9 ms·
A lot of failures here: 1) Caller-ID spoofing. It straight out should not be possible to spoof government phone numbers, 911, etc. My Android has "Scam Likely"
by djflutt3rshy 6y ago
A lot of failures here:
1) Caller-ID spoofing. It straight out should not be possible to spoof government phone numbers, 911, etc. My Android has "Scam Likely" show up when a scammer calls (I believe this is part of the STIR/SHAKEN protocol), this should be expedited, expanded, and improved upon.
2) Someone should not be able to buy $3000 of Target gift cards without doing a lot of explaining. Personal experience: The grocery store I go to; the registers will straight out refuse to ring up above $500 of gift cards, you have to use the Customer Service desk where their agents grill you (and I do mean grill you, their default mode seems to be "You're being scammed", especially if you're on the phone with someone).
3) If I buy gift cards in New York, there's zero reason someone in Bangalore, India should immediately be able to redeem those gift cards. Perhaps Target could should spend some of their data collection techniques on this instead of trying to figure out if your daughter is pregnant so they can send you maternity coupons.
4) Is there a reason unused gift cards bought within a certain amount of time shouldn't be refundable?
- ianwalter 6y agoI was thinking about #3 as well, but I was thinking that the scammers don't actually use the gift cards right? Don't they just re-sell them in order to launder them? I was also wondering, if you realize you've been scammed right afterwards, is there a process for reporting the numbers to the issuer so they can freeze them and try to refund the victim? I feel like that should be required somehow.
- jonas21 6y agoAccording to the article, the laundering is done in the US: > Once the scammers obtain gift card numbers from a victim, they transfer them to a group of US-based “runners,” who liquidate and launder the funds — either by buying resellable goods at the store or selling them via gift card resale sites. Some even have their own gift card resale apps.
- Spooky23 6y agoThe whole gift card game is a big scam. Between lost cards, the obvious money laundering and tax avoidance grifts, etc, it's a pretty absurd instrument.
- nitrogen 6y agoI'm familiar with a story of an ecommerce site that offered a discount on digitally delivered gift cards to encourage holiday gifting. But they didn't think to prevent people from buying more gift cards with those gift cards.
- Normal_gaussian 6y agoNearly 20 years ago there was a large supermarket in the UK that had two 'points' offers on that intersected on bananas. Cue an enterprising few to buy all the bananas (with banana points), then quickly use all their points on other items. My school ended up with a heap of free bananas from a parent :D
- quickthrowman 6y agoThe old infinite money trick, I like it!
- ux-app 6y agoSorry, i must be slow, what's the scam here? If I buy a $10 gift card with a $10 gift card, aren't we just swapping $10?
- gbrits 6y agoIt's the discount. E.g.: $10 buys you a $12 gift card .. buys you a $14.4 gift card... ad infinitum
- cortesoft 6y agoIt is an interest free loan to a company, with a high likelihood that it will never be collected.
- tracer4201 6y agoThis is a really well written response. How do you feel like we could enforce #3? I suspect someone would use a VPN to fool any location/verification system, or is there something else going on here? RE: Target data collection Determining if someone is pregnant so they can find ways to get that person to shop at Target drives their bottom line. What incentive is there to invest as much in preventing scammers from succeeding? I don’t know what the solution is, but doing something (even an information campaign) is better than nothing at all.
- arafa 6y agoGift cards are often used for money laundering and fraud, because they act as de facto currency but are not subject to the same regulations. I think the key is limiting the extent to which they can be used as currency, which is related to what you mention and what the article mentions. I don't know that full Know Your Customer laws should be in force here with gift cards, but both Target and the bank that facilitates these transactions should be doing more to prevent these.
- coredog64 6y agoI can’t remember if it was here or Twitter, but there was a story on how gift cards were being used in an informal economy in US prisons. It was easy to transmit the required information and it didn’t violate internal prison rules about holding US currency.
- gowld 6y agoIt was covered in Orange Is t The New Black, for one.
- deleted 6y ago[deleted]
- shkkmo 6y ago> 3) If I buy gift cards in New York, there's zero reason someone in Bangalore, India should immediately be able to redeem those gift cards. Perhaps Target could should spend some of their data collection techniques on this instead of trying to figure out if your daughter is pregnant so they can send you maternity coupons. I don't see why data collection is necessary here, if gift cards are such a fraud vector, why not put a 24hr delay in activation on gift card purchases over a $100 to give scammees a chance to understand what happaned and prevent the scammers from profiting.
- walrus01 6y agoRe: #1, nothing is ever going to fully fix that. SS7 and the PSTN are built on 30+ year old tech where the phone carriers all trust each other. SHAKEN/STIR isn't going to fix it either. The only thing that's going to fix caller ID spoofing and calls coming in via grey market VoIP SIP trunking providers is to burn the PSTN to the ground and start over. Breaking interoperability with the world's installed base of circuit switched, 25+ year old PSTN equipment is not on the table for the big phone carriers.
- pbhjpbhj 6y agoI think the phone companies are complicit in #1. They sell a lot of phone minutes to companiess using foreign call centres that want to seamlessly spoof local calls so they choose not to change. There's no reason, for example, for call coming from a foreign country to - when received in my countries routing centres - get a local phone number in caller ID. That should be illegal. Foreign calls, if they're really running against PSTN tech limitations (which I doubt as I thought offshore calls were all routed via internet) then they could easily create hardware to blank out offshore calls caller ID info (and preferably replace with just the international dialling code). But then your bank would have to admit where their call centres are, and they pay more to phone companies than individual customers do. Which comes to why there's no legislation (in UK) demanding action from local phone companies; presumably because they pay the politicians more than we do too.
- gowld 6y agoHuh? Banks would be happy for caller ID to verifiably say Bank Foo or 1-800-certified-callback-number.
- wildrhythms 6y agoI don't think the previous commenter is saying that banks don't want verification; they're saying that banks (among other large companies that outsource their customer service) benefit from caller ID spoofing to conceal the true geographic origin of the call. I think the underlying issue is that current telecom carriers permit spoofing to entire swaths of number blocks without much verification.
- ggggtez 6y agoTo be fair about (3), I think they already do that. They mention in the article that the cards are redeemed by people in your country. Unfortunately, the gift card is an item that is intended to be easy to give to other people, just like cash. This doesn't seem like an easy problem to solve. I think (4) has the most chance of success. Even just adding a 4 hour "activation time" on cards worth more than $250 would make the scam just a little harder to pull off, and real consumers would rarely be inconvenienced. The guy in this story would have realized he was scammed and had ~4 hours after the call to try to fix the situation.
- gav 6y agoIf you had to show id when redeeming gift cards over a certain amount, merchants could use this to track down "runners". Though I imagine that a lot of them are probably recruited in a similar way to the work from home scams. The real problem is that merchants are not incentivized to fix the problem as they make money from it.
- jpkoning 6y ago>Even just adding a 4 hour "activation time" on cards worth more than $250 would make the scam just a little harder to pull off That's a good idea. Implicit in this idea is that victims can call a customer help number and get gift card balances frozen and reversed. I don't know if this is possible to do right now. If so, fraudsters might start up a new scam. Buy $1000 in Target gift cards, spend the money at Target, call up Target and claim that a scammer stole the funds, and then get $1000 back, netting $2000. Target would have to build a new department just to adjudicate gift card claims. At which point it might decide that it's just not worth the hassle of issuing gift cards.
- sjburt 6y agoScammers want cash, they don't want $1000 of Target merchandise that they have to figure out how to sell. Gift cards aren't quite cash, but they're easier to sell.
- mustardo 6y agoI used to work on a platform that ran on the POS and issued various gift cards via the receipt printer (think prepay mobiles) or actived physical gift cards like these. For products we could there was a cooling down time of a few hours between purchase and redemption. This also made it harder for the sales clerk to scam
- c3534l 6y agoFor 3, they're not keeping the cards for themselves, they're selling them online.
- Spoom 6y agoOne thought is that gift cards could have a one day delay before they can be spent. I'd imagine that 90% of gift cards are intended as presents anyway and thus would be unaffected, but the delay would still grant a cancellation window to scam cases like this.
- prostoalex 6y agoAnecdotally I have a completely legitimate use case for that - apps like Fluz http://joinfluz.app.link/BETA http://joinfluz.app.link/BETA and MileagePlusX kick back some dollars (or airline miles) for purchasing vendor gift cards through them. Frequently as I am in the checkout line at Kohl's or Home Depot I'd buy a gift card for myself with the intent to wipe it out in the next few minutes at the checkout (Fluz, for one encourages that, and will send a notification whenever you're near a retailer that's in their network).
- gnicholas 6y ago> Someone should not be able to buy $3000 of Target gift cards without doing a lot of explaining Apparently it was $1k at Target and another $2k at Safeway. This was just under the limit of $1030 per person per store at Target. Perhaps the limit should be lower, or employees should be instructed to be more wary. I imagine Target doesn't want to be too strict here, both because they don't want to inconvenience customers making legitimate purchases, and because they don't want to give up the revenue derived from scammers defrauding people (not that they would ever admit to the latter).
- gowld 6y agoNo way does Target make enough money on stolen gift cards that it's worth the legal and reputational risk of condoning them.
- megablast 6y agoWhat costs?
- 9nGQluzmnq3M 6y agoThe OP states they've spent "hours" on the phone with Target, which has already more than obliterated whatever slim profit they made on that $1000 gift card (commissions are around 5%).
- megablast 6y agoOnly if they had to hire someone new.
- Dylan16807 6y agoOn average, using up 10 hours of employee time in a big company paying people to act as support will cost the company 10 hours of pay, plus overhead. It's not frutiful to examine it as 0 0 0 0 0 $30000 0 0 0 0.
- bobbiechen 6y ago>My Android has "Scam Likely" show up when a scammer calls (I believe this is part of the STIR/SHAKEN protocol) I'll point out that (at least on my phone with T-Mobile), "Scam Likely" comes from T-Mobile's "Scam ID" service. STIR/SHAKEN produces a different message, "Caller Verified", when a caller is confirmed. Source: https://www.t-mobile.com/support/plans-features/scam-id-and-scam-block https://www.t-mobile.com/support/plans-features/scam-id-and-...
- nikanj 6y agoIs it possible to make your phone just flat out completely decline those calls?
- Cactus2018 6y agoT-Mobile tags suspect numbers with "Scam Likely". Opt-in to decline these calls by dialing #662# - https://www.t-mobile.com/resources/call-protection https://www.t-mobile.com/resources/call-protection ps. Forward text message SPAM to 7726 - https://www.t-mobile.com/responsibility/privacy/fraud-spam/sms-spam https://www.t-mobile.com/responsibility/privacy/fraud-spam/s...
- aahhahahaaa 6y agoI suspect this is an issue of retailers not caring enough to spend the money to fix the issues? Being scammed is a bad experience, but it's not the retailer's fault. Plus it generates a significant amount of revenue. This seems like something the Consumer Finance Protection Bureau could collect data on and put some sane regulations in place? The gift card industry is poorly regulated in general.
- joshuaissac 6y ago>If I buy gift cards in New York, there's zero reason someone in Bangalore, India should immediately be able to redeem those gift cards. According to the article, that is not what happens; instead, the gift cards are redeemed in the US: 'Once the scammers obtain gift card numbers from a victim, they transfer them to a group of US-based “runners,”' The runners described above would probably have some kind of presence in most major US cities, and they could just pick a runner in the nearest major city to the victim without raising any location-based red flags. Note that neither Safeway, nor Target have retail stores in Bangalore (or anywhere else in India), only offices.
- zakember 6y ago> Perhaps Target could should spend some of their data collection techniques on this instead of trying to figure out if your daughter is pregnant so they can send you maternity coupons. Why though? One makes them money and the other... also makes them money but by doing nothing about it