How I lost control of our bank accounts to a phone scammer
robservatory.com
robservatory.com
“With all due respect, you called me. How do I verify you?”
“Well you have to answer the question otherwise we can’t fix this over the phone.”
“OK that’s fine, just give me some way to contact you when I call the main number.”
“No, there’s no way to do that. If your don’t answer these questions now, you’ll have to go to a branch.”
This was entirely surprising to them. In the end I had to go to an office and show my forms of ID, which I found amusing because they didn’t even bother to verify that the name on the check matched the account. But anyway. This bank, at least, is not yet on board with good security practices.
Perhaps I should have said: here are five possible transaction amounts and dates. Tell me which one is real and then I’ll verify my identity to you.
If you run into one of them, the quickest resolution is calling their preferred services line and saying “I just got a call from the Fraud Department but was disconnected; can you transfer me?”
Like why didn't you start with that! Some companies just don't teach their reps to care about security.
Last week I got an email notice that a payment was due for a household bill. It came from mailer@constantcontact.com and contained a link to a Google Form which asked for a credit card number. The form itself even has Google's warning not to provide credit card numbers down the bottom. It never even named my agent, where I was living or what the bill was for or anything that made it believable.
I forwarded it to them and said I wanted to report some potential phishing. A legitimate person responded from their mailbox noting that they don't accept excuses like that, and pointing out the bill must be paid and noone else had ever questioned it.
I work so hard to train users about scams but I just have no idea what to do about the rest of the world.
Assume that it's only going to get worse and act accordingly.
I received a PayPal phishing email once which included PayPal's actual security footer at the bottom. It helpfully pointed out that communications from PayPal will always address you by name, never as "Dear customer".
I was amused by this, since the phishing email started off with "Dear customer".
There must be some population of people out there who are looking for the footer, but not bothering to think about what it means. (Or possibly a population of scammers who copy the official formatting without checking whether it's something they really want.)
> How do I know this is not a Spoof email? PayPal is committed to preventing fraudulent emails. Emails from PayPal will always contain your full name. Spoof or "phishing" emails tend to have generic greetings such as "Dear PayPal member". To learn more, go to the PayPal website and click Security.
I genuinely can't distinguish official Paypal emails from phishing emails - and that's because the Paypal emails look like bad phishing emails rather than because phishing emails are so sophisticated.
EDIT: Good write up here: https://cantoriscomputing.wordpress.com/2017/03/04/paypals-e...
This isn’t a hypothetical concern either, having spam filter go crazy happens more often than you expect, and some of them drop emails completely rather than putting them into a spam folder (looking at you Microsoft).
Unlike PayPal we make it easy to verify our domains. https://monzomail.com
I ignored them and sent the spoofed emails to the spoof addresses at both eBay and Paypal, which seemed to be entirely ignored. After the required amount of time passed I reported the auction winners as non-paying, and I finally got my seller's fees "refunded" to my eBay account.
Then, a couple of weeks ago, I attempted to get eBay to actually transfer my fee credit to my bank account. eBay responded with, "We would really love to help you out with this. but due to COVID-19 we can't."
Somehow one of the fraudulent buyers has had an eBay account since 2012, and it's still active and has a 92% positive feedback rating. Their current auctions include a used gynecological examination chair. It's as if they're flaunting the fact that they can get away with whatever they're doing without being held accountable by either eBay or Paypal.
I have a paper letter here from my dentist, the purpose of which is to explain that they've cancelled all routine appointments, because duh, of course they have.
The letter addresses me as "Mr" in some places and as "MrNicholas" (no space) in other places. But to be fair it also claims the problem is COVID-9 (not COVID-19) so I'm guessing that correctness was not the number one focus of the person typing it.
It's an NHS dentist, so unless we have millions of deaths I expect the practice will continue to exist and receive funding as before. Such practices are funded partially on the basis of the number of patients who are notionally "theirs" to look after and that hasn't changed even if providing non-emergency services is not a priority now.
And on subsequent emails people only look for rough visual similarity as a sanity check. That's why scams keep it there.
The E-mail started «Dear $FORNAVN...» (Where ‘fornavn’ is Norwegian for ‘first name’)
When I called them up to ask, the helpdesk rep just sighed and suggested that the mail merge script had probably crapped out. Again.
Again, same situation, wanted to very who I was and when I wanted them to verfy who they was we ended up in a circle-dance.
But it is important and getting their number or in your case, a branch to go into - something you can prove with a degree of confidence is important. Many will happily give out information. In my early days of work(before CLI and still analogue exchanges afoot) a friend pulled a joke upon me, phoned up pretending to be TAX office and to verify details. It's easy to fall foul of such things and been a source of many scams against less aware and older people less savy of such.
One way is to partialy give information and ask them for some back that they are verfying againt.
Also if you ask them to verify details they will (legit even) use the data protection law flavour of the country to say they are not allowed to do that and very easy to get into a circle-dance.
Which makes online more secure than the whole phone network with all it's legacy overhead opening up to abuse such as spoofing. Bit like the early days of the internet and spoofing IP's, not so easy today (mostly if routers configured right as most are).
I discovered it is a real hassle to change a business operating account number. Providers who, in the past, were happy to start doing ACH through your account with minimal documentation require a lot more to change that ACH account number. In one case, they asked for something I don't think I can provide (a scan of a canceled check) as the bank doesn't send those anymore. I'll have to see if they really only need a void check.
I was recently targeted by I-don’t-know-what. Third party opened a fault ticket on my BT FTTC line, and then through a combination of SMS SC spoofing, real links to BT systems, and false links to very plausible looking “book an engineer visit” screens tried to get me to invite a criminal over to play with my technology.
The idea was likely to get me to welcome some unknown party into my home to mess with my router - I would assume putting some kind of packet sniffer in place to skim data and cards - but I honestly have no idea to what ends.
As a general rule, I ignore all communication from banks and service providers, as I’ve nearly fallen for a “card fraud” scam twice - the second time, they already had my card, and had already done some petty fraud that they wanted to talk to me about, with the hope of me giving them access to my online banking. The worst case in ignoring them is that they will try again. If it’s actually important, they’ll keep trying. If it’s fraud, I’ll notice and will contact them.
The problem is that number is nowhere on the website. How do I know that text is actually from HSBC? How do I know the number I’m being asked to call is legit?
I’ve tried to explain to HSBC that they are training their customers to be susceptible to scammers but they just don’t get it. I had this conversation with someone in the fraud department where I said, “at least put that number on your website somewhere, so if I go to Hsbc.co.uk and search it turns up” “we don’t want to publicise the number sir” “Well out it on a page that isn’t displayed on the site, but which still shows up in a search if I search for the number” - “I’ll pass on your concerns”. That was about 10 years ago. They still do it.
When I got a fraud call and was asked to authorise I told the agent that I didn't trust them unless I had a number to call to verify, so the agent on the phone told me to call the number on the back of my debit card. They give every person the number explicitly now.
The banks got rather upset when the gov sent that COVID-19 text with a link in it. Silly move, and we’ve seen plenty of fruadsters take advantage of it.
And there is no one to blame but the carriers. I really hope the FCC's new anti-spam rules kill this problem dead in the water.
Just keep a registry of every organization that you've given permission to to fake phone numbers, and which phone numbers they're allowed to fake. Make them route those calls through a special system and give them a secret token that that system will verify. Centralize your client/token/virtual phone number registry across all carriers (it's no different from certificate-authorities). If one of the accounts starts sending spam calls, revoke their token. Done.
STIR/SHAKEN is handling this at the provider level. There are an awful lot of PBX installations out there, with hundreds of makes and models and service lives in decades. You are absolutely not getting every business with a trunk line (e.g. essentially every business with more than one telephone) to participate in a protocol change.
It seems to be related to other stuff the US is behind on, but I've given up on finding out how it could be fixed in the general (last 20 years) political climate.
We had an effective program for a few years eliminating telemarketing calls on landlines.
Banks sometimes make it hard to do the right thing. Last year my bank called me, I didn't answer the unknown number and they left a message. The message had a phone number to call and a case number. I'm not going to call a number someone gives me, so I called the main number and asked to be transferred. After a few transfers to the wrong people, it eventually became clear they couldn't transfer me to this particular fraud department.
I physically went into a bank branch. A very nice banker there tried to call them for me, spent 20 minutes on hold and being transferred around. They were able to confirm the call was real, and what it was about. But the final conclusion was, there was no possible way to reach the person in this fraud department, they had to call me. We arranged a 1 hour window where they would call me and I'd be sure to answer the phone.
There is a government agency cold emailing people, telling them to fill out a form that that asks for Bank Name, Account Number, and Routing Number.
Way to teach people to be safe.
At the same time the IRS is telling people to avoid scams by not clicking links in emails: https://www.irs.gov/newsroom/irs-issues-warning-about-corona...
That looks super shady.
In fact my bank recently did try to reach me for fraudulent charges and they did it by text and at the end it said "call the number on the back of your card" so I would suggest just like the IRS will never call you directly; assume your bank will never call you. They might text you, email you, have their app send you a notification but never a call. and they will always say "call the number on the back on your card"
They don't care about security at all; they just want to be able to say "we warned you" if you get robbed.
This is also more broadly true of the consumer lending industry. One of the things that totally boggles my mind is that consumer loans are bought and sold, and then a consumer just receives a random letter one day: "hey, start sending your payments to me now!" How on earth is the poor consumer to know that the random person who is demanding money actually holds the note? And it's not like the student loan or the auto loan or the mortgage loan originator actually has a phone number one can call where someone actually reliably will answer the phone and will actually know whether the note was sold or not (have you tried to get a student loan servicer on the phone?)...
I think probably the only solution for that industry is to legislate rational security practices at them.
Sometimes when a legitimate company asks me to verify something, they do it by telling to me. As in, "I need to verify your date if birth. Is it xx/yy/zzzz"?
"Scammers using line-trapping technology to trick victims, police warn"
I suspect they affect landlines, but the articles have confusing photos showing smartphones.
Basically, if you hang up your landline, it doesn't sever the connection.
Having DND enabled all the time could have unintended side effects though.
They have multiple types of verification codes, like ones for wires and another verifying your identity if you call customer service.
Avoiding fraud is complicated already and will continue to be a problem forever. As people get better at identifying scams, the next one will emerge. As companies create new policies to avoid fraud, "jerk"s will figure out ways to manipulate it.
I'm not sure a long term solution exists.
I think the only thing that helps is time. The longer a technology has been around, the harder it is to fake. Fraudulent gold or currency is pretty tough to do and the people tasked with tracking down the offenders are effective. With most internet-based scams, the technology is emerging. It will take a long time for detection and mitigation to catch up.
Obviously there are ways to prepare yourself, and rules to follow, and red flags to watch for. But you won't really follow the rules unless you believe that "yes, it can happen to me". It might be when you are busy or fatigued or in the middle of a big transaction or whatever.
Writing the story is good for the ones that don't know.
I had to explain that it was, in fact, and showed her the software that we had licensed ...
Fortunately, the carrier put the order on hold and sent her a text message asking her to confirm the order, so I was able to regain access to the account and reverse the purchase.
I called the carrier's security, told them the story and gave them the address of the hotel where the scammer would be picking up the phones he had ordered, but they were not interested in following up.
Why would they be? All they're interested in is avoiding transactions that might be marked as fraudulent, they're not interested in actually fixing the issue. Thats the polices issue, not your carrier.
Disclaimer: I do not work for Plaid, but have used it in the past.
/s
If your bank every does that to you, close your accounts and switch banks.
Why did he not realize this after the fact and point it out as a missed red flag? Has anyone had their bank read them their SSN over the phone? That sounds like a massive PII compliance issue.
The deeper lesson here is the power of cognitive dissonance. If you get even slightly fooled, your egotistic brain will Stockholm Syndrome you into working for the attacker, to postpone the embarrassment of acknowledging to yourself you got a little bit fooled. The worse it gets the deeper your denial will grow to stop you from cutting off the attack.
With everything available online, there is no reason to step into a branch or have an ongoing phone ‘relationship’ with a bank. I can’t remember the last time a financial institution called me about an account. Even credit cards have moved away from fraud check calls to simple and foolproof yes/no verification messaging.
Outside of non-specific marketing and upsell calls, any call I get out of the blue can only be a scam.
1) Because the whole system was designed back in the day of one single integrated phone company (Ma Bell/ATT in the US), so having any form of authentication was unnecessary, because only the one single phone company was ever responsible for handling anything phone related.
2) Because caller-id is an 'add on' that has no relationship to the underlying phone number "address" that is actually used to route phone calls. It is just an extra text string sent along from the call initiator for the purpose of appearing on a display at the destination end.
Is this seriously a thing? A bank that uses one-factor login? Not only that, but a weak one too? This seems absolutely ridiculous. Why would anyone use such a terrible bank? Isn't the bank at least required to try to protect the customers money? It's usually not that hard to get a hold of a number belonging to someone else. Where in the world is this?
SSN is alsp a stupidly bad usage as an authentication factor. A lot of people have access to it, it's not unique to the service and you can't just change it whenever you want.