Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

291–300 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#291
Number 1 rule of banking and other services, they NEVER ask for your password or other authentication code. Usually I don't even think they would contact you by email or by phone.

If they really suspect a fraud, they would block your account, and eventually ask for a meeting.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#292
post #183

Earlier quoted context omitted.

> My bank no longer allows me to reset my password without calling them (thanks bank). So how are they going to verify it’s you who is calling them?

Ask for things like postcode, birthdate, etc.

None of these are secret, asking for these things provides no security.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#293

Reading this thread reminds me of when I was subject to a social engineering attack by people who claimed to be the FBI. The voice messages they left sounded unconvincing so I ignored them on the basis the real FBI would have better ways to contact me. Couple days later two FBI agents show up in my driveway asking why I didn't respond to their voicemail..

Or maybe it was just super persistent scammers dressed like FBI agents!

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#294

Earlier quoted context omitted.

I wonder if bank staff are in on it sometimes. I once was at a bank branch and had the teller pick up the phone, call another teller and tell her my balance in a foreign language that I happen to speak fluently (but don’t look like I should). I wanted to ask her why she would be doing that, but I was a bit more meek in my younger days.

I had something not exactly like this occur to me. It wasn't something I overheard, but I'm pretty sure it went something like this: 1. You talk to a teller at a branch, and they bring up your account details. The teller see's you have a mortgage with the bank, but registered to a different branch. 2. They have some sort of incentive from the mortgage specialists at their own branch or management, to refer those acco…

What's an "early renewal" in this context? Mortgages aren't things I think of as requiring renewal at all.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#295

I used to hate it that my bank requires a physical trip to the branch for cred reset. No more.

I used to pure online banks were the future, but no I wouldn't touch a bank that doesn't have a physical branch somewhere close.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#296

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…

You should be careful even about doing that if you are on a landline. There is a landline scam where they don't let the call disconnect, so when you hangup and then think you are dialing the bank, you are actually still connected to the scammer.

Always use your mobile phone to make the call (although I'm sure its only a matter of time before even that is compromised).

https://toronto.ctvnews.ca/etobicoke-couple-defrauded-of-mor...

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#297

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

The biggest mistake was offering any information. You never offer information, you only confirm or deny things that they tell you. If they insist on things like member id, or email, you hang up, and call the bank yourself.

We as a society need some form of standardized ISO 9001-level protocol where ALL companies handle security the same way. They all ask the same questions, they don't allow first-tier support access to passwords or changing password, only specialized tier-2 support has this power, etc.

If all companies like banks, Amazon, Facebook, etc standardize their procedures in a way that leaks no information, or engage customers in a way that leaks no information, then it will make it harder to phish people because phisher will be forced to ask weird questions that customers will detect as weird.

The problem right now is that some companies ask for last 4 digits of SSN, last 4 digits of credit card, some ask for email address, etc, etc. A phisher can put all those together so if you reduce the attack surface it makes it very very hard.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#298
post #174

Earlier quoted context omitted.

>When I read the thread now, it's obviously full of red flags. I was successfully manipulated, and whilst I'm certainly not as clever as all the people pointing out they would have caught this from sentence one, I believe I'm also not the lowest hanging fruit in terms of a target :-) Makes you wonder what this will look like when these scams evolve another couple of generations in terms of complexity ... I think this…

Most people claiming they would have spotted it are probably wrong anyway. They're reading the messages with the knowledge that they were sent by a scammer. Any idiot can identify these things in hindsight knowing what they're looking at. Without that context, with other things on their mind, it's much more likely they'd have been duped too.

Absolutely. You're in the middle of something else. Your "bank" calls you. You're thinking "What the hell do they want and how can I deal with this as quickly as possible?" Etc. I like to think that I'd never fall for any of these scams and I'm sure I'm more conscious of the possibility than I would have been at one point. But I can't really swear that distracted me whose mind is 75% focused on some other task is as security-aware as I like to think I am.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#299
post #251
post #222

Earlier quoted context omitted.

Can you elaborate why you believe smartcards are less secure than your mobile phone?

All the ones I've seen have no security, either it's just a changing password (e.g. RSA key), or you input your card (optionally entering your PIN which you share with every POS terminal / shop) and get a password. My phone requires a password (which I can set to be arbitrarily secure, not 4-digit PIN (LOL)) or a fingerprint (which is something noone can steal, unlike a credit card... or at least I'd notice it's miss…

RSA SecurID is not a smartcard. It's basically equivalent to TOTP except as a physical object rather than a phone app. There's secret baked into the SecurID and the issuer knows that secret so they can use it to generate the same one time code.

You seem to imagine that your phone, on which you run most likely not only a wild variety of apps from potentially untrustworthy sources, but also a web browser, which is a huge attack surface facing the Internet, is more secure than a simple smart card and that doesn't make a whole lot of sense.

In both cases the main real world security is that bad guys will probably need to _steal them_ which is difficult and a completely different skillset from the skills to make phishing emails or lie on the phone. But the phone is a bit worse here because maybe they can attack that remotely via, as I mentioned, your web browser, instant messaging stack or other components of a very complicated device.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#300
post #174

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

>When I read the thread now, it's obviously full of red flags. I was successfully manipulated, and whilst I'm certainly not as clever as all the people pointing out they would have caught this from sentence one, I believe I'm also not the lowest hanging fruit in terms of a target :-) Makes you wonder what this will look like when these scams evolve another couple of generations in terms of complexity ... I think this…

They say the generic rule of thumb here is urgency. If you can't take your time, it's a scam. I was previously scammed several times with urgency, but as a rhetoric trick under a premise of impatience.
Post reply on HN