this post was submitted on 10 Jul 2023
37 points (100.0% liked)

Cybersecurity

5650 readers
197 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 1 year ago
MODERATORS
 

Last night my sister called me in a panic. She got a call from a "usbank" claiming that they managed security for her credit union on weekends (first 🚩). They listed off her SSN and other credit information to prove to her they were real. I wasn't there so I couldn't tell her that this was another major red flag. She gave them her banks account number. My other family members were there and called her credit union to check. The real bank walked her through what to do.

She didn't lose any money but came scary close to it. I've had her freeze her credit. Put up a alert on her credit. Changed all her passwords (saved in 1password). Set up token based authentication and I'm trying to convince her to use Google voice for sms 2fa.

Should she even bother with dark web monitoring or anything like that?

Edit: phone number used by scammers: 12104170000 I don't believe this is their actual number. It was likely spoofed. Be cautious before trying to scambait it

top 9 comments
sorted by: hot top controversial new old
[–] [email protected] 14 points 1 year ago (2 children)

It honestly sounds like you did everything right. I would’ve suggested everything you did. Credit freeze is #1, then passwords is #2. You did great.

As for your question, I’ve actually used several monitoring services and have had an overall positive experience but it’s definitely a mixed bag and YMMV. Some info I get is very specific and therefore helpful. Sometimes it’s extremely generic ie an alert that your primary email has been found on the dark web…. Ok, I would’ve gotten a similar repose with an “have I been pwned” search. I’ve been involved in like 15 days breaches, I fully expected that email to be found on the DW by now.

I also got these services all for free. One is permanent via my credit union which is great. I’ve gotten others as consolations from companies that have had breaches with my data.

I personally think it’s worth it to her even if she has to pay for a year or two and reevaluate from there, given her situation.

[–] [email protected] 4 points 1 year ago (1 children)

I'm trying to find if she can get one free maybe through 1password. I know they have a basic service that basically checks if a login has been compromised like have I been pwned. Do you know if any credit cards offer a service?

[–] [email protected] 2 points 1 year ago

Oh jeez yes I believe master card does, I believe with citi 2% cash back all purchases cards. Please verify that first.

[–] [email protected] 3 points 1 year ago (1 children)

A question on what you said. Why change the passwords, though, unless she reuses or uses schemes at the first place? SSN & credit card info seem to leak quite a bit nowadays.

[–] [email protected] 4 points 1 year ago (2 children)

So sorry I don’t understand your question, schemes? Reuses schemes?

Generally speaking it’s always a good idea rotate passwords/secrets if any form of compromise is suspected . It’s just good practice, imo.

Yes CC info doe leak often, easier remedied with a cancellation, les so with SSN. We should not be using that for ID purposes in the first place and I hope we stop that practice.

[–] [email protected] 4 points 1 year ago (1 children)

Thx for stating your opinion. Sorry for being unclear. reuse = use same passwords in different accounts; schemes = password patterns with some reused portions.

[–] [email protected] 2 points 1 year ago

I understand entirely now what you meant, the phrase I haven’t heard before!

In that case though, I’d say, with schemes yes definitely, as you’re more at a disadvantage because you follow a pattern, vs not doing so and having a unique password ( and ideally a unique username/ email for every account! Use a email forwarding service like simple login!)

[–] [email protected] 4 points 1 year ago

I think they meant when users have dumb patterns for their passwords like if your lemmy pwd was Evok3lemmy! and your reddit password was Evok3reddit!, etc.

[–] [email protected] 6 points 1 year ago

Me: Oh that's horrible! Terrible! Thank goodness you were there for your sister! Phone number was... 210??? Wut wuuuuuut!!! River city represent!!!