I heard this from a security guy and was under the impression it was one of the sacred laws of security. If it's not, it should be - it's a rule of thumb that would stop 90% of social engineering attacks I hear about.
I heard this from a security guy and was under the impression it was one of the sacred laws of security. If it's not, it should be - it's a rule of thumb that would stop 90% of social engineering attacks I hear about.
Then, the next time I went to use my card, it was blocked. I called the bank again and spoke to someone new, who informed me that the original calls had been legitimate - they had the same reference number and everything - and the card had been blocked due to lack of response!
Obviously a false positive on the scam detector is less of a problem than a false negative, but was still pretty incredible. No idea what was with all the people talking about being scammed from that number online; I can only assume that they (like the first rep) assumed it was a scam, since if the bank needs to call you, they should tell you to call back using the number on your card, not some random number they give you. But apparently that's exactly what they did.
In the standard/credit card section (not, for example, credit card debt collections), it was rare to have to make outbound calls, but when they were needed, no information could be given out until the customer answered security questions. Some customers questioned this because it was exactly what they’d been told never to do. They were told that of course it was right to be cautious, and they could call back, but that they would need to wait in the queue and likely speak to a different person. This was all before they could even be told what they were being called about.
Perhaps half the people questioned the process upon receiving the call (“you called me, and you want ME to prove who I am?”, but very few hung up and called back.
From memory, this was mostly improved later on - no security questions needed unless some sort of action needed to be taken on the account.
The only thing we can do about "bank behaviors make it easier for scammers" is to change bank behaviors. It's not an easy process, but unfortunately it is a necessary process.
Guess it will take a few years of getting slapped for it to filter down.
The process to get listed is the same as a scammer’s process to ensure you get listed.
Some exchanges will say “no we would never handle this with DMs over telegram”
/gets listed by being introduced to someone with a DM over telegram/
The critical extra step that they missed was to check that the line was disconnected before calling out. They were using a landline.
The scammers called them, but didn't hang up. Then, when my neighbour called out to their bank, they pretended to be answering that call - going through security, etc.
My neighbour then did whatever the scammers said - because they couldn't possibly be scammers.
The workaround to this is to use another phone (e.g. switch to mobile), or if that's not possible, apparently you can wait several minutes until the exchange times out the connection.
https://security.stackexchange.com/questions/100268/does-han...
I was confused because I was calling to make a song request and had no idea that this contest was initiated because they had just played a certain song.
Modern "landlines" when used with DSL or fibre are also no longer "true" landlines, instead the modem/router acts as a SIP client and gives you an FXS port to plug an analog phone into. While it could theoretically emulate this behavior (by keeping the SIP session open for a few more seconds), I don't believe any of them do - in any case it's trivial to test by calling a different phone that you control, hanging up on your "landline" and seeing whether the other phone hangs up immediately (it should) or if the line is held open for some more time.
If this is still a thing (I frankly don't see the purpose of it), it would only apply to real landlines where your phone is directly connected to your phone socket without a modem/router in between.
Someone would call and all the phones would ring (or you might turn off the ringers on some of them so only one main phone actually rings). So someone might pick up the phone in the entrance hall and the caller would ask to speak to Becky, and Becky’s mom would yell up the stairs ‘BECKY PHONE’ and then put the receiver back down while Becky runs into her big sister’s room to grab the upstairs phone, and carry the whole phone, trailing on its wire, into her bedroom, slamming the door on the wire for privacy, before she picks up the receiver to answer.
On the shows they would sometimes hang up the phone, then somebody else picked up a receiver and the call continued?? Phones don't work like that! Go try it on your real phone, and you'll see!
It never occurred to me that US phones worked differently than Aussie phones.
The fact I was so bothered by this probably says an awful lot about what sort of person I was as a child. Its no accident I fell in love with computers.
Editing to add that more detail, since I’m basically contradicting your memory of how it worked:
I’m fairly certain it didn’t work if you dialled out, so you may not have come across the circumstances to test it. Also, the other person would probably also need to be participating in testing it, because otherwise they will hang up as soon as you do.
I’ve just remembered another detail - I think there was something different about the tone you heard. If you received a call, and the other person hung up, you would hear the disconnected beeps. If you made a call, and the recipient hung up, I think you would hear the disconnection, but then just silenced.
By the way - I was also confused by seeing how phones seemed to work in the US - like pushing the hang up sensors (is there a name for these?) once to switch lines for call waiting. I never really connected their strange behaviour with how the phones in Aussie worked.
Actually, is this all related to party lines? I’m fairly sure Aussie had these. NZ did.
Some other comments said there was a timeout after which the call was disconnected if the receiver hangs up.
Well, a few decades ago (80s-90s), at least, landlines sure did work like that in Australia, if you were the one who received the call. I played around with that a lot as a kid. Maybe you just tried it on calls you initiated?
This is dumb though. Just don't put it down until becky picks up.
I could also theorize about the different switching actions going on, where up until the other party picks up there's already only one phone on the line, but that's getting into phone system/phreaking stuff that is way out of my depth.
This is similar to the other answer regarding answering a different phone in the same house, but perhaps more necessary if sharing a line with neighbours. Distinctive ringtones may have made this phone line non-disconnection behaviour unnecessary though.
I’ve never experienced a party line - but they sound ridiculous (and fun).
The most anecdotal statement ever, but a data point nonetheless.
[0] https://bc.ctvnews.ca/beware-of-the-delayed-disconnect-phone...
Edit: Just read up on the disconnect time (10 seconds for some providers) and yes, a sophisticated scammer could indeed emulate the various tonalities.
The thinking by phone companies is essentially: guy calling pays for the call, so we can milk each call for a few extra cents each time even if they're shady or a wrong number.
https://security.stackexchange.com/a/100342/143105
TL;DR It was just how analog phone worked, users came to rely on it, digital exchanges reimplemented it (with a timeout)
Yes: https://bc.ctvnews.ca/beware-of-the-delayed-disconnect-phone...
Looks like you would have fallen for it.
So if you're served by a switch that operates this way, the scammer just holds the line open, plays dialtone and ringback tones appropriately, and you're none the wiser.
https://blog.haschek.at/2016/how-a-scammer-stole-500-dollars...
I'll also point out that the author seems to have some complicated arrangement for their phone number(s), presumably in the name of security, that in fact got in the way of identifying this to be a scam.
And I agree about author - if he had said that he violated an easy rule and owned that I would take his credentials more seriously. Everyone makes mistakes, but he didn't list this simple, well-known rule as a way of preventing this.
That seems a bit extreme, but if their procedures are so crazy as to require circumventing another system's security procedures, I'm not going to bank with them.
I actually had a bank send me an email asking for information that came from another domain, had a header that looked liked it had been badly scanned in, and had links to domains they don't own. When I ignored it, I eventually got a notice that my car loan was in jeopardy because I hadn't provided that information.
They had no clue why I was so upset about that email.
I paid off my loan immediately and never looked back, even though the interest was less than I make off the stock market.
The author had a lot of signals pointing toward legitimacy to counteract their natural skepticism, it was a stressful situation and the nature of a phone call puts time pressure into the decision making, increasing the odds of a mistake.
Your example points out that false positives on the "scam or ham" decision do have a cost to the contact recipient too, so "never respond to anything" comes with risks and costs too. It's hard to be perfect.
Everything up to that point matches exactly what happened when I got a call from my own bank (Charles Schwab) regarding fraudulent charges. However, whenever Schwab sends me a code (or Bank of America, Coinbase, etc) the code comes with a message stating that an employee will never ask you for this code.
The fact that OP is an "expert" yet fell for this shows me that they are in fact not an expert here. Don't get me wrong, the execution by the scammer was slick, but I would expect an "expert" to be familiar with their own bank's policies:
"Wells Fargo will not call or text you requesting an access code. We may ask for an access code when you call Wells Fargo customer service. Always contact us using a trusted number on the back of your card or wellsfargo.com."
2) As you have noticed yourself, legitimate banks do what they can to make their actual requests indistinguishable from scams, and "not falling for that" can have severe consequences.
I also do a callback (verifying the number they give me via a google search) but it seems like almost no one else does. On one of these calls from a bank, I asked the agent whether anyone else asked to do a callback, and they said no one ever did this.
Nope, I do basic stuff like this too. And it's basic stuff. As in, can be defeated by simple wiretaps in infrastructure outside your control.
Overdue bill? Okay cool thanks, I’ll call back and ask to speak to someone, hang up.
Compromised card? Okay cool thanks, I’ll call the number on the back of my visa, hang up.
(This one happened to me) Relative in another country is dying of cancer and needs money for some obscure procedure and doesn’t want to tell anyone else about it only me so don’t call anyone about it? Okay cool, I’ll check and get back to you.
I don’t care how important the matter is; your house could be on fire! If you are calling me and need any type of personal info whatsoever, I hang up and call you or someone I know related to you or just Google that thing!
Same with door to door salespeople. No thank you goodbye.
Hi, the government is giving $5000 credits for people to add insulation, blah blah blah. Can we do a free evaluation? No! I would have heard of this free money falling from the sky from someone I know.
No thank you, hang up, give zero info don’t even confirm my name, close the door or hang up. Goodbye, won’t phish me.
This is... occasionally a real thing. Drives me nuts that they choose to implement it this way though.
Anyways, maybe there was nothing wrong with providing those details. Maybe they were already available to him on his screen. But the act of asking for that info and making it commonplace for people to just provide it is how so many scams are successful. I don't know how we get away from bad security practices being the norm.
Every time they call me, they just say, "Hi smeej, it's NAME at Dr. NAME's office. We have an update for you, so go ahead and hang up and call us back."
Works like a charm!
I thought that was fairly standard in banking/credit card fraud as well. That's how I was directed to proceed when I got a call from my CC company about fraud: "please call the service number on the back of your card regarding potentially fraudulent transactions"
Last week, I cancelled my Netflix subscription and been trying to remove my credit card details from my account to prevent surprise reactivation in the future. There wasn't an option to do it online, so I went in their chat support and ask them to remove my CC information from my account. Then they asked me to provide my CC number to validate who I am. I told the rep that I am not comfortable sharing my CC information over the chat and prefers only give out my service code or alternative information. This rep kept ensuring that it is secured and they can't see what I am typing in. I asked them to initiate it and I will decide if it is trustworthy to put it down. I got the prompt and it asked for a full CC number. I declined the prompt and told them that I'm not comfortable doing that. And it didn't help that the rep are unintentionally behaving like a scammer. I shared my concerns about the rep behavior and remarks that scammers can say those things. The rep understand my concerns and asked for other information like the email address that is linked in the account and what are two recent activity on the device I uses. I gave out the information and validated I am the accountholder. Then the rep processed my request and I see my CC information is removed from my Netflix account.
I asked for a callback number instead. They hung up and made me go through the entire process again, culminating in a new inbound call a day later and a new sms.
Also: Just call your official bank/card phone number yourself. This number should be on the back of your debit/credit card.
I won't as a policy give out information to an incoming call, and I do call back if they want any info from me. But my working memory is not endless. The topic of discussion had changed three times before he was asked for any information, and the information still wasn't PII, it was a confirmation code. The scammer knew enough about him that he wasn't especially on alert. I can well imagine that flag in my mind that I was on an incoming call having been lost before we got to that point. And I suspect that's exactly how the scam was designed.
I think that any phone calls from a bank about fraud should only be a notification and them telling you to "go to the website, the Contact page, there you will find a number to call in case of fraud". Without naming a web address. And the search engines should mark bank websites and the like as protected, so neither competitors nor scammers can buy ad space when people search for a bank by name.
When I don't recognize a number, I don't pick up. I tell them to email me/text me and that they provide when they called and with what number. Then I might call them back.
Asking extra effort from unknown people will do a few things:
- Scammers won't do it (not yet anyway)
- Spammers won't do it either
- Anyone lazy won't do it
Yeah, BZZZT! End of conversation. Hang up.
all banks should often remind their customers of this. mine does.
banks and phone carriers should do scam and fraud trainings for customers. or friendly reminders.