I was just subjected to the most credible phishing attempt I’ve experienced
271–280 of 360 posts
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#2721. Phishers call someone and pretend to be from their bank. If they've guessed the right bank and the person gives away their details, they win!
2. If they don't, and question the phishers authenticity, the scammers say "sure, just call us on the number on the back of your card".
3. The cardholder hangs up, and then dials the number for their bank, which they know and trust, because they've called it before or it's come from their card.
4. They get connected to a service representative, answer security questions, confirm that the transactions are valid, and then can relax.
5. A few days later, they get a call from their bank saying there's a whole lot of fraud on the account.
The trick to this one is that the phishers (a) call the cardholder on a landline and (b) when the cardholder thinks they've hung up, they haven't - the phishers just play a hook tone and then a dial tone.
In Australia at least (not sure about elsewhere?) if you call a landline number, the caller must end the call, or at least it used to be that way (I haven't owned a landline phone for a _long_ time. There's probably also a significant skew towards the elderly in landline owners, and in susceptibility to scam calls.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#273Earlier quoted context omitted.
I had that same issue with Amex, they phoned, said there was a concern with my card and then wanted me to go through identity checks before saying more. They also got quite stroppy when I refused and asked them to prove their own identity first! Eventually they did suggest I call the number on the back of my card, but I was annoyed by their lack of professionalism by this point (I mean, they are asking me to do stuff…
Why would a letter be genuine? That seems easier to spoof then phone or email?
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#274Earlier quoted context omitted.
I'd wager >50% of those that claim "Ah ha! I'd spot it here!" would fail in real life. Arm-chair quarterbacking is easy. Spotting the scam in real life, when you're walking down the street or otherwise distracted with life? Much harder.
I don’t know... this is not a “social skills” thing. It’s a very simple rule that should be easy for anyone to follow: never talk to any business who calls you. Ask who they are, hang up, and call the official customer support number. That’s it. No wizardry, charisma, or smooth talking ability needed. Get who they are and hang up. Personally, I don’t even answer the phone anymore unless the number is one of my contac…
But, the responses on Twitter weren't "never talk", they were "I'd know it was a scam as soon as..." (implying they'd allow the call to get that far).
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#275Earlier quoted context omitted.
I think if they gave you a number to bypass the general queue that you’re still vulnerable to an attack, right? The only way to ensure you’re calling amex is to call the number you know, otherwise the scammer will have you call another one.
It would be reasonably trivial to build a phone system that lets the agent generate a OTP of sorts. "Hey, we need to talk about your account. Call our general enquiries number on our website, press 9 and enter 'XXXXXX' to be reconnected to me."
Edit: perhaps the extension would be per transaction, not per-agent, and when the customer calls the extension, the agents system can automatically pull up the customer’s account. These extensions should expire, but given the length of some customer calls, and how often I’ve been disconnected from customer service lately, perhaps it should be on the order of hours, not minutes or seconds
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#276Earlier quoted context omitted.
My bank does this. Two texts: 1: "We need you to verify some transactions. You will receive a text from with the transaction details" 2: "Do you recognise these transactions? Reply Y if yes, N if no" Y -> "Thank you for verifying the transactions. If any transactions have been declined, you may been to repeat them" N -> "Your card has been blocked and a new one ordered. Please contact us if you need any further advic…
These are what I usually see, or else an automated call with the same approximate script. Is there anything insecure about doing this one? The only thing I can think of is a MiTM where your account credentials are already compromised and they are using your answers to reset your password.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#277OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#278Re: I was just subjected to the most credible phishing attempt I’ve experienced
#279OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#280OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
The recipient may believe they had starred the number because of this, making them more likely to pick up the call.