Today i just had a call from someone claiming to be from credit card service center. She introduce herself, confirm my name and ask some background check of my credit card usage. Sounds warm and friendly like most call center.
The next thing she says i am selected from hundreds to received a complimentary Discount Card that will enable me to get discount on stuff bought with my credit cards. And ...there is no additional membership fees i have to pay. Sounds too good to be true. She then confirmed the mailing address to send the discount card and wants to confirm the card number and expiry date.
Caller : Sir, we need to confirm your card credentials, you are using mastercard correct?
Me : Yes
Caller : Your card number starts with 5134 or 5200?
Me : It starts with 5134..
Caller : Do you mind telling me the whole number?
Me : Its 5134 XXX....
Caller : And this card expires on 2014 correct? What month is it?
Me : its November.
Caller : Oh, So you only had this card last year. Can you give your bank membership number for the card?
Me : I am sorry, Bank Membership number?
Caller : Yes, Can you remember it?
Me : I don't think so.
Caller : Its ok sir, the membership number is at the back of the card right after the space where you sign. There should be some numbers there.
Me : Hmm.. I cannot give that number. You will be able to use this card for online transaction.
Caller : (Silent for 2 seconds) But sir, we wont be able to confirm your card and will not be able to send you the discount card.
Me : Nah, Its ok, i don't need it. nice try though. (hang up).
So folks, this is one example where social engineering can be used to get information from you. Always remember that your credit card security number is not to be shared with anyone else since most online transaction only requires your card number, full name on card, expiry month/year and the security number. All those information they can easily get except for the security number. Some other banks like maybank uses TMOS password to verify the card on top of the security number. But TMOS is also limited to some merchants.
But my question is, how did they get my number and also most of the card information? They have my phone number, home address, full name on card... I think i should give my bank card center a call..
Showing posts with label IT. Show all posts
Showing posts with label IT. Show all posts
Friday, January 27, 2012
Thursday, March 18, 2010
FBian

An email virus, designed to steal passwords of Facebook users, is making its rounds. — Reuters pic
FB USERS.. PLS BE ALERT!
New password-stealing virus targets Facebook
BOSTON, March 18 — Hackers have flooded the Internet with virus-tainted spam that targets Facebook’s estimated 400 million users in an effort to steal banking passwords and gather other sensitive information.
The emails tell recipients that the passwords on their Facebook accounts have been reset, urging them to click on an attachment to obtain new login credentials, according to anti-virus software maker McAfee Inc.
If the attachment is opened, it downloads several types of malicious software, including a program that steals passwords, McAfee said yesterday.
Hackers have long targeted Facebook users, sending them tainted messages via the social networking company’s own internal email system. With this new attack, they are using regular Internet email to spread their malicious software.
A Facebook spokesman said the company could not comment on the specific case, but pointed to a status update the company posted on its web site earlier yesterday warning users about the spoofed email and advising users to delete the email and to warn their friends.
McAfee estimates that hackers sent out tens of millions of spam across Europe, the United States and Asia since the campaign began on Tuesday.
Dave Marcus, McAfee’s director of malware research and communications, said that he expects the hackers will succeed in infecting millions of computers.
“With Facebook as your lure, you potentially have 400 million people that can click on the attachment. If you get 10 per cent success, that’s 40 million,” he said.
The email’s subject line says “Facebook password reset confirmation customer support,” according to Marcus. — Reuters
kata aku: ini nama dia PHISHING ya.....
Tuesday, March 16, 2010
dah sedia?
Anda dah sedia ke utk yg lebih mudah.. 1 lebih mudah? Cuba dgn betul.. insyaAllah.. yg MUDAH... MESTI MARIIII... hehehehe....
kata aku: Mmg mudah! betulllllll.....
kata aku: Mmg mudah! betulllllll.....
Thursday, February 11, 2010
Thursday, February 4, 2010
Project1: IDM
What is IDM?
Ini Degil Mangkuk? Kena tau tu dulu baru bole cerita pasal Pa$sp#raS3 ya...
kata aku: mari mula mengenal huruf
Ini Degil Mangkuk? Kena tau tu dulu baru bole cerita pasal Pa$sp#raS3 ya...
kata aku: mari mula mengenal huruf
Wednesday, February 3, 2010
Project1#1: Pa$sp#raS3
kata aku: passphrase is not a password.. it's passphrase ;)
Subscribe to:
Posts (Atom)