS and/or email when/if you don't answer (this was our SOP when I was in a fraud detection team years ago). We'd also usually tell them to call the number on the bank of your card (because not everyone is able to look up the bank's website, shockingly, so this is the most universally applicable way to give people a number) but my usual spiel was "call us on the number on the back of your card or from our website".

There's also no real way for you to know that they're legit, but an interesting reassurance one bank I know uses is to provide your month and day of birth and ask you for the year (as just part of the verification process). The partial info probably helps some people but I still wouldn't go for it - too many people know my birthday.

Post reply on HN