6 ms·
I was recently a target of a UK online bank phishing scam (not Monzo). They were highly sophisticated. They knew details of recent transactions, including bank
by throwaway_qwe 3y ago
I was recently a target of a UK online bank phishing scam (not Monzo). They were highly sophisticated. They knew details of recent transactions, including bank transaction numbers that don’t show in any qif export or anything. They had a plausible reason to call (based on said visibility). They had researched my name and everything about me and my family that is online. They faked caller ID. Their ‘patter’ was so advanced that I do not know this extra layer of protection would have helped much. Luckily I didn’t finish the steps and lost no money.
It is clear the bank has had a severe exfiltration event. There are other reports that online. IMHO the law should make banks report breaches to the ICO and a record of the nature and size of the breach be public.
Through the process I learned that in the UK you can call 159 to directly contact your bank fraud dept (most banks) https://stopscamsuk.org.uk/159 https://stopscamsuk.org.uk/159
I also learnt about the police’s Action Fraud hotline to report cybercrime. https://www.actionfraud.police.uk/what-is-action-fraud https://www.actionfraud.police.uk/what-is-action-fraud
The phisher was very determined. They called back in 15 minutes claiming to be from the bank fraud dept returning my call. Then 2 weeks later they called back claiming to be from Action Fraud.
However prepared you think you are for such an attack, my advice is to have utmost caution for every single call from anyone claiming to be anyone.
I also have a Monzo account. Even if they called me
I wouldn’t use this. Hang up. Call them. Don’t let them call you.
- switch007 3y agoWhich bank? (Slightly worried UK resident here!)
- throwaway_qwe 3y agoOne of those on the 159 programme https://stopscamsuk.org.uk/159 https://stopscamsuk.org.uk/159 Honestly, I’m not sure it matters. They’ve all had such incidents. I read somewhere that about 30% of your fees and mortgage interest go toward fraud mitigation,monitoring, and restitution. I always live by these rules - call them back, don’t talk to them - ask why you need to do anything. It’s exceedingly rare a bank would call you to do something legit there and then. “I will do it later” will help. In fact that’s how I caught the phisher as I noted the aggravation in 1% of his voice. - use credit cards, not debit cards, for purchases. They have far more protection. - use all the 2FA and password complexity you can - never use real info for challenge questions. Never use maiden name of mother etc. you can put “14 green fish” as the answer to the question if you like. - make sure they are FSCS regulated, and try not to exceed that limit. - understand FSCS does not cover you most phishing attempts, since the bank will claim they tried to warn you and were not negligent - use private tabs for bank interactions Through this experience I have learned not to trust “what we know about you” information they share. Do not underestimate HUMINT. A bank snitch could give up something as seemingly innocent (to them) as your “join date” and it be a lynchpin piece of info for a scammer. This may all seem obvious to an HM reader. But it’s worth refreshing and reiterating.
- lozenge 3y agoCould the breach be at an Open Banking service that lets you view and aggregate your bank details such as Emma, Money Dashboard, TrueLayer? Some marketing/voucher companies are also using this sort of integration now such as Airtime Rewards.
- throwaway_qwe 3y agoThis is possible. I had the account linked to a very well known and popular service that is owned by another bank. I don’t want to use names. But “bank transaction ids” were known I do not know if this is part of the spec. My theory was some export from bank 1 for openbanking was breached or in bank 2’s import was breached. But the news items are about bank 1. Also, they knew details like the date of account opening which was different to date of first transaction. I was not using openbanking in many places but I have now turned it off everywhere.
- jtaft 3y agoWhat about stolen mail? Would any of this details be in a bank statement?
- throwaway_qwe 3y agoNo paper bank statement. No email bank statement. Only qif/csv export. iPhone app only (not web). Fairly sure it was either an inside job and/or openbanking API implementation.
- otteromkram 3y ago[flagged]
- plagiarist 3y agoI am usually this cynical, but they don't really even support the post, they urge readers to hang up and call directly.
- veleek 3y agoBut the very last line says they wouldn’t trust this feature and they have a Monzo account?
- throwaway_qwe 3y agoIt’s not coincidental. I had a story to tell and didn’t want to use my main account. Monzo is OK and I have a 2nd business account with them. I find it expensive personally, at £5pm, since other banks offer free service and per transaction costs that total less for me. After the phishing attempt I moved to NatWest, of all places.
- grecy 3y ago> Hang up. Call them. Don’t let them call you. This is the golden advice. Never, ever speak to anyone about anything important if they contacted you. Call, text, email, whatever. End it and you contact them. It doesn’t matter if it’s the bank, power company or telco. Even if HR called me or the CEO. Hang up, call them back. It adds 5 seconds to ensure all is good
- deleted 3y ago[deleted]
- timnetworks 3y ago> This is the golden advice. This bears repeating. It's so simple to check in using another known-good contact method, and btw phone calls are still cool.
- nerdponx 3y agoAs everyone else is rightly saying, phone calls are only still cool if your bank or other institution agrees, which some do not.
- lxgr 3y ago> btw phone calls are still cool. Not to large corporations. Have you called one lately? It's a minimum of five minutes of bartering, begging and pleading with the IVR to let you speak to a human, and even then a successful outcome is anything but guaranteed.
- teeray 3y agoUsually doing what the IVR asks is the slowest path. Confusing it by mumbling nonsense so it thinks it can’t understand or ramming never-ending DTMF tones up its input buffer until it chokes works well. For certain companies and certain departments (usually where my ongoing satisfaction is a concern for the company), I’ve sometimes found yelling repeated expletives at the hold music gets me connected faster. I have nothing to substantiate it, but my conspiracy theory is that there’s a customer rage meter that can be gamed (remember “calls may be recorded for quality assurance“). By contrast, when my call is a pure cost center (e.g. product warranty claims), I’ve found there’s a mandatory hold time to encourage you to hang up.
- yardie 3y ago> Even if they called me I wouldn’t use this. Hang up. Call them. Don’t let them call you. This has become increasingly difficult in my experience. Where calling the local branch I have the actual relationship is just dumped into the IVR. They make it very hard to speak to an actual human being bank employee.
- flatline 3y agoAll I can get is callbacks for some places. This is newish. You can call, wait in the queue for 20+ minutes, get routed to voicemail, and leave an option for a callback. That’s it. And the CSRs won’t reveal any semi-secret info to confirm who they are, they just want info to confirm your identity. It is frustrating because “calling them first” for anything billing related has been my go-to for a decade.
- Guvante 3y agoI just make them tell me how to do it. If they are behind an annoying IVR they usually know how to get back to themselves. Of course don't take their word on what number to call, make them point to a part of their website that shows the number.
- yencabulator 3y agoThe (US) banks I've experienced will give you an "incident number"[1], you can call the number on e.g. your credit card or bank's website and say you have an incident number and you'll be connected to a rep who can pull up the details. [1]: or something like that, I forget the exact words
- gpvos 3y agoMight be nice if you could enter that incident number from the initial phone menu instead of waiting for a human first.
- yardie 3y agoMy card has an international number which is US +1-(AreaCode)-XXX-XXXX. It used to bypass the IVR and send you directly to the top of the queue to a CSR. Because who has time to putz around the IVR when you're paying .25-.50/min to make an international call. Sadly, because some customers figured it out, it just routes you into the queue.
- hermitcrab 3y agoOn landlines IIRC there is some feature that allows them to stay on the line after you hang up. So when you try to call the bank, you get the scammers again. https://security.stackexchange.com/questions/100268/does-hanging-up-on-a-uk-landline-call-not-terminate-the-connection https://security.stackexchange.com/questions/100268/does-han... So try to call the bank from a mobile.
- ethanbond 3y agoNow that is insane. Totally sounds like one of those things that paranoid old people believe about newfangled technology, but nope, just extremely weird protocol design.
- jjav 3y ago> Now that is insane. Remember it used to be a switched physical circuit. In the early days the switching was done by people, later it was automated. But you still had a circuit from phone to phone. When one side hung up, the circuit is still live. Eventually it timed out and the switch disconnected it, but it took a while (don't remember how long). So you could hang up a phone, walk to a different room and pick up another phone and the same call circuit was still live (as long as the other side didn't also hang up meanwhile).
- traceroute66 3y ago> just extremely weird protocol design Its not really weird if you look at it in context. People who are not Gen-Z whipper-snappers will recall the era. Before cell phones, before DECT home phones, before wireless cordless home phones you had fixed phones. You had a master socket and then, optionally, one or more secondary sockets (depending where you lived, you were either permitted to install these secondary sockets yourself, or you had to call in the telco to do it). Anyway, so what would happen is that your friend from school would call you up. Inevitably your parent would answer the phone because they were, for example, in the kitchen cooking your dinner. There would then be a shout across the house "Bobby its Johnny ... AGAIN !". The call-transfer process would involve your parent hanging up and you picking up the nearest secondary handset. Hence the exchange needed to keep the A-end of the call live whilst you completed the B-end "transfer". The same generation of people will also recall the ability to abuse the mechanism to quietly spy on someone else using the phone. :)
- doingtheiroming 3y agoThese are by far the hardest kinds of fraud for banks to deal with right now. They’re so convincing that even when the bank detects them, the customer still demands the transactions go ahead because they’re so bought into the fraudsters. We need this kind of authentication to become normal for everyone for any transaction.
- jacquesm 3y ago> IMHO the law should make banks report breaches to the ICO and a record of the nature and size of the breach be public. The law already is that they should report breaches to the ICO, at a minimum you should report this to the ICO and if you can you should name the bank, possibly right here in this thread so that others have a chance to find out. It's a throwaway so why not use it?
- c0pium 3y ago> Hang up. Call them. Don’t let them call you. Louder for the folks in the back. All bank cards should be required to print this on them.
- mynameisvlad 3y agoI got a call from Amex fraud prevention and the voicemail explicitly told me to “Call X or the number on the back of your card” which I really appreciated.
- vkou 3y agoThe best advice for dealing with this kind of fraud is knowing that there are exactly three things that can happen in a conversation with the fraud department. 1. "Did you make these purchases?" 2. "Yes" -> "Thanks, bye." 3. "No" -> "Thanks, we're disabling your card, and sending a new one to your address. If your address has changed, please pick it up at the branch." Any deviation from this is a scammer posing as the fraud department. Any attempt to gather any information from you, besides 'Did you make these purchases?' is a scam. They know who you are, if they didn't, they wouldn't be calling you.
- idk1 3y agoCould you let us know how you spotted it was a fraud please?