I was just subjected to the most credible phishing attempt I’ve experienced(twitter.com)
twitter.com
I was just subjected to the most credible phishing attempt I’ve experienced
https://twitter.com/digitallawyer/status/1181348689756864513
353 comments
My simple policy is I never give out any information if I'm cold-called. If they claim they're my bank, I say I'll call them back on the number printed on the card, and ask the caller which department I should be put through to. Legitimate callers have never objected to this approach, and it saves me any stress - same policy, no matter the caller, no exceptions, no need for me to try and figure out if I'm being phished.
Go to the police? Let us know how that works out for you. I did that once, after a highly credible phishing attempt (that, ultimately, I did not fall for). This was in Germany.
Me: Here is what happened to me, I'd like to file a police report.
Police: Well, with these internet scams, the fraudster is usually in another country, meaning we can't really do anything about it.
Me: They used perfect German, used information that I only ever provided into a non-public database of a German-based business that must have had a breach of some sort. The fraudster also used pictures of apartments in Germany that must have been taken here.
Police: Well, still. The person actually doing all of that could have been doing all of that from another country. Usually Russia or China or something.
Me [thinking to myself]: Yeah, Russia, or China, or some country where law enforcement generally presumes, even against all evidence, that any and all cybercrime is happening outside their jurisdiction and therefore not doing any law enforcement at all when it comes to cybercrime. Like what is happening right here right now.
Me: Well, I realize that nobody is going to start an investigation into this specific thing that happened here, but still: Isn't anyone at least compiling a database so that, once patterns become bigger and more apparent, an investigation of sorts may become warranted, etc?
Police: Nope. Nobody doing that. You can file a report. But I can tell you right now that nobody is going to look at it or do anything with it. Also, we kind of have more important things to do, here at the station. I mean: It's your choice. I can't stop you. Just telling you how it is.
Me: Okay, thank you, goodbye.
Me: Here is what happened to me, I'd like to file a police report.
Police: Well, with these internet scams, the fraudster is usually in another country, meaning we can't really do anything about it.
Me: They used perfect German, used information that I only ever provided into a non-public database of a German-based business that must have had a breach of some sort. The fraudster also used pictures of apartments in Germany that must have been taken here.
Police: Well, still. The person actually doing all of that could have been doing all of that from another country. Usually Russia or China or something.
Me [thinking to myself]: Yeah, Russia, or China, or some country where law enforcement generally presumes, even against all evidence, that any and all cybercrime is happening outside their jurisdiction and therefore not doing any law enforcement at all when it comes to cybercrime. Like what is happening right here right now.
Me: Well, I realize that nobody is going to start an investigation into this specific thing that happened here, but still: Isn't anyone at least compiling a database so that, once patterns become bigger and more apparent, an investigation of sorts may become warranted, etc?
Police: Nope. Nobody doing that. You can file a report. But I can tell you right now that nobody is going to look at it or do anything with it. Also, we kind of have more important things to do, here at the station. I mean: It's your choice. I can't stop you. Just telling you how it is.
Me: Okay, thank you, goodbye.
I can understand how people would fall for this one. With 20/20 hindsight, asking for the member number is fishy - it doesn't actually verify anything. And when my bank calls me, it is always automated - I only get a person talking to me if I ask for it through the automated systems. So in a way, any actual person calling would be a red flag. But in the moment, I can see why it sounded legit.
My parents have taken their precautions against phishing to extreme levels. They don't speak into the phone when unknown numbers call. At all. If they choose to answer, they wait for someone on the other end to talk and then decide whether to speak or hang up. They have heard horror stories of people getting their voices recorded and replayed into automated systems, so if someone calls and asks, "Hi, Is this <name>?", they avoid even saying "Yes", and instead ask who is calling. It may be paranoia, but as the saying goes... just because you are paranoid doesn't mean that they are not out to get you.
My parents have taken their precautions against phishing to extreme levels. They don't speak into the phone when unknown numbers call. At all. If they choose to answer, they wait for someone on the other end to talk and then decide whether to speak or hang up. They have heard horror stories of people getting their voices recorded and replayed into automated systems, so if someone calls and asks, "Hi, Is this <name>?", they avoid even saying "Yes", and instead ask who is calling. It may be paranoia, but as the saying goes... just because you are paranoid doesn't mean that they are not out to get you.
One I almost fell for, was a tab that changed to a Gmail login screen in the background. When I switched to it, I thought I had gotten logged out and entered my password. Luckily 2fa saved me. Did not use a pwd-manager at the time, that also would probably have prompted some red flags when it didn't auto-fill.
Saw this on Twitter this morning. Sounds like they must have engineered it and set things up beforehand because they (a) knew which bank he was with and (b) had everything set up ready to log in when they got his ID number and received the password reset code from his text message.
I guess one thing that could have mitigated this quicker is if the text from the bank had said "Here is the code you requested to reset your online password" instead of a generic "Your authorisation code is..."
I guess one thing that could have mitigated this quicker is if the text from the bank had said "Here is the code you requested to reset your online password" instead of a generic "Your authorisation code is..."
So here's a problem with banking "2FA". It's not clear what the number they send you by SMS is used for.
My Gmail account has 2FA. The token is only used for login. If anyone asks me for it over the phone, there's only one reason.
Banks use 2FA sometimes at login, sometimes over the phone, and sometimes to authorize transactions. That should be made transparent in the message, but it usually isn't.
Imagine: "Your temporary pin for identity verification is 373123, and expires in 5 minutes."
"Your temporary pin to authorize a transfer for an amount ending in $xxx4.23 is 522185 and expires in 5 minutes."
My Gmail account has 2FA. The token is only used for login. If anyone asks me for it over the phone, there's only one reason.
Banks use 2FA sometimes at login, sometimes over the phone, and sometimes to authorize transactions. That should be made transparent in the message, but it usually isn't.
Imagine: "Your temporary pin for identity verification is 373123, and expires in 5 minutes."
"Your temporary pin to authorize a transfer for an amount ending in $xxx4.23 is 522185 and expires in 5 minutes."
This is very scary for the average person. I've taken to simply not answering any questions (not even to confirm my name) if someone calls me. If my bank calls me then I call them back on a number that's on their web site.
The easiest way to avoid this entire class of attack, is to never be willing to answer any kind of question from someone who calls you. Always hang up, Google the customer support line for the business, then call them.
A rover scammer called my wife yesterday. She felt pretty quick that it was a scam.
I tried to call the number back from my phone (it was seemingly a regular local phone number in the LA area and I love fucking with scammers) and an automated response told me that “no Rover account could be found for my number, please visit Rover.com/help for more” which I thought was very sophisticated of them to really try and prove authenticity.
So then we called it back, from her phone, and it connected right away. The person on the other end said, “Ashley?” and I responded (in my non-female voice, not that there aren’t many men named Ashley) “yes, hello, how are you?” - they hung up immediately.
Ultimately my wife called Rover via their 1-800 number and it was indeed a scam. People try to ascertain your login creds to redirect funds. Basic stuff... but I was impressed at whatever basic twilio system was built to try and mask the scamminess with that automated message.
I tried to call the number back from my phone (it was seemingly a regular local phone number in the LA area and I love fucking with scammers) and an automated response told me that “no Rover account could be found for my number, please visit Rover.com/help for more” which I thought was very sophisticated of them to really try and prove authenticity.
So then we called it back, from her phone, and it connected right away. The person on the other end said, “Ashley?” and I responded (in my non-female voice, not that there aren’t many men named Ashley) “yes, hello, how are you?” - they hung up immediately.
Ultimately my wife called Rover via their 1-800 number and it was indeed a scam. People try to ascertain your login creds to redirect funds. Basic stuff... but I was impressed at whatever basic twilio system was built to try and mask the scamminess with that automated message.
The most surprising part is that they were able to gain access to your account using just the code texted to you. It's called second factor for a reason. The bank should still have sent you a password reset email.
Reading this thread reminds me of when I was subject to a social engineering attack by people who claimed to be the FBI. The voice messages they left sounded unconvincing so I ignored them on the basis the real FBI would have better ways to contact me.
Couple days later two FBI agents show up in my driveway asking why I didn't respond to their voicemail..
Couple days later two FBI agents show up in my driveway asking why I didn't respond to their voicemail..
Interestingly the most... clever, if not necessarily convincing, phishing attempt I've heard of, went like this:
1. Phishers call someone and pretend to be from their bank. If they've guessed the right bank and the person gives away their details, they win!
2. If they don't, and question the phishers authenticity, the scammers say "sure, just call us on the number on the back of your card".
3. The cardholder hangs up, and then dials the number for their bank, which they know and trust, because they've called it before or it's come from their card.
4. They get connected to a service representative, answer security questions, confirm that the transactions are valid, and then can relax.
5. A few days later, they get a call from their bank saying there's a whole lot of fraud on the account.
The trick to this one is that the phishers (a) call the cardholder on a landline and (b) when the cardholder thinks they've hung up, they haven't - the phishers just play a hook tone and then a dial tone.
In Australia at least (not sure about elsewhere?) if you call a landline number, the caller must end the call, or at least it used to be that way (I haven't owned a landline phone for a _long_ time. There's probably also a significant skew towards the elderly in landline owners, and in susceptibility to scam calls.
1. Phishers call someone and pretend to be from their bank. If they've guessed the right bank and the person gives away their details, they win!
2. If they don't, and question the phishers authenticity, the scammers say "sure, just call us on the number on the back of your card".
3. The cardholder hangs up, and then dials the number for their bank, which they know and trust, because they've called it before or it's come from their card.
4. They get connected to a service representative, answer security questions, confirm that the transactions are valid, and then can relax.
5. A few days later, they get a call from their bank saying there's a whole lot of fraud on the account.
The trick to this one is that the phishers (a) call the cardholder on a landline and (b) when the cardholder thinks they've hung up, they haven't - the phishers just play a hook tone and then a dial tone.
In Australia at least (not sure about elsewhere?) if you call a landline number, the caller must end the call, or at least it used to be that way (I haven't owned a landline phone for a _long_ time. There's probably also a significant skew towards the elderly in landline owners, and in susceptibility to scam calls.
I don't understand why there are still banks that do SMS verification. It has been proven so many times now that that it is vulnerable to both phishing (proven here), sim swapping attacks, etc.
The banks here in the Netherland all have (well, except for one maybe) hardware authentication devices. They are portable smartcard readers, you insert your card, enter your PIN on the device itself (not your computer or phone) and transfer a digest from your PC to the reader by typing or scanning a QR code (some readers have a little camera). You then type the signature into your computer or phone.
The readers for my bank even have a screen, that tells you what you are signing, like a login, or transfer of which amount to which bank account. Photo here [0].
The banks are very clear that they will never ask you to use the device over the phone. And that double confirmation by showing the sign action on the screen of the reader makes any form of phishing really hard.
IMO these smart card readers are the best compromise between convenience and security for banking.
[0] https://4.bp.blogspot.com/-6c1NGHew1P8/VBqvTeqDQdI/AAAAAAAAf...
The banks here in the Netherland all have (well, except for one maybe) hardware authentication devices. They are portable smartcard readers, you insert your card, enter your PIN on the device itself (not your computer or phone) and transfer a digest from your PC to the reader by typing or scanning a QR code (some readers have a little camera). You then type the signature into your computer or phone.
The readers for my bank even have a screen, that tells you what you are signing, like a login, or transfer of which amount to which bank account. Photo here [0].
The banks are very clear that they will never ask you to use the device over the phone. And that double confirmation by showing the sign action on the screen of the reader makes any form of phishing really hard.
IMO these smart card readers are the best compromise between convenience and security for banking.
[0] https://4.bp.blogspot.com/-6c1NGHew1P8/VBqvTeqDQdI/AAAAAAAAf...
I keep getting astonished by how bad online banking security is in the UK and US.
Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset.
Last time I needed a new token issuer dongle, I had to actually visit the bank and sign stuff.
Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset.
Last time I needed a new token issuer dongle, I had to actually visit the bank and sign stuff.
The bank I'm currently at has this "obnoxious" text around verification numbers:
Don't EVER communicate the following verification number to anyone, including <bank> collaborators: 123456
SMS OTP should always have that or similar text.It sounded sketchy from the moment they asked for a pin code that they sent to your phone. It's easier to talk from the outside, but that should always be a red flag. What exactly would they be confirming by sending a PIN to the same number they were already contacting?
But that's a great heads up. Phishing is not just about obviously fake e-mails to hotmail accounts.
But that's a great heads up. Phishing is not just about obviously fake e-mails to hotmail accounts.
Banks have such shitty security over the phone and they train us to do stupid stuff like giving out personal info when they call.
For example, your real bank in the U.K. ask for your date of birth and address for ‘data protection purposes’ when they call you, or they won’t even tell you what the call is about.
How are people supposed to understand what is OK to give out and what isn’t when these details, often used as security questions are somehow fine?
For example, your real bank in the U.K. ask for your date of birth and address for ‘data protection purposes’ when they call you, or they won’t even tell you what the call is about.
How are people supposed to understand what is OK to give out and what isn’t when these details, often used as security questions are somehow fine?
I'm sorry, I'm missing something between
> Me: <gives member number> (that number, by itself, is useless).
and
> Once I gave my member number, the attacker used the password reset flow to trigger a text message from the bank. > They used this to gain access to the account.
What happened here? How does an exposed useless member number trigger a password reset? Would the reset request not have come to an email account, presumably a well-protected one?
> Me: <gives member number> (that number, by itself, is useless).
and
> Once I gave my member number, the attacker used the password reset flow to trigger a text message from the bank. > They used this to gain access to the account.
What happened here? How does an exposed useless member number trigger a password reset? Would the reset request not have come to an email account, presumably a well-protected one?
When sending SMS or other notifications, always include the purpose. "You requested a password reset, the PIN to completel the reset is 112938181".
Ideally the pins are also in different formats, so your normal PIN to login is a 6 digit number, the password reset is a 12 digit alphanumeric.
Ideally the pins are also in different formats, so your normal PIN to login is a 6 digit number, the password reset is a 12 digit alphanumeric.
I think it's interesting to see how hard we've worked on making the web secure by adding all sorts of checks and protocols, but we've neglected to do the same with basic telecoms.
When I first started using web based communication platforms like Twitter and Nexmo I was really surprised to learn that I could put anything in the from field when sending a text message. All I could think was that it was a weakness that was ripe for abuse.
I believe there was a case in Germany a few years back where a group of phishers had online banking login details for several hundred users but couldn't initiate transfers without entering a PIN sent to the account holders phone via SMS. So the phishers set up a fake telephone company so that they could issue SS7 commands and have the account holders phone's temporarily redirected to another number where the PIN could be intercepted.
I think there is a false assumption amongst many people that the telephone system is inherently secure. Stuff like the above and all the robo calls coming from false numbers should warn otherwise.
When I first started using web based communication platforms like Twitter and Nexmo I was really surprised to learn that I could put anything in the from field when sending a text message. All I could think was that it was a weakness that was ripe for abuse.
I believe there was a case in Germany a few years back where a group of phishers had online banking login details for several hundred users but couldn't initiate transfers without entering a PIN sent to the account holders phone via SMS. So the phishers set up a fake telephone company so that they could issue SS7 commands and have the account holders phone's temporarily redirected to another number where the PIN could be intercepted.
I think there is a false assumption amongst many people that the telephone system is inherently secure. Stuff like the above and all the robo calls coming from false numbers should warn otherwise.
In EU, there is the (recent) implementation of a (new) directive, PSD2:
https://en.wikipedia.org/wiki/Payment_Services_Directive#Rev...
That carries with it the requirement of SCA:
https://en.wikipedia.org/wiki/Strong_customer_authentication
In practice (here in Italy) you have a client number (secret) a password/PIN (also secret) AND either a SMS to your mobile with a one time code or a Smartphone app (yikes!), there used to be hardware tokens generating one time authorization codes that have now been retired.
https://en.wikipedia.org/wiki/Payment_Services_Directive#Rev...
That carries with it the requirement of SCA:
https://en.wikipedia.org/wiki/Strong_customer_authentication
In practice (here in Italy) you have a client number (secret) a password/PIN (also secret) AND either a SMS to your mobile with a one time code or a Smartphone app (yikes!), there used to be hardware tokens generating one time authorization codes that have now been retired.
Seems to me the bank should take more care for resetting a user's internet banking password. For example as far as I know, all banks in the UK need you to call them up and answer a couple of verification questions before reseting any login details.
Quick question: What would an attacker gain from getting into your bank account?
From mine (french big bank), they could be annoying (asking the bank to close accounts, ordering new checkbooks, getting all kind of information on past transactions, wire money between my accounts), but I can't see how one would effectively leverage that.
I mean, an attacker goal would be to draw money in some way; all money wirings to external bank accounts are protected by a code (SMS or in-app verification), with a 24h delay between the time one enters a destination account and the actual wiring.
Is that any different with other banks? Is an attacker able to effectively draw money as soon as they get access to the account?
From mine (french big bank), they could be annoying (asking the bank to close accounts, ordering new checkbooks, getting all kind of information on past transactions, wire money between my accounts), but I can't see how one would effectively leverage that.
I mean, an attacker goal would be to draw money in some way; all money wirings to external bank accounts are protected by a code (SMS or in-app verification), with a 24h delay between the time one enters a destination account and the actual wiring.
Is that any different with other banks? Is an attacker able to effectively draw money as soon as they get access to the account?
[deleted]
My wife had the same thing happen to her but luckily our bank clearly says that this is a password reset pin code (don't share with anyone) type of message along with the pin code in the SMS. So, my wife refused to give it to the person on the phone.
A better sms password reset flow would be to first send a text asking "A password reset has been initiated. Was this you? Reply: YES or NO". Then after a YES confirmation they send the reset code along with the same big "Don't share with anyone on the phone" message.
A better sms password reset flow would be to first send a text asking "A password reset has been initiated. Was this you? Reply: YES or NO". Then after a YES confirmation they send the reset code along with the same big "Don't share with anyone on the phone" message.
This is partly an issue with phone calls as a medium. If the bank only contacted you through the app, this couldn't happen unless the app itself was compromised somehow.
E.g., the Monzo app has a chat functionality built in. If, upon a fraud attempt, a notification appeared in the Monzo app, it would certainly be legitimate.
If the ease of conversation offered by chatting with voice is necessary, add a link in the chat that has the user call the bank, not the other way around.
You can't easily verify that someone is who they say they are over the phone.
E.g., the Monzo app has a chat functionality built in. If, upon a fraud attempt, a notification appeared in the Monzo app, it would certainly be legitimate.
If the ease of conversation offered by chatting with voice is necessary, add a link in the chat that has the user call the bank, not the other way around.
You can't easily verify that someone is who they say they are over the phone.
His first mistake was to read back the verification number? Why would they legitimately asked for this theoretically?
To verify he has the phone they just called him on?
You should never have to read back a verification code.
To verify he has the phone they just called him on?
You should never have to read back a verification code.
If someone is asking you the PIN so they can confirm it is you, you can ask them to give you the PIN so that you can tell if it matches or not.
Something nearly exactly the same happened to me. It was through my Venmo account. I was stressed at the end of a long day and they got pretty far before I realized what happened. The key thing is that the number listed on Caller ID on my Android phone came from "Venmo" and matched their customer service number so I completely let my guard down. Embarrassing.
- The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them.
- The caller called me twice in rapid succession (First ignore the call from a number you do not know. Then they call back again immediately: "maybe this is urgent / important"). Another person in the thread, who fell for the scam, noted this same pattern.
- It is better if banks include a security warning / specific reason the code is sent with the password reset pins and similar credentials. My bank did not. Another twitter user noted being subject to the scam, and just glancing over the warning copy. So it helps, but it is not perfect. Especially pre-coffee.
- My bank no longer allows me to reset my password without calling them (thanks bank).
When I read the thread now, it's obviously full of red flags. I was successfully manipulated, and whilst I'm certainly not as clever as all the people pointing out they would have caught this from sentence one, I believe I'm also not the lowest hanging fruit in terms of a target :-) Makes you wonder what this will look like when these scams evolve another couple of generations in terms of complexity ...