this post was submitted on 27 Mar 2025
665 points (99.0% liked)
Technology
68187 readers
3750 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I almost fell for a bank scam a couple years back. Basically, I had just gotten a new phone w/ GrapheneOS, which doesn't have Google's scam number protection (I was well aware, that's not the issue) and I hadn't yet transferred my contacts, and I received a call about a fraud alert on a card. This has happened a few times, and usually it's a pretty straightforward call where they verify my identity before asking me about certain transactions. As a bit of background, I was on vacation at the time and I got the call while waiting in the parking lot while my SO ordered something at a food truck.
Anyway, the call progressed like this:
I immediately called my bank and sorted things out, and we figured out nothing was stolen because I didn't provide the second code (that was to link an external account to suck my money out). Because I was in an unfamiliar setting and honestly pretty tired (we drove all day the day before), I just skimmed the text in step 2 w/o reading that it was a user-initiated code (i.e. for a password reset) instead of a bank initiated code (i.e. verify identity).
I consider myself a pretty security-conscious person. I use a password manager, MFA everywhere I can (preferring TOTP), I'm a lead backend SW engineer who has caught multiple security issues, etc. However, I fell for the scam and missed the safeguard that should have protected me. Fortunately it all worked out, but I did have to change all of my account numbers and login, which wasn't particularly fun while on vacation. That bank is fortunately one of the few that supports TOTP in my country, though I had avoided setting it up because it required a special app (Symantec VIP) and calling in (no self-service). I now have it set up and feel much better about my account security.
I'm fairly certain I annoy the people at my bank because I always insist on calling them back at their official number if they ask for any personal information. I don't fuck around with my bank security. I did however get got a couple of more years ago back when the chrome browser window phishing attack first started and had my Steam account stolen for a solid minute.
That's the attack where they simulate a browser window so what you think is a oauth popup is actually just inpage javascript and CSS.
Yeah, I'd really rather avoid waiting on hold every time there's a fraud alert or something. It doesn't happen a lot, but I have a lot of cards (like 10) and I often have one that gets an alert most years. It's usually not an issue, especially since I don't usually have money at the same institutions where I have a credit card, this was a special one where it's a card I only use at like 3 places (Steam being one of them) because it's for purely personal spending (as opposed to "family" spending).
If I wasn't on vacation, hadn't just gotten a new phone (I enter my bank's numbers as contacts), or wasn't impatient (I was hungry and waiting for food), it wouldn't have been an issue. It was just a perfect storm of opportunity. Now it's even less likely because I now use TOTP and my understanding is that there's no reason the bank would ever ask for that code (I think they only send text).
It happens.
Yup, what you're describing sounds inline with how Corey Doctorow fell victim to fraud.
This one?
It's completely different. In that case, they were able to set up a fake business to accept payments, which is way more sophisticated than what happened to me. In my case, they just needed my login name and phone number, and I had reused the login name on several sites, so a number of places could have been involved in a breach. All the scammer had to do in my case was:
That's it, just two pieces of information, some smooth talking, and a little luck that I don't catch on. Corey Doctorow's situation required quite a bit more setup than that:
That's a lot more sophisticated than what happened to me.
He got scammed again? Damn. Sorry, I was referring this one. And not really the details of the scam, but it was the wrong place / wrong time element that reminded me.
Edit: the article you linked is older, so I guess not "again".
Oh yeah, that's a lot more similar.