My simple policy is I never give out any information if I'm cold-called. If they claim they're my bank, I say I'll call them back on the number printed on the card, and ask the caller which department I should be put through to. Legitimate callers have never objected to this approach, and it saves me any stress - same policy, no matter the caller, no exceptions, no need for me to try and figure out if I'm being phish…
I was just subjected to the most credible phishing attempt I’ve experienced
91–100 of 360 posts
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#92Earlier quoted context omitted.
But, if I don't hang up the received and the counterparty hangs up, then the line tone is the one of the "busy", not the one of the "free", and I'm unable to dial anyone until I physically hang up to reset the line. Or at least that's how it works back home. Is it different in UK ? I suppose it's something that less attentive people might fall for anyways.
Wow, this really is something if done right. I don't use a landline now, but if I remember, the caller needs to disconnect for the line to actually be disconnected. So even if the callee tries to disconnect by hanging up, the caller is still actually connected. If the callee picks up the receiver again and hears a dial tone, they'd be none the wiser. But I guess the scammer would also need to detect a key-press tone…
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#93I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…
> Last time I needed a new token issuer dongle, I had to actually visit the bank and sign stuff. I'm glad UK banks try to avoid physical dongles because having to go to the bank and sign stuff to get one is not always convenient, not to mention you need to carry around the dongle everywhere, and if you lose it while you're in vacation it's yet more troubles. Phone 2FA would be good but a bit pointless because the 2FA…
Can't you just lock the stolen phone?
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#94My parents have taken their precautions against phishing to extreme levels. They don't speak into the phone when unknown numbers call. At all. If they choose to answer, they wait for someone on the other end to talk and then decide whether to speak or hang up. They have heard horror stories of people getting their voices recorded and replayed into automated systems, so if someone calls and asks, "Hi, Is this ?", they avoid even saying "Yes", and instead ask who is calling. It may be paranoia, but as the saying goes... just because you are paranoid doesn't mean that they are not out to get you.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#95In EU, there is the (recent) implementation of a (new) directive, PSD2: https://en.wikipedia.org/wiki/Payment_Services_Directive#Rev... That carries with it the requirement of SCA: https://en.wikipedia.org/wiki/Strong_customer_authentication In practice (here in Italy) you have a client number (secret) a password/PIN (also secret) AND either a SMS to your mobile with a one time code or a Smartphone app (yikes!), ther…
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#96Earlier quoted context omitted.
There seems to be broad consensus amongst the commenters that this is the most reliable defense against this kind of attack. Makes sense. If they are able to intercept my outbound calls, it's probably an entirely different level of sophistication and targeting.
I read about a landline attack that would keep the line open when you put the receiver down, play a dial tone, and then wait until you’d entered a number before putting you back on with the scammer
But almost everybody today has a digital phone, any kind of mobile telephone or desk VoIP phone is digital, "hanging up" ends the call because the telephone itself decided to do that, everything is just packets. So this trick won't be effective against most people today.
Likewise "dialling" today is an out-of-band digital step rather than a bunch of pulses or tones sent in-band that an attacker can just ignore.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#97Earlier quoted context omitted.
But, if I don't hang up the received and the counterparty hangs up, then the line tone is the one of the "busy", not the one of the "free", and I'm unable to dial anyone until I physically hang up to reset the line. Or at least that's how it works back home. Is it different in UK ? I suppose it's something that less attentive people might fall for anyways.
Wow, this really is something if done right. I don't use a landline now, but if I remember, the caller needs to disconnect for the line to actually be disconnected. So even if the callee tries to disconnect by hanging up, the caller is still actually connected. If the callee picks up the receiver again and hears a dial tone, they'd be none the wiser. But I guess the scammer would also need to detect a key-press tone…
GSM and VoIP also do not allow this behavior without engaging call waiting on subscriber side.
This only happens with old fully analog connections. Not sure which country or public operator still has this kind of PSTN.
For the difference, peruse ITU-T G.175 and Q.522 standards. SE (switching element) will disconnect the routing on your side. It took me a while to find the actual standard number.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#98My simple policy is I never give out any information if I'm cold-called. If they claim they're my bank, I say I'll call them back on the number printed on the card, and ask the caller which department I should be put through to. Legitimate callers have never objected to this approach, and it saves me any stress - same policy, no matter the caller, no exceptions, no need for me to try and figure out if I'm being phish…
> My simple policy is I never give out any information if I'm cold-called. That's what I do. When someone calls me and then proceeds to ask me security question to allegedly assert my identity I reply "well, you called me so how do you prove to me who you are first?" I usually get a "err..." but on one occasion the guy was rather rude and hanged up. The worst thing is that most of the time these calls are genuine. Th…
The fact that they had an immediate answer to the question obviously means that they were asked this question all the time. I wonder how many people happily handed over the info?
It seems that they now just play a recorded message asking to call, and then automatically hang up.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#99OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#100This is very scary for the average person. I've taken to simply not answering any questions (not even to confirm my name) if someone calls me. If my bank calls me then I call them back on a number that's on their web site.
If my bank calls me then I call them back on a number that's on their web site. I'm always amazed at how stupid the security situation is in these cases. Banks, telecoms services, etc. do actually call up and try to 'take me through security', and when I say "tell me something you know about me first so I know you're who you say you are", the best they can usually manage is "well, uh, you bank with [Bank]". It just p…