OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
I never give any information to anyone who calls me, apart from people I already know like friends and family. If they say they are from the bank I apologize and say that I will contact them independently via the number that is on my card. I don't even confirm my name. Some banks think I am being difficult, but I stick to this principle regardless.
I was just subjected to the most credible phishing attempt I’ve experienced
311–320 of 360 posts
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#312Go to the police? Let us know how that works out for you. I did that once, after a highly credible phishing attempt (that, ultimately, I did not fall for). This was in Germany. Me: Here is what happened to me, I'd like to file a police report. Police: Well, with these internet scams, the fraudster is usually in another country, meaning we can't really do anything about it. Me: They used perfect German, used informati…
Thinking of this I would have continued like: Me: are you confirming that if I start a scam you will not investigate it? Police:...? Me: Ok , then thanks a lot, I know now. Police: umm, wait maybe..
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#313Earlier quoted context omitted.
I had that same issue with Amex, they phoned, said there was a concern with my card and then wanted me to go through identity checks before saying more. They also got quite stroppy when I refused and asked them to prove their own identity first! Eventually they did suggest I call the number on the back of my card, but I was annoyed by their lack of professionalism by this point (I mean, they are asking me to do stuff…
I think if they gave you a number to bypass the general queue that you’re still vulnerable to an attack, right? The only way to ensure you’re calling amex is to call the number you know, otherwise the scammer will have you call another one.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#314Earlier quoted context omitted.
>Of course it’s illegal? Fraud tends to be illegal. That’s as far as I’m willing to believe your “of course”. I do not believe most countries have laws regarding caller ID spoofing. I know that in my country IMEI spoofing is (Bizarrely!) sort-of prohibited as forgery (as in IDs, documents or “anything of evidential/testimonial(?) value”), but can’t find anything regarding phone numbers. I know that in the US it’s onl…
> it’s only illegal to spoof your number for fraudulent purposes Seems like you’re gettig bogged down in semantics sir
This is technically spoofing caller ID, but is clearly not fraud.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#315Earlier quoted context omitted.
What's an "early renewal" in this context? Mortgages aren't things I think of as requiring renewal at all.
Ah sorry, maybe it's a Canadian thing. I have a mortgage with an amortization that's say 20 years. But I actually enter into an agreement and a rate for say 3 years. At 3 years myself and the bank need to enter into a new agreement, or I can shop around for the best rate for the next term with other providers (although some banks have been clever in the rules trying to prevent this). An early renewal would be doing a…
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#316A better sms password reset flow would be to first send a text asking "A password reset has been initiated. Was this you? Reply: YES or NO". Then after a YES confirmation they send the reset code along with the same big "Don't share with anyone on the phone" message.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#317Yikes. Can't believe you gave out your PIN. The member number by itself is not useless... it's half of the login credentials.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#318OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#319Earlier quoted context omitted.
To send money over £250, RBS still use hardware card readers for their MFA flow. You put your debit/credit card in the device, entry your normal pin and then a code that is displayed on the website. It's a little inconvenient of you don't have the device with you when you need to send large amounts of money but in general it's great to have rather than SMS. Of course, I expect that eventually they'll move to SMS too…
Under the new EU rules 2FA over SMS is not allowed because it is possible to transfer phone numbers to other devices (through social engineering or simply because providers reuse old numbers) and thereby intercept the code. Instead most banks use an authentication app so that 2FA is bound to a single device.
Some Polish banks definitely allow using SMS as a second-factor.
(And some even let you use a permanent cookie for that. :-O)
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#320OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
"I was just subjected to the most credible phishing attempt I’ve experienced"
Everyone has been subjected to the most credible phishing attempt they've experienced. Need to find another qualifier ;)