Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

21–30 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#21
post #9

This is very scary for the average person. I've taken to simply not answering any questions (not even to confirm my name) if someone calls me. If my bank calls me then I call them back on a number that's on their web site.

If my bank calls me then I call them back on a number that's on their web site.

I'm always amazed at how stupid the security situation is in these cases. Banks, telecoms services, etc. do actually call up and try to 'take me through security', and when I say "tell me something you know about me first so I know you're who you say you are", the best they can usually manage is "well, uh, you bank with [Bank]". It just perfectly trains us to fall for scams.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#22
OP here. Just a couple of the things I learned since I posted the Twitter thread:

- The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them.

- The caller called me twice in rapid succession (First ignore the call from a number you do not know. Then they call back again immediately: "maybe this is urgent / important"). Another person in the thread, who fell for the scam, noted this same pattern.

- It is better if banks include a security warning / specific reason the code is sent with the password reset pins and similar credentials. My bank did not. Another twitter user noted being subject to the scam, and just glancing over the warning copy. So it helps, but it is not perfect. Especially pre-coffee.

- My bank no longer allows me to reset my password without calling them (thanks bank).

When I read the thread now, it's obviously full of red flags. I was successfully manipulated, and whilst I'm certainly not as clever as all the people pointing out they would have caught this from sentence one, I believe I'm also not the lowest hanging fruit in terms of a target :-) Makes you wonder what this will look like when these scams evolve another couple of generations in terms of complexity ...

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#23
It's even worse in Russia - fake caller ID makes you think you are talking with the bank, mobile phone operators don't seem to be doing much, or at least didn't a couple of months ago.

That said, all the banks I used send you along with the confirmation code a description of what you are actually confirming.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#25

It sounded sketchy from the moment they asked for a pin code that they sent to your phone. It's easier to talk from the outside, but that should always be a red flag. What exactly would they be confirming by sending a PIN to the same number they were already contacting? But that's a great heads up. Phishing is not just about obviously fake e-mails to hotmail accounts.

Many actual banks and brokerages do exactly this

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#26

Saw this on Twitter this morning. Sounds like they must have engineered it and set things up beforehand because they (a) knew which bank he was with and (b) had everything set up ready to log in when they got his ID number and received the password reset code from his text message. I guess one thing that could have mitigated this quicker is if the text from the bank had said "Here is the code you requested to reset y…

Which bank you have is not very secret information. Any payment exposes that information.

It's a very clever scam, but it's also a very insecure bank if this is enough to authorise payment. Get a different bank that uses 2FA, makes it clear what an authorisation code is for, and doesn't call you for this kind of sensitive information.

If they really do need to reach you quickly to stop a fraudulent transaction, a simple "that's not mine" should suffice. They know they're talking to you because they're the ones calling you. If the person making that payment has also stolen your phone (entirely possible) they will not deny they made that transaction, because they want that transaction to stand. That means only confirming it's your transaction in this situation is suspicious, not denying it.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#27

The easiest way to avoid this entire class of attack, is to never be willing to answer any kind of question from someone who calls you. Always hang up, Google the customer support line for the business, then call them .

My bank does that. They call you and say "we need to talk about some fraudulent transactions, can you please ring the helpline and ask to talk to Dave".

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#28
My simple policy is I never give out any information if I'm cold-called. If they claim they're my bank, I say I'll call them back on the number printed on the card, and ask the caller which department I should be put through to. Legitimate callers have never objected to this approach, and it saves me any stress - same policy, no matter the caller, no exceptions, no need for me to try and figure out if I'm being phished.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#29
post #23

It's even worse in Russia - fake caller ID makes you think you are talking with the bank, mobile phone operators don't seem to be doing much, or at least didn't a couple of months ago. That said, all the banks I used send you along with the confirmation code a description of what you are actually confirming.

This is really a SS7 issue not a Russia issue, spoofing outbound caller ID in the USA/Canada is also trivially easy using any major SIP trunking provider.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#30
post #10

I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…

> Last time I needed a new token issuer dongle, I had to actually visit the bank and sign stuff.

I'm glad UK banks try to avoid physical dongles because having to go to the bank and sign stuff to get one is not always convenient, not to mention you need to carry around the dongle everywhere, and if you lose it while you're in vacation it's yet more troubles.

Phone 2FA would be good but a bit pointless because the 2FA app is on the phone, and so is the banking app. Personally I'm satisfied with the way UK banks handle security - it's secure, they block suspicious transactions, etc. yet it doesn't get too much in your way.

I don't think UK banks are less competent, it's just a fine balance between usability and security.

Post reply on HN