Number one thing I tell folks in my security training is to never respond or click a link on an inbound message. Instead, look up your bank or service provider and make an outbound call (or direct URL navigation) to them.
Number one thing I tell folks in my security training is to never respond or click a link on an inbound message. Instead, look up your bank or service provider and make an outbound call (or direct URL navigation) to them.
I had a call from my bank, and they before the they could even tell me what it was about, they asked me to answer some security questions. When I pointed out out how ridiculous that was, and I asked them to prove their identity first, they didn't even have process for it. Calling back was also impossible since apparently there was no way to get connecter back to the person with whom I was speaking.
I was unable to get back in touch with them, and a week later someone else called from the bank trying to do the same, and the same thing happened again. I refused to answer their security questions and they had no way to prove their identity.
The next time they called, they didn't ask for the security questions anymore and just got to the point immediately. They have never asked for it since. I wonder if I'm flagged in their database as someone who shouldn't be asked security questions.
It looks like you didn't even try it. In order to do what the GP described, when your bank calls you, you say nothing and answer nothing. You hang up and call back on a number you know.
> Calling back was also impossible since apparently there was no way to get connecter back to the person with whom I was speaking.
You don't have to. You just ask the bank when you call them back: did someone just call me a little bit ago? What about?
If the bank can't answer that question, it's time to find another bank. Any reputable bank will be able to look at your file and see that a call was made to you and what the issue was.
> The next time they called, they didn't ask for the security questions anymore and just got to the point immediately. They have never asked for it since.
This does not look like success to me. It looks like failure. What your bank should be doing is sending you a message via some known channel--like the message center on their website, where you can see messages for you when you log in--telling you that there is an issue that you need to call them about. If you're giving information to someone who calls you out of the blue and says they're from your bank, you're setting yourself up to be scammed.
I did do exactly that. I asked them for a reference that I could give when I call back. They couldn't give me that. I then did try to call them back, and said "someone called me about something just now, what was it?" and they were not able to tell me.
> If the bank can't answer that question, it's time to find another bank.
Thankfully, that's not my normal bank. This was the bank that has by car loan. That's my only interaction with them. It's unlikely I'll have more business with them.
> This does not look like success to me. It looks like failure.
Absolutely. This along with the other issues suggests that they value convenience over security. Also, this is not a small bank we're talking about.
I have never seen issues this bad with other banks, but the problem is that when there are banks that get away with this, that suggests people in general do not make a fuss about it and simply accepts whatever people tell them on the phone. If nothing else, it proves why phone scams work.
If the bank didn't even have an answer when I asked them to authenticate themselves, that suggests very few people even ask.
Asked who? The people who called you out of the blue and you weren't sure it was legit? I wasn't recommending that at all. I said, explicitly, that you say nothing and answer nothing when you are the recipient of the call. You only say or ask anything when you are the one who initiated the call, to a number that you already know via some other information channel belongs to the bank.
> I then did try to call them back, and said "someone called me about something just now, what was it?" and they were not able to tell me.
Did they say there was any issue with your account? If there wasn't, then that would indicate that the previous call you got out of the blue was not legit. If they weren't even able to tell you that, then yes, this sounds like a really incompetent bank.
> If the bank can't answer that question, it's time to find another bank. Any reputable bank will be able to look at your file and see that a call was made to you and what the issue was.
That won't help: all the phisher has to do is make a call at around the same time that the legit employee called you. The person you called back would probably not be able to tell you what the call should be about anyway.
And I'm saying that even if the customer support knows about the call, that doesn't mean that the next call you get in 2m from the bank is legitimate.
In all cases, anyone reaching out to you from your bank should be treated as not legitimate. The only way to do this is to call the bank yourself, and get put through to the person who wants to talk to you.
Any other way including the way you said you'd do it is vulnerable to phishing.
I'm saying that checking with the bank doesn't indicate that a call was legitimate, so there's no point in checking with the bank.
If you call the bank, using a customer service number that's already known to you, either they will say there's an issue with your account or they won't. So calling them does tell you, indirectly, whether the previous call (that you hung up on and gave no information to) was legitimate or not. But more importantly, it tells you, regardless of the status of the previous call, whether or not there is an issue with your account, and that's what you care about.
Note that you never have the bank call you back in this scenario. You call them, and that's it. You don't call them and ask them to call you back.
How does the phisher have information about what time the bank is calling?
You shouldn't have to get back to that exact person. Just their department.
Hopefully, this particular experience is rare, but the fact that it can happen at all is somewhat concerning
As it stands, I’d be afraid of needing to wait 30 minutes in hold, and getting billed 30 minutes of call time by the phone company for the privilege. I’m not from the US, so it’s possible that your banks are doing this part better than the local ones, but that’s always the worry with the phone for me.
> I’m not from the US, so it’s possible that your banks are doing this part better than the local ones, but that’s always the worry with the phone for me.
Since the person is asking about what it’s like here I’m providing that perspective. In Canada banks also provide 1800 numbers so it should generally be free. I thought Canada has mostly unlimited plans but I haven’t had a Canadian phone plan in over a decade.
We are well paid, and as such majority of HN'ers should qualify for premier banking. One of the advantages in that is that you get access to quality in-house customer service, and may be able to call them directly from the banking app. (A really nice feature.) They tend to have good availability too. The plural of anecdote is not data, but I've never had to wait for longer than five minutes when I do have a problem that requires CS's involvement.
https://symantec-enterprise-blogs.security.com/blogs/threat-...
Ehh that doesn’t change anything as far as having to call back. CallerID is trivially spoofed everywhere.
When I initiated a wire transfer, my bank did call me to confirm it.
What's worse, when I called back, I didn't reach the same department and it took half an hour to sort it through.
It was all legit, but was indistinguishable from a scam attempt.
It is not correct that banks will never call you in the US.
Heck, I'm pretty sure I've gotten sales calls from them as well, though I never stay on the line long enough with those to be sure.
I use credit cards (in particular, an Apple Card) for almost every transaction. In fact, I seldom carry cash, which has been a problem, from time to time.
I won’t use Venmo, or PayPal with direct bank account connection. It has earned me scorn, but you really only need to have a problem once, to learn religion. I don’t use credit cards for Venmo or PayPal for cash transactions, because cash advance fees.
I always pay my account in full, every month. It also means I get Apple Cash, for a slush fund.
I do use direct bank account connection for a few things like utility bills, but that is a fairly primitive setup process, where there is no doubt about the other end. Even so, many outfits now allow bill pay, via credit card.
The solution to the time wastage problem is for the bank to have a better method of sending you information than random calls out of the blue. Most banks have a message center on their website, where you can see any messages waiting for you when you log in and can send messages in reply.
What bank doesn’t have toll free dialing numbers, and what voice plan in 2021 doesn’t have unlimited voice calling minutes?
As it stands now I receive ‘legitimate’ calls from a credit card company to open new options on my account. Or from my phone company to switch my plan. And the interesting part is that as it is ultimately to improve the caller’s monthly numbers, they won’t offer the same conditions online or through mail, I tried. And calling back the same person is a royal PITA. So in some cases, it costs me to not deal with transactions on the phone, inbound, from a person I need to trust to be what they say they are.
The lesson in these times is don’t answer your phone… the phone companies are completely overrun.
But but it'll filter out most of such scams which are "online-only".
It was “Synchrony Bank,” telling her she was victim of a fraud. I contacted the real Synchrony Bank, and let them know about the fraud. The contacts stopped.
A letter can be discussed with friends and family. It's much easier to dismiss without a con artist whispering in your ear.
After being transferred during after hours, American Express asked me for some unnecessary information and I hung up. I called back and got someone different with a local US accent and I told them what I encountered and they said that's normal (facepalm).
I called back during normal business hours and the more expected experience occurred.
Even if some transactions is suspicious they tell me to call them.
The only working approach would be to make a law that phone companies must ensure that caller numbers cannot be spoofed in any way and make them responsible for loses due to spoofed numbers.
And require that banks publish which phone numbers they call customers from (like spf is for email), and do so in a format that mobiles can use. So the mobile can show the customer "this is really your bank" or "unknown caller".
https://bc.ctvnews.ca/beware-of-the-delayed-disconnect-phone...
https://security.stackexchange.com/questions/100268/does-han...
If it does, then you should be able to infer that the previous inbound call has (probably [1]) hung up, and it is now safe to call your bank.
[1] A sophisticated enough scammer could hold the line, give a fake dial tone, detect that the number you are dialing is not the bank number they expected you to dial, dial that number themselves on a different line, and relay between that line and yours to convince you that you really did have a clear line, and then keep holding the line when you then hang up and try to call the bank.
It’s impossible to implement good user behavior when the banks themselves are wildly negligent.
So... they then say "what is the code?" that specifically says "DO NOT share this code". I know what's going on, mostly, but it was still confusing.