OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
I was just subjected to the most credible phishing attempt I’ve experienced
331–340 of 360 posts
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#332I can understand how people would fall for this one. With 20/20 hindsight, asking for the member number is fishy - it doesn't actually verify anything. And when my bank calls me, it is always automated - I only get a person talking to me if I ask for it through the automated systems. So in a way, any actual person calling would be a red flag. But in the moment, I can see why it sounded legit. My parents have taken th…
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#333It's even worse in Russia - fake caller ID makes you think you are talking with the bank, mobile phone operators don't seem to be doing much, or at least didn't a couple of months ago. That said, all the banks I used send you along with the confirmation code a description of what you are actually confirming.
This is really a SS7 issue not a Russia issue, spoofing outbound caller ID in the USA/Canada is also trivially easy using any major SIP trunking provider.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#334Re: I was just subjected to the most credible phishing attempt I’ve experienced
#335Re: I was just subjected to the most credible phishing attempt I’ve experienced
#336Scammers have been triggering password resets and 2factor to seem legit for long as it has existed.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#337Earlier quoted context omitted.
>that's bound to a smartphone as a signature. Big yikes, that's a no for me.
This is the same system I'm talking about. You can use your smartphone and a PIN, or you can get a hardware dongle. Same authentication API from the banks POV.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#338Earlier quoted context omitted.
Which bank you have is not very secret information. Any payment exposes that information. It's a very clever scam, but it's also a very insecure bank if this is enough to authorise payment. Get a different bank that uses 2FA, makes it clear what an authorisation code is for, and doesn't call you for this kind of sensitive information. If they really do need to reach you quickly to stop a fraudulent transaction, a sim…
> Which bank you have is not very secret information. Any payment exposes that information. Still, it means they had to spend some time to prepare for this specific person. Aside - here in Europe, the account numbers including bank code is pretty much public information. Something like e-mail address. After all, you can only send something in there. To withdraw, you need login credentials.
Unfortunately, that's no longer true; with the SEPA Direct Debit system, money can be taken from an account with just the person's name, address, IBAN and BIC (the info required to fill a "SDD mandate"). I think there are some verifications you need to pass to be able to create direct debits, but it still seems like a move in the wrong direction, in my opinion.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#339Earlier quoted context omitted.
Ah sorry, maybe it's a Canadian thing. I have a mortgage with an amortization that's say 20 years. But I actually enter into an agreement and a rate for say 3 years. At 3 years myself and the bank need to enter into a new agreement, or I can shop around for the best rate for the next term with other providers (although some banks have been clever in the rules trying to prevent this). An early renewal would be doing a…
Ah, that's interesting and subtly different from the way it works in the US. The most common mortgage loan here is simply a 30-year fixed rate loan. We do have 3 and 5 year fixed loans, but they just revert to a floating rate after the fixed term so there's no presumption that you have to get a new loan at the end of the fixed term even though it's often a good idea. Those loans have also fallen out of favor substant…
As a borrower, there's a big risk with a balloon payment that you may not be able to find financing when it's due, so having a full term loan is very desirable.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#340Earlier quoted context omitted.
My bank always says "There is an issue with your credit card/account, please call the number on the back of the card/your branch as soon as possible." and has for years. The only time they do otherwise is on very specific instances where they provide the info, "did you just buy something at store XXX for approximately $YYY" All banks and credit institutions should be required by law to do this.
Capital One has an app, every time my card is used I get a push notification. This is the best solution in my mind. I can actively monitor my card usage and call if I see something suspicious.