Lame phone dodgers fleece finance's foolish and fat fingered

A hundred top US finance companies targeted


Scammers are attempting to fleece a hundred top US financial companies by registering phone numbers close to those in use by the firms, engineer Scott Strong says.

Of some 600 top financial institutions across the US, 103 or about 20 percent had scammers register their numbers with only the last few digits altered in a bid to conceal identity fleecing exploits.

Strong of Pindrop Security said scammers would place calls to victims and masquerade as a bank phone operator to retrieve identity information.

"There is a high likelihood that numbers that are very similar to financial institution numbers are being obtained by fraudsters [who are] scamming people calling the wrong number or who are calling customers," Strong told Vulture South.

"They're not immediately taking money from clients on the call, what they are doing is taking information that may be piece together with other data they have for defrauding at a later time."

"If you've responded to one of their voicemails, you've moved yourself up their attack lists."

The company began examine the fraud after a US credit union client discovered four nearby numbers that were used to fleece customers.

The unnamed credit union worked with its telco to shutter the number.

It was unknown how much cash had been fleeced from victims in the so-called misdial trap or what became of the identity information the crooks steal.

It was a small but novel part of a wider fraud that cost the US an estimated $2 billion a year.

Attackers were spread across the world with spoofed gateways likely in use in the UK and similar countries, and there appeared to be no clear organisation between the groups.

While the fraudsters were enjoying what might be the most basic fleecing since Oliver Twist emptied pockets, they would be out of business in short order if financial firms tested neighbouring numbers for misdial traps.

"Literally just call the numbers," Strng said. "If they pick up and claim to be your organisation, well then it's pretty-well certain they're fraudsters and you should call your telco." ®

Similar topics


Other stories you might like

  • China reveals its top five sources of online fraud
    'Brushing' tops the list, as quantity of forbidden content continue to rise

    China’s Ministry of Public Security has revealed the five most prevalent types of fraud perpetrated online or by phone.

    The e-commerce scam known as “brushing” topped the list and accounted for around a third of all internet fraud activity in China. Brushing sees victims lured into making payment for goods that may not be delivered, or are only delivered after buyers are asked to perform several other online tasks that may include downloading dodgy apps and/or establishing e-commerce profiles. Victims can find themselves being asked to pay more than the original price for goods, or denied promised rebates.

    Brushing has also seen e-commerce providers send victims small items they never ordered, using profiles victims did not create or control. Dodgy vendors use that tactic to then write themselves glowing product reviews that increase their visibility on marketplace platforms.

    Continue reading
  • IBM deliberately misclassified mainframe sales to enrich execs, lawsuit claims
    Lawsuit accuses Big Blue of cheating investors by shifting systems revenue to trendy cloud, mobile tech

    Special report IBM has been sued by investors who claim the company under former CEO Ginni Rometty propped up its stock price and deceived shareholders by moving revenues from its non-strategic mainframe business to its strategic business segments, allegedly in violation of securities regulations.

    The investors' securities fraud lawsuit [PDF] was filed on Tuesday, April 5 in a southern New York federal court. It names as defendants not only IBM but current and former executives including Rometty, former CFO Martin J. Schroeter (now CEO of IBM spin-off Kyndryl), current CFO James J. Kavanaugh, and current CEO Arvind Krishna.

    IBM "improperly and in violation of Generally Accepted Accounting Principles ('GAAP') embarked on a fraudulent scheme to shift billions of dollars in revenues from its mainframe line of business to its Strategic Imperatives and CAMSS line of business," the complaint reads.

    Continue reading
  • Cybercrooks target students with fake job opportunities
    Legit employers don't normally send a check before you've started – or ask you to send money to a Bitcoin address

    Scammers appear to be targeting university students looking to kickstart their careers, according to research from cybersecurity biz Proofpoint.

    From the department of "if it's too good to be true, it probably is" comes a study in which Proofpoint staffers responded to enticement emails to see what would happen.

    This particular threat comes in the wake of COVID-19, with people open to working from home and so perhaps more susceptible. "Threat actors use the promise of easy money working from home to collect personal data, steal money, or convince victims to unwillingly participate in illegal activities, such as money laundering," the researchers said.

    Continue reading
  • Yale finance director stole $40m in computers to resell on the sly
    Ill-gotten gains bankrolled swish life of flash cars and real estate

    A now-former finance director stole tablet computers and other equipment worth $40 million from the Yale University School of Medicine, and resold them for a profit.

    Jamie Petrone, 42, on Monday pleaded guilty to one count of wire fraud and one count of filing a false tax return, crimes related to the theft of thousands of electronic devices from her former employer. As director of finance and administration in the Department of Emergency Medicine, Petrone, of Lithia Springs, Georgia, was able to purchase products for her organization without approval if the each order total was less than $10,000.

    She abused her position by, for example, repeatedly ordering Apple iPads and Microsoft Surface Pro tablets only to ship them to New York and into the hands of a business listed as ThinkingMac LLC. Money made by this outfit from reselling the redirected equipment was then wired to Maziv Entertainment LLC, a now-defunct company traced back to Petrone and her husband, according to prosecutors in Connecticut [PDF].

    Continue reading
  • Singapore introduces potent anti-scam measures
    Plans to block more scam sites, share liability between banks and customers

    Singapore will step up up efforts to stamp out phishing and spoofing, ministers told the island nation's parliament on Tuesday.

    The topic earned ministerial attention after instances of attacks and scams soared recently. The standout example is the attack on Southeast Asia's second-largest bank, the Oversea-Chinese Banking Corporation (OCBC). In the OCBC bank scam, threat actors stole a combined SG$13.7 million ($10.2M) from 790 customers by spoofing text messages in what minister of finance Lawrence Wong referred to as "by far the most serious phishing scam seen" in Singapore.

    Wong detailed [VIDEO] several ways banks would be expected to improve security, including using more diverse machine learning algorithms to strengthen fraud detection tools to identify suspicious transactions. Banks will also be required to block suspicious transactions in a more consistent fashion, require additional customer confirmations for high-risk transactions or changes to account details, expand biometric technology, and accelerate adoption of – and preference for – mobile banking apps.

    Continue reading
  • Former tech CIO jailed for setting up £475k backhander scam with IT outsourcing firm
    One-time head of Hampshire Police IT gets six years

    A pro-outsourcing CIO whose first act at a new employer was to set up a £475,000 backhander scheme has been jailed for six years.

    Brian Chant, 62, took the bribes after joining procurement services firm Achilles in 2011, Southwark Crown Court heard.

    One of the first things he did was recommend outsourcing of various IT functions, suggesting three companies to Achilles' board for the £22m SPTL and Systems Plus IT contracts.

    Continue reading
  • Theranos CEO Elizabeth Holmes found guilty of fraud: Blood-testing machines were vapourware after all
    Fallen Silicon Valley darling defrauded investors, says jury

    Elizabeth Holmes, founder of US health-tech firm Theranos, has been found guilty of defrauding investors after a California jury found she had lied about her company's technology.

    Holmes, 37, reportedly showed little emotion when the verdicts were read out. The jury found her not guilty of four charges of defrauding the public, though this was cold comfort when set against the other seven charges of defrauding investors and wire fraud. She has denied the charges.

    The trial has had significant impact in California's Silicon Valley, where Holmes' company Theranos had been held up as a multibillion-dollar example of tech changing the world for good. Founded in 2003 by Holmes, Theranos advertised itself as a medical company whose technology could detect diseases using a finger-prick blood test.

    Continue reading

Biting the hand that feeds IT © 1998–2022