Hacker News new | ask | show | jobs
by digitallawyer 2488 days ago
OP here. Just a couple of the things I learned since I posted the Twitter thread:

- The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them.

- The caller called me twice in rapid succession (First ignore the call from a number you do not know. Then they call back again immediately: "maybe this is urgent / important"). Another person in the thread, who fell for the scam, noted this same pattern.

- It is better if banks include a security warning / specific reason the code is sent with the password reset pins and similar credentials. My bank did not. Another twitter user noted being subject to the scam, and just glancing over the warning copy. So it helps, but it is not perfect. Especially pre-coffee.

- My bank no longer allows me to reset my password without calling them (thanks bank).

When I read the thread now, it's obviously full of red flags. I was successfully manipulated, and whilst I'm certainly not as clever as all the people pointing out they would have caught this from sentence one, I believe I'm also not the lowest hanging fruit in terms of a target :-) Makes you wonder what this will look like when these scams evolve another couple of generations in terms of complexity ...

31 comments

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiate a call (usually they launch straight away into verifying who I am, asking me a ton of personal details before I even know that they're legit... sigh) and would just ask me to call them back on an official number (not one they give me over the phone, obviously) instead. If that were standard practice, I think these kind of scams would be a lot easier to detect.
>my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are"

Amex got quite offended when I did this, and almost chastised me when I got through to an agent after making the outbound call myself. They argued that because they only asked for limited personal information (DOB) it was fine...

I would still do it again!

I had that same issue with Amex, they phoned, said there was a concern with my card and then wanted me to go through identity checks before saying more. They also got quite stroppy when I refused and asked them to prove their own identity first!

Eventually they did suggest I call the number on the back of my card, but I was annoyed by their lack of professionalism by this point (I mean, they are asking me to do stuff - giving out information to unknown callers - which they themselves always tell customers never to do!) I said I wasn't going to phone a general number and get stuck on hold for hours over an unknown issue - either give me some reference to get through quickly to the right person, tell me what the problem is now, or send me a letter. But they kept claiming that they couldn't send out letters in the post :-(

In the end, I finally received a letter by mail telling me that there were problems with my direct debit payments. So it was a genuine call but their inability to securely make these calls is frustrating.

I think if they gave you a number to bypass the general queue that you’re still vulnerable to an attack, right?

The only way to ensure you’re calling amex is to call the number you know, otherwise the scammer will have you call another one.

Call the number of the back of the card - "Press X if you have been given a code by us". Effectively, you're calling <number on the back of the code> + <reference to queue skip>.
It would be reasonably trivial to build a phone system that lets the agent generate a OTP of sorts.

"Hey, we need to talk about your account. Call our general enquiries number on our website, press 9 and enter 'XXXXXX' to be reconnected to me."

I was just thinking about how the agent could generate ephemeral PBX extensions. OTP-like would definitely be the way to go.

Edit: perhaps the extension would be per transaction, not per-agent, and when the customer calls the extension, the agents system can automatically pull up the customer’s account. These extensions should expire, but given the length of some customer calls, and how often I’ve been disconnected from customer service lately, perhaps it should be on the order of hours, not minutes or seconds

Not a different number to call, but instead a shortcut through the usual automated phone menus - e.g. I've had a bank tell me to phone their number and then enter an extension to take me straight through to the right person.
Just ask for an extension to reach them at when you call their public number.
Why would a letter be genuine? That seems easier to spoof then phone or email?
Cost.

Email is pennies per thousands.

Phone calls are cheap especially for nonconnected or robocalls (which would cost for a postal contact).

Postal mail costs $0.50 US in postage alone. The full-up cost of a mail campaign is often several dollars per mailed item, though in bulk, and with bulk rate, I believe it's closer to $0.40 (postage plus a few cents for paper and envelope).

That would cover many thousands of email contacts, possibly nearly as many phone/VOIP attempts.

And the systems required to successfully and accurately generate a postal response on request are also high.

Low-cost systems are high-fraud systems.

Not sure if it’s true, but I’ve heard that mail (at least in the US) is safer because the cost to send letters is high enough to deter bulk sends vs email/phone, that postal inspectors are relatively effective at catching people, and that the laws around mail fraud make prosecutions easier.
I got a scam letter from someone claiming to be Canada Revenue Agency, so I wouldn't bank on that either.
It might not be genuine. But what one should do to resolve the problem described in the letter is to go to the regular amex website, log in, and update your debit information.
My preference is to have multiple points of contact. Email+phone and the alert is sent simultaneously both ways. This happened recently when a purchase I made was flagged. I got a text asking to approve the charge. Not trusting SMS I checked my email and saw the same message as the text and a link to take further action.

I was disappointed that no alert was sent through the banking app. That would be the most secure option but is explicitly disallowed in the notification settings.

It's not so much that the letter is guaranteed to be genuine.

They can include information in the letter they can't include on a phone call, as the mail service is performing the authentication.

My health insurer won't talk to me on the phone without me confirming identity, even if they called me, but they'll happily mail the info.

Never call the number off the letter, though.

I also do this every time when my doctor's office or insurance calls. They have to verify your identity to give you medical information. I need to verify their identity to give them my personally identifiable information.

I think eventually they got the point because now they have a secure online email system and just leave a message asking me to call back. They still leave a return phone number, but it's getting better.

At least with an email you can hopefully verify the headers. A phone number is too easily spoofed these days and the end user has no real means of verification.
My bank always says "There is an issue with your credit card/account, please call the number on the back of the card/your branch as soon as possible." and has for years.

The only time they do otherwise is on very specific instances where they provide the info, "did you just buy something at store XXX for approximately $YYY"

All banks and credit institutions should be required by law to do this.

Capital One has an app, every time my card is used I get a push notification. This is the best solution in my mind. I can actively monitor my card usage and call if I see something suspicious.
I'm surprised that this isn't a requirement for banks considering the very large number of scams going on in the US.

In India, getting an SMS/Email confirming every card usage is a legal requirement imposed by the Rserve Bank of India. The same goes for card usage itself. All credit and debit card POS transactions need the card PIN to be approved. Likewise, all online transactions require MFA.

AMEX does this and it's honestly great. Unfortunately my credit union doesn't, but I use credit for most transactions anyway.
chase does this too.

applepay, for all my cards, gives me an immediate push notification, despite some cards not doing so for regular chip/swipe transactions. really like that feature & also wish all cards did it for all transactions.

My AmEx does that too. I really like that feature.
I wish all banks and CCs offered this feature.
It's worth searching on their site / calling them, since in my experience every time over the last couple years I have dug, I have found it offered.
My bank does this. Two texts:

1: "We need you to verify some transactions. You will receive a text from <number> with the transaction details"

2: "Do you recognise these transactions? <date/store/amount x 3> Reply Y if yes, N if no"

Y -> "Thank you for verifying the transactions. If any transactions have been declined, you may been to repeat them"

N -> "Your card has been blocked and a new one ordered. Please contact us if you need any further advice"

These are what I usually see, or else an automated call with the same approximate script. Is there anything insecure about doing this one? The only thing I can think of is a MiTM where your account credentials are already compromised and they are using your answers to reset your password.
These fraud alert calls (in my experience of course) generally don't have any ID verification so there's no real danger from the user side in interacting with them. They just ask do you recognize these charges and that's it and then initiate any fraud response. From the bank side the worst is if the number has been hijacked but the user would still be able to dispute the charges later through the normal means but CC cloners probably rarely do that so it's not a huge issue.
You should be careful even about doing that if you are on a landline. There is a landline scam where they don't let the call disconnect, so when you hangup and then think you are dialing the bank, you are actually still connected to the scammer.

Always use your mobile phone to make the call (although I'm sure its only a matter of time before even that is compromised).

https://toronto.ctvnews.ca/etobicoke-couple-defrauded-of-mor...

Luckily I don’t have a landline so it’s all mobile :)
I don't do that. I say "are you crazy, you are a bank and asking me to prove who I am? You called me. You prove who you are first."
Yes, you’re right, I did say something like that once but the end result was the same: they asked me to call the number on my card.
While spoofing numbers on incoming calls is far easier, it is also possible for an attacker to redirect your outgoing calls from the right place in the phone network.

You just shouldn't consider any aspect of the phone network to provide authenticity or confidentiality.

I had an experience indistinguishable from the phishing attack being discussed - with the only difference that I initiated the phone call. A transaction I had initiated had triggered some fraud warnings and my account was locked.

They asked for my account number, name, and address for verification. When they got to the point that they sent me a code over SMS and wanted me to tell it to them over the phone, I stopped them and explained that this is also the exact set of steps required to reset my account and that I wouldn’t do it.

I went to a branch in person to unlock my account and the person helping me asked me to enter my password on their terminal so that they could “see the error message”.

I’m still not sure if some parts of this were a more advanced phishing scheme than I had thought was possible, even though it does just seem like a set of confusing practices by the bank.

I wonder if bank staff are in on it sometimes. I once was at a bank branch and had the teller pick up the phone, call another teller and tell her my balance in a foreign language that I happen to speak fluently (but don’t look like I should).

I wanted to ask her why she would be doing that, but I was a bit more meek in my younger days.

I had something not exactly like this occur to me. It wasn't something I overheard, but I'm pretty sure it went something like this:

1. You talk to a teller at a branch, and they bring up your account details. The teller see's you have a mortgage with the bank, but registered to a different branch. 2. They have some sort of incentive from the mortgage specialists at their own branch or management, to refer those accounts to their own mortgage team. 3. The mortgage department at the new branch calls me, and says I can do an early renewal at a lower rate, if I come in and see them.

Anyways, I did the early renewal at my original branch, as I had a connection to a manager at that location. Either way, I ended up shaving a good chunk of interest by renewing a year early.

What's an "early renewal" in this context? Mortgages aren't things I think of as requiring renewal at all.
At least if you're at the bank, the typical separation of powers would at least ensure they're caught promptly, should something go wrong.
You initiated the call to what number? The number on your card? If so, that's ridiculous.

(Obviously, initiating a call to a number provided by a potential scammer offers no protection. If someone is intercepting and redirecting your outgoing calls via the phone network, I'd say you probably have a bigger problem than a declined transaction.)

I get these calls from time to time, and any bank with proper training should be 100% okay with you questioning their authenticity. There are some replies which indicate that the agent is annoyed... That's just poor training.

As for them initiating a phone call, it still does remain the best way to contact someone urgently, usually falling back to SMS and/or email when/if you don't answer (this was our SOP when I was in a fraud detection team years ago). We'd also usually tell them to call the number on the bank of your card (because not everyone is able to look up the bank's website, shockingly, so this is the most universally applicable way to give people a number) but my usual spiel was "call us on the number on the back of your card or from our website".

There's also no real way for you to know that they're legit, but an interesting reassurance one bank I know uses is to provide your month and day of birth and ask you for the year (as just part of the verification process). The partial info probably helps some people but I still wouldn't go for it - too many people know my birthday.

I always say to them: I can not identify myself to you because I cannot authentic who you are.

And explain to them that we, as a society, need to come up a way of authenticating inbound and outbound calls to ensure we are connect with who the other party claims to be because when you do this it conditions society in to responding and that’s how phishing attacks occur.

society could fix all sorts of problems if we had a public key infrastructure...
Banks have this in place already - EMV cards have powerful cryptoprocessors. In Germany we can use chipTAN, it's a small cheap reader for your card where you scan a six-binary-blinking screen that transmits the transaction data, then the card signs it and you get a six-digit TAN back. You can also manually enter the hash to be signed ("start code" is the technical term) and you get the TAN.

Customer support could ask you to authenticate using the TAN already, the hurdle is that you would need to carry the reader at all times.

Unrelated to banks, I believe it could be possible to extend SS7 signalling to not just transmit the caller ID but also a crypto signature/public key which the phone then can verify - or your phone provider could. Think of something like HSTS with a global database, if there is no match for the phone number the provider patches the call through, but if there is an entry, all providers can check for the public key transmitted by the caller and refuse to patch the call if it's missing or faked.

Would you happen to know what kind of signature scheme they use?
IIRC the German system is proprietary, the specs are available only after payment of a couple hundred euros.
I don't know about the German system, but here they use EMV-CAP: https://en.wikipedia.org/wiki/Chip_Authentication_Program
My bank seems to use a similar scheme. It appears akin to TOTP with 8 numbers. But the secret is inside the black box. They also have something like a QR code but with RGB colors (does not work with blue light reducing features).
We are in some kind of Stone Age of The digital age...
Or maybe some sort of interconnected web of people who trust each other...
That would be pretty good privacy.
Like the web of trust from GPG?
The WoT originated with PGP (though obviously GPG implemented it as well), but yes, that was the joke.
> "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are"

Correct. If someone calls me, the onus is on them to prove to me that they are who they say they are.

However, I usually just block ALL unscheduled phone calls, period. Not only do I not have time for unscheduled interruptions, but banks have secure websites and if they can't make proper use of them, too bad, they aren't going to reach me by trying to call me. They should know that phones are easy to phish with, and stop using phone calls to initiate communication.

Ideally what I want is an e-mail saying "we saw some suspicious transactions, please /log in/ to check that there is no fraudulent activity" or even a more general "please log in for an urgent message" with a suspend button in the online interface.

Good point, and in fact I haven’t gotten such a call in a long time. All the “did you make transaction X” type calls now go through their app or via sms, so don’t get those calls anymore. I can’t actually remember the last time the bank called me, but maybe 6 or 7 years ago they called me a good few times. Nowadays I actually also block incoming calls unless in my contacts or I’m expecting it. I communicate mostly online and outside family, rarely get phone calls. So I really don’t care to answer a random call.
Why would they need to verify you when they call your phone? When I got theses calls personnaly it was a robot voice that was simply asking if a few of my transactions were done by me. It only happened twice, and I feel they make sure to include both actual transactions and a few fake ones to verify your truthfulness because in both case I had one that was clearly wrong that I never saw in my transaction log and they didn't replace my card.
This. I always tell them I'll call them back if it is someone I don't know who needs to discuss sensitive matters. It's the only way to be sure.
> It is better if [...anyone...] include a security warning / specific reason the code is sent with the password reset pins and similar credentials.

I think anyone building such systems (either via e-mail or SMS or whatever) should at least remember THIS.

Send something like this via SMS:

> The password reset code you requested via our website is 12345. We will never ask you for this code except when you requested a password reset.

1. What is requested 2. How was it requested 3. Is it safe to pass this to some other human being

Okay, 4. in better English ;) As opposed to:

> Your caller verification code is 12345, please read this code to your banking agent to verify your identity.

Also, ChipTAN is great: https://en.wikipedia.org/wiki/Transaction_authentication_num... If your bank would use this, it would be require extraordinary smart social engineering (or a really naive user).

Hey, this is actually how it works in Turkey. All SMS messages for transaction purposes from banks have a disclaimer, which indicates whether to share the code with customer service representative or not.

For example, for online transactions, the SMS includes a warning to not share the code with anyone, while SMS codes for telephone banking tells you to share the number with the representative.

The only text messages I get from my bank are descriptive confirmations of actions I did. At the end of every message it says to contact them by phone if you don't recognise the action.

My bank uses a scanner to authorize pretty much all actions. It scans some sort of RGB QR code [0]. When scanned you'll see the IBAN you're sending the money to and the amount you're sending. I think that when the IBAN is in your contacts it shows the name instead of the IBAN.

But most importantly it shows a descriptive message of what action you're verifying. I think the only actions that don't require the scanner are small transactions through their app and marking your card as broken/stolen in the app.

[0] https://www.rabobank.nl/images/how_does_the_rabo_scanner_wor...

BofA gives a disclaimer when you have a 2FA code texted to you (still wish they supported TOTP, but whatever).
>When I read the thread now, it's obviously full of red flags. I was successfully manipulated, and whilst I'm certainly not as clever as all the people pointing out they would have caught this from sentence one, I believe I'm also not the lowest hanging fruit in terms of a target :-) Makes you wonder what this will look like when these scams evolve another couple of generations in terms of complexity ...

I think this is a social skills moment. For those that claim it's "easy" to spot: This is not the right time for people to brag about how they would have totally spotted it. This is mostly for protecting people who (as most people in this world) don't have time to build up a solid understanding of all aspects of internet security. If you don't care about these people, as some sort of Darwinian schadenfreude, stfu. If you do, focus on their perspective, not your brilliant detective skills.

I'd wager >50% of those that claim "Ah ha! I'd spot it here!" would fail in real life. Arm-chair quarterbacking is easy. Spotting the scam in real life, when you're walking down the street or otherwise distracted with life? Much harder.
I don’t know... this is not a “social skills” thing. It’s a very simple rule that should be easy for anyone to follow: never talk to any business who calls you. Ask who they are, hang up, and call the official customer support number. That’s it. No wizardry, charisma, or smooth talking ability needed. Get who they are and hang up.

Personally, I don’t even answer the phone anymore unless the number is one of my contacts. Looking at the last 30 days of call history, a good 95% of my incoming calls were spammers who didn’t leave a message or spammers who did.

The last time a legitimate number called me I didn’t recognize was probably a year ago. It was my daughter’s school. They left a message and I called them back immediately. That’s probably the safest way of dealing with the security trash fire called the phone system.

Yeah, hanging up and calling the 800 number on your card is the best route.

But, the responses on Twitter weren't "never talk", they were "I'd know it was a scam as soon as..." (implying they'd allow the call to get that far).

Most people claiming they would have spotted it are probably wrong anyway. They're reading the messages with the knowledge that they were sent by a scammer. Any idiot can identify these things in hindsight knowing what they're looking at. Without that context, with other things on their mind, it's much more likely they'd have been duped too.
Absolutely. You're in the middle of something else. Your "bank" calls you. You're thinking "What the hell do they want and how can I deal with this as quickly as possible?" Etc. I like to think that I'd never fall for any of these scams and I'm sure I'm more conscious of the possibility than I would have been at one point. But I can't really swear that distracted me whose mind is 75% focused on some other task is as security-aware as I like to think I am.
They say the generic rule of thumb here is urgency. If you can't take your time, it's a scam. I was previously scammed several times with urgency, but as a rhetoric trick under a premise of impatience.
Just realizing that a phishing-attack like this is nowadays impossible in the EU: proper two-factor authentication is mandatory now (Revised Directive on Payment Services, PSD2), even just for login. TAN-codes generated for transactions need to incorporate the data of the transaction (recipient and amount), so that a phished TAN cannot be used to authorize a different transaction. I think even a simple SMS TAN may not be allowed any more (could be MITM-abused to authorize a different than the intended transaction).

Here is a summary of what customers and phishers have to face since september:

https://wso2.com/library/articles/2019/06/strong-customer-au...

The security part of PSD2 is starting to look like another cookie law. Banks of course didn't implement any proper 2FA like U2F but rather send you scrounging for the phone with their app every time you want to look up a transaction or an account number, something that didn't require second factor until the directive.

In fact, because it makes checking recent transactions that much less convenient, it probably made me less safe because I do it much less often.

TOTP is in terms of usability not very different from PhotoTAN or ChipTAN, so I don't see how these methods aren't "proper 2FA".

U2F is a useful method, but it's not common at all (even in IT most companies don't provide it, not even the website we're on right now, nor PayPal), and it's not understandable how this isn't "proper 2FA".

In addition, the directive requiring the purpose of the code to be fixed and shown aside it, either in the app generating it, or in the push notification, is a very useful security aspect which most other 2FA solutions miss — even U2F can't differentiate between a login and a transaction authorization.

I don't like TOTP. U2F, however, is both convenient and secure. You touch a dongle, you're in, and at the same time there is no way to get access to your account without physically stealing the dongle. It's a proper second factor to a password.

Other solutions are either or. There is a benefit to confirming particular actions (with the info about the action) in the app but it's unnecessarily inconvenient for mere login.

U2F isn't widely supported but I managed to secure virtually my entire high-value Internet presence with it. Google, OVH, Coinbase, and Stripe all support it. Let's be honest, for HN I wouldn't bother with any second factor. I have the password saved in the browser and that's more than enough.

Here we have ChipTAN - I put my card into a special reader (some photodiodes plus keypad and display), hold the diode-end of the reader onto my PC display and a flickering image on the website transfers some info to the reader. On the reader I then see some info on the transaction (IBAN and amount), plus a TAN. I then enter that TAN on the banks website.

So an attacker would need to alter the image (simple) and cause a collision (hopefully difficult) or somehow abuse an error in the reader firmware.

It seems there is now a QR variant of that (which increases the attack surface since now it has to understand a more complex data format).

If my bank would have had me install an App or use SMS 2FA I would have kindly asked them to .... off (or, if they think their "2FA" is safe, just connect their mobile phones to this totally unsuspicious looking USB device).

ChipTAN on wikipedia: https://en.wikipedia.org/wiki/Transaction_authentication_num...

Interesting thanks for the write-up.

One thing that I've frequently heard is that in any type of fraud call you should always hang up right at the beginning and call the bank back.

Seems like no matter how sophisticated the attackers, this defense will always foil anything along the same lines of what happened to you. The only way I can see this countermeasure failing is if the scammers can somehow manage to intercept inbound calls to the bank's customer service number.

I agree. The same goes for email obviously. But some financial institutions are actively luring customers into doing the wrong thing.

Paypal really stands out on this one. They are regularly sending me emails with a link to their login page to view my recent transactions (regardless of whether or not there are any transactions). This is clearly negligent.

Okay, so it's not just me. I've never clicked on what are apparently real paypal emails, because I have legitimately always assumed they were phishing e-mails that made it past my spam filter.

They're real. They're really real paypal e-mails. Wow.

I believe them to be genuine, but if you need incontrovertible proof, Paypal has you covered! :-)

All messages contain the following "clarification":

"How do I know this is not a Spoof email?

Spoof or 'phishing' emails tend to have generic greetings such as "Dear PayPal member". Emails from PayPal will always contain your full name."

So unless the bad guys can get their hands on a database full of names and email addresses, we're safe. And Paypal can honestly claim that "the security of our customers is very important to us!".

It is a pretty good idea, but only sufficient if you don't have much money. For large balances it might be worth someone's time to bribe your local telco worker or subvert your SS7/Diameter routing so that your calls route via an intermediary (i.e. make your phone a roaming number, route it's calls to an attacker controlled exchange in e.g. India). It is even simpler to listen in to your legitimate call and hear your phone banking password and secret Q&As.

Calling via a landline or via an operator assisted call would make such tricks much more difficult.

Some great papers on Diameter and telco security here: https://www.bell-labs.com/usr/silke.holtmanns

There seems to be broad consensus amongst the commenters that this is the most reliable defense against this kind of attack. Makes sense. If they are able to intercept my outbound calls, it's probably an entirely different level of sophistication and targeting.
I read about a landline attack that would keep the line open when you put the receiver down, play a dial tone, and then wait until you’d entered a number before putting you back on with the scammer
Analogue telephones are creating (or at least in modern times simulating) a circuit, which doesn't close until the caller hangs up.

But almost everybody today has a digital phone, any kind of mobile telephone or desk VoIP phone is digital, "hanging up" ends the call because the telephone itself decided to do that, everything is just packets. So this trick won't be effective against most people today.

Likewise "dialling" today is an out-of-band digital step rather than a bunch of pulses or tones sent in-band that an attacker can just ignore.

> I read about a landline attack that would keep the line open when you put the receiver down

I experienced this once, but not as a scam, I think there must have been some kind of fault at the exchange... the other end was a mobile phone and they didn't end the call, just putting the phone back in their pocket - the landline wouldn't disconnect, whatever signal was send, even disconnecting the phone entirely and plunging it back in. I didn't understand how exactly, but it made it pretty clear the (landline) telephone is not in control of the connection.

Learned about this too today. With the scammers playing the dial tone sound to trick the victim... Clever.
Yes, this has been the recommendation for a long while. Always call back on the official number you got elsewhere, not the caller ID number.

Sometimes the one calling you is already suggesting you to do this just to verify. Especially bank and police I noticed.

IMHO this should be the law for financial and medical institutions tc. They should not be allowed to call and ask the receiver to provide verification information.
It doesn't need to be the law: I never provide any information to someone who calls me, unless I have a way of authenticating them.
You're set, then. But the reason a law would be beneficial is it would condition everyone's parents and people who aren't as awesome as you to stop trusting callers and start calling a known-good number.
>It is better if banks include a security warning / specific reason the code is sent with the password reset pins and similar credentials. My bank did not. Another twitter user noted being subject to the scam, and just glancing over the warning copy. So it helps, but it is not perfect. Especially pre-coffee.

I'm seriously surprised there are banks that send SMS codes without a reason for the code. All banks I deal with always send the reason for the code. For example: "This is a new payee addition authorisation code. Last 4 digits of the payee's account number are XXXX, the code is: XXXXXX" or "This a transaction authorisation code for the amount of $XX.XX, to an account ending digits XXXX. The number is XXXXXXX."

I would seriously reconsider giving your business to a bank that doesn't do that.

Interestingly there was an EU regulation passed recently that sets certain standards requiring 2FA for certain operations performed by bank customers. Having set up the 2FA auth app on an elderly relative's android phone and having to set up a pin to unlock a device as this is one of the 2FA app requirements and then spending 2 hours explaining how to unlock the phone, how to use it with a tablet to log in, how to authorise payments etc I have mixed feelings. On one side, it is a pretty secure system that will lower the number of victims of fraud. On the other hand it is a massive inconvenience for elderly people. I like the SMS verification system if done right. I think 2FA is a bit of an overkill.

Elderly are the most common subject of these attacks. So it is especially important to set strong protection for them. The inconvenience is regrettable but necessary.
2FA for banking is not overkill!

You can make 2FA really easy if you want to, now that EU req. 2FA there will probably be more banks with reasonable solutions.

I have seriously reconsidered giving my business to a bank that does do that: I'm not a fan of sending transaction amounts or account info via text. My bank does this (and over email!); their security posture is fairly decent otherwise, but why oh why send transaction amounts out into the world where they can be intercepted by anyone between here and there?

Think about the useful information for an attacker in messages like that: Recent transaction details can help an attacker auth on a call, account numbers can do the same. And large transactions are catnip, alerting attackers to worthwhile victims.

"The caller called me twice in rapid succession" this is to bypass the "Do not disturb" functionality on iOS if you have "Repeated calls" enabled. https://cdn.cultofmac.com/wp-content/uploads/2014/04/Do-Not-...
I noticed a political robocall taking advantage of this just yesterday, and there went any possibility that I would vote for this person. Your robocall did not constitute an emergency _you asshole_.
The biggest mistake was offering any information. You never offer information, you only confirm or deny things that they tell you. If they insist on things like member id, or email, you hang up, and call the bank yourself.

We as a society need some form of standardized ISO 9001-level protocol where ALL companies handle security the same way. They all ask the same questions, they don't allow first-tier support access to passwords or changing password, only specialized tier-2 support has this power, etc.

If all companies like banks, Amazon, Facebook, etc standardize their procedures in a way that leaks no information, or engage customers in a way that leaks no information, then it will make it harder to phish people because phisher will be forced to ask weird questions that customers will detect as weird.

The problem right now is that some companies ask for last 4 digits of SSN, last 4 digits of credit card, some ask for email address, etc, etc. A phisher can put all those together so if you reduce the attack surface it makes it very very hard.

To me, the biggest red flag is asking for any identifying info in a conversation they initiated, especially without them initially providing some sort of privledged information to you first.

Unfortunately, some banks do this. (I'm looking at you, U.S. Bank.)

It's like someone calling me and then asking me who they're speaking to. Really? You called me! (Assuming they're not returning a missed call, of course.)

If (someone claiming to be) a bank calls/texts you, (and it's not immediately after a declined transaction) you always hang up and call the number you already have for the bank.

Even if it is after a declined transaction, you still don't provide any info. If they ask if you attempted a $101.89 purchase at "big box store," you should simply respond yes/no, and provide no other info.

If you didn't attempt that transaction, they especially don't need to confirm any other info.

In your tweets you mention "And now... joyfully resetting all my passwords, filing a police report, getting additional fraud detection in place". What passwords are you talking about and why do you need to reset them? As far as I can tell no passwords have been compromised in the attack as you describe it.

Or do you suspect that there's been an other, undisclosed breach that the scammer used to get your name and phone number? I suppose it's plausible but it seems like it wouldn't be too difficult to get that info.

Should have written that more clearly. More accurate verbiage would have been "changing all my banking credentials, and enabling all possible notifications". I have no reason to believe other credentials were compromised, and have unique pw in place for nearly everything.
> My bank no longer allows me to reset my password without calling them (thanks bank).

So how are they going to verify it’s you who is calling them?

Ask for things like postcode, birthdate, etc.
None of these are secret, asking for these things provides no security.
Pro-tip, perform mutual authentication:

"Can you give a reference number (they will have a case number), and tell me where I can find your department's number on your website please. [Edit] I will call you back."

I've never had a bank or other financial institution have a problem with this approach. I don't give myself the opportunity to be fooled, because all of us can be fooled, it's how I respond to every single call from a business.

It should be noted that Caller ID spoofing is possible with pretty basic equipment. It's illegal in most countries but there's nothing technically preventing you from doing it. Which is crazy IMO.
SMS number spoofing is even easier, and available via almost all programatic SMS services. Usually used to set the sender name.
>It’s illegal in most countries

Would love to see a citation for this.

Of course it’s illegal! All developed countries have strict rules about how you can use Telecomms networks. Of course scam artists don’t care about these rules ... Its not hard to find out further information abour this. Check with your local Telecomms regulator, google or even the Wikipedia page!
>Of course it’s illegal?

Fraud tends to be illegal. That’s as far as I’m willing to believe your “of course”.

I do not believe most countries have laws regarding caller ID spoofing.

I know that in my country IMEI spoofing is (Bizarrely!) sort-of prohibited as forgery (as in IDs, documents or “anything of evidential/testimonial(?) value”), but can’t find anything regarding phone numbers.

I know that in the US it’s only illegal to spoof your number for fraudulent purposes.

> it’s only illegal to spoof your number for fraudulent purposes

Seems like you’re gettig bogged down in semantics sir

How is that semantics? Fraud is already illegal literally everywhere, so spoofing your number for fraudulent purposes will obviously be a part of that crime.

If this is intended to defend your original claim, you’re being utterly ridiculous. You made a specific claim about caller id spoofing, not fraud.

For example, If you’re spoofing a random number for telemarketing calls that’s just not fraud.

Its a common feature for PBX'es to rewrite their outgoing caller ID on forwarded calls to match the origin caller ID. Say you've got an office desk phone that you have set to forward to your cell phone while you're out. Someone calls your desk phone, it forwards the call to your cell phone, what caller ID should be displayed? Technically the call to your phone is coming through your desk phone (well, your office's PBX), but doing that would mask who is actually calling. So the PBX rewrites its caller ID info to appear to be as the origin when it calls your cell phone.

This is technically spoofing caller ID, but is clearly not fraud.

> The caller called me twice in rapid succession (First ignore the call from a number you do not know. Then they call back again immediately: "maybe this is urgent / important").

This also gets past some Do Not Disturb modes.

With regard to the phone number spoofing: I recently had an actual call from American Express's security department marked by AT&T as "Fraud Risk," presumably because it's been spoofed in the past. It delayed the detection and resolution of the theft of my card number (not by much, but still...). It's criminal that we haven't better secured the Caller ID system.
I've recently read about a similar attack, but in Brazil.

Translated: https://translate.google.com/translate?sl=pt&tl=en&u=https%3...

Original (Portuguese): https://threadreaderapp.com/thread/1179903474244444160.html

Same approach, they also pretended to be from the bank calling about an irregular transaction. In this scam, it seems they hijacked her home phone line. She tried to call from her cell phone, then they called back to her home phone and said all communication should be from it, to ensure she was at a different location.

I got a similar call a few months back. They didn't ask for my PIN, but did ask for some other sensitive information. Fortunately I was able to verify afterward that it was legitimate by initiating a call to the bank using the number on their website (in case the original was spoofed), and they confirmed a record of the call in their system. But this was after I'd given them some information.

Phone number spoofing has to stop. There is no excuse anymore.

> When I read the thread now, it's obviously full of red flags. I was successfully manipulated, and whilst I'm certainly not as clever as all the people pointing out they would have caught this from sentence one, I believe I'm also not the lowest hanging fruit in terms of a target :-)

I think it's soo easy to spot scams because 99% of them are so shit, poor spelling, talking nonsense.

If scammers simply spell checked their scams I would fall for them all.

Not sure if still the case, but this used to be done specifically to weed out people who weren't quite gullible enough.

https://www.telegraph.co.uk/technology/microsoft/9346371/Nig...

Step one for me when I am giving sensitive information is always "let's end this call and let me call you". I had gotten an e-mail from my bank and I called the number in the e-mail without thinking to lookup the support number on my own first. The number was legit and it gave the fraud dept a chuckle but it very well could've been a fake number
Calling twice in rapid succession is an emergency feature for Android (possibly other) phones when in Do Not Distrub mode. It bypasses the DND when you call twice like that. Usually, only the numbers on your Starred list can call without getting blocked by DND.

The recipient may believe they had starred the number because of this, making them more likely to pick up the call.

On iOS you can choose whether to allow or block repeated calls, but as far as I can tell it's an all or nothing toggle. If it's enabled, anyone can get through by calling twice.
I never give any information to anyone who calls me, apart from people I already know like friends and family. If they say they are from the bank I apologize and say that I will contact them independently via the number that is on my card. I don't even confirm my name. Some banks think I am being difficult, but I stick to this principle regardless.
I think it's more likely that some scammers think you're being difficult. Shouldn't that be standard procedure for a bank?
Once I gave my member number, the attacker used the password reset flow to trigger a text message from the bank. --> They used this to gain access to the account.

How did they to gain access from "password reset flow"? How could they tell your last transactions?

This is actually fairly common now, unfortunately. Many reports of Uber drivers being tricked into getting their account hacked using this method to obtain the 2FA pin sent via SMS so they can drain their balance or switch the bank account on file.
Sorry for OT, but I'm Belgian, a software developer, and have a law degree too - can I pick your mind on legal tech in Europe a bit? I can only find your twitter handle, do you have an email address I can reach you on?
Hi Roel, Twitter DMs are open.
Every financial institution has a mobile app now. They should just add a secure voice chat feature to the app instead of relying on phone calls.
The best defense against a scam is familiarity. Thanks for sharing this, hopefully it protects someone else.
I would say Thanks for the call. I'm hanging up now to call my bank to verify this.
How do we know you are the OP?
Sorry for the nitpick on grammar but

"I was just subjected to the most credible phishing attempt I’ve experienced"

Everyone has been subjected to the most credible phishing attempt they've experienced. Need to find another qualifier ;)

thanks for sharing and sorry it happened to you. sad to say but, i would be suspicious with if any interaction with a bank is going this easy and is this convenient...
If the password reset procedure is over SMS, wouldn't any interception of that token have allowed the attackers to access your account and even initiate outgoing transfers?

A scam phone call seems like a clumsy way of doing it. It also risks alerting the victim to what's going on.

It surprises me that it is legal to conduct banking operations to the general public in this way. In many countries (including all of EU since SCA) that is not the case.