You receive a call on your phone. The caller says they're from your bank
mastodon.social
mastodon.social
I myself have an additional rule that I always reject calls from unknown numbers, unless I expect one (delivery, taxi, etc).
There needs to be a better way to verify.
I have no idea about phone systems so this mighy be out of touch
This model also doesn’t work for businesses that route all outgoing calls through one number, as that is essentially caller ID spoofing.
The Google dialer does ask me whether unknown callers were businesses and try to ID businesses that enough people report
Well, then, looks like the problem was solved nearly three years ago!
The banks (and utilities etc) are training the Boomers that they will call and claim to be from the bank.
I. have. no. words.
It was legit.
The few times this has happened, the note is simply 'call the bank's 0800 number and quote your account number', their robo menu will then automatically forward me to whoever is trying to reach me as soon as I hit the 'speak your account number' menu point (and if for some reason that fails, it then goes to a human operator who will then forward me to whoever was trying to reach me.
I've never even had a whiff of them being annoyed by this chain of events the 3 or 4 times it's triggered (always due to steam triggering fraud protection)
> I myself have an additional rule that I always reject calls from unknown numbers
I'm highly skeptical of unknown numbers and they're almost always telemarketers or scam calls but ... my circle includes people who can lose phones, have batteries go flat, ask others to pass on a message, etc - fully whitelisting isn't always an option.
This is generally true, but...
In Switzerland calls from banks (and doctors and lawyers) don't submit numbers. That's due to secrecy laws (at least in the case of banks)
That said, in 45 years I never received a call from a bank.
Be careful about this. Scammers have bought Google adverts to advertise fake phone numbers for banks, so "ask Google what my bank's phone number is" unfortunately isn't secure against scammers.
I mean, yes, you need to independently source the official number; just make sure that your father knows how to do that and doesn't try to do it in a way which may be compromised.
He has actual paper phone books, several address books, and spent some time as a naval signals officer ..
We're both of generations that have always been skeptical of infomation on computers ... I can't imagine life as someone who'd ask google what my banks number is.
Wiretapping the Secret Service Can Be Easy and Fun | Bryan Seely | TEDxKirkland
You can avoid 99% of all phone scams by never giving personal information out on an unsolicited call. Regardless of what the caller’s phone number appears as.
A legit caller won’t care if you call back yourself.
Where do you live that this is possible? I'm genuinely curious. In most places a phone number is required to open a bank account or use most/any government services.
What's your full name?
What's your date of birth?
Etc.
The Bank lady on the other end of the phone one day was most put out when I asked those same questions so that she should identify herself to me also.
I would hang up and verify the phone number and then call them back if it checks out, or more usually I ring the Bank using my own version of the Bank's phone number and ask to speak to 'Charlene' or whoever it was.
They called.
They ask me for my personal info to verify me.
I said I was uncomfortable, could they verify who they are.
They said they can’t for security reasons for MY account.
I refused to give out info. They hung up.
Turns out, it WAS the bank. In 2023, I’d assume this should be figured out. Especially, since they send out like a 100 emails about “your bank will never call you and ask for your personal info”.
I knew enough to read between the lines, but on the surface it sure was confusing to be asked for something they said they would never ask for.
About ten years ago (it was my top Google+ post, if that dates it for you) I emailed one of their emails to me to their fraud department, because it was so ridiculous, urgent calls to action, obfuscated links, no identifying information that only the bank would have known. They're fraud department thanked me for reporting this obviously fraudulent message, to which I replied that it wasn't fraudulent, to which they were flabbergasted.
Even if they ask "hello is this so-and-so" just say "how can i help you" ... don't answer any information based question. zero of them.
It doesn't have to be awkward or weird.
But when I used to, I turned it into an even more fun game that you described
My goal was to waste as much of their time, and as little of mine, as possible.
Hi, this is so-and-so from DIRECTV. We’re calling with a special offer….
Oh sweet! I’m so annoyed with my cable company
That I let them get into their spiel
A quick sec, I got a pot on the stove
Disappear for 30s
Oh hey, sorry, you were saying about 150 channels?
Let them get going
Ah, shit. Paperboy is at the door. Gimme a sec I’ll be right back, this sounds like an awesome deal
And so on, with longer and longer gaps between each fake reason for disappearing, and more enthusiasm for his pitch each time I returned
I remember the DIRECTV example in particular because I tied That dude up for over 40 minutes.
Barely impeded my watching Farscape and kept him from harassing anyone else for the duration.
My personal best was 2 hours and 10 minutes before it was me that got sick of playing them.
After that I put the "This Number Out of Service" tones (http://www.k3pgp.org/telezap.htm) on my answering message. That knocked out a lot of the spam diallers.
Usually I don't answer any number that's not on my contacts list, and let them go to voice-mail. If they really need me, they'll leave a message.
Yet after one day abroad, they blocked my card and needed me to call them and have them call me a couple of times to validate my identity and purchases. _During their office hours, meaning in the middle of the night for me_.
Sure enough, as I was trying to buy furniture for my new place, the same thing happened to me. They blocked the card and when I called them they scolded me for not letting them know that I was traveling. I told the agent that I did in fact let them know, and asked them to update the account to note that I lived overseas.
Some 5 years later I needed to use one of those accounts again. I diligently phoned the bank, let them know I lived overseas and that I was going to use the card. I used the card, the transaction was blocked, I called and was again scolded for not telling them that I went on holiday.
I swear the 'notes' they add to your account are just an eye-roll and then a call disconnect.
It's a pretty clever idea for the scammers to exploit the in-app notification to fool the end-user. I wouldn't blame them for being scammed in this manner. However, the post then goes on to say:
> Then he asked me to confirm the last 12 digits of my card number, cvv and expiry date.
That to me is a big red flag, and I hope that I would have spotted it if I was the one being scammed. If it was really someone from the bank, they would already have access to this information and wouldn't need an end-user to give it to them.
Although in this case, it may have been too late by that time to limit the damage. They may have been asking for this info as just the cherry on top. I'm assuming that responding to the in-app notification was probably the main thing they needed to extract the savings.
And the whole "tell me all of your credit card details except the first 4 numbers that only identifies your bank"-thing should immediately scream scam.
When I asked to call them back to verify, they said (from memory):
- Call us back on the main line, you can find it on website.
- Press option 9
- Enter the five-digit code: 51762
And got transferred straight back to the caller.
I thought this was a fantastic idea.
I was called by my bank once. They wanted to know if I had spent two thousand euros in a fashion store in Rome. No, I said. They needed no sensitive information for what came next: They cancelled my card and sent me a new one. Later, I logged in at the bank, saw the fraudulent charge, and used their standard protocol for disputing the charge. It was soon reversed. End of story.
I see no reason why the bank would have to verify my identity for something like this, or why I would have to verify theirs.
"This is Coinbase support, we've noticed a suspicious transaction originating from 'Salt Lake City, Utah'. If this was you, press 1. If not, press 2'".
I pressed 2 but it proceeded anyway with "We see that you did not initiate this transfer, please expect a call from Coinbase within 3 minutes".
After about 10 minutes a man with an American accent (ironic given that Coinbase support routes you to an Indian call center) called claiming to say something about how Coinbase was compromised and I needed to change my passkey and move my funds to a custodial wallet. I logged into my Coinbase account and said "I don't see any transfers". He said "yes, we don't show them to you because they've been flagged, but they were in the amount of <off by an order of magnitude of what I have in Coinbase>". I asked him "how do I know you're Coinbase?", and he said "certainly I can send you a verification email", which he did. The domain name wasn't verified and gmail flagged it as spam. He stayed on the call then said, "next I'll send you a reset password link". Then I asked "how about you tell me how much I have in each currency". He said a number that was off by an order of magnitude. Then I hung up. He tried calling back but I didn't pick up. Later, I checked my email and saw there was indeed a "reset coinbase passkey" email in my spambox.One idea that would mitigate against this, while also not imposing significant burden to the customer is to have the procedure be that the app simply instructs you to hang up your call, and then after dials a randomly selected number from a large pool of numbers the bank controls, that has been wired up to (given your phone number) connect you back to the bank and directly to the agent that has called you. If your phone number dials any other number from the pool during this time (the attacker is trying to race you to call back the bank while spoofing your number), then the account flagged as being potentially under attack.
As well, you get a lot of things for free:
- user is familiar with the phone UI, and knows how to mute/use speaker phone.
- put the call on hold if another incoming call comes in,
- able to call someone and make it into a conference call, - more reliable on shitty internet.
Does any of you know similar software for (non-google) Android?
Edit: Hmm, I'm getting a 404 on one of Google's development pages for it. I'm wondering if they killed it already in less than 4 years... It wouldn't surprise me, unfortunately.
It does work well though. I get a lot of spam calls and texts a month (the result of my political donations, which I didn't realize were public info and easily harvested by spammers, sigh... fucking NGP Van). The Pixel filters out the overwhelming majority of them, thankfully. The call screening works exceptionally well for spam calls, since most just hang up.
The Pixel is a perfectly generic phone, IMO, but the spam blocking is amazing. I switched to an iPhone for a few months, but the spam (even with several third party apps) made it unusable and I eventually got another Pixel instead. About the only thing it consistently does better.
If your banking app could easily see if you're in a call and who you are calling / who is calling you, this would be a lot easier.
Even without that info, banks could solve this by requiring all customers to initiate all calls from the app. In case a customer lost their mobile device, they'd let them proceed on the phone, but send a bunch of alerts to the device that it was just reported stolen and to immediately hang up if you were still the owner.
The step people fail at isn’t ID’ing whether a caller is “real”, but by handing over their card details to anyone at all without personally contacting them via a known channel.
Hang up.
Call your bank.
Let yourself be put through to the caller.
I’ve had a call from them before and when they first greeted me they made it clear they know my full name and details, and told me up front if I have any doubts before continuing I can call the main number and use the voice-assistant to ask for a specific department. I did, and was put through in under a minute.
My previous bank wouldn’t even do 2FA other than via SMS, and also would only let you do 8 character alphanumeric passwords. The contrast between banks is wild for this day and age.
There are other reasons to rip into CBA but on this they are doing well.
Months later I got a call from the Income Tax Department saying I was in big trouble. I had done something very bad. I hung up.
But the third time was wild. Something was wrong with my credit card. They had to replace it. They were even able to trigger a 2FA code. I hung up and changed my password.
Turns out I was right. I don't fall for this trick.
2. The bank must have the registered number/s for customers and clear procedures on how to deal with calls from numbers unknown to bank.
3. Attackers clearly knew the above flaws of the banking system and processes.
4. Chase must take immediate actions for pp. 1 and roll out the update. But then I am not sure how about nowadays but 10 years ago it was pretty easy to spoof callerid.
[1] It works like this: Their "telephone" is an IP device with a camera that connects to their TV. When they make a phone call, they do sign language into the camera. This gets routed to a call center with a sign language interpreter, who makes a voice call to the person that the caller is trying to talk to. When the hearing person replies, the audio goes back to the call center, where the interpreter does sign language into a camera in their cubicle. That sign language displays on the deaf person's TV.
Scammers like this arrangement. At least one interpreting company (VRS) had to fight with the FCC about whether their interpreters could let the deaf person know that the call was a scam. The FCC's position was that this was supposed to be a faithful translation of the communication. But that was very hard on the interpreters, who were watching this person get scammed, helping this person get scammed, and couldn't do anything about it. Eventually the FCC relented, and now the interpreters can let the deaf person know it's a scam call.
2. The scenario is that the deaf will repopulate, not that they will specifically repopulate with "non-scamming progeny".