OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
> It is better if [...anyone...] include a security warning / specific reason the code is sent with the password reset pins and similar credentials. I think anyone building such systems (either via e-mail or SMS or whatever) should at least remember THIS. Send something like this via SMS: > The password reset code you requested via our website is 12345. We will never ask you for this code except when you requested a…
I was just subjected to the most credible phishing attempt I’ve experienced
141–150 of 360 posts
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#142This is very scary for the average person. I've taken to simply not answering any questions (not even to confirm my name) if someone calls me. If my bank calls me then I call them back on a number that's on their web site.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#143In EU, there is the (recent) implementation of a (new) directive, PSD2: https://en.wikipedia.org/wiki/Payment_Services_Directive#Rev... That carries with it the requirement of SCA: https://en.wikipedia.org/wiki/Strong_customer_authentication In practice (here in Italy) you have a client number (secret) a password/PIN (also secret) AND either a SMS to your mobile with a one time code or a Smartphone app (yikes!), ther…
Also, when you're wiring money to someone, my bank is now requesting to input certain digits of the amount and destination account into the app. Those digits are then factored into the 2FA algorithm. I am not sure if this adds substantially to the security though.
If you only need "a code" whether it's to send $40 to a close friend or your entire account balance to an account you've never heard of that was created yesterday in a foreign country - then the scammers only have to trick you into trying to do the former, even though what they want to achieve is the latter, so that you'll give them a code which is what they need.
The bank can do a good or bad job of communicating what's going on and actually preventing the fraud, depending on whether the understanding of what they're trying to achieve was pushed down all the way from regulators to the engineers building the system.
The best systems here don't give you (and thus the attackers manipulating you) a lot of opportunity to manipulate things, but they do present you with information that should be raising red flags if you're being tricked. For example if the app says "Enter the six digits shown on the web page" and you just mindlessly copy those digits, an ordinary customer may not know why it's those six digits, bad guys with a fake web page can tell them to put whatever they want. Whereas if the _app_ says "Enter the whole dollar amount to send" then bad guys may struggle to explain why they want you to type 5839, your entire account balance, when you wanted to send $40 to the supposed friend in need and your suspicions might be raised enough for the scam to fail.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#144Me: Here is what happened to me, I'd like to file a police report.
Police: Well, with these internet scams, the fraudster is usually in another country, meaning we can't really do anything about it.
Me: They used perfect German, used information that I only ever provided into a non-public database of a German-based business that must have had a breach of some sort. The fraudster also used pictures of apartments in Germany that must have been taken here.
Police: Well, still. The person actually doing all of that could have been doing all of that from another country. Usually Russia or China or something.
Me [thinking to myself]: Yeah, Russia, or China, or some country where law enforcement generally presumes, even against all evidence, that any and all cybercrime is happening outside their jurisdiction and therefore not doing any law enforcement at all when it comes to cybercrime. Like what is happening right here right now.
Me: Well, I realize that nobody is going to start an investigation into this specific thing that happened here, but still: Isn't anyone at least compiling a database so that, once patterns become bigger and more apparent, an investigation of sorts may become warranted, etc?
Police: Nope. Nobody doing that. You can file a report. But I can tell you right now that nobody is going to look at it or do anything with it. Also, we kind of have more important things to do, here at the station. I mean: It's your choice. I can't stop you. Just telling you how it is.
Me: Okay, thank you, goodbye.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#145OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
Or do you suspect that there's been an other, undisclosed breach that the scammer used to get your name and phone number? I suppose it's plausible but it seems like it wouldn't be too difficult to get that info.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#146It's even worse in Russia - fake caller ID makes you think you are talking with the bank, mobile phone operators don't seem to be doing much, or at least didn't a couple of months ago. That said, all the banks I used send you along with the confirmation code a description of what you are actually confirming.
>> mobile phone operators don't seem to be doing much It is in the protocol. Operators are not the only problem here. https://en.wikipedia.org/wiki/Caller_ID_spoofing
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#147My simple policy is I never give out any information if I'm cold-called. If they claim they're my bank, I say I'll call them back on the number printed on the card, and ask the caller which department I should be put through to. Legitimate callers have never objected to this approach, and it saves me any stress - same policy, no matter the caller, no exceptions, no need for me to try and figure out if I'm being phish…
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#148Earlier quoted context omitted.
> My simple policy is I never give out any information if I'm cold-called. That's what I do. When someone calls me and then proceeds to ask me security question to allegedly assert my identity I reply "well, you called me so how do you prove to me who you are first?" I usually get a "err..." but on one occasion the guy was rather rude and hanged up. The worst thing is that most of the time these calls are genuine. Th…
My bank did this once - called me out of the blue and started asking for answers to security questions. I asked them how I could be sure it was definitely them and they said to call the number on my card and ask for a particular department, which I did, and it turned out it was indeed genuine. The fact that they had an immediate answer to the question obviously means that they were asked this question all the time. I…
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#149OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…
And explain to them that we, as a society, need to come up a way of authenticating inbound and outbound calls to ensure we are connect with who the other party claims to be because when you do this it conditions society in to responding and that’s how phishing attacks occur.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#150Earlier quoted context omitted.
IMHO this should be the law for financial and medical institutions tc. They should not be allowed to call and ask the receiver to provide verification information.
It doesn't need to be the law: I never provide any information to someone who calls me, unless I have a way of authenticating them.