GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Terence Eden (edent@mastodon.social)'s status on Friday, 03-May-2024 03:44:57 JST Terence Eden Terence Eden

    You receive a call on your phone.
    The caller says they're from your bank and they're calling about a suspected fraud.

    "Oh yeah," you think. Obvious scam, right?

    The caller says "I'll send you an in-app notification to prove I'm calling from your bank."

    Your phone buzzes. You tap the notification This is what you see.

    Still think it is a scam?
    1/3

    In conversation about a year ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/112/372/406/504/640/952/original/e58813c2dc165422.png
    • Haelwenn /элвэн/ :triskell: likes this.
    • GreenSkyOverMe (Monika) and Steve's Place repeated this.
    • Embed this notice
      Mrs Cloudy (cloudymrs@mastodon.scot)'s status on Friday, 03-May-2024 06:55:06 JST Mrs Cloudy Mrs Cloudy
      in reply to
      • essjax

      @essjax @Edent I had the same in Scotland. I hung up because I thought it was a scam, so they froze my account. I had to find a still open branch and go in person to make an appointment because the branches no longer have phone numbers. At said appointment, I asked why they didn't use the banking app they pushed me onto, to inform me of a suspect transaction, and was told they aren't set up to do that.

      In conversation about a year ago permalink
    • Embed this notice
      essjax (essjax@essjax.com)'s status on Friday, 03-May-2024 06:55:08 JST essjax essjax
      in reply to

      @Edent I had my bank call me about suspected fraud and they had no way for me to confirm they were legit. I said I'd call them back and they didn't have an external number I could call. Their tone suggested nobody had ever checked. One of the biggest banks in Australia / NZ.

      In conversation about a year ago permalink
    • Embed this notice
      Terence Eden (edent@mastodon.social)'s status on Friday, 03-May-2024 11:29:00 JST Terence Eden Terence Eden
      in reply to

      The scammer is on the phone to you.
      Their accomplice is on the phone to your bank, pretending to be you.
      Your bank send you the notification.
      You accept, and scammers proceed to drain your account.

      Someone has just lost £18,000 because of this.
      https://www.reddit.com/r/UKPersonalFinance/comments/1cih3kd/been_scammed_over_18000_through_my_chase_account/

      2/3

      In conversation about a year ago permalink

      Attachments


      Haelwenn /элвэн/ :triskell: likes this.
      GreenSkyOverMe (Monika) repeated this.
    • Embed this notice
      Terence Eden (edent@mastodon.social)'s status on Friday, 03-May-2024 11:29:00 JST Terence Eden Terence Eden
      in reply to

      It *is* a genuine notification. But it isn't confirming the bank is calling you.

      Should the bank word that differently?

      In a rush, would you read it thoroughly?

      Most likely, in a panic about the fraud, you'd confirm it was a genuine notification (it is!) and accept it.

      3/3

      In conversation about a year ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
      13 barn owls in a trenchcoat, マリオ (Mario Menti), mark and Rich Felker repeated this.
    • Embed this notice
      Dan McDonald (danmcd@hostux.social)'s status on Friday, 03-May-2024 11:29:48 JST Dan McDonald Dan McDonald
      in reply to

      @Edent

      Wow a man-in-the-middle attack with a real life person actually in the middle! 😮

      In conversation about a year ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      MadMike77 (madmike77@chaos.social)'s status on Friday, 03-May-2024 16:22:49 JST MadMike77 MadMike77
      in reply to
      • Captain Janegay 🫖
      • Glitzersachen.de
      • Extreme Electronics

      @glitzersachen @CaptainJanegay @Extelec @Edent I've grown up with computers and work as a DevOps. I regularly speak with friends about security.
      This scam is unsuspicious as hell. A good reminder that I'd need to remind myself why the person needs my passcode.
      I'd have fallen for this MITM, I'm pretty certain.

      In conversation about a year ago permalink
      clacke likes this.
    • Embed this notice
      Glitzersachen.de (glitzersachen@hachyderm.io)'s status on Friday, 03-May-2024 16:22:51 JST Glitzersachen.de Glitzersachen.de
      in reply to
      • Captain Janegay 🫖
      • Extreme Electronics

      @CaptainJanegay @Extelec @Edent

      It's a men in the middle attack. And quite obvious in my opinion.

      Only proper reaction: I call you back, gimme a number and your name. Then phone via the front desk of your bank.

      In conversation about a year ago permalink
    • Embed this notice
      Captain Janegay 🫖 (captainjanegay@mastodon.coffee)'s status on Friday, 03-May-2024 16:22:52 JST Captain Janegay 🫖 Captain Janegay 🫖
      in reply to
      • Extreme Electronics

      @Extelec @Edent That's normal. It's to confirm that someone else hasn't just stolen your phone. The rest of the thread explains, but this *is* a legitimate notification, it's just being misused.

      In conversation about a year ago permalink
    • Embed this notice
      Extreme Electronics (extelec@mstdn.social)'s status on Friday, 03-May-2024 16:22:53 JST Extreme Electronics Extreme Electronics
      in reply to

      @Edent Id go with yes, its a scam, Why does it need your passcode if you are already logged in to their app.

      In conversation about a year ago permalink
    • Embed this notice
      a libi rose (rose_alibi@post.lurk.org)'s status on Friday, 03-May-2024 16:22:58 JST a libi rose a libi rose
      in reply to

      @Edent you're making a leap by assuming i answer phone calls

      In conversation about a year ago permalink
      clacke likes this.
    • Embed this notice
      Simon Wood (simonwood@mastodon.social)'s status on Friday, 03-May-2024 16:34:29 JST Simon Wood Simon Wood
      in reply to
      • flabberghaster

      @flabberghaster @Edent I have had my actual bank call me, and then ask me (via security questions) to verify that I am actually me. I feel that was *training* customers to divulge information insecurely, as I had no way of knowing that they were who they were, and they wouldn’t have provided it if I’d gone along with their request.

      In conversation about a year ago permalink
      clacke likes this.
    • Embed this notice
      Simon Wood (simonwood@mastodon.social)'s status on Friday, 03-May-2024 16:34:30 JST Simon Wood Simon Wood
      in reply to

      @Edent I think I’d be taken in by that. My thought was: why do they need to check they’re on the phone to me if *they* called *me*? But on balance I’d decided it was just poor wording or an ill thought through system (both of which I still think, in fact!) so I wouldn’t have challenged it.

      In conversation about a year ago permalink
    • Embed this notice
      flabberghaster@mas.to's status on Friday, 03-May-2024 16:34:30 JST flabberghaster flabberghaster
      in reply to
      • Simon Wood

      @simonwood @Edent one might assume even if they believed the bank was calling them, that they still need to confirm they got you and not someone else.

      In conversation about a year ago permalink
    • Embed this notice
      SuperDicq (superdicq@minidisc.tokyo)'s status on Friday, 03-May-2024 20:16:02 JST SuperDicq SuperDicq
      in reply to

      @Edent@mastodon.social Another good reason to say no to proprietary banking apps. My bank account can only be accessed using a physical non-internet connected 2FA key device.

      In conversation about a year ago permalink
    • Embed this notice
      SuperDicq (superdicq@minidisc.tokyo)'s status on Friday, 03-May-2024 20:22:02 JST SuperDicq SuperDicq
      in reply to

      @Edent@mastodon.social You can't get fooled by notifications like this if you don't have a banking app.

      In conversation about a year ago permalink
    • Embed this notice
      Terence Eden (edent@mastodon.social)'s status on Friday, 03-May-2024 20:22:03 JST Terence Eden Terence Eden
      in reply to
      • SuperDicq

      @SuperDicq my banking app also supports a physical 2FA token. So what?

      In conversation about a year ago permalink
    • Embed this notice
      Terence Eden (edent@mastodon.social)'s status on Friday, 03-May-2024 20:29:33 JST Terence Eden Terence Eden
      in reply to
      • SuperDicq

      @SuperDicq sure, but you also can't check your balance. Send money to friends. Receive an alert when your card is used fraudulently. Or any of a 100 useful things.
      Telling people to give up extremely convenient features isn't the answer here.

      In conversation about a year ago permalink
    • Embed this notice
      SuperDicq (superdicq@minidisc.tokyo)'s status on Friday, 03-May-2024 20:29:33 JST SuperDicq SuperDicq
      in reply to

      @Edent@mastodon.social I can still do those things, my bank in particular has a decent API and someone wrote a CLI client for it actually.

      But yeah I know giving up "convenience" isn't a good answer here. First of all it's educating people on how to not get scammed. and Secondly it's telling banks to take security seriously by also making them liable in case one of their customers gets scammed by fraud like this.

      In conversation about a year ago permalink
      翠星石 likes this.
    • Embed this notice
      Terence Eden (edent@mastodon.social)'s status on Sunday, 05-May-2024 18:11:23 JST Terence Eden Terence Eden
      in reply to

      I've written up the above scam in more detail.

      https://shkspr.mobi/blog/2024/05/bank-scammers-using-genuine-push-notifications-to-trick-their-victims/

      Remember, no matter how clever and security-conscious you think you are, these criminals are highly sophisticated.

      You have to be lucky every single time. They only have to be lucky once.

      In conversation about a year ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.