4 ms·
I'm sorry, I'm missing something between > Me: <gives member number> (that number, by itself, is useless). and > Once I gave my member number, the attacker u
by devchix 7y ago
I'm sorry, I'm missing something between
> Me: <gives member number> (that number, by itself, is useless).
and
> Once I gave my member number, the attacker used the password reset flow to trigger a text message from the bank. > They used this to gain access to the account.
What happened here? How does an exposed useless member number trigger a password reset? Would the reset request not have come to an email account, presumably a well-protected one?
- elyobo 7y ago> Would the reset request not have come to an email account, presumably a well-protected one? Not in this case (and not in many); verifying access to a phone number is also common and apparently was an option for this bank.
- invalidusernam3 7y agoI might be wrong, but I think the fraudster used the member number (which is basically the online banking login username) to perform a password reset on the banks website. The website sends a confirmation code via SMS, which would be used for 2 factor auth to reset the password. But I also don't understand is: did OP give this number to the fraudster? And even if they did, I would assume the bank would send a second SMS to confirm the password reset. I don't know how it went from "useless" member number to access to the account so quickly. Maybe I'm completely wrong
- jawns 7y agoYes, OP gave this number to the fraudster, not realizing it was a password reset authorization code. OP thought it was a code that established that the person they were speaking with was a legitimate representative of the bank, since they had the power to generate a code that came from the bank.
- magashna 7y agoI've often seen that a password reset completion will trigger an email notification, but not a second 2FA verification to confirm.