Live data from Hacker News

An unprecedented wave of online bank fraud is hitting Britain

reuters.com

101–110 of 224 posts

Re: An unprecedented wave of online bank fraud is hitting Britain

#101

Why can a 78-year old widow's life savings be managed through an online bank system? Bring back local branch offices where people have to manage their high-risk accounts in-person.

You can't even talk to a live support person on the phone anymore. Just moved to the UK (from Czech Republic) and was shocked how everything is IVR here. We are all just numbers in the database here.

For most of us avoiding telephone queues is a blessing.

I have 3 "proper" bank accounts (different banks), a couple of "challenger"/app bank accounts, and 3 credit cards and haven't stepped foot in a branch to open or deal with any of them in 20 years. I've had to get on the telephone with a couple maybe a couple of times.

I couldn't be happier with this arrangement, as long as someone is reachable when shit really does hit the fan.

Re: An unprecedented wave of online bank fraud is hitting Britain

#102
post #52

Earlier quoted context omitted.

That's a big if - why would a scammer risk the liability of operating in the EU if they can trivially outsource to somewhere untouchable?

Because criminals operate in every country and the EU has a large and often English speaking population. It’s the same with the US/UK where plenty of scammers operate in each country while targeting the other. Email doesn’t care about national borders, it does care about language.

> because criminals operate in every country

Sure, they do, but what does that matter; or what does "operate" mean in this sense? You can outsource to elsewhere i.e. you can operate anywhere.

> the EU has a large and often English speaking population

So do many places, the EU is by no means unique in this respect. But there's a reason "cost centres" are being outsourced to India or the Philippines, more often than than the EU. And in the context of criminal operations, "language-speakers" is by far the least important/riskiest factor relative to those that would get you arreseted.

> It’s the same with the US/UK

Is it? Do you have (statistical) examples?

> Email doesn’t care about national borders

Wrt liability, (i.e. Arrest Warrants, the context of this thread) email, or at least the senders of, do care; more-so than language. Unless you are implying criminals care more about maximising profit than getting caught?

Re: An unprecedented wave of online bank fraud is hitting Britain

#103

What's always missing from stories like this is how the crooks get the money out. Considering that all Western governments have achieved total surveillance on our banking and made it impossible to have anonymous bank accounts, I'd like to see a detailed analysis about why they can't follow the money and see who gets it. Every scenario I can think of seems like it should be either traceable or actionable. Scenario 1:…

> Considering that all Western governments have achieved total surveillance on our banking

> and made it impossible to have anonymous bank accounts,

These are not the same things, as anyone who works in logging and tracking will tell you. Just because there is some tracking of you, or an ability to track you does not mean that all activity could be noted or flagged. If I purchase from a new online vendor, how would my bank know if it was me or not?

Re: An unprecedented wave of online bank fraud is hitting Britain

#104

A recent new scam is delivery text (SMS) messages [1]. You are expecting a parcel delivery and receive a text message saying you have missed a delivery. The text asks you to rearrange delivery by paying for the cost of re-delivery. The link takes you to a scam website asking for payment from which you enter card details. I have had these scam delivery text messages. On one occasion, I almost fell for it because the s…

This is presumably easier because via SMS use of an url shortener would be the norm.

Re: An unprecedented wave of online bank fraud is hitting Britain

#105

A recent new scam is delivery text (SMS) messages [1]. You are expecting a parcel delivery and receive a text message saying you have missed a delivery. The text asks you to rearrange delivery by paying for the cost of re-delivery. The link takes you to a scam website asking for payment from which you enter card details. I have had these scam delivery text messages. On one occasion, I almost fell for it because the s…

yup, now with EU/Brexit import duties and VAT on everything, the carriers (DHL/UPS/FedEx) have been made responsible for collecting the fees on the govts. behalf, but they also don't want to slow down delivery, stop it at customs, send a letter to you, wait 3 days for you to pay, etc - so they send a text with a link to a really shady payment gateway where they tell you there's a fee to pay. Mind you, this is what th…

This only makes sense if the courier has your digital contact info. Some of them don't even hold your parcel now, they just send it anyway, alongside an invoice with the duties due.

Re: An unprecedented wave of online bank fraud is hitting Britain

#106

Ooh we're still the capital of something. Personally I think this comes down to ineffective education in many cases. Yes, some of these scams are getting quite impressively advanced, and they tend to target older people who are declining in cognitive ability, but so often the victims are absolutely unwilling to admit they were a bit stupid. It's always someone else's fault, like the bank, or the police, or Facebook,…

It's not just old people. Plenty of young tech savvy people fall for these scams as well. The scammers are extremely well practiced, and are extremely good at using misdirection and pressure cooker situations to make it extremely difficult for people to recognise the scam in the moment. Some of the scariest aspects of these scams is that they frequently use the banks own fraud protections and alerts against victims,…

It's tempting fate to say it, but I've not fallen for a scam, or a phishing attempt, and I've been subjected to many. Natural distrust and cynicism perhaps. I don't answer the phone to unknown numbers, I don't click links in emails, I don't do business at the door or over the phone, and I don't believe anything other people tell me (can report that my girlfriend hates this aspect of my personality).

The head of accounts in my previous company fell for a bank transfer scam (urgent payment request forwarded "from the CEO"), so I have seen it happen to young people, but I wouldn't say that person was "tech savvy". Being able to use a computer doesn't make you tech savvy, and I would say the number of tech savvy people is probably close to identical between younger and older age groups. Being intelligent in one aspect doesn't make you smart at everything else (which is why I avoid doing plumbing). What is missing is critical thinking and cynicism. I highly doubt most people check the full email source of anything they receive that looks important, but they should. People rely too heavily on technology to tell them when something is wrong, and they shouldn't.

The scam example you describe is easily avoided: don't enter your details in the fake package website in the first place. Don't answer the phone to the unknown number. Don't believe them when they say they're from the bank. Don't do anything anyone tells you to. And if they try to rush you, that should make you stop and think why.

I don't doubt the scams are getting pretty clever, but that doesn't mean the victims can't also be a bit stupid. Yes it's sad that they have fallen for it, but to shift all the blame elsewhere is unfair - we are ultimately responsible for our own actions.

Re: An unprecedented wave of online bank fraud is hitting Britain

#107
For too long, the onus has been on us, the bank customer to prove our identity using a series of "security" questions. However, we can't actually prove that _they_ really are our bank: AFAIK there's no mechanism in place.

So how about a facility for setting up a passphrase on your account that _you_ could ask the bank for?

"I'm your bank".. "What's the passphrase?" "errrrr...." "goodbye scammer".

Re: An unprecedented wave of online bank fraud is hitting Britain

#108

Ultimately you can't really stop people from falling for con men, but I do feel part of the blame lies with banks and other institutions for normalising out-of-the-blue phone calls. How would you know a call from the bank about fraudulent transactions was fake? They do that! I've even had legitimate calls from them where they refuse to pass my security questions because of data protection. Pure madness.

Yeah NatWest are majorly guilty of this. They used to phone me with a script that was like: NW: "Hello, am I speaking to ?" Me: "Who's asking?" NW: "I'm calling from the NatWest fraud team, we'd like to verify your transactions. First we need to ask some security questions: what is your account number?" Me: :| Online-only banks like Monzo/Starling are better at this aspect - they never seem to phone anyone, which at…

Monzo has some app integration with their phone staff too. They can send push notifications to open the app to a certain point etc,

Re: An unprecedented wave of online bank fraud is hitting Britain

#109
post #62

Earlier quoted context omitted.

How are these databases used to police/punish the stereotypical Nigerian scammer?

I don't think that's a reasonable question, not all scammers are Nigerian. Some are based in the UK, others in Europe. Also the EU had data sharing agreements and collaboration outreach with police forces all over the world that we also lost access to. That's one of the complications with our data sharing with the EU; they have agreements to share data with non-EU countries on the basis that their data is only shared…

> I don't think that's a reasonable question, not all scammers are Nigerian.

Than a non-sequitur, why would it matter? superbugs that originate in hospitals can escape and cause harm beyond a hospice; and if certain locales, Nigeria being the famous example of, are harder to touch, then those places will be selected-for for by scammers.

Consider that certain places are harder to police than others (which is basically the whole premise of this thread in the first place - than the EU is better policed than the UK); or that criminal operations could operate somewhere other then their place-of-origin.

> Some are based in the UK, others in Europe.

And if the European ones are more likely to get caught, there will be fewer of them, and a lot of those that remain won't operate locally.

> Also the EU had data sharing agreements and collaboration outreach

I don't doubt data-sharing is more difficult, I question if it makes any (long term) difference to remote (i.e. over the phone, or email) scams.

The question is how does that data relate to catching scammers who trivially outsource from elsewhere? Does the EU have any data on which EU companies run scams out of Nigeria[*0]? Even if the EU has a data-sharing agreement with Nigeria, I doubt the government even keeps tabs on the scammers. Plus, you can always move to wherever there isn't such a data-sharing agreement e.g. somewhere semi-hostile/antagonistic to Europe.

[0] SIDENOTE: I would mention somewhere other than Nigeria, so not as to seem to "pick on" the place, except - 1) Nigeria is established as famous for scams already, b) that would only make me more susceptible to downvotes from people triggered by me mentioning their somewhere-they-hold-dear in a negative light.

Re: An unprecedented wave of online bank fraud is hitting Britain

#110

I had a long argument with HSBC UK Security a few years ago where I was completely unable to get the to understand they were putting their customers at risk. In the event that something looked strange on your account the 'HSBC Fraud Department' would text you and ask them to call you on a phone number. A phone number that didn't appear anywhere on their website. "We don't want it public. OK,well at least put it on a…

And don't get me started on banks sending out emails chock full of "Click this link!" It's like they're setting people up to get phished.

I have three bank accounts and none of them send emails with links. If they send any email to start with, they just say go read your messaging/documents on your bank account.
Post reply on HN