Earlier quoted context omitted.
US credit card companies aren't any better. I recently had a similar "fraud alert." The company ditched travel notices in 2016 claiming their AI was good enough to replace it. A few weeks after traveling I had a very small purchase flagged (under $20 at a place like Target). When I called the number they asked me for my complete credit card number, social security number, they didn't know my phone number or email and…
Incidently for those with a VPN installed on their phone do not use your banking app while the VPN is running. The current "We don't need you to tell us where you're going we can figure it out" leads to me getting locked out 100% of the time i use the banking app on my phone with the VPN on and then try to use the card at a nearby store. Obviously there's two different sources of my location incoming and that causes…
An unprecedented wave of online bank fraud is hitting Britain
181–190 of 224 posts
Re: An unprecedented wave of online bank fraud is hitting Britain
#182Earlier quoted context omitted.
Amex?
I guarantee that experience wasn't with American Express. My experience has been that Chase has invested heavily in automated fraud management /and/ that it works reasonably well, but they have no real paths outside their strict processes for going around it. American Express is much more personable, at least for high value accounts, and still allows you to insert travel advisories which have date ranges.
Re: An unprecedented wave of online bank fraud is hitting Britain
#183In a twist of irony, my 76 year old mother took in a immigrant who attended her church and was in a difficult situation. He'd come to the US on a lottery visa, was working and going to college while renting a room from her. After some years, it was time for his family to join him in the US. He flew to his home country of Cameroon to retrieve them, but the bribes he had to pay to get them out exceeded his cash on hand…
What happened later? Did they manage to get out?
Mom passed last year, and the heartfelt words from the entire family were the greatest tribute we could have asked for.
Re: An unprecedented wave of online bank fraud is hitting Britain
#184Ooh we're still the capital of something. Personally I think this comes down to ineffective education in many cases. Yes, some of these scams are getting quite impressively advanced, and they tend to target older people who are declining in cognitive ability, but so often the victims are absolutely unwilling to admit they were a bit stupid. It's always someone else's fault, like the bank, or the police, or Facebook,…
In my case, the attacker had control of my solicitor's email.
A few days before he sent me a letter instructing me to deposit money to the correct account, the attacker sent an email from the solicitors email server (Dkim verified by Gmail), with a different account.
This was in the context of a thread about the conveyancing on a house purchase so I was expecting to have to transfer money somewhere.
I admit my own failure in the process but I think there's room for improvement in the whole process of buying a house too (like why don't solicitors get buyers to enter the correct account info proactively at the beginning of the process)
Re: An unprecedented wave of online bank fraud is hitting Britain
#185Earlier quoted context omitted.
US credit card companies aren't any better. I recently had a similar "fraud alert." The company ditched travel notices in 2016 claiming their AI was good enough to replace it. A few weeks after traveling I had a very small purchase flagged (under $20 at a place like Target). When I called the number they asked me for my complete credit card number, social security number, they didn't know my phone number or email and…
Not all US credit card companies are like this. I specifically remember a few years ago that my Mom got a call from AMEX about some fraud on her card, to which she responded “I never get calls from you, how do I know this is real?”. They said no problem, just hang up and call the number on the back of your card. I believe some banks even skip the call entirely, and just prompt you to call the number on the card.
With Citi: * it's non-native-English support. No judgement of course but I don't appreciate the language barrier when the entire job of customer support is communication. * Support generally seems to be very low-context and low-power. The person you talk to generally can't actually do anything, only escalate. * Support seems very disjointed and prone to missing details.
I was burned by Citi support in a pretty big way:
1. I was moving cross-state, and we were selling (under contract) our old house and not yet closed on the new one. In between, we were living with my parents.
2. Literally the first day we were at my parents, some fraudy charges showed up on my citi card. I called, they cancelled the card, etc. I told them I was not currently at my address on file, I was at my parents, is this OK, etc. They said yes, that's fine, they'll send replacement cards to the new address. I very specifically verified with them that they were sending them to the right place, and the person even got a little tired of me being so tight about it. Ok, I figured, I feel like I've gone above and beyond on my end to make sure this works right.
3. 2 days later, I see on my security camera that the old cards have been delivered to the front door of the old house, 300 miles away.
4. I call back, and they tell me they don't see any record of me having requested a different address. Sigh. I ask if they can cancel those cards and re-send them to the right address this time. They say yes, we go through the loop again, etc.
5. I wait a day or two and no cards show up at either location. I call back again. I get told there's no record I asked to cancel these cards or re-send them. This rep finally tells me they can't re-issue the cards again so soon, and need to wait 5 more days. In the meantime, these active cards are just sitting on my porch in a big envelope that says "CITI - URGENT - PLEASE STEAL ME" written all over it.
And, you know, I really needed to use this card since I was trying to buy appliances for the new house.
I ended up resolving this by just making an extra trip back to the old house anyway just to finish cleaning it up and to grab the cards since I needed to go one more time anyway. I called back to make sure they weren't going to cancel these cards, and of course there was no record I'd ever asked to cancel them, etc.
Compare this to AMEX support. Native english speakers, they seem to have the power to actually just fix things for me, etc.
So, while I still use my citi card just to keep the credit line open, my Amex card is my pinch hitter and cornerstone.
Re: An unprecedented wave of online bank fraud is hitting Britain
#186Earlier quoted context omitted.
In the US the criminals forge the ANI so it looks like a legit number, e.g a local business. We just never answer the phone. Real people can leave voice-mail.
I'm familiar with this custom. Unfortunately, I've adopted the habit of not leaving voicemail (if I'm determined, I talk gibberish until the callee picks up). And I haven't listened to recorded VMs for years. Way back when, I actually bought a machine for answering phone-calls. I have no idea what I was thinking :-)
Re: An unprecedented wave of online bank fraud is hitting Britain
#187I had a long argument with HSBC UK Security a few years ago where I was completely unable to get the to understand they were putting their customers at risk. In the event that something looked strange on your account the 'HSBC Fraud Department' would text you and ask them to call you on a phone number. A phone number that didn't appear anywhere on their website. "We don't want it public. OK,well at least put it on a…
I can't verify that the text is from Natwest, but it seems relatively safe, as I'm not providing any personal information in return, so this seems a reasonable first line security mechanism. Of course someone could clone my SIM, in which case there's no protection, but it does raise the bar for using a stolen cards, and I think that's the intent.
If my bank ever does call me, they have to leave voicemail because I don't answer calls from unknown numbers. And then I call back using the number on the back of the card.
Re: An unprecedented wave of online bank fraud is hitting Britain
#188Earlier quoted context omitted.
From TFA: > While security experts and senior bankers said many fraud attacks could be traced overseas - including from India and West Africa - Britain is also increasingly exporting attacks. > ... > "It's popular to say the fraud threat is imported into the UK, and I don't think that bears analysis," said NECC's Reed. "There is a significant UK nexus to a lot of fraud, our operational experience is showing that."
From personal experience working on this problem I would strongly agree with idea that a lot of bank fraud is home grown. The police in the UK have a very poor track record of actually dealing with bank fraud. The nature of the crime, and way UK policing works, means there's a significant number of disincentives to actually investigating bank fraud. Two of the biggest showstoppers is location/jurisdiction and trainin…
There was a period when almost every day I had Royal Mail drop through my letterbox envelopes containing various fake documents (passports, driving licences, National Insurance letters, ID cards from various EU counties). Someone was mailing those from a nearby post office and putting my address on the back of the envelopes as the sender. A fraction could not be delivered and got returned to the "sender", some having travelled to, and returned from, other countries.
I reported this several times, both to Action Fraud and to the police. At some point I spent an entire Friday evening sitting at a local police station, thinking that, if I brought the documents to them in person, the police would be less inclined to think I was some crackpot making the whole thing up. I also thought that the fact the documents were being mailed from a post office across the road from the police station might pique their interest (the letters had tracking numbers and so I could look up their journeys on the Royal Mail web site).
In the end this turned out to be a waste of time. The front-office police person were clearly pretty unhappy with having to deal with this, but escalated to someone who "knew more about these things". The latter applied the investigative method of typing "Portuguese driving licence" into Google Image Search and comparing the results with one of the licences I gave them. After a further escalation to an even more specialised officer, the conclusion was that the documents were indeed fake.
I got a crime reference number and a clear indication that I would never hear from them again, which I indeed haven't.
Still have all the docs (the police didn't want to keep them). They stopped coming after a while.
Re: An unprecedented wave of online bank fraud is hitting Britain
#189Earlier quoted context omitted.
> I would expect the same social-engineering to be able to convince the user to not raise the alarm during the 2 week cooldown period. It would be interesting to test this. Having read through a number of APP fraud cases, including victim statements. One persistent theme is that the pressure cooker environment that scammers create to get victims to send money is very effective as getting them to ignore warning signs.…
Haha I wonder if you've read my case. I was scammed out of 100k this year. The scammer had control of my solicitor's email and timed the attack perfectly so I was absolutely convinced I was sending money to the right place. Didn't realize until a few days later when the solicitor called me wondering where the money was. The two week thing might have helped us but the scammer would probably just time their attack diff…
A basic house deposit payment redirection scam should be covered, assuming you have evidence that the emails were sent from your solicitors email address.
Re: An unprecedented wave of online bank fraud is hitting Britain
#190I had a long argument with HSBC UK Security a few years ago where I was completely unable to get the to understand they were putting their customers at risk. In the event that something looked strange on your account the 'HSBC Fraud Department' would text you and ask them to call you on a phone number. A phone number that didn't appear anywhere on their website. "We don't want it public. OK,well at least put it on a…
US credit card companies aren't any better. I recently had a similar "fraud alert." The company ditched travel notices in 2016 claiming their AI was good enough to replace it. A few weeks after traveling I had a very small purchase flagged (under $20 at a place like Target). When I called the number they asked me for my complete credit card number, social security number, they didn't know my phone number or email and…
You pretty much have to these days, preferably with the second one being from a different bank and potentially different payment processor. Between random fraud triggers and cards being frozen because of fraudulent charges or attempts, you really need a backup.
I've never had trouble dealing with the problem by phone but I'm still out the credit card in a foreign city for a few days and I may not even be at a location where I can easily have something sent to me.