Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

341–350 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#341

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

Pro-tip, perform mutual authentication:

"Can you give a reference number (they will have a case number), and tell me where I can find your department's number on your website please. [Edit] I will call you back."

I've never had a bank or other financial institution have a problem with this approach. I don't give myself the opportunity to be fooled, because all of us can be fooled, it's how I respond to every single call from a business.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#342
post #243

Earlier quoted context omitted.

I had that same issue with Amex, they phoned, said there was a concern with my card and then wanted me to go through identity checks before saying more. They also got quite stroppy when I refused and asked them to prove their own identity first! Eventually they did suggest I call the number on the back of my card, but I was annoyed by their lack of professionalism by this point (I mean, they are asking me to do stuff…

Why would a letter be genuine? That seems easier to spoof then phone or email?

It's not so much that the letter is guaranteed to be genuine.

They can include information in the letter they can't include on a phone call, as the mail service is performing the authentication.

My health insurer won't talk to me on the phone without me confirming identity, even if they called me, but they'll happily mail the info.

Never call the number off the letter, though.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#343

Earlier quoted context omitted.

My bank always says "There is an issue with your credit card/account, please call the number on the back of the card/your branch as soon as possible." and has for years. The only time they do otherwise is on very specific instances where they provide the info, "did you just buy something at store XXX for approximately $YYY" All banks and credit institutions should be required by law to do this.

Capital One has an app, every time my card is used I get a push notification. This is the best solution in my mind. I can actively monitor my card usage and call if I see something suspicious.

I'm surprised that this isn't a requirement for banks considering the very large number of scams going on in the US.

In India, getting an SMS/Email confirming every card usage is a legal requirement imposed by the Rserve Bank of India. The same goes for card usage itself. All credit and debit card POS transactions need the card PIN to be approved. Likewise, all online transactions require MFA.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#344
post #243

Earlier quoted context omitted.

I had that same issue with Amex, they phoned, said there was a concern with my card and then wanted me to go through identity checks before saying more. They also got quite stroppy when I refused and asked them to prove their own identity first! Eventually they did suggest I call the number on the back of my card, but I was annoyed by their lack of professionalism by this point (I mean, they are asking me to do stuff…

Why would a letter be genuine? That seems easier to spoof then phone or email?

Cost.

Email is pennies per thousands.

Phone calls are cheap especially for nonconnected or robocalls (which would cost for a postal contact).

Postal mail costs $0.50 US in postage alone. The full-up cost of a mail campaign is often several dollars per mailed item, though in bulk, and with bulk rate, I believe it's closer to $0.40 (postage plus a few cents for paper and envelope).

That would cover many thousands of email contacts, possibly nearly as many phone/VOIP attempts.

And the systems required to successfully and accurately generate a postal response on request are also high.

Low-cost systems are high-fraud systems.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#345
post #225

Earlier quoted context omitted.

How is that different, since social engineering works there too?

Not as easily. As I understand it, with Mobile BankID, the attacker goes to the bank web site and then asks the victim to authenticate with their BankID app. With the real BankID, the computer accessing the bank web site needs access to the smart card. Exploitation is still possible of course, but the bar seems higher.

Understood, you can only login at the actual computer, not from anywhere. Should be mandatory for the elderly that are the most targeted victims.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#346

Earlier quoted context omitted.

Ah sorry, maybe it's a Canadian thing. I have a mortgage with an amortization that's say 20 years. But I actually enter into an agreement and a rate for say 3 years. At 3 years myself and the bank need to enter into a new agreement, or I can shop around for the best rate for the next term with other providers (although some banks have been clever in the rules trying to prevent this). An early renewal would be doing a…

Ah, that's interesting and subtly different from the way it works in the US. The most common mortgage loan here is simply a 30-year fixed rate loan. We do have 3 and 5 year fixed loans, but they just revert to a floating rate after the fixed term so there's no presumption that you have to get a new loan at the end of the fixed term even though it's often a good idea. Those loans have also fallen out of favor substant…

Nope, 5 years is a maximum term you can get for residential mortgages, fixed or variable, with 25 years amortization most commonly (so you'll renew it at least 4 times).

Maybe there are other weird types of mortgages but they are usually not available for individuals I think.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#347

Earlier quoted context omitted.

I agree. The same goes for email obviously. But some financial institutions are actively luring customers into doing the wrong thing. Paypal really stands out on this one. They are regularly sending me emails with a link to their login page to view my recent transactions (regardless of whether or not there are any transactions). This is clearly negligent.

Okay, so it's not just me. I've never clicked on what are apparently real paypal emails, because I have legitimately always assumed they were phishing e-mails that made it past my spam filter. They're real. They're really real paypal e-mails. Wow.

I believe them to be genuine, but if you need incontrovertible proof, Paypal has you covered! :-)

All messages contain the following "clarification":

"How do I know this is not a Spoof email?

Spoof or 'phishing' emails tend to have generic greetings such as "Dear PayPal member". Emails from PayPal will always contain your full name."

So unless the bad guys can get their hands on a database full of names and email addresses, we're safe. And Paypal can honestly claim that "the security of our customers is very important to us!".

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#348

Earlier quoted context omitted.

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…

You should be careful even about doing that if you are on a landline. There is a landline scam where they don't let the call disconnect, so when you hangup and then think you are dialing the bank, you are actually still connected to the scammer. Always use your mobile phone to make the call (although I'm sure its only a matter of time before even that is compromised). https://toronto.ctvnews.ca/etobicoke-couple-defra…

Luckily I don’t have a landline so it’s all mobile :)

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#349

Earlier quoted context omitted.

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…

I don't do that. I say "are you crazy, you are a bank and asking me to prove who I am? You called me. You prove who you are first."

Yes, you’re right, I did say something like that once but the end result was the same: they asked me to call the number on my card.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#350
post #321

Earlier quoted context omitted.

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…

> "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" Correct. If someone calls me, the onus is on them to prove to me that they are who they say they are. However, I usually just block ALL unscheduled phone calls, period. Not only do I not have time for unscheduled interruptions, but banks have secure websites and if they can't make proper use of them,…

Good point, and in fact I haven’t gotten such a call in a long time. All the “did you make transaction X” type calls now go through their app or via sms, so don’t get those calls anymore. I can’t actually remember the last time the bank called me, but maybe 6 or 7 years ago they called me a good few times. Nowadays I actually also block incoming calls unless in my contacts or I’m expecting it. I communicate mostly online and outside family, rarely get phone calls. So I really don’t care to answer a random call.
Post reply on HN