When in doubt: hang up, look up, and call back(krebsonsecurity.com)
krebsonsecurity.com
When in doubt: hang up, look up, and call back
https://krebsonsecurity.com/2020/04/when-in-doubt-hang-up-look-up-call-back/
347 comments
Not so long ago, I got a legitimate phone call from my bank's fraud department (HSBC HK) regarding a dispute I had made (someone had used my credit card to book on booking.com).
The bank employee asked me to give him my passport number and acted annoyed when I refused. He couldn't understand why I would not give this kind of private information on a phone call and why it was a breach of security. I then called the bank's customer service hotline and they had no record of the call from the fraud department being made because it's a separate department and they didn't have access to that data. It took 3 days before I got a confirmation from my bank that that call had indeed been legitimate (and that's only because I have a relationship manager)...
So I think Banks are part of the problem, they need to massively step up their training in security so as not to make this kind of demands on phone calls they have themselves initiated.
The bank employee asked me to give him my passport number and acted annoyed when I refused. He couldn't understand why I would not give this kind of private information on a phone call and why it was a breach of security. I then called the bank's customer service hotline and they had no record of the call from the fraud department being made because it's a separate department and they didn't have access to that data. It took 3 days before I got a confirmation from my bank that that call had indeed been legitimate (and that's only because I have a relationship manager)...
So I think Banks are part of the problem, they need to massively step up their training in security so as not to make this kind of demands on phone calls they have themselves initiated.
> But he said he still feels like a chump for not observing the golden rule: If someone calls saying they’re from your bank, just hang up and call them back — ideally using a phone number that came from the bank’s Web site or from the back of your payment card. As it happened, Mitch only followed half of that advice.
Banks could normalize this behavior by having their customer service reps ask customers to do this at the beginning of every call.
"Hi, this is <csr> calling from <bank>. We'd like to talk to you about <subject>. To ensure to you that this is not a fraudulent call, please look up the phone number for this bank and call us back. Thank you."
Banks could normalize this behavior by having their customer service reps ask customers to do this at the beginning of every call.
"Hi, this is <csr> calling from <bank>. We'd like to talk to you about <subject>. To ensure to you that this is not a fraudulent call, please look up the phone number for this bank and call us back. Thank you."
I got an call on my Verizon phone. It showed up as Verizon on the caller ID. The guy said there was a problem with my payment but I was busy and said I'd call back later. When I called that number back later they didn't know what I was calling about. I said "you called me" and they said "oh that's a scam, we never call you. If we call don't pick up"
If Verizon can't stop people from spoofing their own customer support number on their own network, we're all screwed.
If Verizon can't stop people from spoofing their own customer support number on their own network, we're all screwed.
I just had this experience from pnc bank. I don’t even bank with them, but a member of my household does.
The incoming message was automated, asking for (person who lives here) with a visa debit card that has fraudulent transactions. The caller id was a number not listed on the back of the card.
Pressing “1” puts you into the next phase, which asks you to “verify” your identity by - guess what - typing in your full 16 digit debit card number!
At this point I am convinced this is a scam. You google the phone number and you see tons of links saying it’s a scam.
The person calls their regular number on the back of her card and they claim no fraudulent activity.
A few days later I still get these calls so I decide to investigate. Pressing zero a bunch and asking for an agent finally gets me to a live individual. He claims they’re from pnc and they are a different section not connected to the “main” number. He’s able to recite details about the account that only pnc would know, so now I’m not sure.
I email [email protected] asking them to please either say the calls are fraudulent or acknowledge that the phone number associated with these calls is legitimate (it doesn’t appear anywhere on pnc’s web site)
I did get a response - good! But they didn’t actually change the site ... so I suppose in this case anyone who receives notification of fraud on their pnc debit card should email [email protected] to validate the calls are legitimate?
The incoming message was automated, asking for (person who lives here) with a visa debit card that has fraudulent transactions. The caller id was a number not listed on the back of the card.
Pressing “1” puts you into the next phase, which asks you to “verify” your identity by - guess what - typing in your full 16 digit debit card number!
At this point I am convinced this is a scam. You google the phone number and you see tons of links saying it’s a scam.
The person calls their regular number on the back of her card and they claim no fraudulent activity.
A few days later I still get these calls so I decide to investigate. Pressing zero a bunch and asking for an agent finally gets me to a live individual. He claims they’re from pnc and they are a different section not connected to the “main” number. He’s able to recite details about the account that only pnc would know, so now I’m not sure.
I email [email protected] asking them to please either say the calls are fraudulent or acknowledge that the phone number associated with these calls is legitimate (it doesn’t appear anywhere on pnc’s web site)
I did get a response - good! But they didn’t actually change the site ... so I suppose in this case anyone who receives notification of fraud on their pnc debit card should email [email protected] to validate the calls are legitimate?
> “When the representative finally answered my call, I asked them to confirm that I was on the phone with them on the other line in the call they initiated toward me, and so the rep somehow checked and saw that there was another active call with Mitch,” he said. “But as it turned out, that other call was the attackers also talking to my bank pretending to be me.”
Jesus Christ. This is some Inception-level shit. I do not operate on this many levels of meta in real life.
Jesus Christ. This is some Inception-level shit. I do not operate on this many levels of meta in real life.
Krebs mentioned that Mitch logged into his bank account while on the phone with the scammers. That's a HUGE no. We live in a threshold period where acoustic emanation attacks are about to become much more commonplace due to increasing computational capabilities. [0]
Getting you to browse your computer for 10-20 minutes and then log into your bank account could be enough to gain access to your account.
And 2FA is proven insecure with SIM hijacking. These methods have a high up front time investment but will take even less effort than Mitch's gambit once deployed.
https://www.cs.cornell.edu/~shmat/courses/cs6431/zhuang.pdf [0]
Getting you to browse your computer for 10-20 minutes and then log into your bank account could be enough to gain access to your account.
And 2FA is proven insecure with SIM hijacking. These methods have a high up front time investment but will take even less effort than Mitch's gambit once deployed.
https://www.cs.cornell.edu/~shmat/courses/cs6431/zhuang.pdf [0]
On first read, I didn't understand how the call to the bank's customer service department went wrong.
Something about that conversation didn’t seem right, and so Mitch decided to use another phone to place a call to his bank’s customer service department — while keeping the first caller on hold.
“When the representative finally answered my call, I asked them to confirm that I was on the phone with them on the other line in the call they initiated toward me, and so the rep somehow checked and saw that there was another active call with Mitch,” he said. “But as it turned out, that other call was the attackers also talking to my bank pretending to be me.”
What happened is that the attackers made one call to Mitch, and another call to the bank posing as Mitch. When Mitch called the real bank to check up if there was a call in progress, they said yes (the call with the attackers).
Something about that conversation didn’t seem right, and so Mitch decided to use another phone to place a call to his bank’s customer service department — while keeping the first caller on hold.
“When the representative finally answered my call, I asked them to confirm that I was on the phone with them on the other line in the call they initiated toward me, and so the rep somehow checked and saw that there was another active call with Mitch,” he said. “But as it turned out, that other call was the attackers also talking to my bank pretending to be me.”
What happened is that the attackers made one call to Mitch, and another call to the bank posing as Mitch. When Mitch called the real bank to check up if there was a call in progress, they said yes (the call with the attackers).
Side lessons seems to be that scammers have access to a lot of your personal info, which can fool you, and that you should never ever give an OTP over the phone.
An anti nuisance call policy that has served me well and I try to get my folks to adopt is that if there is the merest hint of a delay between my hello and the caller's response, I put the phone down immediately.
I don't think I've ever had an identifiable repeat call, from which I conclude it's both effective and has a low false positive rate.
I don't think I've ever had an identifiable repeat call, from which I conclude it's both effective and has a low false positive rate.
That's what I always told my older family.
If it is about finances, YOU call them at a number on your billing statement that you know is correct, or just go to the bank.
Never make a decision / give info if "they" called you.
If it is about finances, YOU call them at a number on your billing statement that you know is correct, or just go to the bank.
Never make a decision / give info if "they" called you.
At this point, we should really throw away the current phone system and use an authenticated model. There should also be laws forcing the phone companies to not allow this. I get at least 2 spam/scam calls a day and there is no hope that it will reduce.
Does anyone know any good guides for being aware of these things, strategies used by scammers, and what to be suspicious of? Something that isn't patronisingly simple, but not aimed at teach expert users either.
> “But as it turned out, that other call was the attackers also talking to my bank pretending to be me.”
I don't understand this part - the _actual_ bank said that he was on a different line with them? Wouldn't that mean that the scammers had authorised as him already, in which case the account is already compromised? Also, the bank asking for 2FA over the phone also sounds like training into bad habits, but I appreciate there's different approaches with different banks.
This is a pretty similar sequence of events to one a reasonably intelligent but non-tech friend of mine fell for this week: Got an email saying that the TV licence needed to be renewed. They followed the link on the email, didn't check the URL and filled out their account details to set up a direct debit.
Two days later, gets a call from their "bank", telling them that they filled out a scam direct debit (gets victim flustered to compromise judgement) but they need to authorise them first before they can speak any further... my friend challenged their identity but they used the exact same "fake caller ID" trick - to the correct bank number since they had the sort code from step 1, and that identifies the bank. I knew this (caller ID) was possible in general, but hadn't heard of it being actively used in the UK - only from stories in the US. After "verifying" they asked for the 2FA device code, then (registered a card for ApplePay and) asked them to "confirm" the code they had just been texted, which is the point I walked in and was "WTF are you doing?"
About 10 minutes later while in the waiting queue for the actual bank, the actual bank called them - when we said that we wouldn't trust the call they instantly gave us a reference number to quickly recall the case and advised us to call back quickly. Luckily, the bank reimbursed the amounts taken before they locked it off (apparently some UK agreement from a couple of years ago.)
They were pretty shaken up from the experience, and want to know what to look for in the future. It strikes me that a lot of these cases are hitting otherwise reasonably cautious people who aren't aware that something they think is authentication, really isn't, like caller ID.
> “But as it turned out, that other call was the attackers also talking to my bank pretending to be me.”
I don't understand this part - the _actual_ bank said that he was on a different line with them? Wouldn't that mean that the scammers had authorised as him already, in which case the account is already compromised? Also, the bank asking for 2FA over the phone also sounds like training into bad habits, but I appreciate there's different approaches with different banks.
This is a pretty similar sequence of events to one a reasonably intelligent but non-tech friend of mine fell for this week: Got an email saying that the TV licence needed to be renewed. They followed the link on the email, didn't check the URL and filled out their account details to set up a direct debit.
Two days later, gets a call from their "bank", telling them that they filled out a scam direct debit (gets victim flustered to compromise judgement) but they need to authorise them first before they can speak any further... my friend challenged their identity but they used the exact same "fake caller ID" trick - to the correct bank number since they had the sort code from step 1, and that identifies the bank. I knew this (caller ID) was possible in general, but hadn't heard of it being actively used in the UK - only from stories in the US. After "verifying" they asked for the 2FA device code, then (registered a card for ApplePay and) asked them to "confirm" the code they had just been texted, which is the point I walked in and was "WTF are you doing?"
About 10 minutes later while in the waiting queue for the actual bank, the actual bank called them - when we said that we wouldn't trust the call they instantly gave us a reference number to quickly recall the case and advised us to call back quickly. Luckily, the bank reimbursed the amounts taken before they locked it off (apparently some UK agreement from a couple of years ago.)
They were pretty shaken up from the experience, and want to know what to look for in the future. It strikes me that a lot of these cases are hitting otherwise reasonably cautious people who aren't aware that something they think is authentication, really isn't, like caller ID.
Tips from my experience:
1. If someone who calls you asks you for ANY sensitive personal info, just tell them that your policy is to not give any personal info to those who called you, but you’re happy to call the official number. That stops it right there
2. Use email aliases instead of your actual email when creating accounts with eg Amazon Web Services. An email alias is like [email protected] — this way the attacker can’t get the customer service rep to give them access to your account easily.
3. If you use your phone as a 2FA, be on the lookout for sim porting - that’s when they trick the rep into porting your phone number.
I had the third one happen, luckily I acted fast. The attackers couldn’t get into my G Suite email but they got into godaddy to port the domain and MX records to their servers. So they could receive email sent to me, and send email as me. They also changed my GoDaddy password. I had my phone as the 2FA at the time. Better to not have one at all, or use an authenticator app.
I called in and luckily GoDaddy restored my account. Too bad they had no tool to check what changed so I had to check every domain manually.
The attacker was too slow in that regard. But it was telling that I received an email with the subject “Test”. That’s what tipped me off.
1. If someone who calls you asks you for ANY sensitive personal info, just tell them that your policy is to not give any personal info to those who called you, but you’re happy to call the official number. That stops it right there
2. Use email aliases instead of your actual email when creating accounts with eg Amazon Web Services. An email alias is like [email protected] — this way the attacker can’t get the customer service rep to give them access to your account easily.
3. If you use your phone as a 2FA, be on the lookout for sim porting - that’s when they trick the rep into porting your phone number.
I had the third one happen, luckily I acted fast. The attackers couldn’t get into my G Suite email but they got into godaddy to port the domain and MX records to their servers. So they could receive email sent to me, and send email as me. They also changed my GoDaddy password. I had my phone as the 2FA at the time. Better to not have one at all, or use an authenticator app.
I called in and luckily GoDaddy restored my account. Too bad they had no tool to check what changed so I had to check every domain manually.
The attacker was too slow in that regard. But it was telling that I received an email with the subject “Test”. That’s what tipped me off.
I've had this issue a few times with credit card companies, loan companies, and on one or two occasions collections agents. Some very nice person calls in order to discuss an issue with me, but wants me to tell them my birthdate, last-four-of-SSN, and other stuff "in order to verify your identity". They then act annoyed and puzzled that I won't just reel that information off to some rando who called me out of the blue, and start pointing to the caller ID as evidence that they're legitimate. The funniest part of the conversation is when they warn me that we won't be able to discuss this problem if I won't verify my identity, at which point I respond that they called me, so if they don't want to spend any more time on the phone, I'm happy to go back to whatever I was doing and they can try reaching me by some non-brain-dead means.
I feel like if we ran a public education campaign about how easy it is to spoof caller ID, a lot of these scams would stop working, but that's probably just me being foolishly optimistic.
I feel like if we ran a public education campaign about how easy it is to spoof caller ID, a lot of these scams would stop working, but that's probably just me being foolishly optimistic.
On landlines on some networks, it used to be that one person on the call hung up but the other didn't, the call would remain connected for a while. So if the person who had hung up, picked up the phone again, they'd still be connected to the same person, and wouldn't hear a dial tone. This was useful: if you wanted to move to a different phone connected to the same line, say, for more privacy, you just tell the other person what you're doing, hang up, and then pick up in the other room. But some scammers found a way to use this.
Basically, the scammer would instruct a suspicious mark to hang up, look up their bank's phone number, and call back, just as Krebs is instructing. As soon as the mark hung up, the scammer would begin playing a dial tone instead of hanging up. When the mark picked up the phone, they would hear the dial tone, so they would begin dialing at which point the scammer would end the dial tone, wait for the dialing to stop, and then play a few ring tones and then pretend to pick up the phone. This was in the 90s so the technology was there to automate it, but it's simple enough it could have been done completely manually by stopping and starting recordings. From the user's perspective, it seemed they had hung up and made a call to the bank, so it seemed impossible that they were connected to someone else.
Cell phones, which don't stay connected when only one party hangs up, are totally immune to this hack. And this hack has probably fallen out of use since the ubiquity of cell phones has deprived scammers of a viable pool of marks.
Basically, the scammer would instruct a suspicious mark to hang up, look up their bank's phone number, and call back, just as Krebs is instructing. As soon as the mark hung up, the scammer would begin playing a dial tone instead of hanging up. When the mark picked up the phone, they would hear the dial tone, so they would begin dialing at which point the scammer would end the dial tone, wait for the dialing to stop, and then play a few ring tones and then pretend to pick up the phone. This was in the 90s so the technology was there to automate it, but it's simple enough it could have been done completely manually by stopping and starting recordings. From the user's perspective, it seemed they had hung up and made a call to the bank, so it seemed impossible that they were connected to someone else.
Cell phones, which don't stay connected when only one party hangs up, are totally immune to this hack. And this hack has probably fallen out of use since the ubiquity of cell phones has deprived scammers of a viable pool of marks.
Beware that there is also no-hang up scam. Below details are from wiki -
Another simple trick used by the fraudsters is to ask the called parties to hang up and dial their bank, but after the victim hangs up, the fraudster does not, keeping the line open and remaining connected when the victim picks up the phone to dial.[4] When in doubt, calling a company's telephone number listed on billing statements or other official sources is recommended, as opposed to calling numbers received from messages or callers of dubious authenticity. However, sometimes hanging up and redialing is insufficient: if the caller has not hung up, the victim might still be connected, and the fraudster spoofs a dial tone down the phone line to entice the victim to dial. Then the fraudster's accomplice answers and impersonates whomever the victim is trying to call.[5] This is known as a 'no hang-up' scam.[6] Hence consumers are advised to use a different phone when dialing a company's number to confirm.
When in doubt: hang up, look up, and call back "from a different number".
Another simple trick used by the fraudsters is to ask the called parties to hang up and dial their bank, but after the victim hangs up, the fraudster does not, keeping the line open and remaining connected when the victim picks up the phone to dial.[4] When in doubt, calling a company's telephone number listed on billing statements or other official sources is recommended, as opposed to calling numbers received from messages or callers of dubious authenticity. However, sometimes hanging up and redialing is insufficient: if the caller has not hung up, the victim might still be connected, and the fraudster spoofs a dial tone down the phone line to entice the victim to dial. Then the fraudster's accomplice answers and impersonates whomever the victim is trying to call.[5] This is known as a 'no hang-up' scam.[6] Hence consumers are advised to use a different phone when dialing a company's number to confirm.
When in doubt: hang up, look up, and call back "from a different number".
I had a legit call a few months ago from the CRA (Canada Revenue Agency). He was nice enough and sounded calm, and I explained that with all due respect, since he called, I have no way of knowing if he is a scammer or not, so I'd like to call back. He was somewhat taken aback, but not annoyed. I asked where to call, and what to say to get to the matter at hand. After hanging up, I looked up the number, called them back, and got the issue settled. But I was truly surprised that he expected me to talk to him when he called.
The CRA is probably the number one pretend-caller in Canada (Or two, after the RCMP - the federal police), so I was surprised they do not employ this as a standard practice and education for people to protect against scam calls.
I was lucky to keep my wits about me, and that the call indeed was legit, but it shows there's a huge opening for scamming less savvy people.
I was getting a bunch of those canada revenue scam calls a while back. They left a message with some robot voice saying 'there was a lawsuit in my name and blah blah blah blah bullshit' so I looked up the number and read about the scam. Apparently they'd actually managed to rip some people off and they were being searched for. So, the next time they called me, I called the number they left me. Some dude with a French accent answered. I started ranting. I told them if they ever called my number again I'd report them to the RCMP and swore a bunch and was fairly rude.
Funny enough, I never got a call back from canada revenue agency for, being less than polite to them, and the spam calls stopped.
My advice, if you actually get a real person on the line, call them out on their shit and tell them to fuck off. It seems to work.
Funny enough, I never got a call back from canada revenue agency for, being less than polite to them, and the spam calls stopped.
My advice, if you actually get a real person on the line, call them out on their shit and tell them to fuck off. It seems to work.
> Armed with a counterfeit copy of his debit card and PIN, the fraudsters could pull money out of his account at ATMs and go shopping in big box stores for various items. But to move lots of money out of his account all at once, they needed Mitch’s help.
Whoa, a double-tap attack
Whoa, a double-tap attack
>But if your response to such a scam involves anything other than hanging up and calling back the entity that claims to be calling, you may be in for a rude awakening.
My response is not picking up the phone at all.
My response is not picking up the phone at all.
I was recently scammed by either a man in the middle attack or a replay attack due to insufficient authentication of a new party I did business with.
When you are starting a new person to person transaction with an unknown party, it seems impossible to verify that an attack like this is not happening. The attacks could get arbitrarily complex and every defense I can think of has repucussions.
Even trying to start a transaction could be replayed to someone to make it look like I was the one that was doing the scamming.
When you are starting a new person to person transaction with an unknown party, it seems impossible to verify that an attack like this is not happening. The attacks could get arbitrarily complex and every defense I can think of has repucussions.
Even trying to start a transaction could be replayed to someone to make it look like I was the one that was doing the scamming.
> The investigator said another man had called in on Saturday posing as Mitch, had provided a one-time code the bank texted to the phone number on file for Mitch’s account.
Wow. In the UK as far as i'm aware no bank uses auth codes over txt, we have a physical devices to generate one time codes for identification or transaction signing using chip and pin.
Most people here are aware txt messaging is not secure, it's enough of an issue for email hijacking, I'm very surprised banks are using it in US.
Wow. In the UK as far as i'm aware no bank uses auth codes over txt, we have a physical devices to generate one time codes for identification or transaction signing using chip and pin.
Most people here are aware txt messaging is not secure, it's enough of an issue for email hijacking, I'm very surprised banks are using it in US.
> Mitch received a call from what he thought was his financial institution, warning him that fraud had been detected on his account. Mitch said the caller ID for that incoming call displayed the same phone number that was printed on the back of his debit card.
Imho, this is where the phone company should be liable. If I let people masquerade as other users in my software, it would be a critical security bug and I'd be in deep trouble. But we just accept this crap from phone companies.
Imho, this is where the phone company should be liable. If I let people masquerade as other users in my software, it would be a critical security bug and I'd be in deep trouble. But we just accept this crap from phone companies.
I had someone claiming to be from my bank phone me in relation to certain transactions that actually happened, and like a fool I just answered their questions, without verifying who they were.
Later on I called back, to verify that it was someone from the bank who had phoned me.
The call-centre person in the bank who answered my call was unable to confirm or deny if someone from the transaction-checking department had actually phoned me, because it was all very confidential.
Later on I called back, to verify that it was someone from the bank who had phoned me.
The call-centre person in the bank who answered my call was unable to confirm or deny if someone from the transaction-checking department had actually phoned me, because it was all very confidential.
How much time and money is lost to this kind of scam?
We need verified identity for phone numbers and email, with consequences attached to bad behaviour.
We need verified identity for phone numbers and email, with consequences attached to bad behaviour.
There’s basically no reason to ever answer a call from an unknown phone number, let alone engage and divulge private data. If it’s important they’ll leave a voicemail. Going further, I’d say it’s basically safe to always block missed calls from unknown numbers that didn’t leave a voicemail. If it’s important, you’ll hear about it via some other channel.
Poor Mitch. The core of this sounds like another variant of the Mig-in-the-middle attack.
Page 126 (page 10 of the PDF) from RJA’s Security Engineering being my reference...
https://www.cl.cam.ac.uk/~rja14/Papers/SEv3-ch4-dec18.pdf
Page 126 (page 10 of the PDF) from RJA’s Security Engineering being my reference...
https://www.cl.cam.ac.uk/~rja14/Papers/SEv3-ch4-dec18.pdf
"He said he checked his account online several times over the weekend, but saw no further signs of unauthorized activity."
If, in retrospect, you feel someone was attempting to scam you, a better option - I hope - might be to contact the bank's fraud line, explain that you are suspicious, and have them look for suspicious activity.
If, in retrospect, you feel someone was attempting to scam you, a better option - I hope - might be to contact the bank's fraud line, explain that you are suspicious, and have them look for suspicious activity.
Among many other things in this article, it's a good reminder to simply never use a debit card: use a credit card instead as the most you can be out is $50 for any incident of fraud. And if you need cash? How about going to the bank and talking to a teller (or going through the drive-through during social distancing)?
Did a quick Google search the next day and figured the process is legit but people out there have gotten higher bills than before.
Moral is to fight the human-interaction pressures and be adamant on doing your own research. No shame in that.