Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

311–320 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#311

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

I never give any information to anyone who calls me, apart from people I already know like friends and family. If they say they are from the bank I apologize and say that I will contact them independently via the number that is on my card. I don't even confirm my name. Some banks think I am being difficult, but I stick to this principle regardless.

I think it's more likely that some scammers think you're being difficult. Shouldn't that be standard procedure for a bank?

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#312
post #154

Go to the police? Let us know how that works out for you. I did that once, after a highly credible phishing attempt (that, ultimately, I did not fall for). This was in Germany. Me: Here is what happened to me, I'd like to file a police report. Police: Well, with these internet scams, the fraudster is usually in another country, meaning we can't really do anything about it. Me: They used perfect German, used informati…

Thinking of this I would have continued like: Me: are you confirming that if I start a scam you will not investigate it? Police:...? Me: Ok , then thanks a lot, I know now. Police: umm, wait maybe..

Of course the local police department isn't likely to investigate it. That doesn't mean no one is.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#313
post #229

Earlier quoted context omitted.

I had that same issue with Amex, they phoned, said there was a concern with my card and then wanted me to go through identity checks before saying more. They also got quite stroppy when I refused and asked them to prove their own identity first! Eventually they did suggest I call the number on the back of my card, but I was annoyed by their lack of professionalism by this point (I mean, they are asking me to do stuff…

I think if they gave you a number to bypass the general queue that you’re still vulnerable to an attack, right? The only way to ensure you’re calling amex is to call the number you know, otherwise the scammer will have you call another one.

Just ask for an extension to reach them at when you call their public number.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#314
post #224

Earlier quoted context omitted.

>Of course it’s illegal? Fraud tends to be illegal. That’s as far as I’m willing to believe your “of course”. I do not believe most countries have laws regarding caller ID spoofing. I know that in my country IMEI spoofing is (Bizarrely!) sort-of prohibited as forgery (as in IDs, documents or “anything of evidential/testimonial(?) value”), but can’t find anything regarding phone numbers. I know that in the US it’s onl…

> it’s only illegal to spoof your number for fraudulent purposes Seems like you’re gettig bogged down in semantics sir

Its a common feature for PBX'es to rewrite their outgoing caller ID on forwarded calls to match the origin caller ID. Say you've got an office desk phone that you have set to forward to your cell phone while you're out. Someone calls your desk phone, it forwards the call to your cell phone, what caller ID should be displayed? Technically the call to your phone is coming through your desk phone (well, your office's PBX), but doing that would mask who is actually calling. So the PBX rewrites its caller ID info to appear to be as the origin when it calls your cell phone.

This is technically spoofing caller ID, but is clearly not fraud.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#315

Earlier quoted context omitted.

What's an "early renewal" in this context? Mortgages aren't things I think of as requiring renewal at all.

Ah sorry, maybe it's a Canadian thing. I have a mortgage with an amortization that's say 20 years. But I actually enter into an agreement and a rate for say 3 years. At 3 years myself and the bank need to enter into a new agreement, or I can shop around for the best rate for the next term with other providers (although some banks have been clever in the rules trying to prevent this). An early renewal would be doing a…

Ah, that's interesting and subtly different from the way it works in the US. The most common mortgage loan here is simply a 30-year fixed rate loan. We do have 3 and 5 year fixed loans, but they just revert to a floating rate after the fixed term so there's no presumption that you have to get a new loan at the end of the fixed term even though it's often a good idea. Those loans have also fallen out of favor substantially since 2008. Are full-term fixed loans not a thing in Canada?

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#316
My wife had the same thing happen to her but luckily our bank clearly says that this is a password reset pin code (don't share with anyone) type of message along with the pin code in the SMS. So, my wife refused to give it to the person on the phone.

A better sms password reset flow would be to first send a text asking "A password reset has been initiated. Was this you? Reply: YES or NO". Then after a YES confirmation they send the reset code along with the same big "Don't share with anyone on the phone" message.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#318

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…

This. I always tell them I'll call them back if it is someone I don't know who needs to discuss sensitive matters. It's the only way to be sure.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#319

Earlier quoted context omitted.

To send money over £250, RBS still use hardware card readers for their MFA flow. You put your debit/credit card in the device, entry your normal pin and then a code that is displayed on the website. It's a little inconvenient of you don't have the device with you when you need to send large amounts of money but in general it's great to have rather than SMS. Of course, I expect that eventually they'll move to SMS too…

Under the new EU rules 2FA over SMS is not allowed because it is possible to transfer phone numbers to other devices (through social engineering or simply because providers reuse old numbers) and thereby intercept the code. Instead most banks use an authentication app so that 2FA is bound to a single device.

Citation needed?

Some Polish banks definitely allow using SMS as a second-factor.

(And some even let you use a permanent cookie for that. :-O)

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#320

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

Sorry for the nitpick on grammar but

"I was just subjected to the most credible phishing attempt I’ve experienced"

Everyone has been subjected to the most credible phishing attempt they've experienced. Need to find another qualifier ;)

Post reply on HN