5 ms·
I might be wrong, but I think the fraudster used the member number (which is basically the online banking login username) to perform a password reset on the ban
by invalidusernam3 7y ago
I might be wrong, but I think the fraudster used the member number (which is basically the online banking login username) to perform a password reset on the banks website. The website sends a confirmation code via SMS, which would be used for 2 factor auth to reset the password.
But I also don't understand is: did OP give this number to the fraudster? And even if they did, I would assume the bank would send a second SMS to confirm the password reset. I don't know how it went from "useless" member number to access to the account so quickly. Maybe I'm completely wrong
- jawns 7y agoYes, OP gave this number to the fraudster, not realizing it was a password reset authorization code. OP thought it was a code that established that the person they were speaking with was a legitimate representative of the bank, since they had the power to generate a code that came from the bank.
- magashna 7y agoI've often seen that a password reset completion will trigger an email notification, but not a second 2FA verification to confirm.