Amex got quite offended when I did this, and almost chastised me when I got through to an agent after making the outbound call myself. They argued that because they only asked for limited personal information (DOB) it was fine...
I would still do it again!
Eventually they did suggest I call the number on the back of my card, but I was annoyed by their lack of professionalism by this point (I mean, they are asking me to do stuff - giving out information to unknown callers - which they themselves always tell customers never to do!) I said I wasn't going to phone a general number and get stuck on hold for hours over an unknown issue - either give me some reference to get through quickly to the right person, tell me what the problem is now, or send me a letter. But they kept claiming that they couldn't send out letters in the post :-(
In the end, I finally received a letter by mail telling me that there were problems with my direct debit payments. So it was a genuine call but their inability to securely make these calls is frustrating.
The only way to ensure you’re calling amex is to call the number you know, otherwise the scammer will have you call another one.
"Hey, we need to talk about your account. Call our general enquiries number on our website, press 9 and enter 'XXXXXX' to be reconnected to me."
Edit: perhaps the extension would be per transaction, not per-agent, and when the customer calls the extension, the agents system can automatically pull up the customer’s account. These extensions should expire, but given the length of some customer calls, and how often I’ve been disconnected from customer service lately, perhaps it should be on the order of hours, not minutes or seconds
I was disappointed that no alert was sent through the banking app. That would be the most secure option but is explicitly disallowed in the notification settings.
They can include information in the letter they can't include on a phone call, as the mail service is performing the authentication.
My health insurer won't talk to me on the phone without me confirming identity, even if they called me, but they'll happily mail the info.
Never call the number off the letter, though.
Email is pennies per thousands.
Phone calls are cheap especially for nonconnected or robocalls (which would cost for a postal contact).
Postal mail costs $0.50 US in postage alone. The full-up cost of a mail campaign is often several dollars per mailed item, though in bulk, and with bulk rate, I believe it's closer to $0.40 (postage plus a few cents for paper and envelope).
That would cover many thousands of email contacts, possibly nearly as many phone/VOIP attempts.
And the systems required to successfully and accurately generate a postal response on request are also high.
Low-cost systems are high-fraud systems.
I think eventually they got the point because now they have a secure online email system and just leave a message asking me to call back. They still leave a return phone number, but it's getting better.
The only time they do otherwise is on very specific instances where they provide the info, "did you just buy something at store XXX for approximately $YYY"
All banks and credit institutions should be required by law to do this.
applepay, for all my cards, gives me an immediate push notification, despite some cards not doing so for regular chip/swipe transactions. really like that feature & also wish all cards did it for all transactions.
In India, getting an SMS/Email confirming every card usage is a legal requirement imposed by the Rserve Bank of India. The same goes for card usage itself. All credit and debit card POS transactions need the card PIN to be approved. Likewise, all online transactions require MFA.
1: "We need you to verify some transactions. You will receive a text from <number> with the transaction details"
2: "Do you recognise these transactions? <date/store/amount x 3> Reply Y if yes, N if no"
Y -> "Thank you for verifying the transactions. If any transactions have been declined, you may been to repeat them"
N -> "Your card has been blocked and a new one ordered. Please contact us if you need any further advice"
Always use your mobile phone to make the call (although I'm sure its only a matter of time before even that is compromised).
https://toronto.ctvnews.ca/etobicoke-couple-defrauded-of-mor...
You just shouldn't consider any aspect of the phone network to provide authenticity or confidentiality.
They asked for my account number, name, and address for verification. When they got to the point that they sent me a code over SMS and wanted me to tell it to them over the phone, I stopped them and explained that this is also the exact set of steps required to reset my account and that I wouldn’t do it.
I went to a branch in person to unlock my account and the person helping me asked me to enter my password on their terminal so that they could “see the error message”.
I’m still not sure if some parts of this were a more advanced phishing scheme than I had thought was possible, even though it does just seem like a set of confusing practices by the bank.
I wanted to ask her why she would be doing that, but I was a bit more meek in my younger days.
1. You talk to a teller at a branch, and they bring up your account details. The teller see's you have a mortgage with the bank, but registered to a different branch. 2. They have some sort of incentive from the mortgage specialists at their own branch or management, to refer those accounts to their own mortgage team. 3. The mortgage department at the new branch calls me, and says I can do an early renewal at a lower rate, if I come in and see them.
Anyways, I did the early renewal at my original branch, as I had a connection to a manager at that location. Either way, I ended up shaving a good chunk of interest by renewing a year early.
An early renewal would be doing a renewal with the same bank at say the 2 year mark for a new term and interest rate. The bank allows the old contract to expire early, since they're getting the new one for an extended period, like another 3 years. These terms can vary, with 5 years being the most common, but can be shorter or longer and apply to both variable and fixed rate mortgages.
Note: I'm not an expect on this or how it compares to other regions.
As a borrower, there's a big risk with a balloon payment that you may not be able to find financing when it's due, so having a full term loan is very desirable.
Maybe there are other weird types of mortgages but they are usually not available for individuals I think.
(Obviously, initiating a call to a number provided by a potential scammer offers no protection. If someone is intercepting and redirecting your outgoing calls via the phone network, I'd say you probably have a bigger problem than a declined transaction.)
As for them initiating a phone call, it still does remain the best way to contact someone urgently, usually falling back to SMS and/or email when/if you don't answer (this was our SOP when I was in a fraud detection team years ago). We'd also usually tell them to call the number on the bank of your card (because not everyone is able to look up the bank's website, shockingly, so this is the most universally applicable way to give people a number) but my usual spiel was "call us on the number on the back of your card or from our website".
There's also no real way for you to know that they're legit, but an interesting reassurance one bank I know uses is to provide your month and day of birth and ask you for the year (as just part of the verification process). The partial info probably helps some people but I still wouldn't go for it - too many people know my birthday.
And explain to them that we, as a society, need to come up a way of authenticating inbound and outbound calls to ensure we are connect with who the other party claims to be because when you do this it conditions society in to responding and that’s how phishing attacks occur.
Customer support could ask you to authenticate using the TAN already, the hurdle is that you would need to carry the reader at all times.
Unrelated to banks, I believe it could be possible to extend SS7 signalling to not just transmit the caller ID but also a crypto signature/public key which the phone then can verify - or your phone provider could. Think of something like HSTS with a global database, if there is no match for the phone number the provider patches the call through, but if there is an entry, all providers can check for the public key transmitted by the caller and refuse to patch the call if it's missing or faked.
Correct. If someone calls me, the onus is on them to prove to me that they are who they say they are.
However, I usually just block ALL unscheduled phone calls, period. Not only do I not have time for unscheduled interruptions, but banks have secure websites and if they can't make proper use of them, too bad, they aren't going to reach me by trying to call me. They should know that phones are easy to phish with, and stop using phone calls to initiate communication.
Ideally what I want is an e-mail saying "we saw some suspicious transactions, please /log in/ to check that there is no fraudulent activity" or even a more general "please log in for an urgent message" with a suspend button in the online interface.