This speaks more to the incompetence of supposed experts and less to the sophistication of scams.
Agreed. I wish someone would try this level of attack against me - I'm 99% sure I wouldn't have fallen for this particular one, but how can I truly know without going through it? Anyways, I am extremely aware of caller ID spoofing. I use it myself to show a usable callback number on a VoIP outgoing-only line. And the 2FA - I would be incredibly reluctant to give a code over the phone, even if I had initiated the call…
I got the same text about "confirming fraud transactions" and then a phone call from "my bank". I nodded along at his script for a few seconds, before I remembered the constant, unending advice of: "if your bank calls you, hang up and call back on the fraud number listed on your card". I told the person I'd do exactly that, and hung up.
I then checked my card account and confirmed that there actually weren't any fraudulent transactions, so didn't bother calling.
That said, I can absolutely see a world in which a tired or otherwise frustrated me would just follow along the script, and with a similar background to the author (I'm not a security professional, but I work in fintech and on security-adjacent things):
> I also find it entirely plausible that Apple (or Google) would require a bank to jump through these kinds of hoops in order to remove a fraudulently-added payment method from someone's account, and that Wells Fargo's system would be so janky and sloppily-built that this is the least awful way they could figure out how to do it.
This honestly resonates with me as a plausible thought path. I'm pretty confident that I wouldn't have actually provided the two-factor code, but again, everyone has off days, and everyone makes mistakes. That's the core of all of this, that endless refrain: defense has to work 100% of the time, offense only needs to work once.