one poster
Well-Known Member
- Joined
- May 4, 2021
- Messages
- 232
- Reaction score
- 180
Parents (in their 70's) got taken for a decent chunk of money.
MO:
The bank account/types info could possibly come from something like the TransUnion breach but being able to list financial transactions, point to either compromised device/s (giving access to email based "inContact" messages for a recent transaction trail) or bank insider involvement? The email address receiving inContact messages is not listed in haveibeenpwned.
So, questions:
MO:
- phone call from "fraud dept" flagging suspicious transactions.
- dad being cautious volunteers no information but asks the caller questions that are answered correctly (caller can name exact bank accounts, types of accounts, also lists number of most recent financial transactions - including date, where and amount). -> dad feels is legitimate call and proceeds to complete steps as requested.
- to "block" transactions he must now open FNB banking app but not log-in to the app.
- then receives instructions on things to do via the app - unfortunately he can't recall the exact steps but part of it required typing what might be an unfamiliar username (all in lower case, so highly unlikely to be a new password) into a pop-up, receiving an OTP sms that had to be entered and then received what looked like App notifications/push messages confirming that the suspect transactions were blocked.
- caller made noticeable effort to keep facade of security ("just enter the OTP, do not say it aloud - I must not hear it").
- total call duration was just under an hour.
- bit later dad logs into the baking app and notices money gone.
The bank account/types info could possibly come from something like the TransUnion breach but being able to list financial transactions, point to either compromised device/s (giving access to email based "inContact" messages for a recent transaction trail) or bank insider involvement? The email address receiving inContact messages is not listed in haveibeenpwned.
So, questions:
- what was the lower-case username part about? ("forgotten username" reset requires info that was not shared and should be useless without a banking password that was not shared).
- how did dad receive app notifications of blocked transactions? (when dad logged-in later, there were actual blocked transactions in the transaction history for the amounts "flagged" by the "fraud department").
- recommendation for checking android devices for malware (though not impossible, neither parent is likely to click links in sms/emails)?
- recommendation for someone/company to check their network (their setup was done by their wisp and I am not convinced it is particularly secure ). PM welcome. (please, and thank you).
Last edited: