Live data from Hacker News

An unprecedented wave of online bank fraud is hitting Britain

reuters.com

141–150 of 224 posts

Re: An unprecedented wave of online bank fraud is hitting Britain

#141
post #64

Earlier quoted context omitted.

US credit card companies aren't any better. I recently had a similar "fraud alert." The company ditched travel notices in 2016 claiming their AI was good enough to replace it. A few weeks after traveling I had a very small purchase flagged (under $20 at a place like Target). When I called the number they asked me for my complete credit card number, social security number, they didn't know my phone number or email and…

Amex?

I guarantee that experience wasn't with American Express. My experience has been that Chase has invested heavily in automated fraud management /and/ that it works reasonably well, but they have no real paths outside their strict processes for going around it. American Express is much more personable, at least for high value accounts, and still allows you to insert travel advisories which have date ranges.

Re: An unprecedented wave of online bank fraud is hitting Britain

#142

Earlier quoted context omitted.

On traditional landline phones that older folk tend to use (although I guess that's dwindling every year) a common tactic for scammers is to ask the victim to call the number on the back of the card. However the scammers don't hang up they just play a fake dial tone so the victim dials the number thinking they're contacting their bank but they're actually just speaking to the scammers again

How did that work? In the Netherlands, in the 80s-00s at least, hanging up cleared your line, so picking it up again would get you a fresh dialtone even if the other side didn't hang up (and the other side would get a modified "busy" signal if you hung up on them).

Different telephone switches (the big ones in the central offices) have different behavior for clearing the line when one party hangs up. I've heard that some switches wouldn't clear the line for tens of seconds when a called party hung up, and that those switches were common in the UK.

I personally recall people ocassionally being able to hang up one phone before picking up a different phone if they wanted to take the call in a diffent location in the house. Although, I don't remember it ever being very effective, over time (in my corner of the US), it became never effective, so you'd just leave the first phone off the hook and have to hang it up later.

Re: An unprecedented wave of online bank fraud is hitting Britain

#143

Earlier quoted context omitted.

I had a similar experience from HSBC. They called me about a potential fraudulent claim. They asked for my DOB, card number, sort code, you know, to verify "that I am who I say"... all the stuff they SHOULDN'T ask, and stupidly I gave it all up. To be fair, I did because my card had been rejected literally 30 seconds before while trying to make a purchase. But it was only after the phone call ended that I realised wh…

In fairness HSBC calls from known numbers (granted, you may not recognise it the first time, but you can look it up then save it) and publishes numbers where you can call them [1] [1] https://www.hsbc.co.uk/help/security-centre/report-a-problem...

This doesn't help when it's so common to spoof caller-id. The telco industry has blown any trust we can put in this information.

[I just learned that the FCC is considering not allowing calls made outside the US to be spoofed as numbers originating inside the US. I thought that was the whole point behind STIR/SHAKEN, silly me].

Re: An unprecedented wave of online bank fraud is hitting Britain

#144

It utterly infuriates me that banks won't let you use their mobile apps -- which are inevitably their websites packaged in a bundle, with added tracking -- on a rooted (or jailbroken) phone, even though I am sure that the overwhelming majority of users on android who have a rooted device are likely to be the most technically sophisticated, with (in my case) the presence of mind to install updates to their four-year-o…

> expanding the contactless limit ... wallet sniping

I am quite interested in the security details of NFC.

Where is the best information you found? Unfortunately my searches found too little.

BTW: apparently someone managed to use a fault in the protocol to steal well more than the limit. And by the way, if any product proposer mentions a "limit", in order not to be brainless they must also mention a "rate" (e.g. 10€ per hour), and I have never seen anyone do it.

Re: An unprecedented wave of online bank fraud is hitting Britain

#145
post #117

Earlier quoted context omitted.

Not all US credit card companies are like this. I specifically remember a few years ago that my Mom got a call from AMEX about some fraud on her card, to which she responded “I never get calls from you, how do I know this is real?”. They said no problem, just hang up and call the number on the back of your card. I believe some banks even skip the call entirely, and just prompt you to call the number on the card.

On traditional landline phones that older folk tend to use (although I guess that's dwindling every year) a common tactic for scammers is to ask the victim to call the number on the back of the card. However the scammers don't hang up they just play a fake dial tone so the victim dials the number thinking they're contacting their bank but they're actually just speaking to the scammers again

[deleted]

Re: An unprecedented wave of online bank fraud is hitting Britain

#146

Earlier quoted context omitted.

Bank phone numbers should be written on the back of credit/debit cards (and in a lot of countries, they are). "A fraudulent transaction has been detected on your credit card no. *1234, please call the number written on the back of your card", and you're done.

Unless the fraudulent transaction is due to the fact you just lost your credit card.

That number should also be on every single billing statement you've ever received from them, so you know, check that paper or pdf.

Re: An unprecedented wave of online bank fraud is hitting Britain

#147

What's always missing from stories like this is how the crooks get the money out. Considering that all Western governments have achieved total surveillance on our banking and made it impossible to have anonymous bank accounts, I'd like to see a detailed analysis about why they can't follow the money and see who gets it. Every scenario I can think of seems like it should be either traceable or actionable. Scenario 1:…

> What's always missing from stories like this is how the crooks get the money out. Considering that all Western governments have achieved total surveillance on our banking and made it impossible to have anonymous bank accounts, I'd like to see a detailed analysis about why they can't follow the money and see who gets it.

It's not really like this. Banks (and Western) governments are extremely meticulous about recording financial transactions, but have relatively few systems for actually retrieving that information for proactive law enforcement. There are large historical and technical barriers that prevent meaningful advances in the government's ability to surveil bank accounts in real time.

As just one example: interbank settlement over ACH is measured in days, not seconds or even hours. During settlement, anything can happen: the ODFI might try to claw the transaction back, either institution can go bankrupt, the destination account might close, etc. A human frequently intervenes to handle these cases. Banking is eventually consistent, but the fraudster is frequently long gone by that point.

Edit: it's also worth noting that "anonymous" (read: numbered) banking is also really only good for Doing Crime (and Having Crime Done to You). But plenty of countries, including the US, allow you to open bank accounts (and do debit transactions) without an official government ID.

Re: An unprecedented wave of online bank fraud is hitting Britain

#148
post #120

Earlier quoted context omitted.

Red flag number 1 - my bank wouldn't give someone random my telephone number. That would be illegal.

Good thing there are no data leaks or compromises! /s That my bank insists on using essentially now public information now to verify (and refuses to use anything else, even after being repeatedly asked!) is also infuriating. Last 4 of SSN and DOB? Really?

Well, the point isn't that my bank wouldn't "leak" my details - I certainly don't trust them that far. So it's absolutely possible for a random person to get my phone number from the bank. But if a random person were to phone me and tell me that my bank gave them my phone number to be helpful, I'd be calling that out as a lie.

Re: An unprecedented wave of online bank fraud is hitting Britain

#149
post #136

Earlier quoted context omitted.

How did that work? In the Netherlands, in the 80s-00s at least, hanging up cleared your line, so picking it up again would get you a fresh dialtone even if the other side didn't hang up (and the other side would get a modified "busy" signal if you hung up on them).

Because when you hear the other side (pretend to) hang up, you need to not be fooled and also hang up on your side. If you don't hang up on your side, then on older phones you actually have no way of telling the call is still going. On your smartphone, it's easier to not fall in this trap, as the screen is making it harder to type a phone number while the call is still going.

No, this isn't just confusion, this is a real behaviour difference between smartphones and (some) landlines. If someone calls you on a landline, depending on the exchange, hanging up your phone might not be enough to end the call; when you pick up again, you may still be connected to the caller.

It used to be the case that the party who made the call - being the party who is paying for it - was solely responsible for terminating it; then timeouts were introduced; and on many landline exchanges there is still a timeout before the call is actually terminated if the callee hangs up but the caller does not - although these days it is just a few seconds, that may still be long enough that you stay connected to the original caller if you hang up then immediately try to place a call.

Google "called party clear" for gory details.

Re: An unprecedented wave of online bank fraud is hitting Britain

#150

I moved to Britain a couple of years ago, and I was surprised at how many legitimate transactions are done in an insecure way. For example, I had had to talk my credit card number out loud on a telephone call to put a deposit on a flat and to renew some subscriptions. At the same time, most high street banks have terrible security infrastructure: HSBC regularly calls me and asks me to give sensitive information and s…

The US isn't much better. It's still common to hand your credit card to the waiter in a restaurant where they walk off to some terminal in the back with it and do whatever they want.
Post reply on HN