|
|
|
|
|
by londons_explore
2488 days ago
|
|
While spoofing numbers on incoming calls is far easier, it is also possible for an attacker to redirect your outgoing calls from the right place in the phone network. You just shouldn't consider any aspect of the phone network to provide authenticity or confidentiality. |
|
They asked for my account number, name, and address for verification. When they got to the point that they sent me a code over SMS and wanted me to tell it to them over the phone, I stopped them and explained that this is also the exact set of steps required to reset my account and that I wouldn’t do it.
I went to a branch in person to unlock my account and the person helping me asked me to enter my password on their terminal so that they could “see the error message”.
I’m still not sure if some parts of this were a more advanced phishing scheme than I had thought was possible, even though it does just seem like a set of confusing practices by the bank.