Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

301–310 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#301
post #280

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

Calling twice in rapid succession is an emergency feature for Android (possibly other) phones when in Do Not Distrub mode. It bypasses the DND when you call twice like that. Usually, only the numbers on your Starred list can call without getting blocked by DND. The recipient may believe they had starred the number because of this, making them more likely to pick up the call.

On iOS you can choose whether to allow or block repeated calls, but as far as I can tell it's an all or nothing toggle. If it's enabled, anyone can get through by calling twice.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#302

I can understand how people would fall for this one. With 20/20 hindsight, asking for the member number is fishy - it doesn't actually verify anything. And when my bank calls me, it is always automated - I only get a person talking to me if I ask for it through the automated systems. So in a way, any actual person calling would be a red flag. But in the moment, I can see why it sounded legit. My parents have taken th…

I wonder if the criminals start to use automated voice systems, especially if those systems prompt and allow you to input numbers/password from the dialpad, how many more people would fall to the scam.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#303
A rover scammer called my wife yesterday. She felt pretty quick that it was a scam.

I tried to call the number back from my phone (it was seemingly a regular local phone number in the LA area and I love fucking with scammers) and an automated response told me that “no Rover account could be found for my number, please visit Rover.com/help for more” which I thought was very sophisticated of them to really try and prove authenticity.

So then we called it back, from her phone, and it connected right away. The person on the other end said, “Ashley?” and I responded (in my non-female voice, not that there aren’t many men named Ashley) “yes, hello, how are you?” - they hung up immediately.

Ultimately my wife called Rover via their 1-800 number and it was indeed a scam. People try to ascertain your login creds to redirect funds. Basic stuff... but I was impressed at whatever basic twilio system was built to try and mask the scamminess with that automated message.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#304
Something nearly exactly the same happened to me. It was through my Venmo account. I was stressed at the end of a long day and they got pretty far before I realized what happened. The key thing is that the number listed on Caller ID on my Android phone came from "Venmo" and matched their customer service number so I completely let my guard down. Embarrassing.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#306
post #243

Earlier quoted context omitted.

Why would a letter be genuine? That seems easier to spoof then phone or email?

Not sure if it’s true, but I’ve heard that mail (at least in the US) is safer because the cost to send letters is high enough to deter bulk sends vs email/phone, that postal inspectors are relatively effective at catching people, and that the laws around mail fraud make prosecutions easier.

I got a scam letter from someone claiming to be Canada Revenue Agency, so I wouldn't bank on that either.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#308

Earlier quoted context omitted.

I had something not exactly like this occur to me. It wasn't something I overheard, but I'm pretty sure it went something like this: 1. You talk to a teller at a branch, and they bring up your account details. The teller see's you have a mortgage with the bank, but registered to a different branch. 2. They have some sort of incentive from the mortgage specialists at their own branch or management, to refer those acco…

What's an "early renewal" in this context? Mortgages aren't things I think of as requiring renewal at all.

Ah sorry, maybe it's a Canadian thing. I have a mortgage with an amortization that's say 20 years. But I actually enter into an agreement and a rate for say 3 years. At 3 years myself and the bank need to enter into a new agreement, or I can shop around for the best rate for the next term with other providers (although some banks have been clever in the rules trying to prevent this).

An early renewal would be doing a renewal with the same bank at say the 2 year mark for a new term and interest rate. The bank allows the old contract to expire early, since they're getting the new one for an extended period, like another 3 years. These terms can vary, with 5 years being the most common, but can be shorter or longer and apply to both variable and fixed rate mortgages.

Note: I'm not an expect on this or how it compares to other regions.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#309

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

This is actually fairly common now, unfortunately. Many reports of Uber drivers being tricked into getting their account hacked using this method to obtain the 2FA pin sent via SMS so they can drain their balance or switch the bank account on file.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#310

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

I never give any information to anyone who calls me, apart from people I already know like friends and family. If they say they are from the bank I apologize and say that I will contact them independently via the number that is on my card. I don't even confirm my name. Some banks think I am being difficult, but I stick to this principle regardless.
Post reply on HN