The ‘Zelle fraud’ scam: how it works, how to fight back
krebsonsecurity.com
krebsonsecurity.com
Number one thing I tell folks in my security training is to never respond or click a link on an inbound message. Instead, look up your bank or service provider and make an outbound call (or direct URL navigation) to them.
https://bc.ctvnews.ca/beware-of-the-delayed-disconnect-phone...
https://security.stackexchange.com/questions/100268/does-han...
If it does, then you should be able to infer that the previous inbound call has (probably [1]) hung up, and it is now safe to call your bank.
[1] A sophisticated enough scammer could hold the line, give a fake dial tone, detect that the number you are dialing is not the bank number they expected you to dial, dial that number themselves on a different line, and relay between that line and yours to convince you that you really did have a clear line, and then keep holding the line when you then hang up and try to call the bank.
As it stands, I’d be afraid of needing to wait 30 minutes in hold, and getting billed 30 minutes of call time by the phone company for the privilege. I’m not from the US, so it’s possible that your banks are doing this part better than the local ones, but that’s always the worry with the phone for me.
> I’m not from the US, so it’s possible that your banks are doing this part better than the local ones, but that’s always the worry with the phone for me.
Since the person is asking about what it’s like here I’m providing that perspective. In Canada banks also provide 1800 numbers so it should generally be free. I thought Canada has mostly unlimited plans but I haven’t had a Canadian phone plan in over a decade.
We are well paid, and as such majority of HN'ers should qualify for premier banking. One of the advantages in that is that you get access to quality in-house customer service, and may be able to call them directly from the banking app. (A really nice feature.) They tend to have good availability too. The plural of anecdote is not data, but I've never had to wait for longer than five minutes when I do have a problem that requires CS's involvement.
https://symantec-enterprise-blogs.security.com/blogs/threat-...
Ehh that doesn’t change anything as far as having to call back. CallerID is trivially spoofed everywhere.
When I initiated a wire transfer, my bank did call me to confirm it.
What's worse, when I called back, I didn't reach the same department and it took half an hour to sort it through.
It was all legit, but was indistinguishable from a scam attempt.
It is not correct that banks will never call you in the US.
Heck, I'm pretty sure I've gotten sales calls from them as well, though I never stay on the line long enough with those to be sure.
I use credit cards (in particular, an Apple Card) for almost every transaction. In fact, I seldom carry cash, which has been a problem, from time to time.
I won’t use Venmo, or PayPal with direct bank account connection. It has earned me scorn, but you really only need to have a problem once, to learn religion. I don’t use credit cards for Venmo or PayPal for cash transactions, because cash advance fees.
I always pay my account in full, every month. It also means I get Apple Cash, for a slush fund.
I do use direct bank account connection for a few things like utility bills, but that is a fairly primitive setup process, where there is no doubt about the other end. Even so, many outfits now allow bill pay, via credit card.
The solution to the time wastage problem is for the bank to have a better method of sending you information than random calls out of the blue. Most banks have a message center on their website, where you can see any messages waiting for you when you log in and can send messages in reply.
What bank doesn’t have toll free dialing numbers, and what voice plan in 2021 doesn’t have unlimited voice calling minutes?
It’s impossible to implement good user behavior when the banks themselves are wildly negligent.
So... they then say "what is the code?" that specifically says "DO NOT share this code". I know what's going on, mostly, but it was still confusing.
After being transferred during after hours, American Express asked me for some unnecessary information and I hung up. I called back and got someone different with a local US accent and I told them what I encountered and they said that's normal (facepalm).
I called back during normal business hours and the more expected experience occurred.
Even if some transactions is suspicious they tell me to call them.
But but it'll filter out most of such scams which are "online-only".
It was “Synchrony Bank,” telling her she was victim of a fraud. I contacted the real Synchrony Bank, and let them know about the fraud. The contacts stopped.
A letter can be discussed with friends and family. It's much easier to dismiss without a con artist whispering in your ear.
The lesson in these times is don’t answer your phone… the phone companies are completely overrun.
I had a call from my bank, and they before the they could even tell me what it was about, they asked me to answer some security questions. When I pointed out out how ridiculous that was, and I asked them to prove their identity first, they didn't even have process for it. Calling back was also impossible since apparently there was no way to get connecter back to the person with whom I was speaking.
I was unable to get back in touch with them, and a week later someone else called from the bank trying to do the same, and the same thing happened again. I refused to answer their security questions and they had no way to prove their identity.
The next time they called, they didn't ask for the security questions anymore and just got to the point immediately. They have never asked for it since. I wonder if I'm flagged in their database as someone who shouldn't be asked security questions.
It looks like you didn't even try it. In order to do what the GP described, when your bank calls you, you say nothing and answer nothing. You hang up and call back on a number you know.
> Calling back was also impossible since apparently there was no way to get connecter back to the person with whom I was speaking.
You don't have to. You just ask the bank when you call them back: did someone just call me a little bit ago? What about?
If the bank can't answer that question, it's time to find another bank. Any reputable bank will be able to look at your file and see that a call was made to you and what the issue was.
> The next time they called, they didn't ask for the security questions anymore and just got to the point immediately. They have never asked for it since.
This does not look like success to me. It looks like failure. What your bank should be doing is sending you a message via some known channel--like the message center on their website, where you can see messages for you when you log in--telling you that there is an issue that you need to call them about. If you're giving information to someone who calls you out of the blue and says they're from your bank, you're setting yourself up to be scammed.
I did do exactly that. I asked them for a reference that I could give when I call back. They couldn't give me that. I then did try to call them back, and said "someone called me about something just now, what was it?" and they were not able to tell me.
> If the bank can't answer that question, it's time to find another bank.
Thankfully, that's not my normal bank. This was the bank that has by car loan. That's my only interaction with them. It's unlikely I'll have more business with them.
> This does not look like success to me. It looks like failure.
Absolutely. This along with the other issues suggests that they value convenience over security. Also, this is not a small bank we're talking about.
I have never seen issues this bad with other banks, but the problem is that when there are banks that get away with this, that suggests people in general do not make a fuss about it and simply accepts whatever people tell them on the phone. If nothing else, it proves why phone scams work.
If the bank didn't even have an answer when I asked them to authenticate themselves, that suggests very few people even ask.
Asked who? The people who called you out of the blue and you weren't sure it was legit? I wasn't recommending that at all. I said, explicitly, that you say nothing and answer nothing when you are the recipient of the call. You only say or ask anything when you are the one who initiated the call, to a number that you already know via some other information channel belongs to the bank.
> I then did try to call them back, and said "someone called me about something just now, what was it?" and they were not able to tell me.
Did they say there was any issue with your account? If there wasn't, then that would indicate that the previous call you got out of the blue was not legit. If they weren't even able to tell you that, then yes, this sounds like a really incompetent bank.
> If the bank can't answer that question, it's time to find another bank. Any reputable bank will be able to look at your file and see that a call was made to you and what the issue was.
That won't help: all the phisher has to do is make a call at around the same time that the legit employee called you. The person you called back would probably not be able to tell you what the call should be about anyway.
And I'm saying that even if the customer support knows about the call, that doesn't mean that the next call you get in 2m from the bank is legitimate.
In all cases, anyone reaching out to you from your bank should be treated as not legitimate. The only way to do this is to call the bank yourself, and get put through to the person who wants to talk to you.
Any other way including the way you said you'd do it is vulnerable to phishing.
I'm saying that checking with the bank doesn't indicate that a call was legitimate, so there's no point in checking with the bank.
If you call the bank, using a customer service number that's already known to you, either they will say there's an issue with your account or they won't. So calling them does tell you, indirectly, whether the previous call (that you hung up on and gave no information to) was legitimate or not. But more importantly, it tells you, regardless of the status of the previous call, whether or not there is an issue with your account, and that's what you care about.
Note that you never have the bank call you back in this scenario. You call them, and that's it. You don't call them and ask them to call you back.
How does the phisher have information about what time the bank is calling?
You shouldn't have to get back to that exact person. Just their department.
Hopefully, this particular experience is rare, but the fact that it can happen at all is somewhat concerning
The only working approach would be to make a law that phone companies must ensure that caller numbers cannot be spoofed in any way and make them responsible for loses due to spoofed numbers.
And require that banks publish which phone numbers they call customers from (like spf is for email), and do so in a format that mobiles can use. So the mobile can show the customer "this is really your bank" or "unknown caller".
As it stands now I receive ‘legitimate’ calls from a credit card company to open new options on my account. Or from my phone company to switch my plan. And the interesting part is that as it is ultimately to improve the caller’s monthly numbers, they won’t offer the same conditions online or through mail, I tried. And calling back the same person is a royal PITA. So in some cases, it costs me to not deal with transactions on the phone, inbound, from a person I need to trust to be what they say they are.
Though to be fair, scamming is still present here, typically involving calling older people and trying to persuade them to reveal bank access codes during a phone call. There two differences with US banks here: - banks are required never to ask for access credentials over insecure channel (phone/email) (though SMS is also not perfect in this regard); - banks are required to educate customers that they never ask for such credentials, educate about fraud scenarios, etc. And they do (at least the reputable ones)
Seems that the PSD2 regulation (including SCA) are really making payments much safer in Europe when you compare to rest of the world.
Also, to admit: I'm a head of financial institution here, quite knowledgeable of the field, both on regulatory and on technical level.
Like everything, it will require a gigantic scandal before anything is fixed/changed and it will open the door for new issues.
I won’t bore with details, but I’m a lawyer who primarily sues banks for customers. And I’ve seen the lawsuits I file lead/contribute to changes in bank behavior and policy.
The regulatory protections are there. Now lawyers need to punch banks on the nose until they decide they want to do more to stop the fraud in the first instance.
But it’s strange, clients have almost like a Stockholm syndrome with the banks. Their rational is often something like “I don’t want to sue them and make them mad, because that might mean I won’t get my money back”
But you’re not going to get your money back unless you sue. Meanwhile deadlines pass and then you’re screwed (and embarrassed)
1. Credit account are closed without a specific reason being given. (Banks have an obligation to give you a reason).
2. Debit card/checking account fraud. There’s a federal law specifically protecting consumers in those cases.
3. Credit card/. Again, a specific federal law for these cases.
What’s noteworthy for each one of these violations, or, more accurately, for each one of these causes of action, is that there is a right to recover attorneys fees. And whenever you have that, then the consumer has an opportunity to find a lawyer who will forgo any payment unless, and until, there is a recovery. That’s how I pursue the vast majority of my cases. I even cover the filing fee for the consumer.
So when I say consumers need to sue their banks, and they get this response of “well they can’t afford a lawyer,“ i’m pretty sure they can afford free. but this pessimistic mindset seems to have taken hold. And I’d like to try and undo it.
In the UK, banks have put in quite a lot of messaging around the fact that they'll never ask for a password -- so the above line from the article ought to set off alarm bells in most customers' minds.
Of course, there are people, particularly older or vulnerable users, who are impacted by this as they might not be aware. Phone scams to get 2FA codes aren't going away anytime soon, sadly.
Also, as an industry, I wish we could move away from SMS-based 2FA. It's kind of amazing that SMSes these days are a barren wasteland -- mostly automated messages, scams, ... and two-factor codes. And some institutions still use SMSes to deliver two factor codes ... including Paypal in the UK.
“We’ll never ask for your password. And we’re not asking for your password. This is just a one-time authentication token. Your password is safe!”
Every time I read post-mortems on hacks and scams in the US, my mind is a bit blown on just how easy most could have been prevented by tiny bits of government regulation that we Europeans take for granted.
Do not hold the carriers responsible for shit we've done.
Hold the carriers and ISPs responsible for their actual crimes, like selling our data to the government and marketing companies like the world is about to end.
I was a phone store monkey working on close to minimum wage a few years back in the UK. I could absolutely swap someone's SIM with no problems what-so-ever and it typically took only a few minutes for the new one to become active and start receiving SMSes (the old one will still have signal - though no more traffic - for a few hours making detection difficult unless you actively try to place an outbound call).
While we're supposed to verify someone's identity, a dedicated fraudster could absolutely trick us and we were never given any proper identity verification solutions, nor enough training, and frankly not being paid enough to care anyway (which also exposes us to bribery/insider threats).
SMS 2FA will absolutely not be secure as long as minimum wage employees hold the keys to the kingdom, and I'm only talking about in-store employees making UK minimum wage. I'm sure the situation is much worse in offshore call centres.
The reality is, mobile phone companies never started out to be identity providers. App developers did that.
It always fascinates me how poorly people understand the nature of scamming and confidence fraudsters. The banks could have every customer recite on video that they have heard and understood the message - many of them will still be vulnerable.
Each small step along the pathway is only a little more wrong than the last - so by the time the guy on the phone says "and we need you to confirm this code with is" on the phone... yeah. The victim isn't really objective anymore. They are not considering this in isolation, but as part of a relationship the scammer has been building for hours if not days.
It isn't that the messaging is pointless, but it simply cannot and will not protect people from their own fallibility.
Honestly, it is a terribly hard problem - and I actively do not know the right way to manage it without simultaneously restricting access to peoples own resources
But I’ll include the PSA I posted on the article as well:
Attorney here (not legal advice).
Please be aware that there is a short deadline required for Regulatory disputes (approximately 60 days). That could have an effect on your claim. Time is of the essence.
And depending on how soon you notify the institution before the deadline, you can be stuck losing up to $500.
Again, please just know time is of the essence and you want to reach to an experienced attorney ASAP if you suffer fraud.
Good luck to the bank which would like to enforce this. One tried, I told them I am leaving, they said it is a misunderstanding and that of course they did not mean to make me pay these 150€.
Generally, in the US, its 60-90 days (the fact that it’s variable is obviously not ideal) and $500 loss limit.
I just checked, it is now 50€ only, and only if the payment was done with a PIN or SMS/app confirmation. This is the maximum amount (so if you had, say 3 times 300€ of fraudulent transactions, you would pay a max of 50€ total - and like I said it is not likely that the bank will make you pay anyway)
Cards can be created to suit most cases such as one-time transactions, monthly subscriptions and "pre-paid" type cards with a defined total which are tied to one merchant. All multiple use cards are valid for a max of 12 months.
Out of 6 banks across 2 EU countries, only two allowed for that.
Another one had dynamic CVV.
I assumed due to convenience and safety that virtual cards were more widespread in Europe, not least because of the requirements such as 3DS for card payments.
At least fintech companies like Revolut and N26 should be available for most Europeans and they offer virtual cards, though with other limitations/costs.
In France I know that Fortuneo gives that possibility, but for instance Boursorama or Credit Mutuel do not.
It is funny how the banking is different between countries in the EU. France is slowly making its way though the 90's while Poland uses a phone based transaction system (BLIK). I always saw Portugal as bing very modern in that way (you had chips on your identity cards for years, we just got them this year, with the new credit-card format of id cards)
Google has made things worse by making confirmation SMSes very easily identifiable, and interceptable at scale with their SMS verification service which is now being pushed down developer's throats. (Google yr66t3YYkAe that's a Google 2FA ID of some bank, seemingly already actively exploited)
Adding confirmation links inside SMSes is what some money transfer companies did responding to the threat of SMS interception, but I think this made it even worse, at least on Android. It's trivial to coax dozens of popular apps into opening a link in the browser, or webview using Android's "intents," thus completely negating any CSFR protection.
This has happened many times in Sweden in the last few years. Banks almost always tried to talk their way out of any sort of responsibility even though scammers took advantage of their pretty bad processes. The banks processes as well as the apps' designs have improved, but I think the point is that essentially nothing of what happened there in the US wasn't happening in Sweden as well. I presume it's the same with the rest of Europe.
This quote from the article is key:
> “Consumers — many who never ever realized they had a Zelle account – then call their banks, expecting they’ll be covered by credit-card-like protections, only to face disappointment and in some cases, financial ruin,” Sullivan wrote in a recent Substack post. “Consumers who suffer unauthorized transactions are entitled to Regulation E protection, and banks are required to refund the stolen money. This isn’t a controversial opinion, and it was recently affirmed by the CFPB here. If you are reading this story and fighting with your bank, start by providing that link to the financial institution.”
Good to see US regulators aren't letting banks off the hook. They should furthermore come down very hard on any bank that even acts like they might not be responsible since that's essentially fraud.
At the end of the day it's an issue of securing human processes as well as regulators holding banks feet to the fire for problems their processes create.
2FA is absolutely the future and I believe globally payments should move in this direction… I’m just pointing out that even in Europe, this has not been the standard for all that long. That said I hope other countries/regions follow the example — the EEA seems to lead the charge on major online issues, e.g. payments and privacy.
However, it is very sophisticated. They somehow managed to actually get a fraudulent charge on my card. When I got the spoofed message from "my bank", the first thing I did was log onto my legitimate account. Sure enough, there was a charge I did not recognize.
The rest was just a series of unfortunate "rookie" mistakes on my part. But the person who called me was highly professional, easily could have been a real customer support representative and spoke English perfectly with no accent.
They took the max, $5,000. My bank thankfully refunded it.
I always thought there was an underserved market if scammers are just filtering for gullible people. So, about time to see more sophisticated scammers casting a broader net.
Obviously, in hindsight the correct way to handle this is to call the bank yourself. The way the scam works is they spoof your bank's caller ID, and you get a standard "do you recognize this charge? Press YES if you recognize, NO if not".
When you type NO, you get a message stating "our fraud team will be reaching out to you momentarily to resolve this issue", followed immediately by a call from a very convincing "customer support" person, again coming in as a caller ID from your bank.
At this point, I made some "rookie" mistakes as I'd mentioned, but hindsight is 20/20 in these cases where they are trying to keep you on your toes.
It's given me an interesting idea.
If we know the bank will refund through insurance than there's a second level fraud where the victim is in on it for a cut of the profits.
Essentially the theatrics of fraud is done and then victim is refunded by the bank and then secretly compensated by the "fraudster" for their participation.
I may be convinced of that kind of scam. Everyone wants to feel like they're outsmarting the system. There's so many unknowns. Will I get the partial compensation? Will the bank reimburse me? I don't know, but I can see myself doing it. That's a problem
When I use Twilio, I have to prove to them that I control a phone number before I can use Twilio make outbound calls or send SMS messages that appear to originate from my number. This suggests to me that the system is built with assumed trust, like email was originally. Is everything too ingrained at this point to add some type of authentication that would prevent this type of spoofing? Something similar to a CAA record, where the owner of a phone number could say “legitimate calls from this number will only originate from $TELCO and $SMS_PROVIDER” would be nice.
Twilio is doing their own enforcement to help their reputation.
https://www.justice.gov/opa/pr/district-court-enters-permane...
Phone numbers are basically identical to IP numbers in their use, and they are declared by the emitting party. Just as you can spoof IPs in the packet headers, you can spoof the telephone number at the tranport level.
We could upgrade to more secure connections, but the whole point of using the telephone network is because of the legacy. I can't imagine a telco putting significant money into improving the network when no customer will pay more for that (right now arguably, spammers are their first class customers ).
There is not much motivation to fix PSTN (and cell networks that rely on or emulate PSTN) as it's being phased out. So things move slowly.
If they were this would have been solved yesterday
Most likely the only reason a young person will ever have to interact with the phone system is to call 911 for emergency services. Ultimately the spam problem will kill the pstn as we know it.
From the 1976 SNL sketch, starring Lily Tomlin. [1]
Former congressman from NOLA, Bill Jefferson, orchestrated scams involving securing minority-preferred business loans to found rural phone companies. Those rural phone companies would then pay him back by getting pre-arranged contracts from African countries like our phone scammer friends in Nigeria.
When hurricane Katrina hit, they found $90,000 in cash in his freezer. Was pretty close to the $100,000 in cash that the DOJ had videotaped him receiving from the Nigerian government's vice president a few days before.
https://www.nola.com/news/article_ed0819a4-9aab-5510-b68c-41...
The concept of a “phone line” with a fixed number belongs to residential service. Pretty much any business premise has a PBX on it, and that PBX is connected to the PSTN by a bundle of circuits including some voice channels and some signaling channels. Some number of inbound numbers may be routed there. Or not! But that has nothing to do with the signaling on outbound calls.
Now for a small business it would probably be sensible to limit outgoing caller IDs to the inbound numbers routed there. In a larger business, PBXes at different sites are connected to each other by an enterprise network, and to the PSTN through different telecoms in different regions. You may have branch offices that only receive calls via the enterprise network, but make outbound calls on local transit. You may route a call from elsewhere on the enterprise network to exit to the PSTN via that branch office, for cost or redundancy reasons. That’s how Twilio itself works. Lots of IT departments have internal Twilios, in that sense.
The upshot is that you need a fairly sophisticated cross-telecom standard for establishing authorization to present a number on caller ID, and no one got around to building or driving adoption of that until pretty recently.
Because couriers offer spoof calling as an under-the-table service to spam caller organizations.
I have no proof of this, but at this point in time my opinion of telcos is so low that I will assume it is happening until I find out explicitly that it’s not.
The fraudulent message asks for a yes or no reply but does not care about the answer spefically; only that there was an answer. So the victims are the people who couldn't ignore the message and had to say no. Most likely the people who say yes are still taken into account , because they confirmed there was a person behind the number. They'll get a new scam later on.
But the people saying no are the target.
A lot of people feel bad if they don't answer the phone, or a message, or the doorbell. So you prey on their niceness.
How to fight back? Don't. The way to defeat the scam is to not acknowledge it.
Ignore whatever primal urge you have to get involved, or teach them whippersnappers a lesson, and cast it into the void.
I bet that graph is U-shaped of % of people that answer unknown messages vs. age. Kids want to be social, and old people don't know any better. With salty Gen-Xers in the middle.
99.99% of the time I let it go to voicemail. I have since the days of cassette-tape answering machines. The only time I don't is if some just texted and said they are calling. Even when my insurance company hold line asks if I want a callback, I'm too paranoid that a scammer could have infiltrated the callback process.
What do you do when your counterpart won't answer their phone?
I answer calls I'm not expecting when I'm expecting a call. Like from a plumber, a recruiter, a paving company, etc.
If I don't, at best I get to play phone tag, and at worst, the other person gets ticked off and I lose an opportunity. I don't like leaving voice mail, particularly the second or third time.
It would be nice if everyone legit had their main number show up to identify them, and it would be nice if they all answered their phone all day, but they don't.
Grandma was fine, fortunately, and she simply turned her phone off because it was ringing constantly with scam phone calls. She was sick of the auto warranty spam all the time, so she unplugged entirely.
The elderly are the ones that still have landlines and cell phones too, so they often get hit multiple times. It's harder for them to disconnect the landline due to things like Life Alert requiring a landline.
There going to be areas where coverage is poor, but for many people, working out of the home is going to be a considerable improvement.
It was...erm...remarkable in its high production values.
Even compared to the auto warranty ones, which I don't get often, but every now and then.
I also got a "hello...hello...hello" call, and seven hangup/no message calls the same afternoon.
I assume the call I answered was a scammer, but a few months ago, I got one just like that and it turned out it was from my physician's office, and I had some trouble getting ahold of them.
I'm not sure what you mean. Like I said, if someone texts me and tells me they are calling then i'll pick up. Or if I get a voicemail saying, "duh, pick up dingus"... then i'll pick up the next buzz.
That never happens because almost no one I care about uses the phone anyway. Exvept that 0.01%.
Right, even 80-year-olds can text these days. You're talking about personal friends who almost never call from unknown numbers.
But with professionals? Would you miss an appointment for a root canal or spend an extra day without your car because you won't answer the phone?
And plenty of people have websites, but on the whole, most local business interactions start with a phone call, and usually it goes to voicemail or a receptionist, so I have to answer when they call me.
Even small time businesses have websites, but they don't do anything usually so it's clear you have to call.
Also, sometimes they try to embrace the Internet, and then they get hacked...
My primary care doctor had a patient data breach by their accountant. A different practice failed to set permissions propertly on the patient information on their portal, and never said anything to me, but silently scrapped it. A plumber that I had over once had all their client information stolen about six months later and vigorously spammed/phished.
Nobody has ever suggested WhatsApp to me. But I gather it's disproportionately popular in some countries.
If the call comes out of nowhere, or if it's from a hidden number, then I'll silence it rather than declining (i.e. hit the power button rather than actually acknowledging the call, so it carries on ringing in silence until they give up instead of being told I'm busy). If it's important they'll leave voicemail or send an email.
The bonus of it only ringing for your contacts is that when your phone does ring, you know it's something relatively important.
Completely changed my relationship with my phone.
What happens if you don't respond to those? Presumably, the transaction will be blocked -- but can you be sure? It would cause me a lot of anxiety not to resolve the issue right away.
This is the real red flag here. No workflow that I'm aware of ever has you read a one-time code to a human, it only ever goes into a text field.
Their standard text messages for auth codes say: Wells Fargo will NEVER call or text you for this code. DON'T share it. Enter code 123456 online to send $1.00.
Their verification text said: Free Msg: Use Wells Fargo verification code 123456 to verify your identity. Reply STOP to stop msgs. Call 1-800-869-3557 if you didn't request this code.
If I place a large wire with my bank, they text me a code and ask me to read it back to them. Granted, I will only do that if I initiated the call.
A while ago, I scheduled a wire transfer through Chase to go through the next day.
While asleep, I got an automated call from Chase asking me to confirm that the wire transfer was placed by me.
By the time I had woken up, my online banking and my bank cards had been shut off.
This is not consumers fault. Everyone is used to banks not being completely impatient and expecting immediate responses. For some other example, by law, you only have two days after a transaction to respond to fraud, or else you could be looking at $500 lost instead of $50. Not immediately answering the phone could make a difference of $450!
It seems like a simple mitigation on the bank's end would be to add warning text to the 2 factor authentication.
"You have requested to change your password via our web portal at yourbank.com. If you did not request to change your password via the web portal, or if someone asked you to give them this number, then it is possible that someone pretending to be a bank representative is attempting to hack your account. The code to change your password is ..... Do not share this code with anyone."
I would personally feel a lot better if every bank had the ability to only allow 2FA via OTP, or only physical key, or even email. My bank uses a "Security Word" which is crazy to me.
They also exploit a small slip up and escalate it into a catastrophic one. For example the scam might start with the assumption that caller ID is accurate, or the assumption that because there is fraud on your account the person is actually from the "fraud department", or the assumption that hanging up a landline terminates the call.
Each of those are small slipups, but they get people bought into the fiction, and then as the scam escalates they don't stop and think through the sequence and realise that the initial assumption was flawed.
Besides that, I think you are right. Binding 'signatures' to what you are authorizing is one of the ways to prevent your authorization from being re-used. There are parallels in cryptography where you sign not just data but also what it will be used for. Otherwise an attacker might reuse your signature.
"SECURITY WARNING The one-time code you requested will arrive shortly. DO NOT give this code to anyone. If someone's calling you and asking for a code, they DO NOT work for O2. Call us on 202 if you suspect fraud so we can protect your account."
"Be alert to fraud NEVER share this code, including with O2 staff. Help us protect your O2 account. To swap your sim, enter code 123456."
Props for including this in the article! All too often the basic legal situation is never explained, leaving victims to believe that blatantly illegal crap is "just the way it is". For example, "identity theft" and fraudulent medical bills.
[0] https://www.consumerfinance.gov/compliance/compliance-resour...
Luckily her credit union was quick to restore the funds with minimal hassle.
Then, some days later I got 3 more payments in similar $1.xx amounts. I refunded 2, but for the 3rd one PayPal wanted to charge some fees. At which point I just blocked the dude.
No idea if this was a genuine mistake or a scam. Anyone knows??
Turns out I forgot I told a friend to reimburse me for beers we had a few weeks before that, and his payment service was verifying my account.
Online banking and all of this digital access to my monies makes me nervous as heck. Double-edged sword. (Yes, I have 2TF hard tokens on all major accounts.)
I was in the Dominican Republic last year and I got a notification that someone had sent me $100 via CashApp. It wasn't a person I recognized, she looked clearly Dominican in her photo, and I presumed it was a similar sort of scam. (I assumed someone saw I had whatever "send to someone nearby" setting turned on, saw I was a foreigner, and decided to try for an easy mark).
I didn't refund it, I didn't cancel it - I just did nothing. And you know what happened?
Absolutely nothing. I waited for the phone call asking me to send the charge back. Nada. I waited for a text explaining it was a mistake. Nada.
It was over a year ago and I still have the $100. So.....maybe it was an actual, genuine mistake?
What's wild is my parents aren't the phishing victim types. They know about not reusing passwords, not sending passwords, not trusting phone calls, all of that good stuff. I'm really curious how they got got.
“This is <bank>, you requested a password reset. Your code for this is 123456. Using this code will change your password. Call us if that’s not what you want.”
Or something along those lines.
Yeah it’s still a fundamentally flawed process, but until they replace the entire process with something better, a slight change in wording would help save some people.
At the very least there should be distinct codes for identity verification when on the phone with your bank and when performing other activities.
> Ally: As Security measure, we will never ask for this number over the phone. Security code: xxyyzz. Call 1-877-247-2559 if you did not request a code.
IIRC, there was one time I did have to verify a code over the phone, and the message that came with it was completely different.
I remember I had to opt-in to get zelle transfers activated. Information, terms of the service, and separate activation of email/phone were done at that time just for zelle. I suppose nowadays it's streamlined... which is not so good if customers don't even know what zelle is.
This seems great but there’s value in these transfers as well.
I had a pair of Apple Watches I was selling and someone wanted to use Zelle to pay for them.
No one has ever wanted to pay for a p2p transaction with me using Zelle.
I said since they had the money in the bank, they would just need to pull it out on the way over. (It was still during banking hours)
They wouldn’t do it. Kept pushing Zelle as a safe way to send money.
By targeting people who will trade real items for Zelle transfers, it doesn’t matter if the compromised account owner gets their cash back.
I even offered to meet them at the bank. They were scamming.
The target is the unaware seller, who has no recourse when the funds magically disappear from their account. They are out whatever goods they had for sale.
It is not typical to take down the license plate or copy the drivers license of someone buying something from you.
There was another one that came in between them that felt the same (language that I think of as "conversational robotese"), but appeared to be VPN phishing.
That isn’t 2FA.
It directly goes to voicemail and they can leave a message if it's important. Should the message involves anything that I might consider important, I simply call my bank and ask for a follow up.
If it's an absolutely critical matter and I don't call or follow up, the bank will send a letter instead which I can then either call or go to the bank for further inquiries
I do the same thing if I get a suspicious email / text from my bank.
Finally, I never really click the links in the emails because I have my bank's website as a bookmark so I'll just use that.
It seems to me that SMS codes are much more often abused like this than other second factors are.
I feel like this is a solvable problem. Don't allow anyone to spoof the caller ID. Ever.
If the bank's phone number can't be "spoofed" then it can only have 1 outgoing call at a time, otherwise, each agent will have an independent line and a unique number.
Financial institutions do not take security seriously, and they don’t take their customers time seriously.
The onus is always on the consumer to protect their accounts. When institutions decide to change their features the customer is not at the table, they’re on the menu.
Not to say that such a service would not also have vulnerabilities. But you hear about all the bounced check / advance fee / text message validation scams going on now, and you would think that the banks would want to get this liability off their hands and into a central service that they can just be rid of the responsibility. (ok, on the other hand, having an irrevocable transfer system might introduce new problems as well, but still...)
I find it unfathomable why we continue to saddle ourselves with one of the most ancient check-writing based systems in the world that people in other countries laugh at us for (or ask in puzzlement, "what is that?"), and have to make all these terrible workarounds to deal with.
Simply describe the action being taken and its significance. Not just a random code message.
The fact that banks use that as a second authentication factor is beyond baffling, and all liability should land on them.
https://scaminvestigations.substack.com/p/better-than-the-ma...
No way a fake banker can get you to sign a nonce for them using your private key.
Scammers have a do not call list. The only people on it are violent drug lords and members of congress. The first will kill them, the second will kill their business (by fixing the phone system).