At some point I said that I would accept the account number as authentication and they were unwilling to provide that. I don't know why they--a legitimate fraud-prevention department--expected to be able to cold-call a customer and receive identifying information. They should be actively working to prevent customers from turning over this information to "just anyone who rings them at home."
I ended the call and contacted my bank via their online banking system and via that system they vouched for the original call and provided a number to call back. I lodged my complaint that their own fraud department was calling customers without any ability to self-authenticate. Not sure what happened from there; I've not had to deal with that process again since.
I wish every bank did this as standard practice! Hang up, dial the customer care number on the back of the card, then dial the digits supplied by the support rep.
Better yet, print instructions right on the back of the card: "don't engage any support representative you did not call directly." Training customers to do this (perhaps even through proactive callouts?) would work to significantly reduce this kind of fraud.
Except apparently to prevent this form of fraud you need to hang up, then call from your mobile, so that the "support rep" can't just stay on the line and do what the guys in this story did (fake a dial tone, make it seem like you've called the customer care number).
And if they don't, no harm, no foul (to the scammers)
This though, is where this scam is cunning, they use the fact that people feel safe calling a well-known number. I'd like to think I'd have offered the bank to cut off my cc rather than send it, but who knows...
This was the Visa at the RBS bank in Scotland, not sure what they are doing over there.