Would You Have Fallen for This Phone Scam?
krebsonsecurity.com
krebsonsecurity.com
Virtually all call traffic I receive that doesn't fit the above is outright scam attempts, fake IRS / CRA threats, bizarre calls in Mandarin or Cantonese or post-sales "check-ins" to see if I want to spend more money with a service I've already paid for.
So it's unlikely I'd personally fall for this, simply due to a lack of opportunity for the would-be scammers.
That said, with the level of sophistication they're employing I could very easily see how people get trapped by it.
They were a big thing a few years back when Trump was talking about walls and kicking people out of the US; I thought they had died off, but I've also stopped answering my phone.
However, I find it interesting that those calls started shortly after I graduated college and started my first big tech job.
[DHL/FedEx/the Chinese consulate] has an urgent package for you to pick up.
[Failure to pick up the package will result in the package being returned to the original sender./The package has been confiscated in customs due to irregularities. Failure to contact us will result in a formal investigation.]
Please call us... etc.
I assumed they want money in order to complete the delivery, but searching online it appears they want to verify someone will be home and nothing comes of it.
Seem to be some thought they're verifying names and addresses. Weird.
This guy calls claiming to be from the Beijing police. They claim that after she left China, someone stole her identity and tried to make some transactions in her name. They managed to stop him, but now they're investigating and they need to gather evidence. And so they need to get her id and bank account details, etc.
For a while they completely had both of us, and we believed everything they said up until they were asking for her details. She asked for a name and id number, and said she'd call them back. When she looked up the real Beijing police phone number and called them, they said they had no idea what she was talking about.
I've been receiving Chinese language spam on both my Canadian and U.S. numbers for about five years now, and all of them have been DHL impersonators, PRC consulate impersonators, and people impersonating my mobile phone provider "您好,這是Freedom Mobile中文支持blah blah blah"; I've never heard an immigration-related one claiming to be a U.S. or Canadian immigration or customs body.
> Many banks including TD Bank on the East Coast of The US, and throughout Canada are now using voice recognition technology for their telephone banking.
> You can only imagine how easily that is spoofed as well.
That's absolutely hilarious... because the technology that allows a person's voice to be recognized is the exact same technology that allows it to be imitated.
Even worse, the snake oil is leaking to non-banks as well. For example, Amazon now seems to insist on doing an email challenge for every login. Very unfriendly UX. Eventually I'll get around to writing a procmail recipe that grabs the codes out of emails/texts, and spits them to a terminal ready to be pasted.
Is this not true in the US?
They are often now replaced by banking apps that offer a similar feature, as my consumer account with the same bank has done.
We still don’t have chip and PIN, and we most certainly don’t have TOTP 2FA.
Works like a charm. If they have something important they'd leave a voicemail or text message or email anyway.
Banks, insurances, institutes etc will never get my phone number. And my money will never be in a place where I have to worry about it getting scammed. Stolen maybe - but that thief would be very lucky.
And all this fuzz and lack of comfort (simply ordering stuff) [especially during times like these] because I’ve become very paranoid, because of situations like that...
I suspect there are better schemes that can be adopted when the user has access to both a phone and another connected device that can foil MITM attacks using SSL but you can't always guarantee that a user has access to a web browser or app.
In this case all phone calls from the bank should proceed like so (and it should be made illegal to act otherwise): "Hi I'm calling from Example Bank fraud department. Please go to your banking details and find the phone number for the fraud department and call the number listed and quote the reference ABC. I will now hang up and await your callback"
Would it be terribly complicated to make single use credit cards? Like if you have an app from your bank (which they push on you these days, anyways), you could generate a new virtual credit card for every transaction?
Phone numbers cannot be used as sole auth.
This also shows the total flaw in the phone infra. Why can't I rely on the phone number I see?
There are massive holes in most government institutions. You just need to encounter them.
Just one example from many of the Australian government failings:
You may receive a phonecall from Centrelink. It'll be from a private number, so there's no need to even spoof it. They ask for your date of birth, Centrelink ID and address to validate you, which just also happens to be everything you need to steal someone's account.
If you refuse to identify without them first identifying, or if you ask if you can call Centrelink directly to be reconnected, you'll find, you can't.
I received a call from Centrelink, in a week when I also received three other calls purporting to be from Centrelink. I can't tell you which one was the legitimate one, just that I was punished for refusing to communicate over the phone, and had my account closed.
(An account that it took the Minister of Health intervening on my behalf to open - Centrelink are incapable of assessing my illness, and thus my account always ends up in a limbo of processing, without me receiving benefits, whilst still being incapable of most work.)
Similar things exist with the Tax Office, the security puss that is mygov, and so on.
I've had similar stories from friends out of the UK and France. Governments don't know how to deal with situations where they cannot just say that they are the authority.