Looks like a new scam

Oct 08, 2020 Last reply: 5 years ago 71 Replies

It's for your own protection to prevent some hacker impersonating you. There's no chance the hacker also has your phone.

If you want to leave your Paypal account open to anyone with your account name and password then I believe you can disable "second factor" authentication.

Some sites, such as Amazon, don't require you provide an extra code from your phone provided you're using the same PC you usually do.

Some web sites allow an authenticator app to generate the security code. I use Authy but there are also ones from Microsoft or Lastpass.

However, as I said, they were the real Barclaycard !!! They refused to speak to me until I provided my Barclaycard number.

If they are at the same stage of the game as google/ms/facebook/twitter then they should allow you to create some codes that can be entered in cases where you don't have your phone.

Well, depends what you mean by "native text handling", our Gigaset DECT phones handle SMS on the land line quite happily.

<snip>

Perhaps this is a golden opportunity to check your mobile still works? Most SIMs stop working after 6 months of making no chargeable calls or texts.

Don't you ever venture outside?

I had a call like that recently, but I was suspicious and was right to be so. It was a major scam.

In the past when I have had such calls, it was either a human operator, that would ask questions like "can you name a supermarket where you use your card regularly". More recently its been automated calls that ask for a key presses to confirm you are the target, then possibly something like it will read out 4 dates and ask for confirmation that one is your birthday (without asking which). That's normally followed by a list of the 4 most recent transactions, and asking if there are any you don't believe you made.

I have not had one that jumped straight in with "give me you card number".

There have been numerous examples of phone companies handing out replacement sims to identity fraudsters who then have complete control of 'your' phone number and all your emails.

All of which *should* be impossible if the telco follows it's own security guidelines.

The problems is when they don't and your account gets hoovered out, you can bet they'll fight any liability.

There are still physical branches for the older-established banks, but I would have to walk/drive/cycle/giddy_up 5 miles to get to one of mine.

No they don't; I don't have my email on my iPhone.

Quite. Perhaps most never do any work round the house, so having an expensive phone in a pocket likely to get damaged doesn't matter?

I've got one in the bathroom too. ;-)

Funnily enough I've paid for something via Paypal and got the text to my phone ...

Well to be fair s/he does not need your actual phone, just to convince you mobile operator's call centre to transfer your number to their SIM.

Most of them have many layers of detection built in to try and pick out the dodgy login attempts. I would expect them to profile the type of device, IP address, typical geographic locations, time of day etc. Not to mention all the tracking data the leave littered on computers and devices.

Neither of your articles explains how the scroats get "all your emails" when I don't have email on my smartphone.

I activate my mobile briefly, every few weeks. Ring my landline number and pick up, momentarily. Been doing it for about 20 years.

Of course I venture outside, but I have no need to take my phone, any more than I did before I owned it.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required