Live data from Hacker News

An unprecedented wave of online bank fraud is hitting Britain

reuters.com

151–160 of 224 posts

Re: An unprecedented wave of online bank fraud is hitting Britain

#151

In a twist of irony, my 76 year old mother took in a immigrant who attended her church and was in a difficult situation. He'd come to the US on a lottery visa, was working and going to college while renting a room from her. After some years, it was time for his family to join him in the US. He flew to his home country of Cameroon to retrieve them, but the bribes he had to pay to get them out exceeded his cash on hand…

What happened later? Did they manage to get out?

Re: An unprecedented wave of online bank fraud is hitting Britain

#152
post #117
post #64

Earlier quoted context omitted.

US credit card companies aren't any better. I recently had a similar "fraud alert." The company ditched travel notices in 2016 claiming their AI was good enough to replace it. A few weeks after traveling I had a very small purchase flagged (under $20 at a place like Target). When I called the number they asked me for my complete credit card number, social security number, they didn't know my phone number or email and…

Not all US credit card companies are like this. I specifically remember a few years ago that my Mom got a call from AMEX about some fraud on her card, to which she responded “I never get calls from you, how do I know this is real?”. They said no problem, just hang up and call the number on the back of your card. I believe some banks even skip the call entirely, and just prompt you to call the number on the card.

My US cards send me texts and I reply Y.

Re: An unprecedented wave of online bank fraud is hitting Britain

#153

What's always missing from stories like this is how the crooks get the money out. Considering that all Western governments have achieved total surveillance on our banking and made it impossible to have anonymous bank accounts, I'd like to see a detailed analysis about why they can't follow the money and see who gets it. Every scenario I can think of seems like it should be either traceable or actionable. Scenario 1:…

It's well documented that a lot of this money goes out of the country by transferring it to a 'mule' with a bank account in the UK, who think they are doing something innocuous. They transfer it to the scammers either via cryptocurrency (basically untraceable) or previously, via an international money transfer service such as Western Union. The latter is also pretty much untraceable. You can pick up money anywhere in the world from these services with some ID. They don't need your address or to really check you are who you say you are, they just want to make sure you have the same name as the one the sender referenced.

Unless the destination country, the destination Western Union office and the person who picked up the money are all willing and able to co-operate, law enforcement in the source country is pretty much stuck.

Re: An unprecedented wave of online bank fraud is hitting Britain

#155
post #117
post #64

Earlier quoted context omitted.

US credit card companies aren't any better. I recently had a similar "fraud alert." The company ditched travel notices in 2016 claiming their AI was good enough to replace it. A few weeks after traveling I had a very small purchase flagged (under $20 at a place like Target). When I called the number they asked me for my complete credit card number, social security number, they didn't know my phone number or email and…

Not all US credit card companies are like this. I specifically remember a few years ago that my Mom got a call from AMEX about some fraud on her card, to which she responded “I never get calls from you, how do I know this is real?”. They said no problem, just hang up and call the number on the back of your card. I believe some banks even skip the call entirely, and just prompt you to call the number on the card.

THat's my experience; they specifically ask you to call the number on the back of your physical card.

Re: An unprecedented wave of online bank fraud is hitting Britain

#156

Earlier quoted context omitted.

On traditional landline phones that older folk tend to use (although I guess that's dwindling every year) a common tactic for scammers is to ask the victim to call the number on the back of the card. However the scammers don't hang up they just play a fake dial tone so the victim dials the number thinking they're contacting their bank but they're actually just speaking to the scammers again

How did that work? In the Netherlands, in the 80s-00s at least, hanging up cleared your line, so picking it up again would get you a fresh dialtone even if the other side didn't hang up (and the other side would get a modified "busy" signal if you hung up on them).

this was (is?) a "feature" that let you answer a call in say the front hall, then hang-up and continue the call in your office as long as the originating caller did not hang up the handset. The scam relies on actually playing a dial-tone and ringing after the victim "hangs up", which is how some people noticed it "sounded weird" and then called their bank on another line or cell phone.

Re: An unprecedented wave of online bank fraud is hitting Britain

#157

What's always missing from stories like this is how the crooks get the money out. Considering that all Western governments have achieved total surveillance on our banking and made it impossible to have anonymous bank accounts, I'd like to see a detailed analysis about why they can't follow the money and see who gets it. Every scenario I can think of seems like it should be either traceable or actionable. Scenario 1:…

[deleted]

Re: An unprecedented wave of online bank fraud is hitting Britain

#158

Earlier quoted context omitted.

I had a similar experience from HSBC. They called me about a potential fraudulent claim. They asked for my DOB, card number, sort code, you know, to verify "that I am who I say"... all the stuff they SHOULDN'T ask, and stupidly I gave it all up. To be fair, I did because my card had been rejected literally 30 seconds before while trying to make a purchase. But it was only after the phone call ended that I realised wh…

In fairness HSBC calls from known numbers (granted, you may not recognise it the first time, but you can look it up then save it) and publishes numbers where you can call them [1] [1] https://www.hsbc.co.uk/help/security-centre/report-a-problem...

If I don't care that you can redial the displayed number and get me this doesn't matter when I spoof my outgoing number though...

Re: An unprecedented wave of online bank fraud is hitting Britain

#159
post #143

Earlier quoted context omitted.

In fairness HSBC calls from known numbers (granted, you may not recognise it the first time, but you can look it up then save it) and publishes numbers where you can call them [1] [1] https://www.hsbc.co.uk/help/security-centre/report-a-problem...

This doesn't help when it's so common to spoof caller-id. The telco industry has blown any trust we can put in this information. [I just learned that the FCC is considering not allowing calls made outside the US to be spoofed as numbers originating inside the US. I thought that was the whole point behind STIR/SHAKEN, silly me].

It does help because you can call back if you recognise the number (which defeats spoofed caller ID) or call the number published.

There's not really any alternative to calling a trusted number.

Re: An unprecedented wave of online bank fraud is hitting Britain

#160

I had a long argument with HSBC UK Security a few years ago where I was completely unable to get the to understand they were putting their customers at risk. In the event that something looked strange on your account the 'HSBC Fraud Department' would text you and ask them to call you on a phone number. A phone number that didn't appear anywhere on their website. "We don't want it public. OK,well at least put it on a…

I had a similar experience from HSBC. They called me about a potential fraudulent claim. They asked for my DOB, card number, sort code, you know, to verify "that I am who I say"... all the stuff they SHOULDN'T ask, and stupidly I gave it all up. To be fair, I did because my card had been rejected literally 30 seconds before while trying to make a purchase. But it was only after the phone call ended that I realised wh…

I hope your admonitions to the call center drone who picked up your call were emotionally satisfying to you, because that's as far as they went. If you want to influence company policy on something like that your best bet is a highly visible social media conversation. The poor call center drone who was the subject of your wrath literally just sighed and stared at the wall for a second after your call then opened up the line to the next person who was going to yell at them.
Post reply on HN