Americans lost a record $10.3B to online scammers last year, FBI says
wsj.com
wsj.com
Just moved into new house, had the cable guy over setting up internet. I get a phone call from "The Electric Company" (they used the real name) saying that I just moved in and I didnt put down a deposit, blah blah, I need to pay $350 now or the power will go off. I needed internet for work the next day, and wifey factors.... I panicked and sent the money. I know, it was stupid, but there was a lot of shit going on, and I just fell for it.
Literally IMMEDIATELY after I pressed the "send money" button, it dawned on me, I realized what I did, I hung up the phone and IMMEDIATELY called my bank asking them to reverse the payment. They would not do ANYTHING. They were completely useless, the person got my money and I had no way to stop it.
A month later, I'm getting trees trimmed, and the company wants payment in Zelle. Begrudgingly I oblige, and send my payment to them over Zelle. It took over 48 hours for the money to be delivered to them. The tree company kept asking me what the heck was taking so long, I had to call my bank several times to see why the money wouldnt send. It was stuck in "pending" for almost 48 hours, and the Tree guys wouldnt do the work until it cleared.
Moral of my ramble: fuck scammers, and fuck Zelle.
Understanding this, banks have crafted Zelle to pass the responsibility down to the customer. It was a very smart move (from the financial industry's perspective).
Right before a trip I wanted to withdraw $60 in cash. I went to one atm, but it showed an error and didn't dispense the cash. So I went to another. Later in the day I saw the first ATM had withdrawn from my account despite the errror.
I called and was told if I wanted to ask for the transaction to be reversed they would cancel my card and mail me a new one. Of course, that meant I wouldn't have the card on my trip.
I ended up eating the $60. Suppose I could have tried disputing further.
I phoned in for an appeal and I was laughed at by the bank employees over the phone, and told I was mistaken and my family members must be the thieves. Claim denied.
No, you were trained to fall for it by companies behaving a lot like scammers most of the time.
I ignored it.
I got it again and ignored it.
On the third attempt, I finally called my bank. It actually was from them, and they really did somehow not have my proof of insurance, and really were going to cancel my loan.
I tried to explain to them what was wrong with the email, but they couldn't understand.
Edit: In the end, I physically went to the bank to handle it. I didn't do anything else remotely with them.
I somehow forgot to pay a bill for daycare, and it went to their payment recovery contractor (it went automatically, without nobody telling me anything despite me going there every day). So the company called, said I had missed a bill and I needed to pay then over the phone with my credit card. Obviously they went mad when I told them I won't pay this way without receiving any king of paper by the mail or something to at least give me the slightest confidence that this wasn't a scam attempt. They ended up mailing me two weeks later, and charged me a fee for late payment…
Seriously, how do you want people not to fall for scammers if legit companies act the same way and charge you for being cautious…
In the US, any business that requests payment outside of credit card/debit card/ACH/checks is questionable.
It happens if you have a history of not being a previous customer with them. I had a notice of good payment history from my previous electric company from another state and the company in the new state still required a deposit.
(every time, me: "Have you bothered to look at the google maps for my home before you called?" Them: "No, let me check... Ohhhh" me: "Yeahhhh... I can't get rid of the trees because they are rooted in the neighbor's property. Not that it wouldn't be quite ironic to remove decades-old trees just to install solar on a roof.")
Perhaps it's time for some regulation - of course, drafted with the extreme care that almost no regulation is written with, but should be...
https://www.americanexpress.com/us/security-center/phishing-...
No such thing for the phone numbers though, and since they were just regular landlines not recognised by Google and not available through a Google search, I declined to provide them any information.
There absolutely needs to be regulation for that, like there is the "Mentions Legales" or "Imprint" in France and Germany (a website needs to have a page who they are actually, with an address and everyhing).
As harvey9 says in a sibling comment, "If they publish an outbound number then scammers will spoof it.", so perhaps publishing a phone number isn't useful - but they should actually state that on their web site, as well as providing a protocol that allows the bank/agency/company/utility to authenticate itself to you.
> "Mentions Legales" or "Imprint" in France and Germany (a website needs to have a page who they are actually, with an address and everyhing).
I like this concept - let's extend it to include an authentication protocol, as above.
Unless telecom operators are forced to take actions to prevent spoofing.
Zelle, Western Union, Venmo, PayPal (family) literally gives you warnings, multiple prompts, to say that it is irreversible, pay it only to known people, dont use it for government payments, make sure to check registered name, and stuff.
We as customers should know that no utility company, gas, power, internet, government offices, their representatives accept or want payments by Zelle. Zelle is great for person to person, or one time cash-like transactions. If one handover wad of cash to a person claiming a utility representative, one would not expect to get that cash back if he was fraud.
Zelle is irreversible by design (unless receiver sends it back). Otherwise what would stop from people using it like credit card chargebacks?. The only time I have heard zelle txn getting reversed is if reciever asks & insists to his bank that this money is not for me, undo this txn. Although there is a variation of fake check scam reverse zelle too. Just liek check, scammers arrange a zelle incoming from victim 1 to victim 2. Then calls victim 2that it was mistake. Please zelle it back to "me". Victim 2 does zelle. Original txn gets recalled because either victim 1 found it or his bank found it. Victim 2 is out of his good money.
In every case where I've gotten a message / phone call informing me that I need to provide some sensitive information or make a transaction, I determine the organization that they are purportedly representing, navigate to the official website, find the relevant contact info, and call back.
I always assumed everybody did this to prevent these exact types of situations.
Let alone calling up and demanding I pay using Zelle...
Every time they call me and ask to "go through verification" - aka I give a random stranger on the phone the personal information they need to identify themselves with my bank - so I tell them I'll call them back instead
Then i call back and get bounced around through multiple teams until inevitably the call drops, I think because my mortgage was bought from another bank so it isn't well understood by customer support
Anyway, I think it is legit calls I get from the bank. I hope it isn't important because i still haven't got through to them to talk about it
They probably bought it from some data broker.
They sell our data to scammers to let them be entirely convincing, and then blame people who fall for it.
Edit: Yardie is correct, this is assuming your counterparty doesn't pay the business fee. So this'll protect you from legitimate businesses, but a scammer isn't going to pay the extra fee to enable reversibility.
I paid an architect for work over Venmo. Work was never done and the architect ghosted me. So I sent all the info to Venmo in a dispute and they told me to pound sand.
Why does it survive?
https://www.forbes.com/sites/adamtanner/2013/07/08/how-the-p...
I'm sure many people just pay them because the hassle of reliably figuring out what's real and what isn't can easily exceed the amount of the bill.
The others went in the trash as soon as they came in...
I'll refuse to do business with anyone who doesn't take a credit card.
Cash doesn't try to rationalize all sorts of slow, obnoxious, and expensive behavior on the basis of fraud protection and then fail to protect from fraud. There's obviously a tradeoff here, the problem is getting stuck with the ass end of both sides. I can't really speak to Zelle, but it's definitely true for ACH and wire transfers.
Neither does Zelle.
> When was the last time you pulled out a stack of $20s and had to wait 48 hours for them to become valid?
Never, but I have also never had that problem with Zelle in probably hundreds of times using it in over a decade.
But I also have never been given counterfeit money via Zelle, which I have been given via cash.
Both mechanisms of transferring money seem to be working pretty well, and both have drawbacks/benefits.
Wasn't Zelle introduced in 2017?
Check the history section here:
"You can send money directly! *"
* If you have a pre-established out-of-band trust relationship and dispute resolution system with the person you're sending it to.
Which basically means you can send money to friends and family and that's about it. But you can also do that with Venmo or CashApp. Any online transaction among strangers that uses Zelle is 100% a scam. Full stop. There's a reason that groups that sell things plaster in giant bold letters to use PayPal G&S.
By far the biggest value-adds of Zelle existing is making it really obvious who the scammers are.
Exactly, and that is how I have used it for 10+ years.
> But you can also do that with Venmo or CashApp.
I could, but then I have trust an additional party (PayPal or CashApp) with access to my money and accounts. This is another risk with no gain.
https://www.earlywarning.com/about
> Introduced the Early Warning brand and became wholly bank-owned.
https://www.investopedia.com/what-is-early-warning-services-...
> Seven major U.S. banks own Early Warning Services: Bank of America, Capital One, JPMorgan Chase, PNC Bank, Truist, U.S. Bank, and Wells Fargo.
And similarly, I feel sketcky carrying large amounts of bills on me, for say buying a car - I'll go to the bank and get a bank check over having that much cash on me.
In my jurisdiction, banks will regularly refund and make whole people who have lost money to scams. They in theory can refuse if they think the owner of the account was careless, but in general they will refund a lot of scams.
One good consequence of this is that scammers now become the banks problem, so they will do more to help educate and prevent scams.
Rather than being able to wash their hands of scams, they will be proactive in making sure transfers are genuine, etc. Of course this can on occasion be a hassle, but in general it's reassuring that the default is not to allow large transfers to "random" people, and even more re-assuring that in general it's the bank who is on the hook for the money.
Of course, in practice it kinda sucks. Zelle requires giving strangers way too much information about you. I won't use it. Much as I dislike PayPal, I use Venmo for this use case.
It is one of its features. The previous method of sending and receiving money involves giving out your bank account number (even if not to strangers, then to PayPal), which means anyone can pull funds from your account using ACH.
Imagine if you went to a restaurant, and the staff refused to serve you until you showed them your bank account balance to prove you could pay. It is an immense failure of law enforcement to not crack down harder on widespread scams.
I fully agree. My identity was stolen and used to sign up for retail credit cards in a spree, and I even did the research for them. I had a timestamp of purchase, the items purchased, and the cash register number. The police could not care less. For one, they are lazy as hell and throw up jurisdictions as an excuse. The mere fact that the thief seemingly only used one store per jurisdiction seemed almost intentional in terms of taking advantage of this. The total amount stolen was $9,000, but I don't think the police gave it a second thought after I contacted them, and this was in a city big enough that had a financial crimes department.
How do you know they are lazy and don't just have an excessive # of crimes to handle?
For example, US police eventually come up with enough evidence for prosecutors to start proceedings only in about 50% of murder cases [1]. Yet police departments spend very little of their time working on murder cases. [2]
Assuming you believe police investigating murders is valuable, I don't see how you can think police should be wasting time on broken taillight stops when they're failing that badly at it. (If the cops can't be reassigned they should be fired and their salaries used to pay cops who can)
[1] Technically I'm describing the murder clearance rate, but I use this phrasing to avoid the common and incorrect implication that a cleared murder means it's necessary actually "solved"
[2] There's no great metric for this. Assuming a police officer who just filed an incident report about a traffic stop for a broken taillight probably wasn't working on a murder case immediately before we can use incident reporting data. For ex, https://data.sfgov.org/d/wg3w-h783/visualization
I recently took an interest into a phishing campaign because the guy was using Amazon SES and kept using new email templates and it kept landing in my inbox. He was an amateur and it was easy to find juice things on his server, and it looked like he was engaging in all kinds of different scams, like phishing for bank logins, defrauding online-shops, identity theft etc. With law enforcement options, I'm pretty confident I could've nailed him with a few hours invested. Get him for one crime, you stop 10 others.
But the last time I talked to a police officer locally, he didn't know what Netflix was so I won't even try to explain phishing to them and how I got this information on the perp.
Ten fully skilled security experts deputized @ 200K/yr. Fifteen assistants at $75K/yr. All personnel grossed up to 140% for fully loaded cost. Hardware, infrastructure, software, hosting services, $200K/yr. Total (((20010)+(7515))*1.4)+200 = $4,575,000/year.
You don't think that such a team could stop $50 million in crime in a year? I'd expect that $500 million would be a slow year and stopping $5billion would be more like it. There is so much of it and such low-hanging fruit...
I know of large corporation divisions where $5 million per quarter was literally their rounding error threshold three decades ago (likely more like $15 million now).
The payoff is so great it is astonishing that some large tech companies don't do it just for the general reputation of the industry. Or the banks for the same reason (e.g., I wont' touch Zelle, both because when I first checked it out it was horribly clunky, my bank wanted $20/month just to use it, and all the persistent scams).
Or, just for lulz. This is rounding-error pocket-change for these corps. If it got going, I could see a rivalry between MS, Oracle, & Alphabet execs for who could dunk the most scam dollars, and jail the most perps...
By "stop", do you mean "prevent from happening", "successfully prosecute", or "identify the perpetrators"?
My answers, respectively, are "no", "maybe, depending on the sample set", and "yes".
Definitely agree that successfully prosecute is harder than ID perps...
But you don't think there's enough scammers based in the US/Canada/EU to chase? Back to the Zelle scams as we started with, and an awful lot of scams that require cash mules, seem pretty trackable if someone puts in the effort, especially when people can drop the evidence at their doorstep.
What’s left would be cases like “I bought this iPhone off eBay and got mailed a brick”. If it was taking your team any longer than literally 10 minutes per successful recovery on average, you’d be better off just using that taxpayer money to reimburse victims directly. It just doesn’t make sense to throw 250/hr labor at a $500 problem.
1. most of them are probably outside the the jurisdiction of the hypothesized team mentioned above
2. that's a lot less than $50 million
3. this could be addressed with regular police work
The phrase "could be" is doing a lot of work there. Yes, all of these crimes could be — and I would argue SHOULD be — addressed by regular (presuming local or state) police work. Sadly, it is not.
Similar to rampant bicycle theft. It definitely could and should be addressed by local cops, but is largely ignored, and ignored even when people bring them real-time tracking of the bicycle. And you're not supposed to go vigilante and get it yourself (partly due to risk to you).
For #2, $50 million, that seems like a lot of crime. But let's take the mailing a brick for an iPhone example. Each one is roughly $1000. So we need 50,000 bricks per year. That's 137 per day. Way too much for one criminal. But with 250 criminals, they only need to send a brick every couple of days. And our cop team needs to average only a single capture per day to stop $50million of crime in a year.
Jurisdiction, yeah, they'd probably need national jurisdiction, since there are probably few crimes where the criminal and crime are in the same town (other than the FB market/Craigslist criminals). So, deputized by the FBI is probably best.
So, not unreasonable to search for a solution that actually works.
I agree that it is not. I am saying that you don't need a team of 10 cybersecurity expertise to show that someone mailed bricks or stole their cousins venmo money. Ten traditional detectives would be cheaper and a better fit.
Any technically sophisticated scams that would require a team of cybersecurity experts are likely already at the scale and scope that the FBI already does address them.
The intersection -- a technically sophisticated scam that is a small dollar amount -- isn't a problem that exists.
The reason that large cities don't spend much time on small dollar crimes is because they have bigger stuff to worry about. Yes, there's definitely people selling stolen phones on my local Craigslist, but there's also people stealing checks out of mailboxes and washing them to steal $50,000+. It makes sense to address the latter first.
Actually, chatting about it, it seems like the ordinary L1/L2/L3 service teams approach could work well. Ordinary up-trained detectives on most cases, when they hit something more complicated, call in the L2 guys/gals, and when it goes over their skillset/toolset, call in the L3 team, etc...
However it gets done, it certainly seems that we need something more than we've got.
You'll still have scammers from India, but you'll also have a lot that are running more elaborate scams and do a lot of damage by defrauding the government and companies.
That being said, it's smart to take precautions, and it's not victim blaming to suggest things people can do to reduce their risk of becoming victims. I teach my kid not to play in busy streets. That's not blaming pedestrian victims for car crashes--it's just sensible, risk-mitigating precaution.
I think that, by far the greater poison holding us back is the obsession with personal responsibility that many people use as an excuse to not have to expend additional effort on dealing with a problem pragmatically. If you are suggesting educating people or giving them tools to deal with scams, that's great. But a lot of people don't want to do that under the very same rationale that you are using to justify it - that the victims could have avoided it. You are saying, "people can avoid this - we need to help them do so", but there is a significant part of society whose opinion on many topics where there is a victim is, "people can avoid this - they need to take responsibility".
When something happens is usually the best time to talk to others about that same thing. A bank exploded? Hey, have you heard that there are ways to spread the risk over multiple banks? A hospital got all their files encrypted and needs to pay a ransom? Let's talk about backup strategies and how to secure infrastructure because that could be your organization.
I don't think people discussing strategies seek to deflect blame from a potential bad actor (it doesn't need to be about crime, accidents happen all the time, and there are plenty of things you can do to lower your risk), they just want it not to happen again, or at least less frequently.
The POTS and e-mail and usenet protocols are embarrassingly broken on this front.
For anybody who is building a communication system: If you are allowing anonymous messages to users is a default behavior and it is impossible or impractical to avoid, you have created a system for spam, scams, threats, and harassment.
Humans blame victims so often they've created a specific term for it - "victim blaming"
Do you think if we let cops put on their pretty SWAT gear and roll into the front yards of white collar criminals' front yards in their APCs they'd start taking these sorts of things seriously?
A friend of the family recently had his email hacked. They sent targeted emails to all his contacts and setup a filter to hide the communication. His brother in law is a stoke victim with impaired cognition and only has access to $12k or so at a time. They were able to scam all of it from him over multiple transfers and he never picked up the phone to call the family friend. The family fiend is also his caretaker and limits his funds access for this exact reason.
The family friend is a retired old GE executive who will probably never run out of money no matter how many cars he buys due to pension funds. I wonder if he was targeted.
1. If a service provider you use reaches out via email asking for money, its fake. Login to their online portal (it took a lot of coaxing to get them comfortable with this...)
2. If a service provider reaches out to you via SMS or Phone call, even if they know your account number or other sensitive data: Tell them you will call them back on the phone number listed on their website. If they insist, its fake.
3. If you aren't sure its fake, just ask me to look at it.
The simple rule of thumb that will keep people reasonably safe is: Do not trust anyone who E-mails or calls over the phone to be who they say they are. If they say they are from business XYZ, hang up the phone and call XYZ's main number and ask for them. While there are exceptions and scammers are getting craftier, incoming calls and E-mail is by far the major attack vector.
If there's a private sector solution to the scam calls that can be charged heavily for, that's what we're most likely to get. The competent parts of government aren't concerned with this stuff. Congress has to make it a concern, but they mostly toil on behalf of corporate lobbyists. Lobbyists aren't hired to help society at the expense of who they represent.
Intelligent, informed voters and honest politicians would have solved this and many other problems already, but we're extremely far from that ideal, and I think still trending away.
I've wondered before if posting in HN threads like this one is a better way to influence policy than going to the polls, since someone with influence could be reading. Maybe what I should actually be doing is writing to my representatives, as that's probably more impactful than either.
My stepfather always tries the factory reset button as if it's just a more hardcore reboot to "fix" the internet when the service is simply out.
Behavioral improvements and education are nice to haves, but constant vigilance has a high cost for folks at this age and it only takes one successful adversarial attempt to succed. In this case, strong controls and guardrails are a superior solution imho.
($dayjob is infosec/risk mgmt)
That's a great idea. And it's easier than ever, now -- at least in my experience. For a while I still had to use bill pay or debit for some of my utilities, but now even those all take credit card. I do it for convenience and the rewards (and because the last time my wife used her debit card it got skimmed), but the result is the same -- 100% of my own spending is on my credit card now. This would work great for my own mother if she gets to a point where I doubt her ability to resist con artists.
With elderly loved ones, as with everything in life, a negotiation takes place.
https://www.truelinkfinancial.com/
https://www.ycombinator.com/companies/true-link (YC S13)
If you come across this comment and need advice in logistics for caring for loved ones, contact info in my profile.
Restrict websites to a few domains on the devices they use. Youtube, wsj, etc...
If they want a new one just tell them to ask you.
It sucks and has problems, but its the only real straightforward and viable option I've seen work.
Source: have grandparents who were regularly getting scammed or close to being scammed on a weekly basis.
But what do we do when we get old? Will we be rational enough to disconnect ourselves? What if we don’t have any children that can help us make this decision?
While I'm confident in the security of Chromebook in general, I'm worried by how readily she pulls out her credit card and types the number into obscure sites for purchasing wedding gifts, etsy items, etc. A few years ago she would click on Facebook ads and buy shit quality products for little reason, but I think she eventually learned not to do that.
At least it's a credit card and not a debit card. My dad manages the banking, and is a bit more sophisticated, but even he does things like install programs meant to protect him that actually expose him to more vulnerabilities. For example, there is some Symantec monstrosity installed on his computer that injects a green checkmark into Google search results next to each site it thinks is "trustworthy."
It's definitely frightening and mostly a numbers game whether they'll be the next victims of a scam.
In my experience, trying to list and explain all of the ways that scams happen actually has the complete opposite effect — either it ends up as information overload and they don't remember it, or they become so fearful of doing wrong in specific situations that they almost certainly become more vulnerable to fear-based attacks as a result.
I tell her that if she ever has any doubt whatsoever that she’s to call me any time any where and I’ll help.
I also promised to cover any financial loss due to eg making a late payment because of my advice.
I think real time alerts or daily summaries sent to trusted caretakers. Another layer is having the caretaker approve of the transactions. Can think of this as 2 factor authentication where they'd have to hack multiple phones or accounts for a successful scam.
For example, seeing multiple gift cards would be suspicious. Or if you know your parents never take out more than 100$ from the ATM.
Sometimes though they willingly scam themselves. My dad gave this real life scammer 30k in advance payment in return for future caregiving services. We told him she was scamming us and he didn't care. When she asked him for more money to buy a new car he finally realized she was truly scamming him.
I told my mother (who is 81) that the answer is always no. There is never an emergency, the answer is always no, she should hang up and then talk to me. Personally, if possible (we live 10 minutes apart) or at least on the phone. Any legitimate need for money can wait that long.
Fortunately, my mother has a somewhat technical background and her mind is 100% still there, so it hasn't ever been a real concern yet. She's skeptical by nature of what she sees online.
It could be as common as sending a pin to YOUR phone or that they actually call the bank to authorize it.
Some join accounts also require approval from both parties to transfer large amounts of money.
Additionally you can open a secondary account for your elderly relatives for daily expenses, they fund this account from their main account.
Anything you do, do it at the banking level, do not rely on your elderly relatives to doge pretty sophisticated scams.
How do you protect your car from your teens crashing it? Don't give them the keys
The ability to reason about money deteriorates with cognitive decline, in large part, I think, because it so abstract.
The solution is for them to not have direct access to control all their finances, but rather get monthly amounts via a trust. That way, downside is limited.
Unless the trustee is a scammer, or worse, one of several adult children who don't agree on how finances should be managed.
Secondly, it is typical to mitigate against a single trustee not acting in good faith by have an odd number of trustees.
So you are saying that if you trust the trustee, they can't be a scammer? I don't agree.
They might break your trust (as the person who originated the trust) but that’s not the same as a scammer. A scammer is someone who who commits or participates in a fraudulent scheme or operation.
The boy that got scammed is so embarrassed that they won't tell anyone and they send the money.
It seems they must be carefully targeting relatively clean cut (so they'll be sure to be embarrassed) and wealthy kids (so they actually have $300 to send). It's mind blowing how well these scammers do their homework
At one point they were targeting Muslim men because they knew the cultural implications of those videos being sent to their communities. I remember reading a story about a raft of suicides linked to that particular scam.
There’s also less sophisticated versions where the scammer will only claim to have hacked the victim’s webcam and demand money to avoid sending it to the victim’s friend list on social media.
After reading about this, I bought a bunch of cheap plastic webcam covers to give to everyone I know. They were only ~$1/ea on Amazon and work great.
Some committed suicide from the shame.
The problem is US law is so fucked up that having sex with someone that's days younger than you can be illegal and punishable by labeling you as a sex offender for the rest of your life. Even if the other person had a fake id and lied to you!
Its not just teenagers, they target older men. I get requests on whatsapp from profiles with an attractive woman's display pic. I sometimes accept these requests and chat with them. They all want to have a video call on whatsapp.
I have never done any video calls with these scammers but their end goal is to have a video call where the woman might be wearing revealing clothes or even nude, get a screenshot where your face is on the call and then blackmail you, if you dont pay up that screenshot will be sent to your contacts.
Oh your daughter is spending her gap year in South East Asia? Find her social media -> download the videos with a sample of her voice -> generate audio of her asking you to help/send money because "she was robbed at a gunpoint" -> message your phone number/WhatsApp/Facebook account etc.
These scams are possible now, but their quality will increase exponentially given that you won't need to know perfect English or be well versed in tech to do this.
My mom almost got tricked by a police scammer saying they have an arrest warrant for her due to not paying a debt and that she would be arrested if she didn't pay the money. Only reason it didn't work was because she didn't have the money and called me crying asking for help. Now she knows to never trust anyone requesting or demanding money over the phone.
The sickening thing is that I'm sophisticated enough to not fall for it. I'm white, I'm college educated, I'm a comfortably employed engineer, I know that I'm at a relatively low risk of being arrested without cause. A lot of other people probably get these calls, probably suspect it's a scam, but don't have the same level of confidence and just hand the money over. These scams prey on the people who can least afford it.
I was also getting voicemails from a lovely recorded female voice saying "someone who loves you very much has asked us to reach out to you, please call us back". Again, rationally I know it's a scam, but still emotionally I feel how nice it would be to think that someone out there cares about me. It much be nearly irresistible to lonely people.
A more clever one I got just the other day started with a text to me in German claiming to be from my son saying he lost his phone and this was his new number. Even though it was preposterous I did take a few moments to recognise it was a scam.
Sarah milner
4424 e bellevueText is one thing, but also thinking of deep faking video/audio. Elderly seem especially susceptible. I have a close friend's grandma that was scammed out of 5k from a fake voice call.
Email, text, and live phone calls are the typical approach. I can’t count how many times people have claimed to be her grandson needing emergency funds (usually bail). She also gets fake invoices via USPS but I manage her mail so it never gets to her. It is never ending.
Flash forward a few days, and she gets an automated called saying something akin to "Your delivery is on hold, please press 1", so she did, and got connected to an "agent" who she started talking with. In her conversation it became obvious to me it was a scammer, so I told her to hang up, but not before she got overly concerned at me.
She's pretty aware of these things, but it was just a right place at the right time kind of thing that caught her off guard even though there were plenty of warning signs.
Scammers abuse this principle by sending out texts to the tune of "Your package is on hold until you pay.". The chances a random person is expecting a package at any given time are pretty good.
I'm just here to watch the goal post move
as in, the crypto numbers could have been any amount and you would have said the same thing.
if it was $1bn you would have said that, $500mm you would have said that.
and thats, in conjunction with nothing in the crypto space having any utility, for you, and nobody else’s utility being valid, for you.
But consider the IRS. They are supposed to go after millions of tax cheats who "scam" the rest of the taxpayers by failing to pay taxes they legally owe[0], but Congress generally does whatever they can to prevent the IRS from enforcing the tax laws. So why would they be interested in going beyond that to pursue scammers that prey on those who are not ultra-sophisticated?
This approach works extremely well for FACTA, so much so that some foreign banks bend local laws to comply. Scammers would get absolutely destroyed if this was implemented.
Scammers could also just move on to cryptocurrencies, which are already subjected to sanctions in some cases with varying degrees of success.
Banks are easier to sanction because they have a more tangible physical presence.
Maybe it’s too expensive to run right now for scammers, but just wait a few months or weeks for the open source models to shrink and improve!
Yeah, uh, the travesty that is the "do not call" federal list is all you need to know.
Like everything these days, if it's not for important people, and by people I mean corporations, the government doesn't care.
You want to know what shows how bad our government is these days? I'd guess that support for Do-Not-Call is probably over 70% popular support, and it never gets implemented properly, enforcement is clearly nonexistent.
There is a decade-long war on consumer protection and credit protections for everyday people.
2nd occurrence - in the past 12 months, I get the classic text message, “Steve, as you know it’s my brother’s birthday and I always send him a $500 gift card. I am in the hospital unable to communicate or take care of this, and I was wondering if you could do it for me - here is his number : 212-xxx-xxxx.” Now I DID know it was his birthday and I DID know she always gave him a $500 gift card (pretty nice sister), and I DID know she was in hospital for a few days. I also knew that he lived in NY so the 212 area code was a nice touch. But I also am very familiar with gift card scams, so I just wrote it off. I was thinking I should just call him, wish him a happy birthday myself and ask him a personal question about his sister to which only he would know the answer. In any event I was just about to board a flight and it would no longer be his birthday when I landed. Then literally 5 mins later I get another text from one of our mutual friends, who lives on the other side of the country - “Steve, is there any way you can help, <name withheld> needs someone to send the birthday gift card to <name withheld>. I told her I could not do it but suggested she might ask you instead.”. Okay this was now getting interesting, The texts came from 2 separate women. I knew both of their Verizon accounts were set up with 2FA (heck I set it up for them!). What’s the chance of both of their accounts being hacked at the same time? (extremely high as any cyber-security expert knows). Both of these women were trusted personal friends - it wasn’t some inside job - they were in fact hacked. Verizon was hacked. Etc. I have some last minute urgent business distracting me, with which I am on the phone with my PA - at the end of that call, I instruct my PA “oh also, send a $500 gift card to <name withheld> at 212-xxx-xxxx from <name withheld>”. I figured she would do it through our Amex facility, which has recourse for such fraud. She just bought one off a website. Now everything that happened I knew better. But it happened anyway. It was one of those perfect storm situations where I just wanted things taken care of and I wasn’t being diligent. I’m not proud of it, quite embarrassed in fact. The ex-husbands of both of those women are cyber-security clients of mine. Part of me even thought it was one or both of them. In the end, THEY were the only ones to whom I reported the scam (oh and whoever is reading this) as I felt a professional obligation. Any cyber-security expert will tell you that it is this social engineering and grooming that is the key to many of these scams. Scammers are even more surreptitious now, using AI-generated voices to leave messages sounding just like the known confidant. Be very wary and just always …. say no!
I didn't fall for it because I figured anyone with a Paypal account can generate and send an invoice through Paypal to any email address. But I wouldn't be surprised if this scam gets a lot of people. It's a well known company, the email is directly from them, and it's a legit looking invoice saying they owe money.
ChatGPT-4 throws some cold water on the idea, naturally, though I still think there's something there:
====
me:
i have an idea for a non-profit foundation that would leverage LLMs to perform "online scam pentesting" at scale, as a public service. basically, we would execute pretend online scams very similar to real online scams that people are victimized by (fake invoices, romance scams, etc), but immediately send the money back if the pseudo-victim falls for it along with a brief explanation of what happened and our foundation's mission, along with a link to an informative webpage with helpful resources on online scams. (if the victim ignores the pseduo-scam, we'd perhaps wait a day and then followup with the same info.)
this seems to me like it'd be potentially legally fraught, though i'm not sure exactly how, or if there's any relevant legal precedent on the topic. what do you think?
ChatGPT:
I am not a lawyer, but I can provide some general thoughts on the potential legal challenges associated with your idea. It's important to consult with a legal professional for advice tailored to your specific situation and jurisdiction.
Consent: Executing pretend online scams without the consent of the individuals involved could potentially be a legal issue. Consent might be difficult to obtain without revealing the purpose of the exercise, which could defeat the purpose of the "pentesting."
Privacy: Collecting, storing, and processing personal information might raise privacy concerns, especially if the information is sensitive. Different jurisdictions have different regulations, such as GDPR in the European Union and CCPA in California, which govern the collection and processing of personal data.
Fraud: Even though your intention is to educate and protect people from scams, the act of sending fake invoices or pretending to be someone else could potentially be considered fraudulent behavior. This could open up your organization to legal liabilities.
Unintended consequences: If someone experiences financial, emotional, or other harm as a result of your "pentesting," they might choose to take legal action against your organization.
Regulation of LLMs: Depending on the jurisdiction, there might be specific regulations governing the use of LLMs, especially for activities that can be perceived as deceptive.
Precedent: While there may not be direct legal precedents for this type of activity, similar cases involving penetration testing and ethical hacking might provide some guidance. However, those cases typically involve consent from the targeted organization, which is a key difference from your idea.
To minimize potential legal risks, you could consider alternative approaches to educating people about online scams. This could include creating awareness campaigns, providing educational resources, or partnering with organizations that share your mission to fight online scams. Regardless of the approach you choose, it's essential to consult with legal professionals to ensure compliance with relevant laws and regulations.
I almost fell for these two because 1. We did get gift cards from ppl few years ago and maybe I didn’t use them all 2. I’m aware of experian credit locking but if I were to do that I would Google experian and not point to that strange domain. Also why is vendor of HSA company contacting us, shouldn’t the HSA company inform us about this hypothetical breach?
https://www.aura.com/learn/how-to-identify-a-scammer-on-the-...
https://www.itgovernance.co.uk/blog/5-ways-to-detect-a-phish...
apparently, if you are a business owner, you can pentest-phish your own employees, this sounds like an interesting business to be in: https://www.knowbe4.com/phishing-security-test-offer-ga-nav
You're lucky if the police will take a report. Detectives will only poke around if they know it's local.
AGs and DAs don't care about small-scale scams and ripoffs and cheats, generally aren't equipped to investigate them, and if the party committing fraud is in another country are likely to throw up their hands and say "not in my jurisdiction."
The only way this can be addressed is the extremely unlikely scenario of making the platforms legally responsible for getting the money back, under the threat of sanctions measured as a multiple of losses or a fraction of total revenue.
Another part of me is kind of horrified at the privacy implications of that, and questions if that potential trade-off would be worth it given that such a service would undoubtedly be run by a private corporation.
I understand this is not just one scammer, but if they pooled that money together, this is kind of level of money that could influence elections in a small country or buy a small army or be used to take over legitimate businesses and use them for further money laundering while paying off politicians and civil servants.
It's like when crypto is stolen. It's harder to process ill-gained proceeds than legally obtained proceeds. This means it takes time to launder it; you cannot just buy cars or whether with it; the govt. and police may be looking for it. So this means it likely has a deflationary effect in the short term by taking money out of the US economy that could otherwise be spent, but in the longer-term may have national security implications if the money goes to fund drugs, terrorism, whatever.
I doubt all the nefariously-collected money will in turn be used for nefarious purposes. It's entirely likely that a good portion of it would be used to do things like, pay for a decent living space for their family, buy a newer car, possibly buy a business to turn to more legit ways to make money that don't have the risk of getting caught.
They outlawed it but when it was going it was ~5-10 billion dollars each year with tens of thousands of employees and hundreds of businesses.
It's a huge problem and has massive implications for world politics.
I don't know if OpenAI/etc keep close enough tabs on usage that they'd be able to identify if they have people abusing their product for these types of scams, but even if they are I'm sure it's just a matter of time before the leaked LLaMA weights or similar are applied for this purpose, if it's not happening already.
Not a clue what's to be done collectively if law enforcement doesn't care beyond the FBI keeping an eye out for "more serious" money laundering stuff (I suspect that's why they actually care as an institution), but I can share a little practical advice that maybe you won't hear elsewhere:
1. If you're substantially financially supporting your parents or whoever else, you're entitled to and need to understand their budget in extreme detail, just like if you were married. They should be able to explain and prove all of their income and all of their expenses, and they should understand that your generosity is not entirely unconditional -- in the same way that you wouldn't be willing to enable, say, a heroin addiction, you also aren't willing to enable literal scams. (And, of course, they should understand why you need this info and what risk you're trying to protect them and yourself against.) This still doesn't protect them fully, since they can e.g. be persuaded to sell their home and send it all off in secret and only tell you about it once it's too late, or just lie and continue sending off small amounts of money over time. But, it helps limit your exposure, and if you're lucky will make them think twice about people they've never met in person soliciting money from them online.
2. If you see a loved one fall for any online scam, that should probably increase your estimation of their ongoing susceptibility to similar scams, even if they seem to "get it" after the fact in that specific case, even if you don't think of them as particularly gullible in general. Perhaps they'll learn and be more careful, or perhaps they won't and you're just learning new information about them that's unlikely to change.
3. Don't underestimate what even simulated love can make people do. My once-good relationship with my mother, who I never would've considered a "bad person" a few years ago and never displayed any antisocial tendencies to me before, was ruined by her repeated and pervasive deception and theft.
I laugh a little at the language. What is the net loss? How many Americans have gained money through online scams? If we want to talk about the impact to the economy, those dollars are not necessarily leaving the equation. Illegal market activity is still market activity.