11 ms·
This happened to me. 1. I believe it began with the hacker getting DOB/SSN. 2. Called wireless provider, and hacker forward all calls and texts to a burn phone
by TaylorSwift 9y ago
This happened to me.
1. I believe it began with the hacker getting DOB/SSN.
2. Called wireless provider, and hacker forward all calls and texts to a burn phone. Eventually, the hacker ported my wireless phone to another provider/number (not sure which), and the phone registered to my provider did not work anymore. The landline phone was also forwarding calls to another number.*
3. Hacker gained access to email (as that email was also within the telco's site). At the beginning, the hacker did not reset the password. After I changed the email's password, hacker was still gaining access to our emails and he/she eventually reset the email blocking my access. (reason was all the text and calls was forwarding to his/her burn phone so he/she can reset the pass anytime)
5. Requested 2FA from bank.
6. Gained access to bank account.
This was over a course of 3 months. It was a nightmare to resolve and paranoia still remained. The hacker later on went opening several bank accounts. Fortunately, this was discovered early. The entire situation was communicated to the FBI, local police, and bank institutions, but I do not think anyone cared.
*I saw two numbers that were being used within my wireless account site to forward the calls.
- adekok 9y ago> The entire situation was communicated to the FBI, local police, and bank institutions, but I do not think anyone cared. Why would they care? It happens dozens of times a day, and the criminals are out of their jurisdiction. If only the police, FBI, politicians, etc. could go after the banks and telcos to improve their security. But no... they see it as their job to destroy security, in order to make you "safe".
- wyck 9y agoThe is a direct correlation between security and fraud related interest/insurance in regards to the cost of use and exposure to fraud. They aren't out to "destroy" your security, it's a liability threshold calculation. At the end of the day secure yourself in life, this include choosing banks that are more stringent based on your needs and what you want to pay.
- joshgel 9y agoWhich banks should you choose? How do you decide?
- swsieber 9y agoI would refine that question: does anybody know of a competent rater that evaluates and rates banks based on security?
- closeparen 9y agoThe ACH model is fundamentally insecure: anyone who knows your account number can pull money from it, and the protocol makes no allowance for the bank to check with you first. I don't think choice of bank matters very much. You can manage your risk somewhat by: 1) Using credit and not debit cards for day to day spending. 2) Maintaining your long term wealth in separate accounts at separate institutions and not linking them directly to anything except your checking account. This minimizes what can be stolen if your checking account is compromised, and makes it less likely that your savings can be stolen directly (account number is used in fewer places). 3) Turning on all the alerting and notification settings you can find, so that you'll hear about unauthorized activity immediately.
- aptwebapps 9y agoI read somewhere that companies that do a lot of ACH payments use different accounts for receiving and sending payments. The receiving account is locked so that it can't send and the sending account is supposed to stay secret. I don't know if that actually works in practice, though.
- creepydata 9y agoIf you give someone a paper check you are giving them your account number in plain text. I don't see how they can make that "secret."
- 9y ago
- deleted 9y ago[deleted]
- MichaelGG 9y agoThey won't go after an attacker if there's not a high amount of damage, like $250K or more. FBI guys are swamped with people calling, and there's just not enough agent time to go around. Same for bank fraud. Ever wonder how people get away with popping someone's bank account, transferring to another local account, and walking off with the cash? For a couple grand, no one's gonna spend the time and effort to track you down. Liability for data breaches limited to companies over X size would be a good idea though.
- panic 9y agoMaybe we should increase the number of agents investigating this stuff, then? Fraud affects many more people than terrorism, but nobody gives the "there's just not enough agents" excuse for that. Also, only investigating fraud when there's lots of money involved means we're only helping rich people, who need the least help. Losing less money doesn't mean less impact on someone's life if that's all they have.
- csomar 9y agoBecause people are more terrified about a random bomb hitting a random place once in a while more than their accounts getting hacked and then finding themselves in a big trouble?
- jessaustin 9y agoIt takes a lot of work by the military-media-industrial complex to keep people that terrified about such a stupid ginned-up threat.
- csomar 9y agoWhich is interesting because it should be the other way around. If you have $250k stolen, it is bad but you are probably wealthy enough you won't go in deep trouble stress. If your whole account is $2k it might be a different world for you and you might relying on these to pay rent, medical expenses which is more serious than an investor not having access to his $250k. Not meaning it is fine to steal $250k from wealthy people but that poor ones being affected (at $2k) is more urgent from a humanitarian perspective.
- gens 9y ago> Why would they care? Because it is their job.
- ktta 9y ago>criminals are out of their jurisdiction We are in dire need of specific cyber security public divisions are people can go to. FBI I believe will have many problems to deal with, and as far as I know, there isn't any cyber-police division capable at the city/state level. Atleast nothing capable of handling incidents like the one mentioned above. The debate of who's job it is can get hairy. Especially with the future where internet is becoming more pervasive, there can be more damage.
- creepydata 9y agoThe FBI claims jurisdiction on crimes committed by foreign national against Americans. It's just hard to investigate and arrest individuals who aren't on US soil, but not absolutely impossible. They arrested a Russian ID theft a while back, but they had to lure him out of Russia to do so, as the Russian authorities didn't cooperate.
- dba7dba 9y agoI don't mean to sound flippant but they don't care. It is their 'job', but they don't care.
- njx 9y agoDid you file a report with FBI? I once was scammed on ebay for a laptop worth $1200 around year 2002. The local police did not get involved so I went to the FBI website and filed a report. I thought nothing is going to happen. They eventually caught the guy and I got my payments in installments (restitution) over several years.
- chrisper 9y agoSo, how much money did you lose if any?
- lordvon 9y agoIt seems this was a popular hack at one time. I hope this no longer happens. Anyway it's great that you were able to "shake it off", so to speak.
- hourislate 9y agoYeah, Identity theft is one of those crimes where the authorities don't really care. It can be quite lucrative for the folks carrying it out since there are no consequences. The police are so overwhelmed and typically it is out of jurisdiction so their options are 0 to none to prosecute. The only way to guard against it is to keep your foot print small and give as little info as required.
- zAy0LfpBZLC8mAC 9y ago> Yeah, Identity theft is one of those crimes where the authorities don't really care. There is no such thing as "identity theft". You can't steal who someone is, that's bullshit. It's rather some party not making sure it's actually you they are talking to, and then claiming that you are responsible for it anyway because they fell for someone else's scam.
- drdaeman 9y agoAnd piracy is an act of robbery on the high seas. When the name sticks, there's usually nothing we can do. Sad but true.
- sowbug 9y agoThat example doesn't use word games to shift the loss to an uninvolved and innocent party.
- uiri 9y agoThe problem with the phrase "identity theft" is that it puts the onus of security onto the consumer to secure their personal details instead of onto the bank/telcos/etc to secure their systems. We should call it what it is: fraud. Whether that's bank fraud, computer fraud or wire fraud, banks should be responsible for compensating individuals for the losses incurred. One way to encourage this change is a change in the language we use surrounding these crimes.
- zAy0LfpBZLC8mAC 9y ago
- doktrin 9y ago> 1. I believe it began with the hacker getting DOB/SSN We [the US] dramatically over-rely on SSN. At least one upside to ubiquitous biometrics will be that we can start layering more authentication measures in an effective and consumer friendly way.
- ryandrake 9y agoRelying on it is not the problem. Treating it (or "date of birth" or "mother's maiden name") as a secret for use in authentication is a big problem. These things are not secret, and having me say mine does not prove that you're talking to me.
- doktrin 9y ago> Relying on it is not the problem. Treating it (or "date of birth" or "mother's maiden name") as a secret for use in authentication is a big problem. I honestly don't see how you didn't just restate what I said with different language, while simultaneously saying you disagree with me. Either way, I agree, and don't really think this is worth a cyber-argument so not sure if I should even be responding. Oh well.
- PeterisP 9y agoIt would be just fine to rely on SSN as an identifier, even to a much larger scale as USA does now, if only it would be clearly assumed that this number isn't secret.
- FabHK 9y agoIn my (shared) office, everyone knew each other's last 4 SSN digits, because whenever on the phone to some random customer service rep, we had to give them to "authenticate".