I'm a scam prevention expert and I got scammed
lupinia.net
lupinia.net
They called me back a minute later (now without Amazon recording the conversation) and asked me for my NVR's serial number so they could connect to my NVR. I was shocked they had a backdoor into my NVR but I figured I'd let it play out. A minute later the technician said that he was having trouble connecting because "an internet virus is corrupting my firewall". I was extremely confused and thought it must be a translation problem. Until he kept insisting it was a problem and became belligerent and angry. He said I needed to pay $300 to have an on-site technician troubleshoot the problem. I got angry because he was making some weird excuse for their camera not working, and wanting to charge me rather than just ship me a replacement. I refused and he started mocking me. I demanded his manager and he ignored me. Eventually I hung up and called Amazon back.
The Amazon technician was helpful and shipped me a replacement. I contacted Reolink via email to complain about their technician. They responded that they have no on-site technicians and that it was a scam!
I was blown away that Amazon would transfer me to a scammer. I contacted Amazon again and let them know what had happened. Hopefully they will figure out how their guy got this scammers phone number and teach him how to find a 3rd party phone number...
1) Amazon is complicit in shady behavior on their platform, whether it's inventory commingling, sketchy sellers repurposing existing, well-reviewed listings for a totally different product or those bribing customers to leave good reviews with gift cards or free stuff.
2) The tech support number could very well be provided by the seller, and you could've bought the camera from a listing from said seller instead of the real Reolink (if the "real" Reolink even sells on Amazon to begin with). Maybe tech support scammers are now using this as a new lead-generation tactic ("legitimately" sell a high-maintenance product but scam anyone that calls for support?).
I use Reolink cameras, in the admin interface there’s an option called UID. Turning that off (theoretically) disables the backdoor. I have my cameras and NVR (which is actually just a python script on an old laptop that uses ffmpeg to capture streams) on their own airgapped lan so I don’t have to worry about blackhats or the ccp using backdoors to watch my kids.
Bought some wireless earbuds a while back, they sent me a horrible knock off. Contacted the store, he said the delivery guy made the switch, took forever but sent me new ones. Left a review stating all of this and warning users not to buy from this sketchy store, my review never saw the light of day.
Then a counterfeit showed up, completely different from the spec sheet and the image on the listing.
I filed a complaint, but they wouldn't give me my money back unless I paid to ship it back to half way across the continent, where they sent it from. Despite them just sending me a piece of electronic waste rather than the real product. Nor would they do anything about the listing.
Never looked back at their scam website again.
I only purchase items that have prime shipping, and that have free returns in case something is wrong. 99% of the time their delivery estimation is accurate, usually within 48 hours of my order or less. If something is broken or I simply don't like it, I return it for free at any one of several places within a 10 minute drive of my house: Whole foods, ups store, or Kohl's. And there's no rush - I have a full month to return the items and the refund is issued before I even get back home after dropping off the item.
Out of the thousands of items I've bought through Amazon, I think maybe one set of Henckels steak knives might be counterfeit (I've ordered two sets of the same knives and they were noticeably different - both seem high quality though).
The parts that aren't amazing is getting items that aren't representative of what I ordered. But refunding is always a breeze when that occurs.
My problem is that it shouldn't be a thing that happens so often (to me). I shouldn't be shipped shoes of the wrong size 3 times before I get shoes of the size I ordered. I shouldn't be buying open box items without being told it's open box. I shouldn't be buying things with the completely wrong thing in them.
Now, all of these can be problems with big box retailers. But the sheer frequency it happens to me on Amazon - it's never happened at this frequency to anyone I know when we would shop in store. Yes, my friend once bought a graphics card at Fry's that just contained a box of rocks. But that was one friend, one time. I've had more of these issues on Amazon, the last ~7 years, than I have for all shopping experiences everywhere else that I've ever shopped combined.
This is my exact experience in Canada so far. But they did something else weird. I wanted to buy Google Store gift card from Amazon and as soon as I made the purchase my account was suspended. It had taken me few hours including lengthy phone call to sort things out. I was told that gift cards are widely used in fraud. Sure, whatever but then why FFS they sell those?
I strongly prefer bol.com. No idea if they ship abroad, though.
Towing companies appear to be a large shell game where your $200 tow is handled my one or more middlemen who eventually get some poor independent towtruck driver to tow you for $75
Amazon should do something that would allow partnering with decent brands. Customers would be happy, brands could keep their reputation, amazon could get a reasonable cut, and they would still sell stuff via flea-market brands and the made up word-salad amazon brands
There are two time when I will use Amazon nowadays:
1) If there is an official store there
Anker is a good example of this. It seems like Amazon doesn't commingle inventory if there is an official store.
2) If I want something faster than Alibaba/Aliexpress
Quite often I can find the exact Chinesium equivalent on Amazon and I get the benefit of returnability if what is advertised is completely out of whack.
This has to be costing Amazon money, but, it's their funeral.
“Is this Jordan’s Tiles?”
“No. This is Patrick. You have the wrong number.”
“It says on their website this is the number!”
“Their website is wrong, this isn’t Jordan’s Tiles.”
more argument with me just hanging up because they’re clueless (someone even had the audacity to ask me what the number was for Jordan’s Tiles like I’m their personal assistant)
And finally I went on Google and searched for Jordan’s Tiles. There my number was on the listing and on a third party source. The right number was on the lower ranking Jordan’s Tiles website. They were so argumentative about being so wrong, it was outside of their ability to understand that the internet can and does give you the wrong information.
It's often cheaper to buy from Amazon but never go through troubleshooting support. Always return or replace.
If that doesn't work, give a 1 star review, wait for the seller to come chasing you with a gift card in return for 5 stars. Change it to 5 stars, spend the gift card, and then change it back to 1 star.
If there were some reliable meta-shopping site that aggregated trustworthy vendors, I would use that--but I can't see how to build one that wouldn't have all the problems of Amazon in the best case; and all the problems of wish.com in the more likely case.
Definitely sketchy behavior on Amazon's part, never dealt with the selling side there so no idea if this is sellers gaming Amazon or just awful market platform in general.
So...what might curtail the proliferation of scams (besides cruel and unusual punishments)? Decentralization? More factors of authentication?
Don't buy 3rd party products sold on Amazon. I always tell people this. They ignore me and then stories like yours pop up.
NOTE: This applies to prime items as well. Amazon's vetting services for 3rd party sellers is nonexistent. I could literally sell you dog shit right now; with no verification I even exist. I've had a seller account for over a decade, and I've not sold a single item. The Amazon Marketplace is an anonymous Craigslist. Please don't forget that.
So buy Amazon Basics and nothing else?
Also I tried to avoid buying from third party sellers but the Amazon website is so deceptive that you are bound to buy something from a third party seller at some point. There is obviously no option to hide third party sellers because that would solve the problem and Amazon's opinion is the problem shouldn't be solved.
You shouldn't be. The amazon store's core business model is allowing scammers to sell garbage to unsuspecting buyers.
Considering they have a backdoor, why did you want a replacement instead of a refund?
I heard this from a security guy and was under the impression it was one of the sacred laws of security. If it's not, it should be - it's a rule of thumb that would stop 90% of social engineering attacks I hear about.
Then, the next time I went to use my card, it was blocked. I called the bank again and spoke to someone new, who informed me that the original calls had been legitimate - they had the same reference number and everything - and the card had been blocked due to lack of response!
Obviously a false positive on the scam detector is less of a problem than a false negative, but was still pretty incredible. No idea what was with all the people talking about being scammed from that number online; I can only assume that they (like the first rep) assumed it was a scam, since if the bank needs to call you, they should tell you to call back using the number on your card, not some random number they give you. But apparently that's exactly what they did.
The critical extra step that they missed was to check that the line was disconnected before calling out. They were using a landline.
The scammers called them, but didn't hang up. Then, when my neighbour called out to their bank, they pretended to be answering that call - going through security, etc.
My neighbour then did whatever the scammers said - because they couldn't possibly be scammers.
The workaround to this is to use another phone (e.g. switch to mobile), or if that's not possible, apparently you can wait several minutes until the exchange times out the connection.
https://security.stackexchange.com/questions/100268/does-han...
Edit: Just read up on the disconnect time (10 seconds for some providers) and yes, a sophisticated scammer could indeed emulate the various tonalities.
https://blog.haschek.at/2016/how-a-scammer-stole-500-dollars...
I'll also point out that the author seems to have some complicated arrangement for their phone number(s), presumably in the name of security, that in fact got in the way of identifying this to be a scam.
And I agree about author - if he had said that he violated an easy rule and owned that I would take his credentials more seriously. Everyone makes mistakes, but he didn't list this simple, well-known rule as a way of preventing this.
That seems a bit extreme, but if their procedures are so crazy as to require circumventing another system's security procedures, I'm not going to bank with them.
I actually had a bank send me an email asking for information that came from another domain, had a header that looked liked it had been badly scanned in, and had links to domains they don't own. When I ignored it, I eventually got a notice that my car loan was in jeopardy because I hadn't provided that information.
They had no clue why I was so upset about that email.
I paid off my loan immediately and never looked back, even though the interest was less than I make off the stock market.
The author had a lot of signals pointing toward legitimacy to counteract their natural skepticism, it was a stressful situation and the nature of a phone call puts time pressure into the decision making, increasing the odds of a mistake.
Your example points out that false positives on the "scam or ham" decision do have a cost to the contact recipient too, so "never respond to anything" comes with risks and costs too. It's hard to be perfect.
I also do a callback (verifying the number they give me via a google search) but it seems like almost no one else does. On one of these calls from a bank, I asked the agent whether anyone else asked to do a callback, and they said no one ever did this.
Overdue bill? Okay cool thanks, I’ll call back and ask to speak to someone, hang up.
Compromised card? Okay cool thanks, I’ll call the number on the back of my visa, hang up.
(This one happened to me) Relative in another country is dying of cancer and needs money for some obscure procedure and doesn’t want to tell anyone else about it only me so don’t call anyone about it? Okay cool, I’ll check and get back to you.
I don’t care how important the matter is; your house could be on fire! If you are calling me and need any type of personal info whatsoever, I hang up and call you or someone I know related to you or just Google that thing!
Same with door to door salespeople. No thank you goodbye.
Hi, the government is giving $5000 credits for people to add insulation, blah blah blah. Can we do a free evaluation? No! I would have heard of this free money falling from the sky from someone I know.
No thank you, hang up, give zero info don’t even confirm my name, close the door or hang up. Goodbye, won’t phish me.
Anyways, maybe there was nothing wrong with providing those details. Maybe they were already available to him on his screen. But the act of asking for that info and making it commonplace for people to just provide it is how so many scams are successful. I don't know how we get away from bad security practices being the norm.
Every time they call me, they just say, "Hi smeej, it's NAME at Dr. NAME's office. We have an update for you, so go ahead and hang up and call us back."
Works like a charm!
I thought that was fairly standard in banking/credit card fraud as well. That's how I was directed to proceed when I got a call from my CC company about fraud: "please call the service number on the back of your card regarding potentially fraudulent transactions"
Last week, I cancelled my Netflix subscription and been trying to remove my credit card details from my account to prevent surprise reactivation in the future. There wasn't an option to do it online, so I went in their chat support and ask them to remove my CC information from my account. Then they asked me to provide my CC number to validate who I am. I told the rep that I am not comfortable sharing my CC information over the chat and prefers only give out my service code or alternative information. This rep kept ensuring that it is secured and they can't see what I am typing in. I asked them to initiate it and I will decide if it is trustworthy to put it down. I got the prompt and it asked for a full CC number. I declined the prompt and told them that I'm not comfortable doing that. And it didn't help that the rep are unintentionally behaving like a scammer. I shared my concerns about the rep behavior and remarks that scammers can say those things. The rep understand my concerns and asked for other information like the email address that is linked in the account and what are two recent activity on the device I uses. I gave out the information and validated I am the accountholder. Then the rep processed my request and I see my CC information is removed from my Netflix account.
I asked for a callback number instead. They hung up and made me go through the entire process again, culminating in a new inbound call a day later and a new sms.
Also: Just call your official bank/card phone number yourself. This number should be on the back of your debit/credit card.
I won't as a policy give out information to an incoming call, and I do call back if they want any info from me. But my working memory is not endless. The topic of discussion had changed three times before he was asked for any information, and the information still wasn't PII, it was a confirmation code. The scammer knew enough about him that he wasn't especially on alert. I can well imagine that flag in my mind that I was on an incoming call having been lost before we got to that point. And I suspect that's exactly how the scam was designed.
I think that any phone calls from a bank about fraud should only be a notification and them telling you to "go to the website, the Contact page, there you will find a number to call in case of fraud". Without naming a web address. And the search engines should mark bank websites and the like as protected, so neither competitors nor scammers can buy ad space when people search for a bank by name.
When I don't recognize a number, I don't pick up. I tell them to email me/text me and that they provide when they called and with what number. Then I might call them back.
Asking extra effort from unknown people will do a few things:
- Scammers won't do it (not yet anyway)
- Spammers won't do it either
- Anyone lazy won't do it
Yeah, BZZZT! End of conversation. Hang up.
all banks should often remind their customers of this. mine does.
banks and phone carriers should do scam and fraud trainings for customers. or friendly reminders.
Went with a local credit union instead
Like maybe the automated "we will never ask you for this info" email should only contain decimal digits and the "we are on the phone and will send you a confirmation code to read back" could only contain alpha characters. Or something obvious and consistent.
Sitting at my desk at work, I get a phone call from my bank on by cell phone. "Mr. Anechoic, there appears to be a security issue with your bank account. We can resolve it for you. For security purposes, can you give your checking account number and the last four of you SSN"?
This is clearly a scam, right? I tell the guy there is no way I'm giving up that info for a random dude that calls me. He stresses again that there is an issue with my bank account, that the account will be frozen, and there is nothing he can do about it without the account and SSN information. I refuse again, and he tells me that I should go to a local bank to get it resolved. I hang up and go back to work. I log into my bank account website, and all seems fine.
After about 20 minutes, something is still bothering me, so I leave work to go to a local branch. I speak to a branch manager about what happened, and she agrees with me that it was clearly an attempted scam and the bank would never call me and ask for that information. But just to be safe, she checks my account on her computer. To our surprise, it turns out there was a security flag on my account!
She calls the bank security desk, they confirm that there was an attempt by someone in another branch a few states to get money from my account and the call I got was legit and logged in their system. We get the account locked out, and then the manager asks to talk to a security supervisor about the messed-up way they reached out to me. The security person basically said "this is how they do things" and didn't see the problem. The bank manager apologized, said it was messed up and she would try to run things up the chain to improve their process.
Damned if you do, damned if you don't.
"Very well. Please repeat to me in writing that if I receive an unverified call claiming to be from Your bank, and asking for my personal details, that I am to give the information and follow all instructions and will not be at fault for damage that might result from this."
As they clearly won't do that, at least the moron will lose face, and quickly so.
That's a big red flag there. So I try and find the phone # of the fraud dept of Citi because anyone can send a text message. Turns out can't find it anywhere in the official Citi site. So I finally give up and call the phone # before they could go further they asked me to confirm a 2FA they would text to me. At that point I noped out and decided if it was a realt problem I'd find out about it another way.
The problem is I now know how easy it is to break into any Citi account just send them a text with a # and pretend to be the bank. The worst part is every every every message I get that is actually being secure always says "You will never be asked for this code" and everytime they ask for it.
It is security theater of the worst degree by incompetents and MBAs and I am getting sick of it.
Hopefully we can at some point stop treating a SSN as a universal password that can never be changed. At least mother's maiden name stopped being a universal security question.
It's security theater giving people exactly what they want. People want to feel secure, but they don't want any amount of actual difficulty in getting what they want from Company A.
Like it or lump it, but regular people really don't want actual security. They want the ease and convenience of no passwords at all, and want someone to blame in case something goes wrong.
Yes, but the real meaning behind that phrase is "You will only be asked for this code by pages served by our domain name or a native app we published." It's unfortunate brevity.
Though, of course, it's completely unrealistic to expect that some bank person would agree to do some weirdo math tricks with SSN numbers :)
Here's one tip for this expert – if you get a 2FA code over text or email that clearly has the line "we will never contact you for this code over phone or text" right under it, DON'T give it to a "support agent" over the phone.
> this is clearly a two-factor authentication code, meant to be entered directly into an authentication page. Which is normally not something that would be relayed over a phone call to a customer service rep. A concern that I raised to Daniel. However, he said that it was part of Apple's system, which they only had limited access to. An explanation that, as someone who works with computers, data security, and API integration professionally, I completely bought
And after reading multiple paragraphs of this person describing money literally taken out of their account in front of their eyes, you get to this line:
> Putting all of this together, the scales started to tip toward this potentially being a scam call, but I still wasn't certain
I really hope they don't have a lot of clients
What makes us vulnerable is that we are human: we get tired, caught up in the urgency of the call and our logical thinking stops working.
The actual story of the article is that we need to design systems that are robust even when people are getting scammed. Able to identify and reverse scamming soon after it happens with easy ways to report it.
I feel like this comment misses the core thesis of the article - that condescension and expectations of human perfection are not effective ways to prevent social engineering attacks and that building systems that anticipate human error is a better approach.
I needed a cashier's check recently at $GIANT_US_BANK.
The teller initiated a 2FA handshake. The text said something like "never give this number to anyone, none of our representatives will ever ask you for it".
I figured scammers probably hadn't set up an entire bogus branch with yelp reviews going back years. I handed it over.
The check they issued cleared, from what I can tell.
If you think that's bad, try applying for a mortgage. It's 100% remote these days, with a mix of multiple communication channels, all bootstrapped with incoming phone calls, emails (and, if you're me, phone numbers from government licensing databases, followed by awkward call backs)
There's a red flag right there — I've never found a bank willing to provide any verification of who they are when calling me. They call me and ask me to give them a code or card number without providing me with any proof of their identity. I've tried to get them to give the sum of the last 4 numbers of my account, but they won't do it.
They always tell me to just call back using the number on my card and try to find my way to the right department. Super annoying.
It's a chicken/egg problem of not wanting to give information first, but a one-way function (hash) is a fantastic idea. The collision possibilities in this particular function are worrisome, though.
It would be difficult to come up with something you could reasonably ask an account holder to figure out on their own that also wasn't easy to randomly guess.
My doctor office required me to provide my DOB before I can schedule an appointment or questioning over the phone. My pharmacist required my DOB before I can get my meds from them. If I don't provide my DOB, they will turn me away and assumed that I'm a scammer.
How else do they prove they are a real bank???
You are making the same dumb mistake this guy made.
It's also a consequence of solutionism, systematic monotonicity, mother-knows-best and externalising costs such that we:
Only add more security solutions on top of existing ones to fix their holes.
Deny the user any choice or agency in setting their own security terms
Never revoke or remove a feature (that would be admitting defeat)
Push the burden in every process on to the user
Create fear in the user - that any misstep will cause them more inconvenience and trouble.
Make security an authoritarian culture such that user will not question or be sceptical.
All of these are antithetical to civic cyber-security that we need available so educated and empowered users can operate technology under their control.
I've been with Wells for over a decade. They have never called me. Never.
I have had "fraud" alerts hundreds of times. They always happen at certain POS, and it's always a text alert.
Some of the stories I read make me viscerally react with "what in the world are you doing with something as simple as a bank account?"
Also a fundamental default is "no action". If you are even slightly suspicious, do nothing. It isn't somehow so important that you stop thinking and just act or react. Just stop.
Really? That's the thing that makes you skeptical and feel the need to use scare quotes?
Banks suck. Hell, mine hasn't even implemented proper 2FA.
And Wells Fargo is so bad they've been caught scamming their own customers:
https://en.wikipedia.org/wiki/Wells_Fargo_account_fraud_scan...
There is a nearly endless list of legitimate reasons for one to hate Wells Fargo.
Once, I got a call about attempted activity on a debit card. The person gave the wrong last four digits of the card number, then the call dropped due to poor cell reception.
This was on Christmas Eve or something. I called the number on the back of the card, but they were an outsourced call center for card replacements. Fraud alerts had been outsourced to a different company, so they had no idea if the call was legit.
I went into the physical branch the next week, and spoke to a manager. They said it could be legitimate or not. I think we ordered replacement cards at that point, and watched the next few statements more closely than normal.
Honestly, the behavior of the scammer sounds more legitimate than the actual non-scam behavior of the last half dozen banks I've dealt with.
But I was pick-pocketed twice in my life. Both failed attempts, but only because of dumb luck. And I thought that would never happen, "because I'm that much present always."
One time I'm wearing a hoodie, and a cheery guy distracts me and sticks his hand into a double-ended pocket and my hand, resting in the other side, instinctively grabs his; a trigger-happy hand-shaking mechanism and a bad choice of pocket. I quickly walk off because his grumpy friend looks like someone who would stab you.
Another time I'm running for the bus, my phone is thrashing forth and back in my pocket, so while running, I quickly grab the phone and stick it in another pocket; two seconds later, a young guy bumps into me, and his hands reach all the way down in the now empty pocket. We land, we stare at each other, and I run for the bus rather than him; I'd have no chance catching him anyways.
So... with some humility: The only way to stay out of trouble is to apply really dumb protocols.
The landline caller ID showed "Madison Police Dept" - the local police. The caller introduced themselves as an investigator working a case with counterfeit bills. "Don't contact your boss/owner because we are not sure if they are in on it." The caller knew details like employees names and the layout of the store. The manager was going through the cash in the back "confirming" serial numbers when the owner got in touch and cleared things up.
I was confused about the end game for the scam, but online I've read a version where they send a courier to pick up the "counterfeit" bills. There's also a version where they convince the employee to purchase moneypak cards to be deposited into an account so that the 6AM audit shows balanced books making up for the counterfeit bills that will be confiscated. [1]
To a person that doesn't know caller ID can be spoofed, getting a call that shows up as coming from the local police department can put you in a mental state that it 100% is the police, and it will take a lot of counter information to realize that it isn't. Between that and the convincing reason to "don't tell your boss", I'm afraid this might be an effective scam until it's more widely known.
[1] https://old.reddit.com/r/Scams/comments/ryp4fg/i_got_scammed...
Standard procedure for everybody in the last 20 years should be: Whenever I get a call about security or fraud from the bank, I thank them for the notification and tell them I will call them back, and hang up. Then I call the number on my credit /bank card, not the number I was called from. Fortunately there is a lost or stolen cards so there is no queue time and tell them I received a fraud alert notification.
They... said that:
> The caller ID showed the correct name and number for my bank, but caller ID data is so hilariously easy to spoof that it might as well not even exist.
Honestly, what is with the low quality comments attempting to undermine this person's credibility?
you can purchase FULLZ from darkweb marketplaces, these contain name and address and social security number and often come with credit card details too
with that, you can do social engineering like this, you can also remote desktop into any computer nearby to their zipcode (from a different darknet marketplace of compromised computers being rented out) and purchase things online from that, making it less likely to be flagged
the idea that "scammers intentionally do obviously red flag things to weed out discerning people and just target susceptible people" is just one segment of the market. doing smarter more cunning things is entirely available and entirely lucrative
I recently had to speak with the Zelle FPD because it had frozen my ability to send (but not receive) after I had made some small trial transactions. Also, I use a Google Voice number with Zelle, which Zelle seems not to like.
I was shocked at the depth of questions that the Zelle FPD agent asked me. My SSN, DOB, address and recent transactions were expected. But then it went deeper: state where my birth certificate was issued. Fine. Car loans I had. Okay, this is all stuff on my credit report. But then it went past me: where my kids were born and their DOBs; my brother's DOB and age; my wife's DOB and age; my mother-in-law's (!) maiden name. Keep in mind this all after I've authenticated myself to my bank including a phone password I have setup. And, it's for a secondary checking account that I have less than $1000 in.
Real bank FPDs have a crazy amount of information on not just you, but also your family members.
I personally would hang up if any of my financial institutions called me and I'd call them back.
I thought it was really unprofessional of them to operate this way.
> I've never heard of a call center system that can accept touch tones seamlessly while a call is active, and it would take extremely sophisticated audio processing capabilities to be able to do that, since the frequencies used by touch tone keys heavily overlap the frequencies of human speech.
It's actually happening all the time. VoIP systems _do_ extract touch tone (DTMF) from the call and convert them to appropriate out-of-band messages (either on RTP or SIP, there are multiple standards). This might also happen with VoLTE, although I didn't verify it myself.
So, while the request was indeed weird, there's nothing technically strange about typing touch tones at any point in a call. Regarding the fact that those frequencies overlap with human speech, it's expected because they were designed to be transferred over phone lines, which are made for human speech frequencies. Since landlines here in Switzerland have been converted to VoIP several years ago, I often hear DTMF tones appearing from nowhere in the middle of a call and covering the voice of the other person. The reason is easy: some intermediate system detected a tone and sent the corresponding SIP/RTP message, while also filtering the tone out of the audio. On the other end of he line, that out-of-band message triggered the generation of an actual in-band tone, whence the result.
Then you must not underestimate the pressure under which you then are, because either way is not a pleasant situation (getting scammed or having been scammed already trying to contain the damage). I fully believe the author that they only skimmed that mail and weren't even aware that this is 2FA. It must have seemed like "just some one-off verification code".
Then I think there is also this phenomenon where experts think that just by being an expert on something, they are immune to it. Not consciously, rationally, but lingering in the subconsciousness. It reminds me of the show "the good doctor" where a seasoned oncologist is diagnosed with a brain tumor and completely blocks off any conversation about it and rejecting treatment. I think that very well illustrates what I mean.
Another anecdote to add here if that Jim Browning, a YouTuber focused on finding scam call centers, getting into their systems to gather information and shutting them down in the end got his YouTube account taken away from him through a scammer on the phone. So I'd be careful with claiming this could never happen to me because I'd never do X. Until the day you do without realizing.
This tactic is actually used by so many scammer, it's weird that a scam prevention expert is saying that kind of things. His sentence prove how effective transferring it to someone else is powerful, how could they transfer us to a supervisor?!
They are working in call centers, they just give their phone to someone else, often time someone with more experience with scams thus better to convince you. In some case I have seen situation where they use that tactic as good cop / bad cop, where the first one is threatening, this bad thing will happens if you don't act quick, etc... and the next one is more on your side, he believe you, but you need to works with him. I even seen some where they say that they have no other choice but to open a police report with your local police, and ask you your local police phone number, act like they talk with them on a second phone (as if they couldn't put you on hold and initiate the call directly on their system) and then say that the police want to talk with you and they will call you directly (I guess using fake caller id again but with the police phone number).
It's all part of their tactic.
The critical difference, though, is that he reported the scammer read off a list of his actual recent transactions.
That part, especially when combined with this second story so soon afterward, makes me think some third-party budgeting tool or something was recently breached and just hasn't announced it yet.
"A ringing phone demands to be answered"
Technology projects a form of authority (disconnected from any real power) in the same way that written words were synonymous to truth for illiterate 13th century peasants.
To follow your logic, which I am not criticising as it's a valid approach given how dysfunctional cellphones are as trustable systems, I would say it's better not to have a phone. But there's the road to living in a woodland shack and eating spider and squirrel broth.
With Vercel, Netlify and many others offering free stating hosting and let's encrypt https certificate there is no excuse to run a site without an SSL certificate.
To me the moral of the story and that you should never ever follow instructions by an alleged bank calling you asking to confirm informations and, even worse, give them codes over the phone. Especially if you are an "expert".
The most unbelievable part is falling for the idea that if you had called back your whole account would be on hold. That was such a smoke bomb that was easily detectable.
If this seemed plausible as your dislike your bank and don't like the service why not take your business elsewhere?
From your own story, if anything, Wells Fargo prevented this from becoming a much bigger problem and acted very promptly to your request.
The most important reason to have it is to avoid the automatic search engine downraking that google now applies to non-https sites (helpfully elevating all manner of spam and scams over decades of technical documentation).
> To me the moral of the story and that you should never ever follow instructions by an alleged bank calling you asking to confirm informations and, even worse, give them codes over the phone.
Unfortunately, as pointed out by many others in this thread many banks engage in and even sometimes require you to comply with scam indistinguishable behavior, making your maxim hard to follow. Even ignoring that, everyone makes mistakes, gets distracted, or has bad days... this makes security very hard, even for experts.
Imagine that domain names contained the public key in them. I Google up "mybank", and it gives me https://8c789ad256afa4ca93f1af6436e7adff51cdd1c380de7d7cc78b... This takes <1000 lines of code to implement and already stops the only thing that HTTPS stops: a noob MITM positioned attacker who can't break into CAs. The MITM can't change the Google results, because you already came from https://a4244aa43ddd6e3ef9e64bb80f4ee952f68232aa008d3da9c78e..., which you somehow obtained before the MITM happened.
Hardware authentication factors are, of course, immune to these sorts of attacks because you can't confuse the victim into forwarding their second factor back to you. However, I don't see why you couldn't construct a specific scam setup for those.
That's where (I hope) I would have stopped; if X sends me an authentication code, the only reasonable place to send it back to is X.
Also, I think the real fraud department would be completely OK with me saying "Oh, thanks for spotting it. I'd like to call you back now please - give me your name and the name of your department, and I'll look it up and call you back - what do I do to bypass transfer hell?".
Getting on the blower to Wells Fargo on the other line was smart, but you need to have multiple lines at your disposal.
Pet theory: voice recordings will be the next fingerprints/DNA, at some point it will be trivial to identify the person based on old recordings. At which point we can retroactively convict these people years or decades later, when they thought they were out of the woods.
Limitations exists for most crimes and torts. Prosecuting someone years or decades later when potentially exculpatory evidence is less available (e.g. no one, even themselves can remember their alibis, etc.) would be highly unjust.
I know that this scam is relatively sophisticated compared to others, but I have to think if I was a scam prevention expert that I wouldn't tarnish my own name by putting a story with this much raw honesty out there.
They basically violated rule #1 of scam avoidance which is that no legitimate business cold calling you will need you to do anything with urgency.
Either that or it's a way to make potential customers feel better about the obvious mistakes they made.
I think it's an absolutely excellent story to publish. The road to becoming an expert in any field or art is paved with failures, and your own failures tend to be the ones you learn the most from. Plus in a field that primarily deals with dishonesty, being this transparent does help build a positive image.
I wouldn't consider sweeping one's mistakes under the rug a virtue. Quite the opposite - I think it shows integrity.
> They basically violated rule #1 of scam avoidance which is that no legitimate business cold calling you will need you to do anything with urgency.
There's an overlap between legitimate but dysfunctional systems and very sophisticated scams that can make telling them apart almost impossible. The author points this out repeatedly - is this a super sophisticated scam or are the bank's systems just that bad?
For example, other commenters in this thread have pointed out instances where their banks would ask them for information that they should never ask for.
Some combination of new consumer protection laws, infrastructure improvements, and law enforcement attention is desperately needed. I don't know why this doesn't get more attention. Is it just the historical attitude that each of us are responsible for protecting ourselves? Is the line too blurry between a legit business and an outright scam?
I wasn't tired, but I got a call at 8AM on a Saturday as I was just about to wake up, and I hadn't slept very well. You may be very aware of all the latest security practices, but in the end you are human, a big bag of emotions swirling around. And it only takes a moment where you are vulnerable to scam you successfully.
The lesson here, I think, is: it could happen to you.
I cannot fathom how a tech professional would do this. I mean, I read their justification, but it still doesn't make an ounce of sense to me, other than their brain was shut off for the entire call.
A normal person knows that scam calls come in all the time, so they're on the alert for them. A normal person has their MFA device or has MFA on text and they know these two mechanisms have codes they should never relay. If they got an MFA via email they'd immediately have their suspicions up.
A normal person, through the normalcy of their system, assumes that if this bank is having trouble dealing with them they'd have trouble dealing with everyone and that's just absurd.
But if you're the _abnormal_ person, then you assume your custom setup is the problem. That's because 99% of the time it is the problem. He's fucked himself into being a social engineering target.
Back in the day, this was a thing with Linux. You'd encounter a bug in a Windows app hosted through the WINE runtime and you'd think "Well, it's WINE, it can't be perfect. I'll just report it on WineHQ and go about my life". Well, sometimes it wouldn't be WINE. It would just be the app itself. But you assumed that because you're the weird one using WINE. Everyone else is using Windows. So you blame your own setup and your bug doesn't get fixed because it's in the wrong place.
So this is my attitude to a lot of security stuff. I want to be the normal user. Huge advantages:
- If something is broken for you, it's broken for everyone. So no one will blame you for consequences.
- If something is weird about it, it's weird; you should be suspicious
- If things go badly for you because of it, no one will blame you because they can relate; you will get help easier
One morning in college I was awakened by a call after staying up all night working on some project. The caller claimed to be from my home country's embassy and was investigating a fraud case I was involved in. He started by confirming my personal information such as DOB and passport number and he had them all correctly. He asked me to physically visit consular office, which I told him was impossible because I was in some program.
At this point I sort of give in, but he asked if I was preparing for piano/music rehearsal - a huge red flag that awakened me from foggy mind. During adolescence I attempted to becoming a pianist and dedicated lots of time to training and competitions, but this is a past that was never mentioned on resume or to friends. There couldn't be legitimate way to relate that experience to me.
I said yes and asked why he knew it. He began talking about my musical experience and what awards I won, without knowing that all these bits sounded to me like a pretentious show of being knowledgeable about my life.
One lesson from this and Op's story is that the scammer can attempt an attack at any moment, including downtime of brain activity.
This is how it is at almost any company I have ever worked for. They always say things like "We prefer that you ask questions if you don't know" or "We would rather get a hundred false reports than miss one valid one." That sort of thing.
And then when you follow through with what they ask for, it's just like the quoted part says.
> results in condescending info-dumps or intimidating interrogations
It's not just a cyber security problem folks. This is pretty much a global problem, because no one ever really wants to be bothered over trivial matters, and no one really wants to believe the boy who cries wolf; even if the wolf is real.
None of this will get better until people in general become both intellectually and morally wiser. So get a drink and some popcorn cause this is gonna be a while.
When I received the call from them, they asked for my date of birth and other information. I explained that I'm not comfortable revealing my details to an incoming call and to give me their extension instead. When I did this with BoA or Chase, they'd immediately understand my concern.
The SFCU person on the line, however, gave me some passive aggressive statement about me causing extra work. This was followed by me calling their official number on their web page and having to wait about 20-30 minutes to get through to the extension number to the same person, which proved that the previous call was legit. However, said person proceeded to mock me for having wasted our time.
I love SFCU but they really need to understand how scammers work.
I've had close to 100% success social engineering confidential information out of financial services companies and other service providers about myself using only information that would be available to a scammer.
So, if a scammer knowing your name and address could call your bank and talk them into giving out your DOB, then going through the effort of calling them back before giving it to them really would have been a waste of time.
Well yes, as you're slowly reading this entire case, with the prior knowledge that he is getting scammed, and having all the time in the world to find the mistake or red flag in his actions, sure enough you'll find it. How very smart and vigilant you are.
But as the article already explains, those are not the conditions in which a scam happens. You don't know you're being scammed. The person sounds helpful, exploiting your inner desire to be cooperative. There's a sense of urgency, which disrupts calm and clear thinking. It was a very sophisticated and well prepared scam, which increases trust and makes you glance over or "forgive" small oddities.
Ironically, the fact that some of you chose to criticize somebody showing vulnerability is very emotional behavior, not rational behavior. Perfect candidates to be scammed.
By the way, are Americans still logging into online banking with a username and password? That's it? Please tell me that's a joke.
For financial institutions identity verification of existing and new customers is a way more complex topic than most people realize. Fraud is an issue but so it’s friction. If it’s too hard to login or to open a new account, people will use/move to a different service. So in the US institutions use “invisible tools” to authenticate users and minimize the risks. Third party services collect huge amounts of user data which is then used to verify customers’ identities in a probabilistic way. (For instance the odds that a fraudster is logging in into your bank account from your phone and from an IP that you have used numerous times in the past are very low) So while the impression is that only a username and a pw are used, that’s not the case.
So in short: security is not the only goal of the financial services available to the masses. The goal is finding a balance between security and friction.
When I called, I immediately got connected to a live person. Second mistake: you can never get through the voice menu to a live person so easily. Anyway, the guy sounded convincing, and said I could get a special discount on renewal, so after some further conversation, I commented that I should be able to log in online and get this same deal, which was my preferred method. At that point, he finally put me on hold and then the call disconnected.
I've had this attempted scam tried on me twice in last 4 months. You know it's a scam for sure when they try to prevent you from hanging up.
Also, always disconnect. Don't just listen for a "dial tone" after they hang up.
I really think this detracts from the credibility of a "Security expert".
* A call comes in from a number I don't recognize, it goes to voicemail.
* The voicemail message says "This is the fraud prevention department at $BANK, please call us back at $NUMBER"
* I pull out my physical card, call the number on the back (which does not match $NUMBER). I go through the menu tree to get the fraud department and ask if the call was legit.
Interestingly enough, at some point the bank modified the menu system so that when you enter your card and the fraud department has called you they'll bypass the menu completely and transfer the call right to that department. Clearly I'm not the only one that does this and they don't necessarily want to discourage this behaviour.
For this reason, I am extremely stubborn about inbound calls. When my bank/superannuation/etc. call me about something and ask for any personal details, I explain to them why it's really not okay for them to be doing this, request a way to call them back via some telephone number that is published on their official website, and then later follow up with a formal complaint.
Who knows whether it actually does any good. Probably not. :/ EDIT: I mean, it definitely protects me, but I don't know if any of these orgs have changed their practices.
I put the effort on the bank, as the bank has the duty to safeguard my money, not the other way around. The bank's responsibility on suspicion of fraud is to block the transaction and summon the account holder.
I use the bank's channels for communication and this does not include random calls. It communicates with me through the bank's web page and app and it has never sent me any email. This is true for my experience in Poland and Portugal. The Portuguese bank used to have a crappy web-banking system and even this worked properly. When I got contacted by my bank, it was an in-person summon with no ability to discuss through the phone, the end.
Being so "remote" these days that we do not consider it important to go to the bank in person is maybe the issue. It is ridiculous one's ability to handle one's fortune in a phone call. It should be bureaucratic by nature.
I can understand being busy but not a single time the article's writer mentioned he will go and sort things himself in the bank. Are physical banks rare in the United States?
As the people most capable of remediating the vulnerabilities in our telecommunication and banking systems, I think we ought to close ranks and insist that our employers do a better job of protecting the innocent, even if it means breaking a few conveniences.
FUD. Hackers and scammers exist, sure, but your friends and family are always most likely going to be victimized by friends and family.
Outsiders have to work to collect intelligence, gain access and obtain your trust. Friends and family already have all three prerequisites.
Bernie Madoff didn't become the most prolific con-artist in history by cold-calling strangers. And consider what demographic is most likely to try recruiting you into the latest MLM scheme.
I'm receiving monthly payments, but once payment bounced back because my local EU bank switched their intermediary bank, something normal client shouldn't care about, but I learned about hard way because WF is not updating their database of intermediary banks and routed my payment through outdated intermediary bank.
I was pretty pissed about my own bank not informing me about changing intermediary bank, so I changed my receiving bank to different one, although in the end it was Wells Fargo problem not keeping their records up to date.
Guess what happens years later after my other bank merger with different bank, Wells Fargo once again ignores new intermediary bank and bounced back the payment.
I dunno if this is standard US international banking experience, but I find it extremely unprofessional and unheard in other countries that payments would be bouncing because bank is too lazy to update their intermediary bank database, not sure what operation they are running in Wells Fargo.
In the end company made exemption for me and they are sending me money directly from their Asian account, because apparently you can't get worse banking experience than with US banks.
After reading all that... I noticed that the "scam prevention expert" isn't serving their site with proper https.
And who knows, maybe the person reading along at the NSA will also enjoy the article :)
That said, I've had a lot of these calls and fortunately not fallen for them once. The funny thing is that eTrade (I think) has a system where you can ask for a callback but then they'll go right into taking your information. When that happens, I followed the play book: I asked for a phone number that I could find on ETrade that I could add an extension for to get to this person. He gave it to me and everything along with some sort of quick access code I was supposed to use to get whomever I hit to pass me along.
Well, I did the whole thing and the person at the other end in the ETrade system that I dialed said "It's okay, I'll just take care of it, sir". I mean, at this point I just sucked it up and went through with the process since I figured I dialed the number from their website to get there and then the extension so surely it has to be legit, right?
But I just know someone is going to point out a way that I could have been scammed through this mechanism.
That extension could be forwarded to an external number.
Long story short, I could have ended up with a subscription on a set of questions for 20 dollars a week, which was given only after a set of legitimate surveys were given on behalf of Apple. I of course notified Apple of this, but I never got the 20 first dollars back, before cancelling the "subscription" I had apparently signed up for.
I really wanted to track the guys down, but they had been very careful in covering their tracks with proxies and mailbox addresses, so in the end I considered it too much work. But I did spam them. Perhaps I could have even used their mail for even more spam, but I suppose they just use throwaway mails anyway.
Not sure how they got through the cracks of Apple, though. IMHO it's pretty damning for the reputation of Apple to work with guys like that.
I got called twice in my life, both times in response to a ticket I had filed but didn't necessarily need a response to (firstly a complaint about some new hardware authenticator that was worse than the old one (I was hoping enough complaints might make them pick a better replacement next time), secondly about phishing-but-legitimately aka Sofort which they now, two years later, finally semi-blocked).
From the post, since it mentions this being routine and normal, plus the comments here, it sounds like americans are called every month or so. Is that impression correct? Is it because of this credit card system where basically anyone with your account number has withdrawal access identical to what we use 2FA (chip and pin) for? With IBAN it's more of a money destination than a source. Direct debit exists but I have yet to see it abused, not sure how that works exactly, and definitely never got a call to confirm this or that.
I would've filed in small claims court but the filing fee is more than the loss. So I looked up all his family info and addresses, and next time in his neighborhood I'll be knocking on their door for my money.
And, I'll just keep finding creative ways to chase him down, online and off, until the day I die. I'm never letting it go and eventually if I had to "take" the money from him through other means (him losing money), that's what I'll do. I'll be sure to double or triple his losses though if it comes to that.
This part sounds weird to me; surely helpdesk employees don't have access to full employee records?
Further, if the scammer already had this much information, couldn't they have used a name of any helpdesk employee who actually does work there?
With all this info they can call up GoDaddy and redirect your domain (and all your emails) to themselves, or call AT&T and sim swap you. Why even call the actual account holder?
https://www.zdnet.com/finance/blockchain/fbi-warns-sim-swapp...
As for these “confirmation” emails or SMS — they are so dumb !!! Why don’t they just include a full description of the ACTION you are supposed to have taken, that you are expected to be confirming? In big red letters before the confirmation number. That way the scammer won’t be able to trick you. Sheesh, these companies haven’t figured out to include that?
Even if your bank is really calling you they will still understand if you call them back on the number you have.
Personally, I've received such calls before, and the first thing I'd ask for is a case number, and that I would call the support number printed on my credit card, to get back to them. Of course, if someone co-opts that number, then I'm also SOL, but I'd imagine then this would be engineering on a larger scale, rather than a specifically targeted whaling attempt.
This says it all. You may be the best expert and everything you want, but when you are tired you are no longer an expert, and it's something that practically can't be learnt to self-identify.
If you think that X will never happen to you, wait until you are tired and we'll see about that.
The issue is, it was a card that I keep only because it's the oldest card I have, that I don't really ever pull out of my wallet anymore. I'm not familiar with the underground stuff but I suppose stolen CC numbers are typically sold reasonably fast (months, not years) and used while they're still fresh? If that's the case, while two random anecdotal data points don't prove anything, I start to wonder if it's possible that WF was recently compromised.
I was buying a 2 yo Toyota car at an official Toyota salesplace. Before this, I've bought three used cars, looked at tons of videos (eg Chris fix on youtube) on how to check the car itself so I don't buy something that risks needing expensive repairs two years later. I wasn't super prepared against the salesman before though. But he wasn't looking like, and behaving like, a salesguy. He was a bit uncertain in his way to talk, and it felt like I was more sure of the buying process than he was.
I had two main concerns - I didn't want to buy a lemon ("Monday specimen") or a crashed+repaired car. The latter may mean things like bearings being slightly out of alignment and leading to wear quicker. So I voiced those two concerns and asked whether this car had ever been repaired, "No, nope.". I asked about service subscription, the guy whispered "I shouldn't say this, but it's better you get it at the other place which is closer to you" (also an official Toyota place).
Since my daughter has allergies, I asked about smoking or animals, "njet, nada, nopes".
Well, a month later the car was completely registered to me and I got access to the Toyota digital registers and surely enough, it had been smacked along the side by a truck. It also already had a service sub pre-payed on it, so that was him getting out of a 350€ service at their place. A final insult was that, as the chemical perfume smell of the cleaning agent came off, it had a foul pungent smell of wet dog.
I confirmed this with the previous owner too, she'd had a dog in the car. Had to buy a replacement air filter and clean the car internally, but at least my daughter doens't call it the "smelly car" anymore.
Pretty happy with the car, and would likely have bought it even if he was completely truthful, but having been lied to, and fallen for it, makes me pretty angry.
Feels good to share the story :). Don't forget to like and subscribe.
I had called their support line to dispute a charge, spoke to an agent for a bit, and they put me in the dispute queue, and then hung up on me after 20 mins waiting. I call back, repeat the process, wait 20 mins and got hung up on again.
Then an hour later, I received text message telling me that my Citi account was frozen, with a (phishing) link to reactivate it.
I had called Citi using a new phone line (not linked to my existing Citi account), so for the phisher to text this new number means that the call center must have leaked it soon after intentionally hanging up on me.
It’s possible that my number was randomly targeted, but the timing was very very suspicious.
Off topic: The site has a contact form and a login page, but no https?
I think it might be time to change banks...
I think a lot of sysadmins following best practices (not every box or estate on the net are compromised, and this is not to say zero-days don't exist) are getting frustrated with security "experts" like this who simply can't even be bothered to practice what they preach...
There isn't a more polite way of phrasing this really...
"Extremely sophisticated?" The tones are just a sum of two sine waves of known frequencies. That's trivial to detect. What am I missing?
I went to read the comments here to see if Daniel somehow acknowledged this
It can be set by the caller to anything, if they have access to some trunk from an operator that allows this. It's another trust based thing, with no automated verification.
Trusting caller ID was the initial mistake. Never trust caller ID with your money. It's like trusting sender names in your spam folder mean anything.
"[...] Wells Fargo will not contact you by phone or text to request this code."
To be fair, that should be about as large as the title text, and displayed before the code. And the scammer was likely doing a good job of keeping the author distracted enough to miss that.
No bank advertises this from what I can tell.
I think if you're going to be a Scam Prevention Expert, you should at least familiarise yourself with the user experiences of these services so that you can detect when they're potentially being used in a scam.
This was too quickly dismissed. If you know a bank isn't up to your personal standards, don't cave into using them anyway! There are so many alternatives that the decision to keep using them should be seen as the primary or root cause of the problem.
This person is not even close to being the best…which is irrelevant, since they should have known better anyway.
That being said, bad stuff can happen to anyone regardless of who they are.
> Lupinia Hosting Is Shutting Down
Original archived here: https://web.archive.org/web/20220331074459/http://www.lupini...
Even if I get a text message flagging a purchase that I initiated I still won’t call the number they text me with I’ll always go to their website via url I type and call the number there. Surprised an expert isn’t doing the same.
NEVER give details over the phone on a call you didn't initiate EVER.
Uhhh, when I see any SE I assume it happened because the user / customer is making use of a giant beuracratic system and nobody knows how it works and what is supposed to be private data and what data needs to be sent where, along with government pointing gun at you to send 5 pieces of ID all over the place ASAP without you ever understanding which ones are needed for what purpose. The very reason these broken, impossible to understand systems exist everywhere is because "the user is too dumb, stop being elitist".
Imagine if you logged into runescape and instead of entering user / pass, it said you need to have your IP address authorized, then you need to get a runescape license, then they need a picture of your iris. But you also sent your iris to some pizza shop to "prove" you own your house, and you have no idea what steps that pizza shop took to secure your iris photo (none). Then to get your IP "authorized", runescape tells you to login to some weird website you've never heard of before, and send it two pieces of photo ID (which you also sent to a paint shop to order paint), and then that website says "please give us your phone number so you can open our secure phone app", and then you open the "secure phone app" and you have no idea what it just did or what data was sent where or what data about you it just assumed you're now supposed to keep secret. I don't know, is this concept like not obvious to internet people? It's called ungroundedness.
The reason I'm writing all this without burning my eyes on this stupid color theme, is because whatever typical bullshit narratives HN will prop up as usual in response to this article here are completely invalid. This classic "boo, hoo, you're an elitist" talking point is irrelevant nonsense because in most cases the user hasn't been tricked; he hasn't been provided with a system that allows him to use it properly. But oh wait I just wrote about this last week as the cliche was made again then. I actually WANT a system that makes "elitists" secure and doesn't care about unqualified people (and I know lots of people who also want this, it's what UN*X users like to think of themselves as): https://news.ycombinator.com/item?id=30780519
That’s because you have a debit card instead of a credit card. Get rid of the debit card. There are Zero consumer protections.
lol
Edit: looks like accessing it over HTTPS just gives you a broken looking site saying "Lupinia Hosting Is Shutting Down".
Her other post also mentions "I'm a professional web developer". Unsure what she does for living. Her site shows lots of interest for tech but not at a professional level.
I think you could argue that this guy gives us this long (and somewhat implausible) story in order to:
a/ support the line of business he is in and
b/ to justify all the privacy intrusions and obstructions that banks are undertaking
"How i used social-engineering and HN to growth hack my scam prevention business" or something like that. This is some grade a bullshit.
Different bank, but they had all the basic information, but then started asking for information that I know they don't need (secret questions and answers) and when I told them it was sus they hung up.
You should never give out ANY information on the receiving end of a phone call. Period. Ask what their name is, what department they are in, hang up, call the number you were provided prior, and ask for the same department/person and describe the details of the call.
If the bank calls you, hangup and call the bank number listed on their website.
A. Fraudulent charges are YOUR BANK's problem, not yours. There is no reason to take any risk or share any information. You can agree that charges are fraudulent, but that's the endpoint of your responsibility.
B. Don't give out any information to an inbound caller. None. (except to acknowledge fraudulent charges)
C. Don't try to figure things out. You don't need to reason through it. This author spends SO MUCH time trying to reason out whether this is or is not a scam call. WHY??? Just hang up and move on. If it makes you feel better, you can always call you bank back.
"Putting all of this together, the scales started to tip toward this potentially being a scam call, but I still wasn't certain. It was all circumstantial and conjecture, and a lot of it seemed very legit, plus the difficulty of accurately putting together the information needed to make an attack like this against me without also including strategic disinformation that would tip me off about where they got their data. I needed more information. It was time to push back on this." >>WHAT??? Why do you need to push back? What's the point? Hang up!
"So, I was immediately suspicious, and started asking technical questions; " >> NOW you're suspicious? Again, why ask technical questions here. Who cares? Move on!
This author spends FAR FAR too much time trying to outsmart the scammer - and in the process gets outsmarted himself.
Edit: Nevertheless, I give the author a WHOLE LOT OF CREDIT for being willing to post this. I'm sure he was a bit embarrassed, but sucked it up for the greater good and education of all of us. Thanks!
No legitimate bank would do this. They say "call the number on your card, and mention reference # NNNNN"
Wells Fargo is a criminal organization: https://en.wikipedia.org/wiki/Wells_Fargo_account_fraud_scan... so there's no reason to assume an impostor would be worse.
Anyways, I am extremely aware of caller ID spoofing. I use it myself to show a usable callback number on a VoIP outgoing-only line.
And the 2FA - I would be incredibly reluctant to give a code over the phone, even if I had initiated the call.
LOLOLOL OP