Live data from Hacker News

I'm a scam prevention expert and I got scammed

lupinia.net

221–230 of 562 posts

Re: I'm a scam prevention expert and I got scammed

#221
post #6

I nearly got taken by a scammer because Amazon transferred me to one. I purchased a set of Reolink cameras on Amazon, (they've been great) one of them failed a couple months in. I contacted Amazon customer support (via my Amazon login and in their interface) and they wanted to troubleshoot with their technical team. Eventually the (very helpful) Amazon technician suggested contacting Reolink for support and started a…

It's really hard recognizing the image Amazon have in the US compared to my personal experience with amazon.de . The service is stellar, shipping both ways is free as long as you buy products covered by prime. Refunds are with no questions asked (as long as you don't start abusing it i guess). As soon as you go into 3rd party sellers the experience gets muddled, though I've had plenty of good experiences with those a…

>" The service is stellar, shipping both ways is free as long as you buy products covered by prime. Refunds are with no questions asked"

This is my exact experience in Canada so far. But they did something else weird. I wanted to buy Google Store gift card from Amazon and as soon as I made the purchase my account was suspended. It had taken me few hours including lengthy phone call to sort things out. I was told that gift cards are widely used in fraud. Sure, whatever but then why FFS they sell those?

Re: I'm a scam prevention expert and I got scammed

#222
On related note - I work for Asian company which sends me money to Europe through their US "offshore" bank account in Wells Fargo.

I'm receiving monthly payments, but once payment bounced back because my local EU bank switched their intermediary bank, something normal client shouldn't care about, but I learned about hard way because WF is not updating their database of intermediary banks and routed my payment through outdated intermediary bank.

I was pretty pissed about my own bank not informing me about changing intermediary bank, so I changed my receiving bank to different one, although in the end it was Wells Fargo problem not keeping their records up to date.

Guess what happens years later after my other bank merger with different bank, Wells Fargo once again ignores new intermediary bank and bounced back the payment.

I dunno if this is standard US international banking experience, but I find it extremely unprofessional and unheard in other countries that payments would be bouncing because bank is too lazy to update their intermediary bank database, not sure what operation they are running in Wells Fargo.

In the end company made exemption for me and they are sending me money directly from their Asian account, because apparently you can't get worse banking experience than with US banks.

Re: I'm a scam prevention expert and I got scammed

#223

There was one time I thought I was being scammed, but it turns out there was an actual issue with my bank account. Sitting at my desk at work, I get a phone call from my bank on by cell phone. "Mr. Anechoic, there appears to be a security issue with your bank account. We can resolve it for you. For security purposes, can you give your checking account number and the last four of you SSN"? This is clearly a scam, righ…

Not the same thing, but relatedly, every legit email I receive from my health insurance is functionally indistinguishable from phishing. They always bounce me through a million weird domains too. It's very discomfiting and makes me worry that I won't be able to pinpoint a legit phishing attempt because it won't stand out.

I love the weird domains - billing is sometimes outsourced through x redirections, and they use weird third party email hosts (CISCO secure email etc) that is halfway broken with CSS for you to upload your employee rosters (complete with socials and DOB's etc).

The domains for these are always commically like phising domains (secure-bank-email.valimail.com etc).

Re: I'm a scam prevention expert and I got scammed

#224
post #68

Earlier quoted context omitted.

For the people who are confused: this is a fairly common thing on landlines in some countries, where the telephone exchange doesn't drop the connection until both ends have hung up, or in some cases when the caller hangs up but not the callee. So it's possible to put your own phone down, but when you pick it up again your phone is still connected to the scammer's telephone. If they play a convincing dial tone, then c…

I accidentally won a radio contest many years ago in this way. I heard "you are caller 2" and then the DJ hung up. I stayed on because I was confused and then a few seconds later he picked up again and said you are "caller 4". So I just stayed on and eventually said I was caller 10 and the 10th caller won the prize. I assume he was switching back and forth between two internal phone lines. I was confused because I wa…

I did that too, except I called the wrong number and won Barbara Streisand tickets. Not my jam.

Re: I'm a scam prevention expert and I got scammed

#225

Earlier quoted context omitted.

> Not much of an expert, caller ID means nothing They... said that: > The caller ID showed the correct name and number for my bank, but caller ID data is so hilariously easy to spoof that it might as well not even exist. Honestly, what is with the low quality comments attempting to undermine this person's credibility?

So what if they said that? I'm not trying to pile on them but the reason people are questioning their credibility is that they fell for a pretty basic scam. Even if they acknowledged that their assumptions were incorrect (knowing Caller Id is very flawed but still falling for it), it doesn't necessarily make the scam any less obvious. Would you not question the credibility of a doctor who falls for say, crystal heali…

> I'm not trying to pile on them but the reason people are questioning their credibility is that they fell for a pretty basic scam.

Yeah, I've read the armchair quarterbacks around here thinking they wouldn't be the ones to get duped if it was them.

Of course, I'll bet if they did get duped, they wouldn't post about it on social media because a bunch of folks would come out of the woodwork to point out how stupid they were.

Personally, I read this accounting and thought "You know, for all my own knowledge about how these scams work, I might've been caught by this one." This specific example strayed into spearphishing territory given the knowledge the attacker had of the victim. This wasn't just an average war dialler. And the time investment, alone, on the part of the attacker makes this unusual compared to your average phone same.

But hey, maybe I'm just not bright enough to hang with the cool kids around here.

Re: I'm a scam prevention expert and I got scammed

#226
post #15

Earlier quoted context omitted.

>It is security theater of the worst degree by incompetents and MBAs and I am getting sick of it. It's security theater giving people exactly what they want. People want to feel secure, but they don't want any amount of actual difficulty in getting what they want from Company A. Like it or lump it, but regular people really don't want actual security. They want the ease and convenience of no passwords at all, and wan…

Of course people want security, how can you say otherwise? What you seem to be talking around is that security researchers have been unable to figure out simpler forms of maintaining a true sense of security, simpler forms of reliability. There is no survey where people say they don't want these things, and if you're relying on the sales figures for Yubi keys or something, that's not a good indicator. And of course p…

You're absolutely right. People do unquestionably want security! They want privacy too!

The issue that the parent is alluding to is that the same users who want these things seem unwilling to make decisions or change behavior to get that security or privacy. Those of us working with security and privacy often wind up with the sense that users want them, but also that users expect them to be automatic and perfect and free. This starts with the computer-illiterate user who finds passwords confusing and goes all the way to developers who find it irritating to be forced to update the libs in their docker images.

Are there better ways? I sure hope so. So far we don't have simpler forms of maintaining true security or simpler forms of reliability. We just have cheaper ways of maintaining a sense of security - and that's theater.

I don't blame people for wanting faster horses. We don't have them on offer though, so in the meantime it might be nice if they were willing to consider what's available.

Re: I'm a scam prevention expert and I got scammed

#227

Earlier quoted context omitted.

This seems to be the classic underdog problem. The traditional retailers that you like today will become third party marketplaces tomorrow if they grow. So the issue is that we only get good service from underdogs and it is destined to fail once the underdog is not an underdog anymore.

That doesn't follow. Just because an online retailer grows it doesn't mean they have to start allowing third-party sellers. In fact, seeing what is happening to Amazon's reputation, that seems like a bad long term move. Short termisum might win out, but it is not a foregone conclusion.

The mechanism is the managers that take over at companies who focus on the short term bottom line (trimming support today, to juice profits tomorrow, to lose credibility years down the road after the bonuses have long landed in their bank account).

And the problem is that Amazon's growth profile (retail-side anyway) is going to be pretty constrained going forwards because they own too much of the available pie right now. So the result is that managers are going to have to look for other ways to trim costs to make numbers.

If you're starting from 0.001% of the retail market and trying to grow 10x it is much easier to do that just by having really good customer service.

Re: I'm a scam prevention expert and I got scammed

#228
post #21

There's one easy rule that could have avoided all of this - never give out any info on incoming calls. If I get a call or text about fraudulent transactions, I'll keep them on hold while I log into the bank website. If I get a call about a late payment, I'll thank them for the info and ask them to stay on while I pay online. If I get an inbound call with a more complex request, I'll ask them for their employee info a…

Agreed. No matter how tired and annoyed I was, I'd have stopped dead at the confirmation code that they asked for. There's absolutely no way I'd have given that to them, even if it meant cancelling my account and using a different bank. That seems a bit extreme, but if their procedures are so crazy as to require circumventing another system's security procedures, I'm not going to bank with them. I actually had a bank…

I think this is a statement easier to conclude in hindsight, especially as you are primed with "this story is describing a scam, definitely". The author describes the thought process and what ended up nudging them toward believing the scammer about the workflow. A code sent like this in a legitimate workflow could be plausible. Maybe it's a requirement to ensure that the customer is indeed acknowledging the operation and the CSR isn't taking actions behind the customer's back, for instance.

The author had a lot of signals pointing toward legitimacy to counteract their natural skepticism, it was a stressful situation and the nature of a phone call puts time pressure into the decision making, increasing the odds of a mistake.

Your example points out that false positives on the "scam or ham" decision do have a cost to the contact recipient too, so "never respond to anything" comes with risks and costs too. It's hard to be perfect.

Re: I'm a scam prevention expert and I got scammed

#229
post #28

Earlier quoted context omitted.

I bet your Amazon rep just searched for Reolink and clicked on a Google ad that happened to belong to the scammers.

Well this initiated a rant, not directly related to ads, but Google in general. This is an internet literacy issue I’ve noticed more and more. People will refer to Google listings as an authoritative source even if the data comes from some third party. “Is this Jordan’s Tiles?” “No. This is Patrick. You have the wrong number.” “It says on their website this is the number!” “Their website is wrong, this isn’t Jordan’s…

.

Re: I'm a scam prevention expert and I got scammed

#230

Banks will never call you. It's that simple. And if they do, hang up and call them back. I've had this attempted scam tried on me twice in last 4 months. You know it's a scam for sure when they try to prevent you from hanging up. Also, always disconnect. Don't just listen for a "dial tone" after they hang up.

This x100! And call them back from a different phone, just in case.
Post reply on HN