Join the Community

23,090
Expert opinions
43,872
Total members
354
New members (last 30 days)
161
New opinions (last 30 days)
29,004
Total comments

Who the f... are you?

  0 2 comments

My mobile phone rang this morning. By the time I reached it, the caller (with blocked caller ID) hang up. A minute later my (ex-directory!) home number rang. I picked up the phone.

The person on the other end of the line told me he was from Barclaycard's fraud investigation department and wanted to verify some transactions (Barclaycard does indeed makes such calls from time to time).

I joked that I cannot be sure he was indeed calling me from Barclaycard to which he replied he would not be asking me for any personal information.

The very first question was: "Who do you bank with?" - "Hm, Barclays, obviously..." - "And apart from Barclays?" - "Why do you need to know?"

He told me again he was there to help me. Did I ask for any help?

"What is your email address?" - "Tell me what address you have on file and I will confirm whether it's the right one." (I have two work addresses and three private ones.)

At that point the guy realized he is not getting anywhere and suggested I called Barclaycard myself "to verify those transactions". Which I did. There were no transactions to verify, and their fraud investigation department had no scheduled outgoing calls in the system in respect of my account.

Social engineering is the key part of spearfishing fraud. It can penetrate even two-factor authentication security to play the classic "man in the middle" attack. To protect consumers, banks need to ID themselves first so that consumers know who they are dealing with. How can that be done in a secure way? That's a million dollar question. Any answers?

External

This content is provided by an external author without editing by Finextra. It expresses the views and opinions of the author.

Join the Community

23,090
Expert opinions
43,872
Total members
354
New members (last 30 days)
161
New opinions (last 30 days)
29,004
Total comments

Trending

Igor Kostyuchenok

Igor Kostyuchenok SVP of Engineering at Mbanq

An Open Letter to Incumbent Banks

Jonathan Hancock

Jonathan Hancock Head of Product & Innovation at The ai Corporation

A Guide to Strategic High-Risk Merchant Management

Taras Boyko

Taras Boyko Founder at BTG Corporate Services Provider

Fintech 2.0: What Makes a Startup Appealing to Investors in 2025?

Ted Sausen

Ted Sausen Director - AML Subject Matter Expert at NICE Actimize

Preparing for the Shift to ISO 20022 – How FIs Can Get it Right

Now Hiring