Live data from Hacker News

An unprecedented wave of online bank fraud is hitting Britain

reuters.com

211–220 of 224 posts

Re: An unprecedented wave of online bank fraud is hitting Britain

#211

I had a long argument with HSBC UK Security a few years ago where I was completely unable to get the to understand they were putting their customers at risk. In the event that something looked strange on your account the 'HSBC Fraud Department' would text you and ask them to call you on a phone number. A phone number that didn't appear anywhere on their website. "We don't want it public. OK,well at least put it on a…

>Even when I said to them "You are training your customers to accept potentially fraudulent text messages" they didn't get it.

You were talking to a call centre worker making close to minimum wage and who's job is to get shouted at by customers all day. Even if they wanted to help you, their opinion would count for nothing.

No wonder they didn't give a shit.

Re: An unprecedented wave of online bank fraud is hitting Britain

#213
post #163

Earlier quoted context omitted.

If someone spoofs the banks number on caller ID (trivial), knows all your security question answers, the bank you bank with, and your number - very few people are NOT going to fall for some kind of attack there correct?

How could they figure out the internal account number without hacking into the bank in the first place? I’m fairly certain there’s no way to derive the account number from a debit card number or any of the info you mentioned.

Via the data leak issue I mentioned? [https://www.bankinfosecurity.com/capital-one-warns-more-data...] which are becoming more and more common?

Re: An unprecedented wave of online bank fraud is hitting Britain

#214
post #213

Earlier quoted context omitted.

How could they figure out the internal account number without hacking into the bank in the first place? I’m fairly certain there’s no way to derive the account number from a debit card number or any of the info you mentioned.

Via the data leak issue I mentioned? [ https://www.bankinfosecurity.com/capital-one-warns-more-data... ] which are becoming more and more common?

You have confirmation that internal account numbers were leaked in the capital one breach?

Re: An unprecedented wave of online bank fraud is hitting Britain

#215
post #213

Earlier quoted context omitted.

Via the data leak issue I mentioned? [ https://www.bankinfosecurity.com/capital-one-warns-more-data... ] which are becoming more and more common?

You have confirmation that internal account numbers were leaked in the capital one breach?

It says so right in the linked article.

Additionally, bank account ‘internal’ account numbers are pasted on every check that goes out and any ACH transfers also include that information, so it’s not like they are hard to cross reference with any of the other major breaches.

SSN, dob, which banks people use (and other financial institutions), which loans they have with whom, etc. also got leaked for pretty much every US adult with the equifax hack.

Re: An unprecedented wave of online bank fraud is hitting Britain

#216

Earlier quoted context omitted.

I had a similar experience from HSBC. They called me about a potential fraudulent claim. They asked for my DOB, card number, sort code, you know, to verify "that I am who I say"... all the stuff they SHOULDN'T ask, and stupidly I gave it all up. To be fair, I did because my card had been rejected literally 30 seconds before while trying to make a purchase. But it was only after the phone call ended that I realised wh…

I hope your admonitions to the call center drone who picked up your call were emotionally satisfying to you, because that's as far as they went. If you want to influence company policy on something like that your best bet is a highly visible social media conversation. The poor call center drone who was the subject of your wrath literally just sighed and stared at the wall for a second after your call then opened up t…

>I hope your admonitions to the call center drone who picked up your call were emotionally satisfying to you, because that's as far as they went.

I've supported a call center. We had specific escalation routes where problems could be sent to higher levels. The most obvious is the "I want to talk to your manager" escalation, but the agents, managers, and QC agents could push buttons that flagged additional review.

My advice for getting attention: don't be rude (EVERYONE is rude, this won't get any one's attention), be CLEAR about the problem AND solution, evoke emotion in the listener (remember, the listener is a QC person who reviews the call days later)

Try something like: I'm on vacation and my daughter was REALLY looking to see a musical. Do you have kids? Mine LOVE Beauty and the Beast - she has her backpack and t shirt, she is adorable. Every time we try to buy a ticket, it gets rejected. I think I forgot to notify you that I'm traveling. I'm so sorry - it just slipped my mind!

Re: An unprecedented wave of online bank fraud is hitting Britain

#217

What's always missing from stories like this is how the crooks get the money out. Considering that all Western governments have achieved total surveillance on our banking and made it impossible to have anonymous bank accounts, I'd like to see a detailed analysis about why they can't follow the money and see who gets it. Every scenario I can think of seems like it should be either traceable or actionable. Scenario 1:…

I know in the USA it is possible to open accounts online only, and when you are online only well it's not a far hop to give a digitally manipulated ID photo, if they ask for one at all. Plus all the info needed to open bank accounts has been breached and released 100 times over at this point.

Re: An unprecedented wave of online bank fraud is hitting Britain

#218

It utterly infuriates me that banks won't let you use their mobile apps -- which are inevitably their websites packaged in a bundle, with added tracking -- on a rooted (or jailbroken) phone, even though I am sure that the overwhelming majority of users on android who have a rooted device are likely to be the most technically sophisticated, with (in my case) the presence of mind to install updates to their four-year-o…

Fraudsters, for better or worse, will also be in that technical category of people who would use rooted phones too. It's easier to just click the configuration option and materially reduce fraud cost for little work than to do the banking equivalent of porting your game to linux.

Similarly with NFC wallet sniping. In practice it doesn't happen, and because it's a merchant credit card transaction, significantly easier to roll back in time once customers start filing charge backs for them, which is a major reason probably why it doesn't happen much in the first place. Physical wallet snipping is also too much work compared to other schemes available.

Re: An unprecedented wave of online bank fraud is hitting Britain

#219
post #117

Earlier quoted context omitted.

Not all US credit card companies are like this. I specifically remember a few years ago that my Mom got a call from AMEX about some fraud on her card, to which she responded “I never get calls from you, how do I know this is real?”. They said no problem, just hang up and call the number on the back of your card. I believe some banks even skip the call entirely, and just prompt you to call the number on the card.

Agreed. I personally carry a Citi card (double cash) because it has the best (for me) rewards, but I also carry an AMEX blue cash preferred for which I pay an annual fee. The customer service I get from amex is DRAMATICALLY better than from Citi. With Citi: * it's non-native-English support. No judgement of course but I don't appreciate the language barrier when the entire job of customer support is communication. *…

When dealing with banks that I know have lousy customer service over the phone I keep recordings. "Recordings may be taken for training and customer service purposes" says the message. Thanks, I'll take your advice.

In the UK the tax-free savings account allowance is per tax year. I paid the money into a not-so-great bank offering excellent rates a few days before the deadline one year and called to create a savings account. Weeks later they've got no record of the savings account, and when I call they explain I'm too late now for "last year's" allowance. I point out that I made the transaction before the deadline and they explain that oops, sadly they don't have that call recorded, and so there's no evidence I actually authorised account creation back then. So I play back my recording, and what do you know, suddenly the bank has a new explanation for what went wrong and wants to pay me compensation for their mistake in not making the account.

A better bank would have eaten the cost of this mistake up front of course, but I already knew this was a lousy bank, that's why they're offering by far the best rates. To attract customers despite the reputation.

Re: An unprecedented wave of online bank fraud is hitting Britain

#220

> The country is the global epicentre for such attacks Oh dear. So the country is the location several Km underground, that is the centre of the attacks? Why has every centre turned into an epicentre? Is "epicentre" easier to understand then "centre"?

Because: 'The country is the global centre for such attacks' just sounds false, or at least unsubstantiated.

Whereas 'country is the epicentre' is more obviously intended as hyperbole.

Post reply on HN