GitHub - Highpoint2000/TropoFo...
Protecting Against Credit Card Scams
https://shkspr.mobi/blog/2012/07/protecting-against-credit-card-scams/
I recently read about an innovative telephone call scam.
A scammer rings the mark and asks for her credit card details. If the mark refuses, the scammer tells her to hang up the phone, then dial 999 and ask for "Sergeant Scammer of the Fraud Squad".
The mark does so, and is connected to what they assume is the emergency services. However, because the scammer hasn't hung up at their end, the call is still active. So the mark isn't speaking to 999, but to the scammer.
Pretty devious. Luckily, it can't work on mobile. But it got me thinking - how could you get someone to give you credit card details over the phone? I'm inspired by both Bruce Schneier's "Movie Plot Threat" competitions and Kevin Mitnick's work on Social Engineering.
Trying to think like "the enemy" is a crucial part of understanding how nefarious people can exploit a situation. I think it should be considered the seventh "thinking hat".
The Goal
I want the victim to willingly give me her credit card details. I do not want her to be suspicious or report my activity to the police.
The Strategy
"Your Barclay's credit card (starting 4304) was recently used to buy £2,103.54 worth of goods in China. If you wish to dispute this transaction, please call 0113 496 0123."
How It Works
There are a number of factors which go into making this a potentially successful scam.
Problems
Now, this fraud isn't without issue. The most notable being that you do not know who has a credit card issued by a specific provider. The scammer would either need some third party intelligence that their victims all use HSBC, or they could just go on a phishing expedition. Spam a few thousand numbers and there will bound to be a few which have the card which is being targeted.
How To Do It
Using services like Twilio and Tropo, it's quite easy to create a telephone menu. It can play back a recorded voice, save all the user's keypresses, then pass the call on to the scammer.
They can even handle the automated sending of the text messages, playing back different messages depending on the caller - "Welcome to HSBC", "Welcome to American Express", etc.
Defending Against This Scam
There are three main strategies for defending against this scam - and they all boil down to trust
Don't Trust An Unknown Phone Number
Save your credit card provider's phone number in your address book. That is the only number you should ring. If someone rings you - tell them that you will take their name and call them back on the official number. If you receive a text - call the official number to check it is legitimate.
Don't Trust Partial Information
The first few numbers of your credit card are fairly generic. Trusting someone who guesses your Visa Electron starts with "4197" is like trusting a psychic who says "You were a bit of a handful growing up, especially in your teens." It's such general information as to be worthless.
Don't Trust The Other Person
I sometimes act deviously. When asked to give my address, I'll give an incorrect house number or post code. If the person at the other end doesn't pick up on the mistake, I assume I'm talking to a scammer. Similarly, you don't have to trust interactive menus. You can input incorrect information, and see if it is accepted without complaint - a sure sign of a scam. Or see if it gets you through to a human.
Is This Scam Possible?
One hurdle is targeting enough people who have the "correct" credit card. The scam would work without the credit card info, but may be less effective.
The cost of sending out the texts is also a constraint. Although text bundles are relatively cheap now.
Shutting down the numbers - or tracing them - is perhaps the biggest issue. Buying a disposable pre-pay SIM is virtually anonymous. A landline number is probably fairly easy to trace - assuming the police have the time and staffing levels to investigate such a scam.
And that may be the deciding issue. If someone reports a suspicious text to the police or their credit card provider, how quickly can the number be shut down? If the scammer is sending out hundreds of fraudulent SMS an hour, it would only take a few responses to make the scheme worthwhile.
Disclaimer
Naturally, you should not attempt this. The penalties for credit card fraud a very serious. This is intended as a thought experiment.
If you want people to willingly give up their credit card information - take a look at the morons on Twitter posting photos of their cards!
I recently read about an innovative telephone call scam. A scammer rings the mark and asks for her credit card details. If the mark refuses, the scammer tells her to hang up the phone, then dial 999 and ask for "Sergeant Scammer of the Fraud Squad". The mark does so, and is connected to what they assume is the emergency services. However, because the scammer hasn't hung up at their end, the…