Why I willingly handed over my credit card and PIN to a fraudster
newstatesman.com
newstatesman.com
Can someone explain this? This seems like a pretty glaring and obvious issue that I'm sure I would have experienced before. Is he saying that if he hangs up the phone and picks it up again and the person at the other end doesn't hang up, then the conversation isn't over?
What I don't understand is how the scammers got his landline number?
This is a really elaborate scam, btw. The few times my cc# has been stolen, some dude just makes a card and uses at someplace like a hardware store and buys $1500 worth of tools before the bank frauds it out. In, out, no contact with me, just a sprint.
It also meant you would accidentally DoS someone by failing to hang up correctly if you initated the call - the pre-mobile equivalent of someone phoning you from the inside of their pocket...
I didn't remember anything about the conversation, only that I got up from bed with a pounding headache and thought no more of it. A few days later my godmother phoned me up:
"Do you remember what you did a few days ago?"
"I think I phoned you up?"
It turns out that while she was talking at length I had passed out from the booze. She had spoken for some time and then I hadn't replied. After some time, finding the call strange, she hung up and picked up, only to find the sound of silence; my room in which I had passed out. This was unfortunate as she had quite a few phone calls to make and she was effectively blocked from doing so. Presumably at some point I came back to some kind of consciousness that was capable of putting the receiver down and staggering to bed, but not capable of remembering. Thankfully I was forgiven and suffered only the punishment of wry disapproval.
So yes - as a young man I accidentally DoS'ed my Godmother because of stupidity and Stella Artois.
(https://news.ycombinator.com/item?id=4825751)
(https://news.ycombinator.com/item?id=4826367)
Here's another newspaper article about the scam. (http://www.guardian.co.uk/money/2012/may/23/credit-card-user...)
EDIT: cultural note - we don't[1] pay to receive a phone call, even with cell phones. Perhaps that makes a difference?
[1] Well, with normal accounts that is. Obviously free-phone 0800 numbers etc are different.
If you think way back, before dtmf/touch-tone phones, when you dialed a number, the line clicked. You press one, the line clicks once. For zero, 10 clicks. This is backwards compatible all the way to rotary phones.
Those clicks are the line being closed and re-opened in rapid succession. You dialled by 'hanging up' repeatedly. So the line can't close the moment you hang up - there's a grace period while it waits for the next click. If the initiating party does't hang up, they emulate this grace period until the exchange times out.
Ever see the "flash" key in a phone? Add a few milisseconds to that and a modern phone system should hangup.
If I remember the story correctly, this resulted in some debate followed by a law change, such that now if the called party hangs up, you have only a few seconds before the connection is broken.
I don't know how it went for the husband though...
In a proper telecom setup, if the hang-up time is longer than the flash time (a few hundred milliseconds) then the call should end - period. This allows you to hang up properly while allowing for call waiting features and the like.
As long as I tell my friend "I'm going to call up, pretend you are whoever I ask for", then when I call up and say "hello is Mr X there?" it's irrelevant whether I just dialed my friend, or whether he was sat on the line waiting for me to fake dial.
The person being duped provides a name and a number.
You leave your line open with a friend. Then you dial the new number, which doesn't work because the line is open, but it appears to work, fooling the person being duped.
Dialing the new number is a required part of the illusion so the person you are duping believes you are calling the person they provided the info for.
If you just dial your friends number and don't use the fake number... and they see you doing that... then that's stupid and your friends would have to be exceedingly trashed to fall for what is essentially you just dialing a friends number and talking to them.
Maybe to add a little bit of diversity:
At least in Germany, I don't recall this ever working.
I was in Barcelona, regular tourist. Here come a guy saying he is a cop, in civil but showing some kind of ID. Saying I might have stolen my own credit card and asking to dial the PIN on his phone. I've fallen for it. They've taken 400 euros from my bank account.
I guess we don't have to blame ourself, scheme exists, we might fall for we might not fall for it. This guys have training we don't, we have good reason to not act in the smartest way!
I hate Barcelona.
You can go to Avila, Segovia, Cuenca, Toledo... all excellent places and with good train and bus connections with Madrid.
At some point I said that I would accept the account number as authentication and they were unwilling to provide that. I don't know why they--a legitimate fraud-prevention department--expected to be able to cold-call a customer and receive identifying information. They should be actively working to prevent customers from turning over this information to "just anyone who rings them at home."
I ended the call and contacted my bank via their online banking system and via that system they vouched for the original call and provided a number to call back. I lodged my complaint that their own fraud department was calling customers without any ability to self-authenticate. Not sure what happened from there; I've not had to deal with that process again since.
I wish every bank did this as standard practice! Hang up, dial the customer care number on the back of the card, then dial the digits supplied by the support rep.
Better yet, print instructions right on the back of the card: "don't engage any support representative you did not call directly." Training customers to do this (perhaps even through proactive callouts?) would work to significantly reduce this kind of fraud.
Except apparently to prevent this form of fraud you need to hang up, then call from your mobile, so that the "support rep" can't just stay on the line and do what the guys in this story did (fake a dial tone, make it seem like you've called the customer care number).
And if they don't, no harm, no foul (to the scammers)
This though, is where this scam is cunning, they use the fact that people feel safe calling a well-known number. I'd like to think I'd have offered the bank to cut off my cc rather than send it, but who knows...
This was the Visa at the RBS bank in Scotland, not sure what they are doing over there.
Even if it's got a chip, what could possibly be stored on the chip's memory that would help? If there's a problem with a card being compromised or cloned, they issue a new one.
So it's wouldn't sound that outrageous for me. Especially if a courier would give me a time like 10am to 3pm and would come at 3:15pm :) Of course, other parts where they need my card for some kind of examination would sound weird. But I imagine I personally could have fallen for that if the other guy is really good, if not for tiny detail that I don't have a landline for about last 10 years... But the trick with calling back really adds a lot to the deal, all the rest s not that suspicious given that.
Getting the customer to call a number is another, they could have transferred the customer. Instead, they wanted to provide a shot of confidence before extracting info that no one, not even the bank should ask for.
No way. If someone claiming to be a bank cold-calls you, you tell them you'll call them back at their official number. Only deal with bank information on a call that you initiated.
I don't know how to work around the flaw in the article. Luckily it's not something we have to deal with here in the US, as far as I know. What a dumb "feature."
But then, a lot of stuff my bank asks me to do doesn't make much sense.
I guess it says something about banks that someone can call you, and ask you to do something weird, and it's okay because "that's what banks do".
Turns out it was the bank, but they don't do themselves any favours.
A couple months ago I was in the pharmacy to pick up a prescription. I handed the pharmacist my card and she walked back to her computer to run it.
A moment later, as she gets back to the counter where I'm standing, my phone (which I was holding) buzzes. I look down at an SMS "fraud alert" from Chase just as she says, "I tried running it twice but it won't go through."
The SMS from Chase had the name of the pharmacy and the total amount and told me I could reply to the message to state whether it was a legitimate transaction (I don't recall exactly what I had to reply with but effectively I was responding "yes" or "no").
I quickly sent back a reply stating it was legitimate and almost instantaneously received a "thanks" message. I asked the pharmacist to run the card again and it went right through.
I just make a personal appearance at a branch when this stuff happens - then they have to sit on the phone to themselves for half an hour while I have a coffee.
But is this something more common in the UK, perhaps? The only scams I run into are these laughable phone calls I get from time to time - recorded messages like, "This is card services from (fake phone static). Your card has been compromised. Please call us back." I never called the number back but from looking up online it seems that pretty much straight off the bat they ask you for your SSN, and I'm guessing they wouldn't have any personal info about you.
I wouldn't be surprised if they got this information from a receipt or something rather than following him home though. As he said, it would be easier to just mug the guy in that case. Following somebody home seems like a lot of investment and risk for a scam that only works on certain percentages of the victims.
- Less effort but requires willingness to use force.
- Doesn't require any knowledge of the phone system or victim's details beforehand
- High risk, since violent crimes can go bad.
- Police care more (although depending on jurisdiction they may take a report and be unable to do anything unless you get lucky and there are leads for them to follow).
Con game:
- Requires more preparation and knowledge
- Allows more time to abuse the card because the victim doesn't know anything's wrong for days.
- Virtually zero risk during the acquisition of the card
- Police care less... these crimes are more difficult to solve/clear.
Anyway, I was trying to muse that spying and following somebody to their home is a lot of work and carries the risk of being noticed and/or caught on camera, getting attacked by their dog, or at the very least consuming your entire evening. Who knows if the victim is going to drive 10 miles out of town or stay at the bar until 4am. Maybe they'll go to their girlfriends place instead leaving you with a bogus address. Maybe they'll notice you from the bar and wonder what the fuck you're doing following them..? It just seems impractical just to get your address.
Whereas getting info from a receipt could be safe & easy and you don't have to get physically close to a victim until you have them on the hook. You could pre filter. You probably don't even need to be at any particular location. Just go through a pile of receipts in the comfort of your own home.
But then again what do I know? Maybe it's ridiculously easy to find a mark and then follow them home.
Wow, what? This seems pretty crazy. I was wondering how they did it until I got to this point.
I wonder where the fraudsters have got all his personal info (including his land-line phone number) from. Even if they got a hold of his receipt that shouldn't contain enough info to get all the other details.
http://wireless2.fcc.gov/UlsApp/UlsSearch/license.jsp?licKey...
Yup, that's my home address!
> whois jrock.us
Yep, that's... a whole lot more info, actually.(Thanks for making me realize that I'll need to renew my license in a few months, I quite possibly would have forgotten.)
Most assumed that it was a vanity callsign but it's actually what the FCC assigned to me nearly 20 years ago.
Getting a name and phone number is easy. After you've followed the person home, poke through their waste paper bin until you find a letter/bill with the info. If the person is listed in the phonebook (often the default) then you just need the surname from the bin and the town/village of the house you're stood in front of.
At least in Europe it's fairly easy to find banks offering accounts with no maintenance/transactions costs , just open two accounts at two different banks, keep the same level of cash in both and if something happens you don´t have to go on a diet of canned beans waiting for the compromised account to be restored.
(Then again, some might argue that now you have twice the chance of being targeted by a scammer).
Twice the chance for half the money. Significantly less for the whole sum (assuming scams are independent events). I think it's a good tradeoff ;).
I was expecting an interesting article about a deliberate handing-over of credit card and PIN to a known fraudster, in an attempt to examine their behavioural patterns and maybe offer some anecdotal insight.
I felt the actual article was much less interesting.
The big risk though is going out to pick up your card, that gives you the opportunity to film them. If you know which ATM they are watching you set up a sting to catch them in the act.
I assume because each number on the keypad has a unique tone, they could extrapolate which keys were pressed?
Also how did they get his phone number? The phone directory?
Most shocking is how did they get date of birth and mothers maiden name!?!?
The telephone exchange listens for those tone combinations to know what number you're dialling. If you have an audio recording of a number being dialled, you can actually figure out the number just by listening to each tone separately and comparing it to the sound made by pressing keys on your own phone. Wouldn't surprise me if the fraudsters did just that, or maybe they used a "spectrum analysis" feature on a PC audio program.
The caller had spoofed their caller ID to reflect a police agency, albeit out of my jurisdiction, but like the OP it was early on a weekend morning and I was quite well hungover, so I readily supplied the requested info.
It was a valuable learning experience and I admit to being "schooled" by the perpetrator but seeing that no actual harm was done I let the matter drop like the lead it was worth.
If only I could ask them what their favorite restaurant is, maybe we'd finally have two-way verification. Nobody else picked McDonalds, right? That's a safe choice?
That's bold.