Feeds

'Untraceable' phone fraudsters eye your credit card

Press 1 for low-tech phishing scam

The Power of One eBook: Top reasons to choose HP BladeSystem

Scams involving email and fake banking websites may get all the attention, but a recent rash of fraudulent phone calls shows criminals haven't given up on more traditional tools for tricking people into surrendering credit card numbers and other sensitive information.

The calls begin with a recording that makes a tempting offer - usually for a lower credit-card interest rate or an extended car warranty - and then invite the caller to speak to a live agent. The agents then ask for information including the credit card number and expiration, name, address, and in some cases social security number and other data. Recipients who have fallen for the ploy report finding charges as high as $900 on their credit card.

Your reporter has received three such calls in as many weeks. After taking the bait for a lower interest rate, an agent named Donna said her company, amorphously called Financial Services, uses its clout to negotiate directly with the issuing bank to lower my rate. Eventually, she put a supervisor named Johnny Davis on the line to answer questions like where Financial Services was incorporated and whether it was a member of the Better Business Bureau.

His answer: "That has nothing to do with the purpose of the phone call. Are you interested in us negotiating your interest rates of your accounts?"

Obviously, Davis wasn't the least bit daunted by the questions and neither were any of his colleagues, judging from similar online accounts, in which recipients report getting an abrupt click when seeking such information. Other people report receiving the calls every day at 3 a.m.

The reason Johnny, Donna and the rest of the cabal can't be bothered with maintaining even the appearance of legitimacy is they know they are largely untraceable. The varying phone numbers that appear in recipients' caller id screens are spoofed. There is little that typical users can do to find the real origins of the call.

"I actually pursued it a little bit," said Dan Clements, head of credit card-monitoring service CardCops after he received a call. But because CardCops, a division of Affinion Security Center, is set up to focus on internet-based abuses, he took a pass on one based solely using phone lines. "I couldn't dig in on it," he said.

Identity theft investigators at Consumer's Union say they are unfamiliar with the scam. Officials from the California Attorney General's office the the Federal Trade Commission didn't return phone calls by time of publication.

That's left people to resort to alternate ways of handling the calls. One person, for instance, started Stopping Heather, a site named after the perky voiced operator whose recording graces the beginning of many calls. Participants are encouraged to log as much information about the calls they receive as possible, including spoofed numbers and the scripts of the scammers. Ad-hoc forums on sites such as 800Notes serve much the same purpose. Others report keeping a whistle or an air horn at the ready.

The surge of calls come as security researchers report an up-tick in so-called vishing attacks, which use VoIP, or voice over IP, to trick people into turning over banking credentials and other sensitive data. Last fall, more than 12,000 people in Texas were targeted in a scam that attempted to capture their account details for eTrade and two local banks, according to a recent report from iSIGHT Partners.

Vishers typically set up demo accounts with one of the many VoIP providers, carry out their attack and then move to another provider. The attacks observed in the report were different from the recent scam, however. They typically rely on emails that encourage recipients to call an automated number and manually enter their account information.

The use of live agents at a time when open-source public branch exchanges and similar gear makes number spoofing cheap and simple is a wrinkle that will take time for enforcers to crack down on.

Says Ken Dunham, iSIGHT's Director of Global Response: "We don't really have the trained individuals in [industry] or law enforcement in place to rapidly respond to these new kinds of threats." ®

If you have intelligence or insight about this or related scams please contact Dan Goodin using this link.

The Power of One eBook: Top reasons to choose HP BladeSystem

More from The Register

next story
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
BMW's ConnectedDrive falls over, bosses blame upgrade snafu
Traffic flows up 20% as motorway middle lanes miraculously unclog
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.