Live data from Hacker News

Voice Phishing Scams Are Getting More Clever

krebsonsecurity.com

221–226 of 226 posts

Re: Voice Phishing Scams Are Getting More Clever

#221

This is why I don't answer the phone unless it's a contact. Everyone else can leave a message.

Did you read the article? The Many people have their bank or credit union in the contacts. This won't help if they're spoofing a bank number. > Cabel Sasser is founder of a Mac and iOS software company called Panic Inc. Sasser said he almost got scammed recently after receiving a call that appeared to be the same number as the one displayed on the back of his Wells Fargo ATM card.

Might as well put your social security and pin number in your phone too. Bank phone numbers in your contacts are a huge vulnerability. Just Google them when needed... or you know, look at the card.

Re: Voice Phishing Scams Are Getting More Clever

#222
post #85

The problem here is the ability to spoof caller ID. This should not be possible. Regulations set up the phone system, regulations need to make this change. I don't care what excuse anyone has, don't care about your stupid PBX or any of that. Caller ID should be mandatory and reliable. Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a…

If we make a regulation that requires protocols to change so that the caller ID to be unspoofable, we might as well also require to make it impossible to spoof an IP address or a sender email address...

I work for an ISP. We filter packets spoofing their IP source address.

SPF, implemented by most major email providers, helps to prevent FROM: spoofing.

Hell, I'm pretty sure our VoIP product drops external calls where the Caller ID matches one of its' own numbers.

These are problems we are solving. These are problems we should be solving in telephony too.

Re: Voice Phishing Scams Are Getting More Clever

#223
post #213
post #64

Earlier quoted context omitted.

I pointed out, each time, that they were the ones who called me so I should be verifying them. "But, sir, WE are the bank and you could be anyone who just answered your phone." There has got to be a word for this and similar behavior. Banks, credit card agencies, mobile phone companies are getting really aggressive with how they handle these sort of transaction based interactions and I'm leaning towards wanting to se…

The reason they are asking you why you missed a payment is because creditors have hardship payment plans for people in certain hardships. They were trying to see if you were eligible.

"You should probably lead with that next time" is all I have to say in response to that.

I'm far more likely to respond positively, even if ultimately I decline if they were to say "We have a program in place-if you think you're going to miss a payment that will help keep your account on track, would you like to enroll?"

versus

"Why were you late making this payment?"

Of the two, when I went through that period of long-term underemployment, I only ever heard the latter, never the former. Such a curt and abrupt question to ask that comes across much more invasive than helpful.

Re: Voice Phishing Scams Are Getting More Clever

#224
post #223
post #213

Earlier quoted context omitted.

The reason they are asking you why you missed a payment is because creditors have hardship payment plans for people in certain hardships. They were trying to see if you were eligible.

"You should probably lead with that next time" is all I have to say in response to that. I'm far more likely to respond positively, even if ultimately I decline if they were to say "We have a program in place-if you think you're going to miss a payment that will help keep your account on track, would you like to enroll?" versus "Why were you late making this payment?" Of the two, when I went through that period of lo…

They tried to tell you that, you just didn't want to hear the message for some reason

"We're asking because we want to do you a favor/we understand things are hard sometimes"

There's more than "a program," creditors have different options/programs, etc. Special options exist for people who were effected by certain natural disasters. They probably would have offered to waive the late fee if you missed a payment because you were in the hospital or something. They were starting a dialog with you about your account status in order to work with you; no need to get all offended about it.

Re: Voice Phishing Scams Are Getting More Clever

#225

Earlier quoted context omitted.

Does this imply I should answer the 1-800 calls and keep them on the line as long as possible? :D

If you suspect a scammer called you, always keep them on the line as long as possible. Feed into the scam and act as gullible as possible, give them fake cc numbers, etc.

haha, "four-flag key" is still an inside joke with my family because of how many times we got a scammer to say it while they "provided tech support" to us :)

Re: Voice Phishing Scams Are Getting More Clever

#226

The problem here is the ability to spoof caller ID. This should not be possible. Regulations set up the phone system, regulations need to make this change. I don't care what excuse anyone has, don't care about your stupid PBX or any of that. Caller ID should be mandatory and reliable. Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a…

Note that on many land-lines this will fail, as the calling party simply does not hang up, waits for silence on the line, then plays dial-tone down it. When you pick up again, it seems like you are connected to the exchange, but when they hear DMTF they just play ringing tones back at you, then pretend to answer as your bank and continue the scam. Bonus points to the scammers if they actually call the number you dialed and MITM the call for extra realism, only jumping in when you get transferred... ;) In fact, I bet you could program Asterisk to do this for you, or similar VOIP PBX software?
Post reply on HN