Live data from Hacker News

I'm a scam prevention expert and I got scammed

lupinia.net

321–330 of 562 posts

Re: I'm a scam prevention expert and I got scammed

#321

There was one time I thought I was being scammed, but it turns out there was an actual issue with my bank account. Sitting at my desk at work, I get a phone call from my bank on by cell phone. "Mr. Anechoic, there appears to be a security issue with your bank account. We can resolve it for you. For security purposes, can you give your checking account number and the last four of you SSN"? This is clearly a scam, righ…

Not the same thing, but relatedly, every legit email I receive from my health insurance is functionally indistinguishable from phishing. They always bounce me through a million weird domains too. It's very discomfiting and makes me worry that I won't be able to pinpoint a legit phishing attempt because it won't stand out.

In the same vein, every corporate "security training" email I've received that's been outsourced to a third party vendor looks indistinguishable from spam and phishing, the exact things it goes on to train you not to open. I scare-quote that because they're universally worthless training programs used to tick boxes on compliance forms and not actual training, so I happily flag them as spam.

I've also recieved company-wide corporate gifts (like $5 digital gift cards) distributed through extremely spammy looking vendors with dubious looking links.

The same goes for the overwhelming majority of vendors, recruiters, and outsourcing companies that are cold-emailing me, it all looks like 50 shades of scam.

Re: I'm a scam prevention expert and I got scammed

#322
post #68
post #42

Earlier quoted context omitted.

Calling on the official number is a good rule. But my neighbour followed that and was still scammed for tens of thousands. The critical extra step that they missed was to check that the line was disconnected before calling out. They were using a landline. The scammers called them, but didn't hang up. Then, when my neighbour called out to their bank, they pretended to be answering that call - going through security, e…

For the people who are confused: this is a fairly common thing on landlines in some countries, where the telephone exchange doesn't drop the connection until both ends have hung up, or in some cases when the caller hangs up but not the callee. So it's possible to put your own phone down, but when you pick it up again your phone is still connected to the scammer's telephone. If they play a convincing dial tone, then c…

Just FYI, this does not and never applied to mobile phones or any kind of entirely digital (SIP, etc) phone system.

Modern "landlines" when used with DSL or fibre are also no longer "true" landlines, instead the modem/router acts as a SIP client and gives you an FXS port to plug an analog phone into. While it could theoretically emulate this behavior (by keeping the SIP session open for a few more seconds), I don't believe any of them do - in any case it's trivial to test by calling a different phone that you control, hanging up on your "landline" and seeing whether the other phone hangs up immediately (it should) or if the line is held open for some more time.

If this is still a thing (I frankly don't see the purpose of it), it would only apply to real landlines where your phone is directly connected to your phone socket without a modem/router in between.

Re: I'm a scam prevention expert and I got scammed

#323
post #211

Earlier quoted context omitted.

This has a similarity to the original story here, in that the original sounded like: "They behaved a lot like a scammer would, but I also totally expect my real bank to behave like a scammer would" .

Many banks today have communications preferences options and I've told all of my banks that do to never call me directly . If I receive any sort of legitimate call from them I immediately follow up with a strongly worded letter that they should not have called me and violated their own security policies. The only thing we can do about "bank behaviors make it easier for scammers" is to change bank behaviors. It's not…

One of the wonders of the world is how much unnecessary data they collect - just because they can demand it - with nary a thought of how much of a liability that is.

Guess it will take a few years of getting slapped for it to filter down.

Re: I'm a scam prevention expert and I got scammed

#324

Earlier quoted context omitted.

> I was blown away that Amazon would transfer me to a scammer. I contacted Amazon again and let them know what had happened. Hopefully they will figure out how their guy got this scammers phone number and teach him how to find a 3rd party phone number... 1) Amazon is complicit in shady behavior on their platform, whether it's inventory commingling, sketchy sellers repurposing existing, well-reviewed listings for a to…

that number 2 is some next generation criminality there!

If you watch Jim Browning or some of the other people that investigate such scams you'll realize that it's not just a couple of idiots in a boiler room; those operations have all the hallmarks of a legitimate company including layers of management, offices, them having meetings to discuss new scam strategies/etc and the scammers being actual "employees" on a standard (low) wage + commission, so I definitely wouldn't be surprised if something like this would happen especially if they've already got a network of local accomplices to launder the stolen money that can easily be repurposed to sell products at cost (in fact that could also be used to launder money, win-win situation right there!).

Re: I'm a scam prevention expert and I got scammed

#325
post #296

Earlier quoted context omitted.

The mechanism is the managers that take over at companies who focus on the short term bottom line (trimming support today, to juice profits tomorrow, to lose credibility years down the road after the bonuses have long landed in their bank account). And the problem is that Amazon's growth profile (retail-side anyway) is going to be pretty constrained going forwards because they own too much of the available pie right…

"short term bottom line" is a comically absurd way to describe Amazon, which has been growing consistently for 25 years.

This comment is peak short-termism! It is comically absurd to refer to 25 years as a long time!

There are companies that have been around for 300 years, in fact prior to rise of venture capital moat companies were multi-generational family business and you would consider how a decision would reflect on your children.

Re: I'm a scam prevention expert and I got scammed

#326
> When discussing scams and social engineering attacks, it's easy for security researchers and experts to present information in a way that implies the victims of these attacks should have known better.

Uhhh, when I see any SE I assume it happened because the user / customer is making use of a giant beuracratic system and nobody knows how it works and what is supposed to be private data and what data needs to be sent where, along with government pointing gun at you to send 5 pieces of ID all over the place ASAP without you ever understanding which ones are needed for what purpose. The very reason these broken, impossible to understand systems exist everywhere is because "the user is too dumb, stop being elitist".

Imagine if you logged into runescape and instead of entering user / pass, it said you need to have your IP address authorized, then you need to get a runescape license, then they need a picture of your iris. But you also sent your iris to some pizza shop to "prove" you own your house, and you have no idea what steps that pizza shop took to secure your iris photo (none). Then to get your IP "authorized", runescape tells you to login to some weird website you've never heard of before, and send it two pieces of photo ID (which you also sent to a paint shop to order paint), and then that website says "please give us your phone number so you can open our secure phone app", and then you open the "secure phone app" and you have no idea what it just did or what data was sent where or what data about you it just assumed you're now supposed to keep secret. I don't know, is this concept like not obvious to internet people? It's called ungroundedness.

The reason I'm writing all this without burning my eyes on this stupid color theme, is because whatever typical bullshit narratives HN will prop up as usual in response to this article here are completely invalid. This classic "boo, hoo, you're an elitist" talking point is irrelevant nonsense because in most cases the user hasn't been tricked; he hasn't been provided with a system that allows him to use it properly. But oh wait I just wrote about this last week as the cliche was made again then. I actually WANT a system that makes "elitists" secure and doesn't care about unqualified people (and I know lots of people who also want this, it's what UN*X users like to think of themselves as): https://news.ycombinator.com/item?id=30780519

Re: I'm a scam prevention expert and I got scammed

#327
post #21

There's one easy rule that could have avoided all of this - never give out any info on incoming calls. If I get a call or text about fraudulent transactions, I'll keep them on hold while I log into the bank website. If I get a call about a late payment, I'll thank them for the info and ask them to stay on while I pay online. If I get an inbound call with a more complex request, I'll ask them for their employee info a…

> In order to do that, I needed to relay a confirmation code that would be texted to me.

Yeah, BZZZT! End of conversation. Hang up.

Re: I'm a scam prevention expert and I got scammed

#328
post #204

I was at my local coffee shop yesterday when the manager was on the phone for 10+ minutes with a scammer. Was a new one to me. The landline caller ID showed "Madison Police Dept" - the local police. The caller introduced themselves as an investigator working a case with counterfeit bills. "Don't contact your boss/owner because we are not sure if they are in on it." The caller knew details like employees names and the…

There was a recent post on HN about big tech companies being scammed by fake subpoena requests from "police".

Re: I'm a scam prevention expert and I got scammed

#329

I wonder who these well-spoken, educated scammers are and how they’re recruited. Pet theory: voice recordings will be the next fingerprints/DNA, at some point it will be trivial to identify the person based on old recordings. At which point we can retroactively convict these people years or decades later, when they thought they were out of the woods.

With costs of living skyrocketing everywhere and wages stagnating if not decreasing (remote work suddenly brings more competition) I wouldn't be surprised if otherwise legitimate people are tempted or even forced to do this out of desperation.

Re: I'm a scam prevention expert and I got scammed

#330

"while I'm no expert, I've never heard of a call center system that can accept touch tones seamlessly while a call is active, and it would take extremely sophisticated audio processing capabilities to be able to do that, since the frequencies used by touch tone keys heavily overlap the frequencies of human speech." "Extremely sophisticated?" The tones are just a sum of two sine waves of known frequencies. That's triv…

I think his point was that it's difficult for a system to conceal the tones from the other party while not interfering with normal speech.
Post reply on HN