Posted on 08/24/2017 4:32:18 AM PDT by Dad was my hero
Is this a scam? Two previous times over the last couple months I was called by someone (Indian accent) telling me that I was due a refund from a transaction I had with their company last year. I vaguely recalled the transaction and they knew the date and exact amount. I just needed to access my computer and checking account so they could give me the money. (red flags all over the place so...) I told them to just send me a check and we'll call it even then hung up.
Well yesterday another call, this time they had enough details to convince me they must have been legitimate, they had the last four digits of the credit card number I used at the time. So we began playing a verbal game that lasted almost two hours.
First they said for me to go to a site and download "teamviewer.dmg" and run it. So I did (starting to have that slight fishy smell). Then they gave me an access code. Now they had access to my iMac. They kept telling me to access my checking account and I'll soon see the money reappear in it. I had some difficulty telling the guy that the credit card I used was a club visa card with no checking account attached. He transfers me to the next person. I again explain that the card has no checking account attached to it. He insists that I'm going to see the money appear in my checking account but I need to access my account. So I told him I was accessing it, just not on the computer they were on, I work from home and my pc (two feet away from my iMac) is accessing my checking account, no money. I need to access it from my computer that they are shadowing! (fishy smell is now getting stronger but I'm still hooked.)
So I finally relent and in the mean time the guy tells me that they are not in the same country so exchange rates will apply, did I understand that? Yes. NOW, ABSOLUTELY DO NOT TOUCH YOUR COMPUTER KEYBOARD OR MOUSE WHILE THIS IS HAPPENING! Got it. Now, because of banking regulations in our country we cannot transfer amounts less than $10,000 so you will soon see that amount show up in your account. Then you need to transfer back to us $9,800 and keep the remaining amount. Well, alarm bells are going off and so I try to move the mouse to the log off section of my account and I am not able to control it, all the while they are shouting at me not to do that. So I reach around the back and cold shut down the computer which disconnects their call from me because my home is using Magic Jack. Another guy was also on my cell phone. BTW, every call that came to me came through as unknown or anonymous.
I ran a malware scan and had Apple support verify that they left nothing on my iMac.
Legitimate? They got that info from credit card receipts and info that are sold to scammers.
Do a credit card transaction and all it takes is an unsavory guy that handles receipts to sell your info.
Had that happen to me (they tried) but I did NOT give the caller any info and blocked the phone number.
I got an email from Mr Rex W Tillerson United States Secretary Of State by profession saying I can pick up my $1,850,000.00 USD as soon as I pay the $320.00 fee ,LOL
Hah. . .sometimes I answer the phone like I answered it accidentally and I’m in mid-sentence rambling on about a murder “we” just committed and how to get rid of the body.
Got the idea from: https://www.youtube.com/watch?v=qq8MbttjZ3Y
Absolutely hilarious!!
Unsolicited phone call ? Indian accent ? Hang up immediately.
On YouMail, you may have to teach the app that a number is a spammer. Block on the phone device and let the Youmail pick-up the call. One of the choices is to select the Youmail tone that conveys the tonal-message that your number is disconnected. Perhaps, I did not word the preceding sentence artfully, but the notion is the robocaller gets sent to spammer hell.
You can also use the wildcard “?” to divert/block large groups of numbers when the spammer has a chunk of numbers that are incremented for the multiple attempts (i.e., 805-918-????) will block all 10,000 numbers from 0000 to 9999.
For the cynical reader, I do use the service but have no other interest beyond sharing my experience with an app that works.
As most of us know, there are scammers on the move constantly as they try to steal control of our very lives and finances. I too experienced such a call as the writer but when asked for computer control and for a credit card number, I flat out refused. Hoping to go further, he transferred me to another guy claiming he was the 1st guys supervisor. The second guy flat out DEMANDED my credit card number which I again refused. Then, he said he would have to cancel my contract with Dish Network unless I gave him that card number. Again I refused and ultimately cancelled the call. I immediately called Dish Network and was told they NEVER call asking for money or card numbers, they only deal with actual mailed invoices, etc. The whole point is NEVER, under any circumstances give your card or personal information to anyone you DO NOT know, in particular those with a foreign accent.
‘And today Im changing my account user IDs and passwords’
Why is that in present, and not past, tense?
You can’t fool me!
That’s the recipe for fresh Gagh!
I had some scammers call me several times per day for nearly a month before they gave up. The caller id showed a local number but the person who left a message always had an accent. (one I could not quite place, perhaps eastern european or middle eastern - definitely not erdu or hindi). They used a robo dialer so they often missed my quick voicemail beep and no message during the handover. They seemed to think I had answered and they always left a message like ‘ hello, hello, hello ... since I cannot hear anyone on the line I will now disconnect.
I just figured anyone calling with a robo dialer from overseas with a spoofed local number was up to no good. Each time I got a call it either went to voicemail or I’d answer and hang up. I started to use it as my signal to step away from the desk and go for a walk or do pushups.
Regards,
If you receive a call from a person with an Indian accent, it is a scam unless the person is speaking Navajo.
Rootkit installation can be automated, or an attacker can install it once they've obtained root or Administrator access. Obtaining this access is a result of direct attack on a system, i.e. exploiting a known vulnerability (such as privilege escalation) or a password (obtained by cracking or social engineering tactics like "phishing"). Once installed, it becomes possible to hide the intrusion as well as to maintain privileged access. The key is the root or administrator access. Full control over a system means that existing software can be modified, including software that might otherwise be used to detect or circumvent it.
Rootkit detection is difficult because a rootkit may be able to subvert the software that is intended to find it. Detection methods include using an alternative and trusted operating system, behavioral-based methods, signature scanning, difference scanning, and memory dump analysis. Removal can be complicated or practically impossible, especially in cases where the rootkit resides in the kernel; reinstallation of the operating system may be the only available solution to the problem. When dealing with firmware rootkits, removal may require hardware replacement, or specialized equipment.
Adding Swordmaker, the FR resident Mac expert for review, comment, and suggestions.
Do bears...?
good advice
Those details suggest that either 1) the original company you purchased from isn’t legit; 2) that company has a crooked employee selling that transaction to scammers or is part of the scammer gang; 3) that company got hacked and all the info you listed was stolen from their server; or 4) the company you purchased from is using a third party firm to process their transactions and THAT transaction firm has problems 1 to 3. So, you see, there are many ways they could obtain those transaction details and them having that info does not make them legit.
Related story: My VERY FIRST e-commerce transaction in the early 90s got hacked. I was at a trade show in Atlanta and, when I returned to my hotel room, there was a message asking me to call my credit card company. My card had been cancelled because the entire database of transactions for Networld/Interop had been stolen and the thieves were making fraudulent charges to the stolen card numbers. Security is obviously much improved since then, but some merchants still keep all transaction info on their servers or the companies they hire to process their transactions keep the info.
Of course it is a SCAM.
I get nearly a dozen scam emails per day. I have a pre-scanner program to look at emails before opening them, and it usually red flags a half-dozen per day. My ISP email also has a spam scan that sends another dozen or so scam to that folder.
If they were all legit, I could be collecting around a $billion (with a b) per week. I get them from old accounts and banks accounts I have never had accounts with. FBI sends some. IRS. The Nigerian price. The UN. The Secretary of State. The Secretary of State of Bozoland. The Irish Lottery. The EURO lottery. and on and on and on.
I have notice an uptick in the number of spam calls to my cell. One new trick they use is having the same area code and a recognizable 3-digit prefix for my area. I answered a couple of those and hung up on that sales pitch.
Now, I run Truecaller on my cellphone. It weeds out a lot of the major spam calls. Somehow, the spammers still get around it and around the FED and state Do Not Call lists.
I do not even click on emailed links to my regular banks, credit cards, accounts. If they send me something, I use MY bookmark to go to their webpage. My ISP even send some phishing emails to the the spam folder — phishing emails using my ISP’s names and logos.
And NEVER download and install ANY program ‘they’ ask you to run on your computer. NEVER NEVER NEVER!
Because I sometimes get calls out of the blue from folks I've never met, referrals from prior clients, I can't just ignore cell calls. But I do not say hello for the first ten seconds or so. That causes the robocalls to hang up and move on and live people to say "hello"?
I suspect it was #3 in your list. But everything is intact as of now. I’ve changed my user ID, password and all monies that were in my bank accounts are still there today. I’ve also put holds on the two cards they had the last 4 digits to and both accounts are sending me new cards and they’ve verified no new transactions have occurred in the last two weeks. Bank and LifeLock have been notified so I’m feeling pretty confident at this point.
A “sale on English lessons” — LOL. I have to remember that one. In the old days, I used to say “I am sending Luigi over to break all of your phone dialing fingers.” I remember one woman breaking down, sobbing “I need this job.”
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.