Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

351–360 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#351

Go to the police? Let us know how that works out for you. I did that once, after a highly credible phishing attempt (that, ultimately, I did not fall for). This was in Germany. Me: Here is what happened to me, I'd like to file a police report. Police: Well, with these internet scams, the fraudster is usually in another country, meaning we can't really do anything about it. Me: They used perfect German, used informati…

I had the exact opposite experience. The DAs office eventually called me to tell me that they didn't catch the perps but were able to kill the phone-number blocks which they had been using for years because no one ever reported them.

Sometimes cops are just lazy (or assholes). When thieves tried to steal the rain gutter from the appartment building on the other side of the road, the cops told me "don't expect us to rush in with sirens and screeching tyres", even after I told them the thieves were still there, in broad daylight.

Later my landlords told me they lost 50k Euros in the previous year because of stolen rain gutters.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#352
post #129

Earlier quoted context omitted.

> Which bank you have is not very secret information. Any payment exposes that information. Still, it means they had to spend some time to prepare for this specific person. Aside - here in Europe, the account numbers including bank code is pretty much public information. Something like e-mail address. After all, you can only send something in there. To withdraw, you need login credentials.

> After all, you can only send something in there. To withdraw, you need login credentials. Unfortunately, that's no longer true; with the SEPA Direct Debit system, money can be taken from an account with just the person's name, address, IBAN and BIC (the info required to fill a "SDD mandate"). I think there are some verifications you need to pass to be able to create direct debits, but it still seems like a move in…

yes and no

as far as i know, to set up a periodic sepa transfer - at least here in SVK(EU), you need to do it in person (although more and more banks are starting to allow this through their web/phone app)

eg. issuing a sepa for my monthly ISP subscription, i put into the system that 1)from this account 2)this amount of money 3)to this exact account 4)with these aditional details/comments/etc...

and if it fails for whatever reason - in my case mostly because once in a while, the amount that should be withdrawn for that month is more than the pre-set money

- the payment gets witheld at my bank / simply fails;

- the other side contacts me via phone/mail/... that there was a failure (which i can check on my bank account, so "kinda-phishing-safe");

the other side is still able to withdraw only that specific amount once in a period (most likely a month), and if anything is amiss, the payment simply fails

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#353
post #224

Earlier quoted context omitted.

> it’s only illegal to spoof your number for fraudulent purposes Seems like you’re gettig bogged down in semantics sir

Its a common feature for PBX'es to rewrite their outgoing caller ID on forwarded calls to match the origin caller ID. Say you've got an office desk phone that you have set to forward to your cell phone while you're out. Someone calls your desk phone, it forwards the call to your cell phone, what caller ID should be displayed? Technically the call to your phone is coming through your desk phone (well, your office's PB…

That’s not spoofing in principal though is it? This just reinforces my point that its very easy to do this with ordinary equipment. There isn’t really any kind of technical safeguards against this stuff, probably just for the convenience of this kind of stuff.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#354
post #239

Earlier quoted context omitted.

> If you’re spoofing a random number for telemarketing calls that’s just not fraud. It absolutely is, and in most civilised countries is illegal. Like, I can totally believe that in the USA where any old lunatic can own an automatic weapon amd nobody gets concerned until he shoots up a school thats the case ye There’s probably some constitutional argument that you can spoof your number based on something ridiculous l…

>in most civilised countries is illegal. I feel like we’re moving goalposts here and “civilised countries” will sooner than later become “English-speaking countries”, in which case I’m totally willing to concede that you’re probably right. Very few countries have found it necessary to prohibit CID spoofing.

> I feel like we’re moving goalposts

More semantics. Yawn. Save it for debate club.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#355
post #353

Earlier quoted context omitted.

Its a common feature for PBX'es to rewrite their outgoing caller ID on forwarded calls to match the origin caller ID. Say you've got an office desk phone that you have set to forward to your cell phone while you're out. Someone calls your desk phone, it forwards the call to your cell phone, what caller ID should be displayed? Technically the call to your phone is coming through your desk phone (well, your office's PB…

That’s not spoofing in principal though is it? This just reinforces my point that its very easy to do this with ordinary equipment. There isn’t really any kind of technical safeguards against this stuff, probably just for the convenience of this kind of stuff.

It is in the literal sense spoofing caller ID and using the same tech you earlier claimed was clearly illegal.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#356
post #77
post #37

Earlier quoted context omitted.

Good idea - but here in the UK there was a scam where they called you and THEN suggested you call the number on the back of the card. They then don't hang up, but play a dialling tone down the line until you dial the number. At which time they 'answer'. This only works on home phones, not mobile, but is worth considering, and warning your family/friends about.

I don't think this works any more. My parents always did this when kids did prank calls. Kept the phone open for hours blocking their line. Did not work last time I tested. Uncertain how long you have to wait before next call though.

In the UK - it was only the person that calls you who could hold the line open. Looks like BT stopped this happening in 2014/2015

Read more about steps taken to prevent this here: https://www.mirror.co.uk/news/technology-science/technology/...

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#357
post #129

Earlier quoted context omitted.

> Which bank you have is not very secret information. Any payment exposes that information. Still, it means they had to spend some time to prepare for this specific person. Aside - here in Europe, the account numbers including bank code is pretty much public information. Something like e-mail address. After all, you can only send something in there. To withdraw, you need login credentials.

> After all, you can only send something in there. To withdraw, you need login credentials. Unfortunately, that's no longer true; with the SEPA Direct Debit system, money can be taken from an account with just the person's name, address, IBAN and BIC (the info required to fill a "SDD mandate"). I think there are some verifications you need to pass to be able to create direct debits, but it still seems like a move in…

All banks I had an account at required verification for any payment order, including the direct debit. Some time ago (before widespread internet banking), you could issue an order that would be verified just against the details you mention _plus your signature_.

I hope it's not possible anymore. At least my current bank lets you authorize direct debit in internet banking app. Anything you do in person requires either logging-in to the internet banking account at the branch or presenting an ID.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#358

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

Once I gave my member number, the attacker used the password reset flow to trigger a text message from the bank. --> They used this to gain access to the account.

How did they to gain access from "password reset flow"? How could they tell your last transactions?

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#359

Earlier quoted context omitted.

Would you happen to know what kind of signature scheme they use?

I don't know about the German system, but here they use EMV-CAP: https://en.wikipedia.org/wiki/Chip_Authentication_Program

No public key crypto?

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#360
post #354

Earlier quoted context omitted.

>in most civilised countries is illegal. I feel like we’re moving goalposts here and “civilised countries” will sooner than later become “English-speaking countries”, in which case I’m totally willing to concede that you’re probably right. Very few countries have found it necessary to prohibit CID spoofing.

> I feel like we’re moving goalposts More semantics. Yawn. Save it for debate club.

When you're wrong you're wrong :)
Post reply on HN