4 ms·
On first read, I didn't understand how the call to the bank's customer service department went wrong. Something about that conversation didn’t seem right, and
by dantiberian 6y ago
On first read, I didn't understand how the call to the bank's customer service department went wrong.
Something about that conversation didn’t seem right, and so Mitch decided to use another phone to place a call to his bank’s customer service department — while keeping the first caller on hold.
“When the representative finally answered my call, I asked them to confirm that I was on the phone with them on the other line in the call they initiated toward me, and so the rep somehow checked and saw that there was another active call with Mitch,” he said. “But as it turned out, that other call was the attackers also talking to my bank pretending to be me.”
What happened is that the attackers made one call to Mitch, and another call to the bank posing as Mitch. When Mitch called the real bank to check up if there was a call in progress, they said yes (the call with the attackers).
- overheadnoise 6y agoI don’t know if I’m just really tired or if the post was just badly written, but I’ll go with the latter since you were confused too. My understanding is this happened: 1. Attacker got a hold of Mitch’s bank card, PIN, and some personal details. 2. Attacker starts pulling out money and buying things here and there to see if Mitch ever notices. Mitch never notices so... 3. Attacker calls Mitch on Friday and pretends to be Mitch’s bank. Attacker doesn’t ask for any details, just alerts Mitch that something was going on with his account to get him to think the bank was looking into it. 4. Attacker calls Mitch’s bank and also Mitch at the same time the next day. 5. Attacker asks the bank to send the SMS verification code to Mitch. 6. Mitch gets the code and reads it back to the Attacker. 7. Attacker repeats code to the bank.
- wingerlang 6y agoI think it was perfectly clear.