Live data from Hacker News

Scammers are abusing an internal Microsoft account to send spam links

techcrunch.com

141–150 of 196 posts

Re: Scammers are abusing an internal Microsoft account to send spam links

#142

Earlier quoted context omitted.

> They are not scam calls What are they, then? Sales/marketing calls? Or some security notifications ("we noticed some suspicious operations in the last 3 days...")? If it's the former, that's still scam in my books. Specifically, it's a first-party scam , as opposed to a third-party scam , where some third party pretends to be your bank. They both should be treated similarly; unfortunately, you can't report first-pa…

In my experience they're security calls. UK has good opt out marketing rules for legit companies. But the usual security call is exactly like a spam call, no authentication from their end, immediately requesting id verification "answer these security questions", and refusing to go off script. People have been asking for years to be able to lodge a security challenge code on their profile that can add confidence in th…

No "challenge code" your profile can be used to authenticate a caller. Profiles get leaked, almost all of them have been at some point, or at least that's the safe assumption to operate under.

Re: Scammers are abusing an internal Microsoft account to send spam links

#143
post #31

Earlier quoted context omitted.

That's the number one rule though. If someone calls you claiming to be your bank, just say "I'll call you back"

Nowadays, when banks call you here, they allow you to verify the bank is actually calling you with the mobile app - you can see their name and number they're calling you from in the app. Also, you can often verify you're you with the app too, same as any other app authorization, so you don't have to share any details over the phone. I feel like this is a pretty good improvement.

That does seem better than blind trust but that app infrastructure could get compromised. I would still be wary in any situation where I did not originate the call with the bank.

Re: Scammers are abusing an internal Microsoft account to send spam links

#144

Earlier quoted context omitted.

Yeah as sibling points out, lots of orgs have scammy official security calls. This leads to a dance I have been through quite often. Hello Them: Am I speaking to Sean Hunter Me: Yes Them: This is . Can you confirm your Me: Yes Them: Err, … sorry I didn’t quite catch that. Me: Yes. Them: I asked whether you can confirm your Me: Yes. I can. Them: err… I can’t talk to you without you passing security. Me: You called me.…

That’s wild. If my bank needs something from me they send an email saying that a message is available in the online portal - or in some cases they send me a physical letter. Anything else would be highly suspicious

Yeah my actually good bank (Starling) have an FAQ in their app saying “We will never call you”.

Re: Scammers are abusing an internal Microsoft account to send spam links

#145

Earlier quoted context omitted.

It's amazing how little information has survived: the only reference I can find right away is https://www.experts-exchange.com/questions/22812691/What-is-... I was working in anti-spam at the time, so I was eyeballing a lot of raw email dumps and writing analysis scripts for "anomalous" urls, so it popped up fairly frequently.

The primary problem is we can't search through time via WayBack Machine where a lot of these things have gone. Took me a while the other day to surface the Choco-Banana Shake Hang which Microsoft deleted from their production site. https://web.archive.org/web/20000608173453/http://support.mi...

There are a few archives of Microsoft KB articles. I found this article in Beta Archive wiki's, which has a full-text search. https://www.betaarchive.com/wiki/index.php?title=Microsoft_K...

Re: Scammers are abusing an internal Microsoft account to send spam links

#146

Earlier quoted context omitted.

Hard to beat Outlook 2007 which had some "smart tags" feature that all referenced "5iantlavalamp.com", and things started breaking when that domain expired.

This story is ludicrous… yet, it seems to check out. https://spamassassin.apache.org/full/3.0.x/dist/rules/25_uri... says this is one of the "Top 125 domains whitelisted by SURBL", and there's an answer on the hyphen site about it: https://www.experts-exchange.com/questions/22812691/What-is-... . Can someone with a Bottom-Surgery account tell us the details?

The Master-Gender-Switch answer doesn't actually answer, it's just an external link that is now broken.

This is the archived version of that link: https://web.archive.org/web/20110204205739/http://www.people...

Re: Scammers are abusing an internal Microsoft account to send spam links

#147
post #75

Earlier quoted context omitted.

In the US Caller ID has been so hopelessly compromised (for almost two decades now, that's on Congress) that financial institutions almost never make outbound calls, and only ever use standardized published numbers; I wasn't aware other countries differ so much. Please tell us more context with regard to your UK banks making multiple unannounced calls demanding your ID ... were you an individual customer? finance dir…

My bank(s) have never called me and if they did I wouldn’t pick up - it’s definitely not a standard in the EU.

My bank (big green French one) pretty much always calls me whenever I do some unusual money transfer, even between my company and my personal accounts (they're both with the same bank), even though the transfers are authenticated either via the app or by an SMS code. However, the people calling me don't ask any details, just "is this vladvasiliu? Is it actually you who initiated this transfer, for x amount on y date?".

Re: Scammers are abusing an internal Microsoft account to send spam links

#148
post #82
post #57

Earlier quoted context omitted.

I have not seen one of these that wasn't a compromised hotel email or booking account. I have had to "help" a hotel get malware/RATs off their system more than a dozen times as a _guest_

I've started to assume that any non-chain hotel is compromised after losing $2k to hackers that completely owned the hotel's email system. Thankfully DMARC made it irrefutable that it was their system at fault and they assumed liability. BEC is shockingly common and difficult to detect until it's too late.

Not just BEC, at multiple non-chains I have found keyloggers, card stealers and everything in between. I refuse to use anything but apple pay on an actual payment terminal (or a 3P booker that passes on a virtual card) and no ID scans or copies.

Re: Scammers are abusing an internal Microsoft account to send spam links

#149
post #104

Earlier quoted context omitted.

Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.

In France, basically every bank say (show in their app and everything) "if we call you and ask anything like code, confirmation, to do an action, anything, end the call and call us back, don't do anything on a call you didn't initiate". Same in their app eg you try to do a sepa wire to a new recipient and you get a warning "are you on the phone with someone ? did someone ask you to do that ? please call your bank by…

And then we have the national post office sending its notifications from the scammiest-looking domain they could find: noreply@notif-colissimo-laposte.info

Re: Scammers are abusing an internal Microsoft account to send spam links

#150

Earlier quoted context omitted.

Yeah as sibling points out, lots of orgs have scammy official security calls. This leads to a dance I have been through quite often. Hello Them: Am I speaking to Sean Hunter Me: Yes Them: This is . Can you confirm your Me: Yes Them: Err, … sorry I didn’t quite catch that. Me: Yes. Them: I asked whether you can confirm your Me: Yes. I can. Them: err… I can’t talk to you without you passing security. Me: You called me.…

One of my banks refused to talk to me over the phone and informed me to go to a branch with 2 pieces of ID. Fair, it was a credit card opened online. Only to find the 2 pieces of ID were just for them to talk to me and ask for more documents. Rubbish like employment letters (uhhhh, how about YOU call my employer instead of me printing out the “letter” they’ll email me?) or tax return stuff mid-year. I cut up the cred…

> how about YOU call my employer

And how would your employer know the call is legitimate and authorised by you?

Post reply on HN