• Hi all and welcome to TheWoodHaven2 brought into the 21st Century, kicking and screaming! We all have Alasdair to thank for the vast bulk of the heavy lifting to get us here, no more so than me because he's taken away a huge burden of responsibility from my shoulders and brought us to this new shiny home, with all your previous content (hopefully) still intact! Please peruse and feed back. There is still plenty to do, like changing the colour scheme, adding the banner graphic, tweaking the odd setting here and there so I have added a new thread in the 'Technical Issues, Bugs and Feature Requests' forum for you to add any issues you find, any missing settings or just anything you'd like to see added/removed from the feature set that Xenforo offers. We will get to everything over the coming weeks so please be patient, but add anything at all to the thread I mention above and we promise to get to them over the next few days/weeks/months. In the meantime, please enjoy!

Bank fraud mobile phone warning

RogerS

Moderator
Staff member
Joined
Jul 21, 2014
Messages
15,531
Reaction score
1,259
Location
Somerset
Well worth listening to the first item here http://www.bbc.co.uk/programmes/b06w53bh

It's about the ease with which a fraudster was able to bypass the two-part security by persuading the mobile company to re-register a new SIM card thus ensuring that the security code texted by the bank went to the fraudsters phone. As far as I can see there is little you can do to prevent this happening to you as it relies on social-engineering and the reaction/attitude of the individual call-centre operator at your mobile company.
 
Yes I heard that on Saturday. It was a bit alarming especially as it was down to weak operator procedures.

I've got three Santander bank accounts that force me to use that system but fortunately I look at them fairly regularly and would notice any strange movements. They also send an alert email for any changes over a preset threshold which I have now set lower just in case.

Hopefully the mobile operators will tighten up a bit on their procedures too as a result of the publicity of this case.

I can't remember the last time I used my phone to make a call or send a text so would not be likely to notice a lack of service if I were to be attacked in this way. As a corollary though, hardly anyone has my mobile number either.

Bob
 
Rod":1yv825cn said:
My bank issues a gadget that gives a PIN number each time you log in - which I hope is safe?

Rod

As far as I am aware it is. My understanding is that it works on the 'best practice' technique of something you have (your card reader) and something you know (your PIN number).

The four digit text number that we're talking about here is in theory perfectly reasonable as it depends on something you have ie your mobile phone. However, once your number gets re-registered to a differen SIM that the fraudster has then your phone is no longer 'yours'. Actually, that's why I said 'in theory'. It is not your phone but your phone number that is the 'device' that you have....so not as good as the card reader.

I Googled card reader hacks but only picked up a few stories from 2009.
 
I just learned that a similar technique has been used for those using a landline for the bank to call. Again - relies on social engineering by the fraudster. They rang up BT and managed to convince them that their landline was faulty and for calls to be diverted to a mobile number. Job done.

And as Andy would say "We're doomed".
 
The one time codes sent by my bank to confirm a new transaction or significant change request are numeric and sent by text. I wonder if that would get translated to a spoken number if sent to a landline?

All a bit worrying Roger. The first time you would notice other than an empty bank account would be that you were getting no incoming calls until such time as the crim had finished with you and turned the divert to his mobile back off.

I've now set up my 3 santander accounts to provide email alerts for credits and debits over £50. It might mean a bit fuller inbox but should help to nip fraud in the bud if I do get hit.

Incidentally I've just had a call from my energy supplier in response to an email question I sent them. the answer was somwhat complex and easier for them to phone. Even for a non account specific conversation, they (EON) asked a security question which I thought was good practise.

Bob
 
Back
Top