It's always infuriating getting email from Amazon or my bank "here's signs of potential phishing emails/texts" that doesn't include an exhaustive list of every email address and phone number that that organization will try to contact me from. That should be table stakes when it comes to phishing avoidance, and it's something that can only be done by the business, not the customer.
Yes, like you say, there's always the chance that someone hijacked an official domain - that's where other things like a formal communication protocol ("we will never ask for your password", "never share 2FA codes", "2FA codes are separate from challenge-response codes used for tech support") and rules of thumb like "don't click on shortened links" come in. Defense in depth is a must, but the list of official addresses should be the starting point and it isn't.
I've had (presumably the fraud department of) AmEx ring me and ask for personal verification details over the phone before they'll even speak to me about ANY details (even just if this is ringing about fraud etc, or how urgent the phone call is), on more than one occasion.
Even though I was pretty confident it was a legitimate call (typically an email notification arrives from them about some odd activity at the same time, or it's whilst I'm making a payment), I decline because surely this is exactly the same as what scammers would do?
Mine has a few times, without the "call us back". So far it's been the fraud department when I made an unusual payment, and have also occasionally gotten "how are we doing?" courtesy calls.
I have confirmed the fraud department one was legitimate, but haven't bothered with the others.
My bank doesn't tell me that. It's this kind of incompetence and lack of responsibility on their part that's leading to scams and phishing being so unnecessarily successful.
I have a HELOC and every time I move, their fraud dept calls me. And to call them back is not on their main bank number. It was super sketchy but legit.
Comments
It's always infuriating getting email from Amazon or my bank "here's signs of potential phishing emails/texts" that doesn't include an exhaustive list of every email address and phone number that that organization will try to contact me from. That should be table stakes when it comes to phishing avoidance, and it's something that can only be done by the business, not the customer.
Yes, like you say, there's always the chance that someone hijacked an official domain - that's where other things like a formal communication protocol ("we will never ask for your password", "never share 2FA codes", "2FA codes are separate from challenge-response codes used for tech support") and rules of thumb like "don't click on shortened links" come in. Defense in depth is a must, but the list of official addresses should be the starting point and it isn't.
Al legit bank will NEVER legitimately call you, except to say "call us back at the number on your card" . Caller ID is not secure.
I've had (presumably the fraud department of) AmEx ring me and ask for personal verification details over the phone before they'll even speak to me about ANY details (even just if this is ringing about fraud etc, or how urgent the phone call is), on more than one occasion. Even though I was pretty confident it was a legitimate call (typically an email notification arrives from them about some odd activity at the same time, or it's whilst I'm making a payment), I decline because surely this is exactly the same as what scammers would do?
Mine has a few times, without the "call us back". So far it's been the fraud department when I made an unusual payment, and have also occasionally gotten "how are we doing?" courtesy calls.
I have confirmed the fraud department one was legitimate, but haven't bothered with the others.
Thanks for the correction!
My bank doesn't tell me that. It's this kind of incompetence and lack of responsibility on their part that's leading to scams and phishing being so unnecessarily successful.
I have a HELOC and every time I move, their fraud dept calls me. And to call them back is not on their main bank number. It was super sketchy but legit.