Live data from Hacker News

Scammers are abusing an internal Microsoft account to send spam links

techcrunch.com

61–70 of 196 posts

Re: Scammers are abusing an internal Microsoft account to send spam links

#61
post #39
post #35

Earlier quoted context omitted.

Ask them their name/ last initial, employee ID or unique identifier for the conversation, direct phone number, job title and what location they're based at. Scammers will pretty much always refuse/argue/hang up on this (once I had one start insulting my mother in Hindi when I asked him this). Then call your bank's proper number and verify all of these details. (But in any case your bank will never call outwards to yo…

Unfortunately my UK banks (and others) DO regularly make calls to me unannounced and demand my ID to 'prove who I am'. They are not scam calls and the callers cannot understand what they are doing wrong. If I'd had more strength in the last round of this stupidity I'd have done a number on them with the regulator. (I used to work in finance and was the director of a regulated financial entity, so I think I'd have a h…

> They are not scam calls

What are they, then? Sales/marketing calls? Or some security notifications ("we noticed some suspicious operations in the last 3 days...")? If it's the former, that's still scam in my books. Specifically, it's a first-party scam, as opposed to a third-party scam, where some third party pretends to be your bank.

They both should be treated similarly; unfortunately, you can't report first-party scams to police.

Re: Scammers are abusing an internal Microsoft account to send spam links

#62
post #52

Earlier quoted context omitted.

What definition of the word scam are you using here? What promise of a product that you pay for that isn't being delivered, with uploading your id to a site on the Internet?

I'm not gonna get hoodwinked into highbrow shenanigans. Social media doesn't need IDs to work, demanding it is a scam.

Rhetoric won't save you from the embarrassing situation you created for yourself. You accused something of being a scam without understanding the definition of the word. Now that your claim has been challenged, you're trying to redefine terms and argue around the issue rather than admit you were wrong.

Re: Scammers are abusing an internal Microsoft account to send spam links

#63
post #55

On a semi-related note, Microsoft security is genuinely terrible. For the past week, my Microsoft authenticator has been pinging about sign-ins from random places. Except the login history page is completely empty. Not even my own sign ins show up. Now, you would be forgiven for thinking it's because my password leaked, but no. The default sign in flow with the app enabled is email + authenticator. No password requir…

> The default sign in flow with the app enabled is email + authenticator. No password required

Isn't this only if browser have some cookie from previous session or IP didn't change?

Edit: just tried (new IP + private window firefox), you are right, I can enter email and select app notification.

Re: Scammers are abusing an internal Microsoft account to send spam links

#64
post #59

Earlier quoted context omitted.

Several of the bank scammers had their profile verified as the bank in the Truecaller[1]. [1] https://xcancel.com/Abishek_Muthian/status/18063480222902113...

Truecaller can tell you about who a phone number belongs to. Truecaller cannot accurately tell you whether or not the person calling you from a phone number is actually in control of that phone number.

Won't stop people from trying to make Truecaller, et al. prove that, though.

The problem here is that the correct security posture of the bank against third-party scams also protects the customers from first-party scams. Telling people the bank will never call them for anything, and even if, they're to always hang up and call the number on the back of their card, works equally well against criminals and telemarketers.

Re: Scammers are abusing an internal Microsoft account to send spam links

#65
post #55

On a semi-related note, Microsoft security is genuinely terrible. For the past week, my Microsoft authenticator has been pinging about sign-ins from random places. Except the login history page is completely empty. Not even my own sign ins show up. Now, you would be forgiven for thinking it's because my password leaked, but no. The default sign in flow with the app enabled is email + authenticator. No password requir…

It is the same company that want to stop SMS 2fa to force you to use their shitty authenticator app.

Re: Scammers are abusing an internal Microsoft account to send spam links

#66
post #31

Earlier quoted context omitted.

Knowing what numbers are real through an official publication is very good, but it only allows you to place trust in calls you make, not calls you receive, because making calls doesn't involve caller ID, receiving calls does, and caller ID is spoofable.

That's the number one rule though. If someone calls you claiming to be your bank, just say "I'll call you back"

Nowadays, when banks call you here, they allow you to verify the bank is actually calling you with the mobile app - you can see their name and number they're calling you from in the app. Also, you can often verify you're you with the app too, same as any other app authorization, so you don't have to share any details over the phone. I feel like this is a pretty good improvement.

Re: Scammers are abusing an internal Microsoft account to send spam links

#67
post #55

On a semi-related note, Microsoft security is genuinely terrible. For the past week, my Microsoft authenticator has been pinging about sign-ins from random places. Except the login history page is completely empty. Not even my own sign ins show up. Now, you would be forgiven for thinking it's because my password leaked, but no. The default sign in flow with the app enabled is email + authenticator. No password requir…

It is the same company that want to stop SMS 2fa to force you to use their shitty authenticator app.

SMS 2FA is the worst factor because of how insecure and phishable the phone network is, it deserves to die out where possible

Re: Scammers are abusing an internal Microsoft account to send spam links

#68
post #55

On a semi-related note, Microsoft security is genuinely terrible. For the past week, my Microsoft authenticator has been pinging about sign-ins from random places. Except the login history page is completely empty. Not even my own sign ins show up. Now, you would be forgiven for thinking it's because my password leaked, but no. The default sign in flow with the app enabled is email + authenticator. No password requir…

Microsoft also has this cool thing where if someone fails to get into your account too many times, your account can get locked and you are asked to reset your password. For a working password.

Even after changing my password, I couldn't login to my email on my phone, so I just gave up. I only use that email for a handful of things anyway.

Re: Scammers are abusing an internal Microsoft account to send spam links

#69
post #59

Earlier quoted context omitted.

Truecaller can tell you about who a phone number belongs to. Truecaller cannot accurately tell you whether or not the person calling you from a phone number is actually in control of that phone number.

Won't stop people from trying to make Truecaller, et al. prove that, though. The problem here is that the correct security posture of the bank against third-party scams also protects the customers from first-party scams . Telling people the bank will never call them for anything, and even if, they're to always hang up and call the number on the back of their card, works equally well against criminals and telemarketer…

I feel like this is kind-of a solved problem in the jurisdictions where banks are liable for customer losses not arising from gross negligence.

If a bank calls their customers directly and trains them to get phished, the bank does not get to claim gross negligence when this happens and has to refund the customer.

If a bank tells their customers that they'll never call them (and actually doesn't), they have much better chances of claiming gross negligence on the part of the customer.

Post reply on HN