SIGforum.com    Main Page  Hop To Forum Categories  The Lounge    Banking scam, now with insiders. Very convincing.
Page 1 2 
Go
New
Find
Notify
Tools
Reply
  
Banking scam, now with insiders. Very convincing. Login/Join 
No More
Mr. Nice Guy
posted
This past week I was targeted with an insidious new twist on a banking scam. No, they didn't get any money. They did have me fooled for a few hours. It also wasted a couple days of my time and now my online banking is all locked down to prevent unauthorized access, which is hugely inconvenient. The scammers have insiders in the credit card monitoring system, and people around the country. They have incredibly detailed personal and financial information making their approach very believable. Not just my name, phone number, email, and home address. They had the local branch address of my bank and brokerage company. Information not available to the general public about my finances. Perhaps from a credit bureau?

The too short version is that the scammers started calling immediately (within minutes) of me getting off the phone with my bank about an actual fraudulent use of my credit card, pretending to be my bank and then my brokerage company. Thus I believed it was real at first.

The lesson is Never believe any incoming call (or text or email) is real. No matter the timing or context with other calls, texts, or emails that you know for a fact are not scams. Unless you dial the call, presume it to be a scam. Never click on a link in an email.

So here's how it worked. Someone attempted to make a fraudulent purchase on my credit card in California. My bank uses a 3rd party company in Atlanta called Falcon to monitor transactions for potential fraud. They send me a text asking if I made that transaction. I don't respond to the text, instead I log into my online account and find the contact information to call. My bank confirms they sent the text (but I believe more accurately it probably came from Falcon on behalf of my bank). The bank cancels my card and will send me a new card.

Then, within about ten minutes of that, I get an incoming call with the caller ID number of my bank. This was the first scammer. She said the problem was more than one attempted use of my card. There were several attempts to log into my account from cell phones, and an attempt to ACH money. She said it had involved also my brokerage company (one of the big name companies). Then she looped into the call a guy pretending to be from my brokerage company's fraud department.

After a minute we get disconnected. He calls back immediately, with the correct caller ID for my brokerage. Slick deception.

His story is that someone impersonated me and tried to wire $30k from my brokerage checking account. He says the FDIC is involved in investigating my local branch office for a series of such frauds. Soon I receive two very high quality documents via email with a spoofed FDIC email address. These documents had a lot of my personal information plus the name of my brokerage company. These were perfect, unlike the usual email crap scam attempts. Stupid me, I was believing the scammers as this was within the first 5 minutes, and I clicked on a link in one of the emails. Luckily no malware breached my firewall.

(There were further attempts the next day to get me to click on links and to install an app on my phone. I was on to them as scammers by then.)

The next morning he called and asked me to go to the local branch office. Of course it turned into wanting me to wire $30k to a "secure FDIC account", or withdraw $30k cash and give it to a courier. The story was to create evidence of teller or manager wrongdoing. That's when I hung up and contacted law enforcement. The scammer's script was really good and worked a lot of psychological angles. Time pressure, anxiety about my account being drained, helping law enforcement, proving my identity at the local branch in person (part of the process to send a wire), authoritative emails from the FDIC, etc.

That's a simplified view of a convoluted sequence. The key to remember is that the first call from the scammer came immediately after I had contacted my bank about an actual true attempt at fraudulent use of my credit card. Thus I was primed to believe it was real. How would a scammer know about the credit card fraud, or about where my brokerage account is? Insiders is how.
 
Posts: 11344 | Location: On the mountain off the grid | Registered: February 25, 2002Reply With QuoteReport This Post
I'd rather be hated for who I am than loved for who I am not
posted Hide Post
Glad you didnt fall for it. I hope the investigation finds the insiders and they do some time in a federal prison!! Mad
 
Posts: 8279 | Location: Bismarck ND | Registered: February 19, 2003Reply With QuoteReport This Post
Member
posted Hide Post
Thursday I received a phone call recording stating my USAA AmEx credit card may have fraudulent charges & I would receive a phone call from the USAA fraud department. About 10 minutes later I recived a call from someone in the USAA fraud department. Both calls showed a caller ID of USAA Claims and the USAA phone number. I was told I had a $536 charge at Sam's in Hawaii and was this a fraudulent charge? I said yes I did not make the purchase and was not in Hawaii. Then he said the charge was made with Apple Pay and my CC number was on a phone. In order to eliminate the charge I needed to give him my credit card number and security code so the number could be removed from Apple pay on the phone. I immediately hung up. How did the caller know I had a USAA AmEx card? I checked and the card was only used 5 times at 3 places for online purchases in the last 2 years. I called USAA the next morning and the credit card fraud department had no record of any charges or any phone calls to me.


__________________________________________________

If you can't dazzle them with brilliance, baffle them with bullshit!

Sigs Owned - A Bunch
 
Posts: 4619 | Location: Nashville, Tennessee | Registered: December 16, 2004Reply With QuoteReport This Post
Leftists, what more
needs to be said?
posted Hide Post
I wish we could make them earn their prison amenities. It’s ironic, take Iran and China, those two countries would probably hang scumbags like this.
 
Posts: 2829 | Location: Illinois  | Registered: July 14, 2010Reply With QuoteReport This Post
Member
Picture of 229DAK
posted Hide Post
The punishment for this fraud isn't enough to deter these scammers.


_________________________________________________________________________
“A man’s treatment of a dog is no indication of the man’s nature, but his treatment of a cat is. It is the crucial test. None but the humane treat a cat well.”
-- Mark Twain, 1902
 
Posts: 10496 | Location: Northern Virginia | Registered: November 04, 2005Reply With QuoteReport This Post
Optimistic Cynic
Picture of architect
posted Hide Post
I've got something USAA-related going on as well. I've had a couple of ACH deposits made to my USAA checking account that were purportedly from Mrs. A's payroll processor. These are not legit as her pay stubs on the processor site show no such activity. I get auto downloads from USAA nightly, and have confirmed the deposits on the USAA web portal. They are not micro deposits as used for account confirmation, nor are they huge sums, in the range of a typical 2 week salary net amount.

I suspect that there will be some attempt to claw back the transactions, although I am happy to keep the money if they really want to give it to me. I plan to contact USAA tomorrow about this to get more information and alert them to the possible fraud. I am not aware of any known theft technique that uses this approach.

I think the postings in this thread, and my experience indicate that the USAA customer data base may have been compromised. Alternatively, maybe it's the backup/online copy of the Apple Wallet's database.
 
Posts: 8039 | Location: NoVA | Registered: July 22, 2009Reply With QuoteReport This Post
Member
Picture of Speedbird
posted Hide Post
Near miss = lesson learned. Good on you for staying alert and sharing.

These fuckers should be found and thrown out of helicopters a few miles off shore.

The POS who stole $30k from 70 something parents is lucky I did not find him. Special place in hell for these types.

REALLY wish POTUS and .gov would get Midevil on this stuff.
 
Posts: 688 | Location: Fort Couch (VA) | Registered: December 16, 2012Reply With QuoteReport This Post
Oriental Redneck
Picture of 12131
posted Hide Post
quote:
The lesson is Never believe any incoming call (or text or email) is real. No matter the timing or context with other calls, texts, or emails that you know for a fact are not scams. Unless you dial the call, presume it to be a scam. Never click on a link in an email.

This has been my rule of thumb for a while now, with scammers getting too sophisticated. I don’t engage, unless I initiate it.

Btw, the caller ID displaying one’s financial institution is well known number spoofing by scammers.

Imo, there was no “insider” involvement. The scammers could have gathered all your information from multitudes of previous hacking incidents that we all heard about. And maybe even ones that no one knows about, yet.
quote:
How would a scammer know about the credit card fraud

They are the ones who initiated it. If you got the name of that supposed “insider”, you should call the bank to verify true or false. My bet is there’s no such named employee.

This message has been edited. Last edited by: 12131,


Q






 
Posts: 31211 | Location: TEXAS | Registered: September 04, 2008Reply With QuoteReport This Post
Sigforum's Official
Metalhead
Picture of DTREND75
posted Hide Post
quote:
Originally posted by 229DAK:
The punishment for this fraud isn't enough to deter these scammers.


The main problem is that most of the scams are outside of the USA, where there is no jurisdiction







Sensitive and caring since August 2009

Some people are like a Slinky....not really good for anything, but you still can't help but smile when you shove them down the stairs.

 
Posts: 3859 | Location: PSST! Look behind you! | Registered: July 16, 2004Reply With QuoteReport This Post
Never miss an opportunity
to be Batman!
Picture of jsbcody
posted Hide Post
quote:
Originally posted by DTREND75:
quote:
Originally posted by 229DAK:
The punishment for this fraud isn't enough to deter these scammers.


The main problem is that most of the scams are outside of the USA, where there is no jurisdiction


Then that is another reason for cruise missiles and Hellfires. If only I was President for a day. Wink
 
Posts: 4343 | Location: St.Louis County MO | Registered: October 13, 2006Reply With QuoteReport This Post
Member
Picture of RichardC
posted Hide Post
quote:
Originally posted by Fly-Sig:
This past week I was targeted with an insidious new twist on a banking scam. No, they didn't get any money. They did have me fooled for a few hours. It also wasted a couple days of my time and now my online banking is all locked down to prevent unauthorized access, which is hugely inconvenient. The scammers have insiders in the credit card monitoring system, and people around the country. They have incredibly detailed personal and financial information making their approach very believable. Not just my name, phone number, email, and home address. They had the local branch address of my bank and brokerage company. Information not available to the general public about my finances. ...


Don't forget the Flock system data, sold to third parties.
License plate ( Dept. Motor Vehicle info), color, make and model of your vehicle, tires and add-on accessories,

all your stickers: (Family stick figures, NRA/Moms Demand Action, Republican/Democrat, campaign stickers,
♡ My Credit Union, ♡ My Dog, ♡ My Car Dealer, ♡ The Manatees,),
Sports teams, Church affiliations, DILLIGAF, Don't Tread On Me,



magnetic appliques like Georgia BullDog heads, , trailer hitch accessories,

Business related wraps and signs, with company names, addresses, contact info;
and 1001 other things I haven't thought of yet, but you can bet AI has.
 
Posts: 17505 | Location: Florida | Registered: June 23, 2003Reply With QuoteReport This Post
Oriental Redneck
Picture of 12131
posted Hide Post
^^^^^ Yeah, all of the above. We have to assume these days that everything about us is an open book out there. Privacy is an illusion. The only thing scammers cannot initiate themselves is our own actions. So, they still have to manipulate the unsuspecting to do this and that in order to drain their accounts.

Another thing folks should do is, log into your account and check your activity. If there’s nothing usual there, then whatever the scammers might claim is just bullshit.


Q






 
Posts: 31211 | Location: TEXAS | Registered: September 04, 2008Reply With QuoteReport This Post
No More
Mr. Nice Guy
posted Hide Post
quote:
Originally posted by 12131:

This has been my rule of thumb for a while now, with scammers getting too sophisticated. I don’t engage, unless I initiate it.

Btw, the caller ID displaying one’s financial institution is well known number spoofing by scammers.

Imo, there was no “insider” involvement. The scammers could have gathered all your information from multitudes of previous hacking incidents that we all heard about. And maybe even ones that no one knows about, yet.
quote:
How would a scammer know about the credit card fraud

They are the ones who initiated it. If you got the name of that supposed “insider”, you should call the bank to verify true or false. My bet is there’s no such named employee.


Yeah, my ground-rule is the same to not engage unless I initiated it. But the close timing of their call to me initially bypassed that. I had just called them, and now literally just a few minutes later while I'm still annoyed about the credit card fraud they call back. At first it didn't register that they called me. It was, in my mind, a continuation of the previous call I had initiated.

That quick turnaround time is super effective. It is also why I believe someone at Falcon was involved. Though my bank did not say it (for cya purposes?), a knowledgable financial security type told me it is known within his circles that insiders are involved.

I agree with your conclusion that the scammers initiated the fraudulent credit card transaction to start the wheels in motion.
 
Posts: 11344 | Location: On the mountain off the grid | Registered: February 25, 2002Reply With QuoteReport This Post
No More
Mr. Nice Guy
posted Hide Post
AI is now able to clone a person's voice and speech mannerisms. The calls from a supposed relative or friend in need of emergency money just became more convincing.

A typical scenario is the grandchild calling a grandparent needing bail money or something similar. Grandparents may not be as adept at knowing a grandchild's voice as a parent/child would.

But now they can perfectly clone voices and how they talk. So one would fully believe they know the person calling them. My child could even get a call from "me" needing money wired overseas because all my stuff including passport was stolen. Of course they'd wire a few thousand to "me".

Having a password set up across the family is a strong way to stop this crime. If such a call comes in, ask for the password. If they can't provide it, it's a scam.

Many of us are now in a favorite scammer target group of over age 65. We have some accumulated wealth and we're perhaps less savvy with technology. The main rules are assume any request for money or personal information is a scam, and slow down.
 
Posts: 11344 | Location: On the mountain off the grid | Registered: February 25, 2002Reply With QuoteReport This Post
Oriental Redneck
Picture of 12131
posted Hide Post
^^^^^ My wife and I set up a password/code a while ago that only we know. It’s not written down anywhere. It’s not stored anywhere, except in our brain. We don’t even speak it out, because you know, all these “smart devices” all around us. If scammers call and pretend to be one of us, in the extremely unlikely case that the phone is answered, they will be exposed instantly. It’s also the code when one of us, God forbid, is in danger.


Q






 
Posts: 31211 | Location: TEXAS | Registered: September 04, 2008Reply With QuoteReport This Post
thin skin can't win
Picture of Georgeair
posted Hide Post
Agreed that this almost certainly wasn't an insider, but instead someone who had triggered the initial alert. Probably intentionally given the chain of events that followed.

Insidiously crafty scheme.



You only have integrity once. - imprezaguy02

 
Posts: 13631 | Location: Madison, MS | Registered: December 10, 2007Reply With QuoteReport This Post
Member
posted Hide Post
quote:
Originally posted by Anush:
Thursday I received a phone call recording stating my USAA AmEx credit card may have fraudulent charges & I would receive a phone call from the USAA fraud department. About 10 minutes later I recived a call from someone in the USAA fraud department. Both calls showed a caller ID of USAA Claims and the USAA phone number. I was told I had a $536 charge at Sam's in Hawaii and was this a fraudulent charge? I said yes I did not make the purchase and was not in Hawaii. Then he said the charge was made with Apple Pay and my CC number was on a phone. In order to eliminate the charge I needed to give him my credit card number and security code so the number could be removed from Apple pay on the phone. I immediately hung up. How did the caller know I had a USAA AmEx card? I checked and the card was only used 5 times at 3 places for online purchases in the last 2 years. I called USAA the next morning and the credit card fraud department had no record of any charges or any phone calls to me.


I had a similar experience with "USAA" a couple of years ago. "USAA" and correct number on Caller ID. I logged into my USAA account and saw fraudulent charges. Almost the same exact sequence of events, except they never asked for my current USAA CC info. Since the old one was compromised, "USAA" wanted me to authorize a new CC, and they had a special partnership with Apple now (new USAA Perk they claimed), so my new CC would be a combo Apple card / USAA card. They read off my USAA info, and since this was Apple related, asked me to create a new Apple ID for the card. Current Apple ID was tied to a secondary email. So I did what was asked, and they said a new CC would be Fedexed to me. Okay, and the call ended.

Well, the next morning, I got an email from USAA (on the primary email that I use with USAA) about some suspicious charges. ??? I called USAA and said that I had already dealt with them about this. Uh no, we haven't contacted you until this morning. Eek
I went over the earlier conversation, and the real USAA said that they didn't have any partnership with Apple. That afternoon I received an Apple Titanium card via Fedex. There was nothing on it denoting USAA. I contacted Apple, and there was already $10K in charges associated with the new CC. I asked to be transferred to the Apple Fraud Department and explained what happened. They showed that my "application" had been made over the telephone by someone with a South Florida phone number. Nope, not me. So Apple marked the CC as fraudulently acquired and closed the account.

I called USAA back, spoke with the Fraud Department, and at their urging, reported stolen identity to all the Credit Bureaus. Fortunately, I wasn't responsible for any of the charges, and didn't have any other accounts impacted. However, the secondary email associated with my Apple ID was flooded with over 7,000 spam emails, which took several days to block and clean out.

Bottom line, the "scary" part, was that the fake "USAA" caller spoke perfect English (no perceptible accent - I study foreign languages as a side hobby and can usually pick one out), and knew things about my USAA account that I thought were secure. There was no background noise (like a busy call center, foreign accents / language). So during my call to the real "USAA", I brought up that the fraudster either had worked or was working with USAA, to know some of the details of my account.

Yes, the fraudsters are real, and sadly, with all that "intelligence", do "bad' things instead of good.
 
Posts: 727 | Location: Middle Alabama | Registered: February 27, 2010Reply With QuoteReport This Post
No More
Mr. Nice Guy
posted Hide Post
quote:
Originally posted by Georgeair:
Agreed that this almost certainly wasn't an insider, but instead someone who had triggered the initial alert. Probably intentionally given the chain of events that followed.

Insidiously crafty scheme.


What leads me to believe there was an insider is the timing. There was some time between receiving the first text and then contacting my bank. But then the scammer called very soon after I ended with the bank.

Also, the initial text is not necessarily generated in the moment as someone attempts to use the card.

Maybe they just wait a certain amount of time after the fraudulent credit card use, idk. There would of course be the chance that I hadn't talked to my bank before they called, and then they'd have to pivot about that. The scammer indicated it was in relation to an already discussed fraud.

Both scammers had slight accents consistent with Alabama. Definitely not foreigners.

Nobody in the end is going to get arrested though over my case, especially since no money was lost.
 
Posts: 11344 | Location: On the mountain off the grid | Registered: February 25, 2002Reply With QuoteReport This Post
Oriental Redneck
Picture of 12131
posted Hide Post
quote:
Maybe they just wait a certain amount of time after the fraudulent credit card use, idk. There would of course be the chance that I hadn't talked to my bank before they called

That’s exactly what I would do, if I were the scammer. Wait for a short time then call you, the victim. Why a short time? Because I know the victim, once he finds out, would never wait any length of time to communicate with the bank regarding the initial fraud charge. The odd is in my favor that you already did call.

Anyway, did you bring up with your bank regarding the potential insider job? I would, if I strongly believe that was the case, and let them investigate if they choose to.


Q






 
Posts: 31211 | Location: TEXAS | Registered: September 04, 2008Reply With QuoteReport This Post
quarter MOA visionary
Picture of smschulz
posted Hide Post
Too many automatically click on responses or give out critical information on the phone. NEVER respond with critical information to anything you did not originate (call, text or email).

I get to fix a bunch of computers that people auto click and get in trouble, the bad things happen if it initiates a lockdown with encryption of their computer or they get hacked on financial matter ~ those are too late for me to fix.

I am surprised there is so much trust in calls and emails by folks now days.
 
Posts: 23900 | Location: Houston, TX | Registered: June 11, 2006Reply With QuoteReport This Post
  Powered by Social Strata Page 1 2  
 

SIGforum.com    Main Page  Hop To Forum Categories  The Lounge    Banking scam, now with insiders. Very convincing.

© SIGforum 2026