Live data from Hacker News

I'm a scam prevention expert and I got scammed

lupinia.net

201–210 of 562 posts

Re: I'm a scam prevention expert and I got scammed

#201
post #42
post #21

There's one easy rule that could have avoided all of this - never give out any info on incoming calls. If I get a call or text about fraudulent transactions, I'll keep them on hold while I log into the bank website. If I get a call about a late payment, I'll thank them for the info and ask them to stay on while I pay online. If I get an inbound call with a more complex request, I'll ask them for their employee info a…

Calling on the official number is a good rule. But my neighbour followed that and was still scammed for tens of thousands. The critical extra step that they missed was to check that the line was disconnected before calling out. They were using a landline. The scammers called them, but didn't hang up. Then, when my neighbour called out to their bank, they pretended to be answering that call - going through security, e…

Was this in the UK? I think they dropped the timeout to help mitigate this. KNow someone else it happened to

Re: I'm a scam prevention expert and I got scammed

#202
This is just very weird to read. What was this scammer’s endgame?

With all this info they can call up GoDaddy and redirect your domain (and all your emails) to themselves, or call AT&T and sim swap you. Why even call the actual account holder?

https://www.zdnet.com/finance/blockchain/fbi-warns-sim-swapp...

As for these “confirmation” emails or SMS — they are so dumb !!! Why don’t they just include a full description of the ACTION you are supposed to have taken, that you are expected to be confirming? In big red letters before the confirmation number. That way the scammer won’t be able to trick you. Sheesh, these companies haven’t figured out to include that?

Re: I'm a scam prevention expert and I got scammed

#203

Earlier quoted context omitted.

> sum of the last 4 It's a chicken/egg problem of not wanting to give information first, but a one-way function (hash) is a fantastic idea. The collision possibilities in this particular function are worrisome, though.

It'd be unreasonable to ask someone to perform a hash of those last four digits (how would your mom respond if the bank asked her for the sha256 hash of her card number?), but it could be helpful to ask questions that don't reveal too much information, like, "is the sum of the last four digits even?" or "is the sum evenly divisible by 3?" It would be difficult to come up with something you could reasonably ask an acc…

> like, "is the sum of the last four digits even?" or "is the sum evenly divisible by 3?"

Exactly. After only a few of these you have an equivalent security level to checking the four digits directly but at each step of the way there is a 50% chance that the attacker, not knowing the number yet, gets it wrong and you stop giving more info. If they do a thousand calls a day, they'll still get some people, but it's probably not you so that's at least a small win.

You might enjoy learning about PAKE/SPEKE, which has similar properties.

> An important property is that an eavesdropper or man-in-the-middle cannot obtain enough information to be able to brute-force guess a password without further interactions with the parties (Wikipedia: PAKE)

Just enough enjoyment to then get depressed wondering why nobody is using these nice things

Re: I'm a scam prevention expert and I got scammed

#204
I was at my local coffee shop yesterday when the manager was on the phone for 10+ minutes with a scammer. Was a new one to me.

The landline caller ID showed "Madison Police Dept" - the local police. The caller introduced themselves as an investigator working a case with counterfeit bills. "Don't contact your boss/owner because we are not sure if they are in on it." The caller knew details like employees names and the layout of the store. The manager was going through the cash in the back "confirming" serial numbers when the owner got in touch and cleared things up.

I was confused about the end game for the scam, but online I've read a version where they send a courier to pick up the "counterfeit" bills. There's also a version where they convince the employee to purchase moneypak cards to be deposited into an account so that the 6AM audit shows balanced books making up for the counterfeit bills that will be confiscated. [1]

To a person that doesn't know caller ID can be spoofed, getting a call that shows up as coming from the local police department can put you in a mental state that it 100% is the police, and it will take a lot of counter information to realize that it isn't. Between that and the convincing reason to "don't tell your boss", I'm afraid this might be an effective scam until it's more widely known.

[1] https://old.reddit.com/r/Scams/comments/ryp4fg/i_got_scammed...

Re: I'm a scam prevention expert and I got scammed

#205
post #21

There's one easy rule that could have avoided all of this - never give out any info on incoming calls. If I get a call or text about fraudulent transactions, I'll keep them on hold while I log into the bank website. If I get a call about a late payment, I'll thank them for the info and ask them to stay on while I pay online. If I get an inbound call with a more complex request, I'll ask them for their employee info a…

This is good advice, despite it being a pain sometimes! I once got a voicemail from the fraud department at my bank, with a number to call back. I googled the number and all that came up were stories about being scammed. So I was 95% sure it was a scam, but called my bank directly just in case. The person who answered assured me they hadn't contacted me, and it was indeed a scam. I later got a follow-up voicemail fro…

I had something similar. One time I got a phone call from a "Scam Likely" and decided to answer it. And it was an automated message from my bank asking if some purchases in another state were real or fraudulent. At this point I began to second guess if it was a scam or not, but had to assume it still was. I ended up logging into my account and seeing the same fraudulent purchases that it listed over the phone. So I called the number on my card and had it all settled. I found it weird that the original call was a false positive though.

Re: I'm a scam prevention expert and I got scammed

#206

> I'm a scam prevention expert and I got scammed After reading all that... I noticed that the "scam prevention expert" isn't serving their site with proper https.

Was the first thing I noticed, but to be fair, there also just isn't really a need for a blog like this. Someone once said something like "I encrypt my innocuous blog because else private becomes suspicious" but by now the internet is largely encrypted and this one blog won't reverse that.

And who knows, maybe the person reading along at the NSA will also enjoy the article :)

Re: I'm a scam prevention expert and I got scammed

#207
I was scammed by a kid locally. He paid me for a motherboard over Paypal, then months later claimed it wasn't approved. I thought it was fishy he mentioned to me having his little brother pick it up. I said no to that. And I insisted on cash, but eventually relented, thinking it would probably be ok. He filed a PP dispute and lost, as I had text messages proving the sale. Then he did a chargeback and won.

I would've filed in small claims court but the filing fee is more than the loss. So I looked up all his family info and addresses, and next time in his neighborhood I'll be knocking on their door for my money.

And, I'll just keep finding creative ways to chase him down, online and off, until the day I die. I'm never letting it go and eventually if I had to "take" the money from him through other means (him losing money), that's what I'll do. I'll be sure to double or triple his losses though if it comes to that.

Re: I'm a scam prevention expert and I got scammed

#208
post #187

> if it was a scam, then this was clearly a bluff to try to reassure me, but he had WAY more information about me than I would expect an average scammer to have you can purchase FULLZ from darkweb marketplaces, these contain name and address and social security number and often come with credit card details too with that, you can do social engineering like this, you can also remote desktop into any computer nearby to…

Be interesting to do a lookup on yourself, is there any information how you go about this ?

I mean you could try to find the large known leaks and go through them yourself

People just cross reference them and sell individual ID packs one by one

There were 15,000,000 people in the Experian leak alone. Most of that information is still valid, we've just gotten numb to it.

Merchants that care about customer support and reviews will just replace an ID for the consumer if its been used before

There isn't a way to try to find who is in a database without the source databases yourself. Merchants don't tell you how they found the aggregate data, they just have reviews from people that say if it was accurate data or not. You could try and ask a merchant if they have a particular person, but I doubt many merchants have a way to sort that themselves, as the files are no longer in a parseable database by the time it reaches them. The organized networks are corporations and conglomerates with separations of knowledge and duties.

All you would be able to do is purchase a FULLZ and get what you get.

Re: I'm a scam prevention expert and I got scammed

#209
post #163

Earlier quoted context omitted.

Reason #99,999 that I don't use Amazon anymore. Just buy stuff in-person, pay the shipping, wait the week, or whatever. You'll be fine I promise.

Stuff in person costs 2X the price though. Especially bike parts. It's often cheaper to buy from Amazon but never go through troubleshooting support. Always return or replace. If that doesn't work, give a 1 star review, wait for the seller to come chasing you with a gift card in return for 5 stars. Change it to 5 stars, spend the gift card, and then change it back to 1 star.

[deleted]

Re: I'm a scam prevention expert and I got scammed

#210
> We always say we'd rather people report a thousand false alarms than fail to report a single real emergency, but if the process of filing those reports results in condescending info-dumps or intimidating interrogations, is it really a surprise that so many people have been trained to just not say anything and hope their suspicions were wrong?

This is how it is at almost any company I have ever worked for. They always say things like "We prefer that you ask questions if you don't know" or "We would rather get a hundred false reports than miss one valid one." That sort of thing.

And then when you follow through with what they ask for, it's just like the quoted part says.

> results in condescending info-dumps or intimidating interrogations

It's not just a cyber security problem folks. This is pretty much a global problem, because no one ever really wants to be bothered over trivial matters, and no one really wants to believe the boy who cries wolf; even if the wolf is real.

None of this will get better until people in general become both intellectually and morally wiser. So get a drink and some popcorn cause this is gonna be a while.

Post reply on HN