Scammers are abusing an internal Microsoft account to send spam links
141–150 of 196 posts
Re: Scammers are abusing an internal Microsoft account to send spam links
#142Earlier quoted context omitted.
> They are not scam calls What are they, then? Sales/marketing calls? Or some security notifications ("we noticed some suspicious operations in the last 3 days...")? If it's the former, that's still scam in my books. Specifically, it's a first-party scam , as opposed to a third-party scam , where some third party pretends to be your bank. They both should be treated similarly; unfortunately, you can't report first-pa…
In my experience they're security calls. UK has good opt out marketing rules for legit companies. But the usual security call is exactly like a spam call, no authentication from their end, immediately requesting id verification "answer these security questions", and refusing to go off script. People have been asking for years to be able to lodge a security challenge code on their profile that can add confidence in th…
Re: Scammers are abusing an internal Microsoft account to send spam links
#143Earlier quoted context omitted.
That's the number one rule though. If someone calls you claiming to be your bank, just say "I'll call you back"
Nowadays, when banks call you here, they allow you to verify the bank is actually calling you with the mobile app - you can see their name and number they're calling you from in the app. Also, you can often verify you're you with the app too, same as any other app authorization, so you don't have to share any details over the phone. I feel like this is a pretty good improvement.
Re: Scammers are abusing an internal Microsoft account to send spam links
#144Earlier quoted context omitted.
Yeah as sibling points out, lots of orgs have scammy official security calls. This leads to a dance I have been through quite often. Hello Them: Am I speaking to Sean Hunter Me: Yes Them: This is . Can you confirm your Me: Yes Them: Err, … sorry I didn’t quite catch that. Me: Yes. Them: I asked whether you can confirm your Me: Yes. I can. Them: err… I can’t talk to you without you passing security. Me: You called me.…
That’s wild. If my bank needs something from me they send an email saying that a message is available in the online portal - or in some cases they send me a physical letter. Anything else would be highly suspicious
Re: Scammers are abusing an internal Microsoft account to send spam links
#145Earlier quoted context omitted.
It's amazing how little information has survived: the only reference I can find right away is https://www.experts-exchange.com/questions/22812691/What-is-... I was working in anti-spam at the time, so I was eyeballing a lot of raw email dumps and writing analysis scripts for "anomalous" urls, so it popped up fairly frequently.
The primary problem is we can't search through time via WayBack Machine where a lot of these things have gone. Took me a while the other day to surface the Choco-Banana Shake Hang which Microsoft deleted from their production site. https://web.archive.org/web/20000608173453/http://support.mi...
Re: Scammers are abusing an internal Microsoft account to send spam links
#146Earlier quoted context omitted.
Hard to beat Outlook 2007 which had some "smart tags" feature that all referenced "5iantlavalamp.com", and things started breaking when that domain expired.
This story is ludicrous… yet, it seems to check out. https://spamassassin.apache.org/full/3.0.x/dist/rules/25_uri... says this is one of the "Top 125 domains whitelisted by SURBL", and there's an answer on the hyphen site about it: https://www.experts-exchange.com/questions/22812691/What-is-... . Can someone with a Bottom-Surgery account tell us the details?
This is the archived version of that link: https://web.archive.org/web/20110204205739/http://www.people...
Re: Scammers are abusing an internal Microsoft account to send spam links
#147Earlier quoted context omitted.
In the US Caller ID has been so hopelessly compromised (for almost two decades now, that's on Congress) that financial institutions almost never make outbound calls, and only ever use standardized published numbers; I wasn't aware other countries differ so much. Please tell us more context with regard to your UK banks making multiple unannounced calls demanding your ID ... were you an individual customer? finance dir…
My bank(s) have never called me and if they did I wouldn’t pick up - it’s definitely not a standard in the EU.
Re: Scammers are abusing an internal Microsoft account to send spam links
#148Earlier quoted context omitted.
I have not seen one of these that wasn't a compromised hotel email or booking account. I have had to "help" a hotel get malware/RATs off their system more than a dozen times as a _guest_
I've started to assume that any non-chain hotel is compromised after losing $2k to hackers that completely owned the hotel's email system. Thankfully DMARC made it irrefutable that it was their system at fault and they assumed liability. BEC is shockingly common and difficult to detect until it's too late.
Re: Scammers are abusing an internal Microsoft account to send spam links
#149Earlier quoted context omitted.
Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.
In France, basically every bank say (show in their app and everything) "if we call you and ask anything like code, confirmation, to do an action, anything, end the call and call us back, don't do anything on a call you didn't initiate". Same in their app eg you try to do a sepa wire to a new recipient and you get a warning "are you on the phone with someone ? did someone ask you to do that ? please call your bank by…
Re: Scammers are abusing an internal Microsoft account to send spam links
#150Earlier quoted context omitted.
Yeah as sibling points out, lots of orgs have scammy official security calls. This leads to a dance I have been through quite often. Hello Them: Am I speaking to Sean Hunter Me: Yes Them: This is . Can you confirm your Me: Yes Them: Err, … sorry I didn’t quite catch that. Me: Yes. Them: I asked whether you can confirm your Me: Yes. I can. Them: err… I can’t talk to you without you passing security. Me: You called me.…
One of my banks refused to talk to me over the phone and informed me to go to a branch with 2 pieces of ID. Fair, it was a credit card opened online. Only to find the 2 pieces of ID were just for them to talk to me and ask for more documents. Rubbish like employment letters (uhhhh, how about YOU call my employer instead of me printing out the “letter” they’ll email me?) or tax return stuff mid-year. I cut up the cred…
And how would your employer know the call is legitimate and authorised by you?