419 Scam of the Day [Email Scams, Phishing, etc.]

From the BBC today:

Police are warning people using Revolut to be vigilant following a significant increase in fraud and scam reports involving financial technology and apps.

The States of Jersey Police said 75% of all scam crimes reported on the island over four weeks had involved Revolut accounts, with victims collectively losing about £180,000.

A spokesperson for Revolut said it took fraud and the risk of its customers being targeted by impersonation scams “extremely seriously”.

“We urge customers to remain vigilant when receiving unexpected calls and remind them that Revolut will never ask them to share passwords, passcodes or security information or transfer money to a ‘safe account’,” the spokesperson said.

Police said the majority of reported incidents followed a common pattern where victims received a telephone call from individual claiming to be from a bank fraud department security team or Revolut support.

Police said: "The caller tells the victim that there has been a suspicious transaction on their account or that their account is at risk of being compromised.

“Victims are then persuaded to provide security information, transfer funds, approve transactions, or grant access to their accounts.”

Officers said, in addition to telephone-based scams, they had also seen several cases where customer accounts had been compromised, resulting in unauthorised access and financial losses.

The spokesperson for Revolut said: "We are sorry to hear of any instance where our customers have been targeted by ruthless and sophisticated criminals.

“Anyone who believes they may have been targeted should end the call immediately and contact Revolut through the secure in-app chat.”

They said the company continued to invest heavily in its sophisticated fraud-prevention systems.

What I’ve seen reports on is the following:
They fake the bank’s login page and have you log in there (the notorious link by mail/SMS) while you’re on the phone with them. You “log in” expecting the 2-factor challenge SMS. So you happily confirm when it arrives, believing you confirm your own login.

But in reality they used your login data you sent to their server behind the fake login page for a real log in. Their login produces the challenge you happily confirm because you expect one, thereby confirming their login and giving them full access to your account.

This is particularly problematic since sometime last year due to the availability of immediate transfers. Before that you at least had the remainder of the day to react and stop the transfers…

@Ace
Swiss landline telephony was fully digitised and switched to VoIP about a decade ago. That’s a problem in case of catastrophes because, unlike before, landline phones now depend on a functioning electric grid and many older people don’t have a mobile phone.

Got an e-mail today. My favourite part is "Guten Tag #recipient_name#. :grinning_face:

2 Likes

Why would the Swiss transfer euros to a Swiss bank account?