Voice Phishing Hits PayPal
Chai Vanilla writes "The latest social engineering phishing attack is now using phones instead of fake web sites. Identity thieves have spammed fake PayPal account compromise warnings to lure users into dialing a phone number and giving up credit card information. Unlike normal phishing e-mails, there is no URL or response address. Instead, the e-mail urges the recipient to call a phone number and verify account details."
Isn't this more traceable than just clicking on some IP in Russia? If I got an email asking me to phone any company, I'd be first looking for a landline. If it was a scam why couldn't I just call the phone company, give them the number and then they'd be able to trace it to an address or person?
I've gotten that phishing mail yesterday, and called the number (1-805-214-4801) immediately. The system's recordings were chopped and barely intellegible, and I was prompted to enter "my 16 digit credit card number" (which was indeed verified to at least follow the basic rules of correctess or be rejected), and its expiry date, but nothing like a name or even the paypal account data.
Where can one complain about such fraudulent 1-8xx numbers to get them shut down? Additionally, how much does calling a 1-805 cost in the US, and is any part of the cost passed to the operator?
There's a small degree of higher risk, but if you get a new disposable cell phone every three days and move around all day you'd be a hard mark to hit.
Too many people are now aware of the "don't click the link" aspect of phishing, but I'm sure there are still pleanty of suckers that assume if they have your phone number you must be legit. I would not be surprised if they find a way to do this through US Mail in a way that hides their identity.
It would be interesting if one day, to get such an online account set up, they make you pass a short test, where they give you ten examples of people asking for your account information in various ways, and you have to answer "give them the information" or "report the incident to phishing.ebay.com". Anyone that answers "give them the information" on any of the questions doesn't get an account.
I wager that alone would eliminate 80% of successful phishes.
I work for the Department of Redundancy Department.
This goes back to decades before the Internet.
[ring, ring]Hello? Hello, is this $TRUSTINGSENIORCITIZEN? I have wonderful news! Congratulations, you have just won a diamond ring in our marketing lottery! There are some shipping and insurance fees, so if you'll just give me your credit card number...".
Law enforcement and consumer groups said over and over not to give out sensitive information unless you placed the call yourself, which is really the same advice as "don't click on the link" if you think about it.
Just got mine in the email this morning.
(530) 204-6800 is a land line based in Davis, CA
The registered service provider is 01 Communications**.
Detailed listing information is not available.
But I do believe we have a right to call people stupid when they do things like fall for a PayPal scam, buy from spam, send important (highly confidential!) information over email, refuse to apply patches (or not know how), and so on, and so on.
Did you know that 85% of dead televisions just have a blown fuse? Did you know the $120 transmission fluid replacement at Jiffy Lube is a twelve dollar bottle of green grease, and the opening and closing of one valve? Did you know that almost everything a plumber ever actually does is run a drain snake and a plunger?
I mean, we have Sex education, we have Driver's education, I don't think it's unreasonable that we know the computer equivalent of wearing a condom, stopping at red lights, buckling your seatbelt...
Here's the difference: one costs people their lives, the other costs them an hour at the local computer shop. I don't think it's unreasonable that we know how to maintain appliances; nonetheless, nobody requires it, because that's batshit retarded.
Most people think I'm a snobbish bastard, like every other Linux user.
It's got nothing to do with your being a Linux user. It's because you're condescending and because you can't fathom that some people don't have the time or the desire to learn to maintain their computers. Believe it or not, some people have better things to do with their lives.
Next time you pull into a jiffy lube, call a repair person, go to a barber shop, buy art tools, purchase clothes or engage in any service activity whatsoever, please remember that that's something you could learn to do and then spend your life doing, just like a seventy year old woman could spend a year reading tech sites and manuals and getting up to speed on jargon.
Guess what? You don't want to either. You're just too dense to tell the difference.
StoneCypher is Full of BS