Phishers getting trickier with working phone numbers

Opinion
Apr 11, 20082 mins

I received what to me was an obvious phishing attempt to gain bank card information as you can see from the image below. Normally, I just delete these but I thought it was odd that the message carried a phone number instead of trying to redirect the victim to a hacked Web site. Most anti-fraud campaigns tell people to call in rather than follow links. So, I decided to give the number a try from my office since our number doesn’t show up on most Caller ID systems. This is what I heard:

Note: The information I entered was essentially a card number of 4321123456788765. Obviously, it’s some cheap speech-to-text system collecting card information – enough that people could use it to create fake card or buy things online. But while I knew it was a ruse from the get go (the 2006 copyright at the bottom of the e-mail is a give away too), what about someone less savvy, like a grandparent? It sounds “official” enough to fool some people. Interesting that it claims my information wasn’t correct. I didn’t bother to try again – maybe the system was just trying to double check/verify the first batch of information entered. The REAL Franklin Bank must be aware of this because it is currently running a warning in big red letters on its home page warning: “Franklin Bank will never ask for your private information, card numbers, pin numbers or passwords – EVER!”. Wonder how many of its customers fell for this? Keith and I discussed this very topic on the Twisted Pair podcast this week while talking about the news coming out of RSA. As I said on the show, always call the number on the back of your card whenever you get something suspicious from the bank, be it in the mail or through e-mail.