Horizon - How to beat the hackers

UKworkshop.co.uk

Help Support UKworkshop.co.uk:

This site may earn a commission from merchant affiliate links, including eBay, Amazon, and others.

RogerS

Established Member
Joined
20 Feb 2004
Messages
17,921
Reaction score
276
Location
In the eternally wet North
Did anyone catch this? Not watched all of it but the opening ten minutes displayed a brilliant piece of social engineering carried out by teenagers that effectively wiped out the entire digital life of one guy. It worked like this.....

1 - hackers rang Amazon to ask for a new credit card to be added to his (the victim's) account ....
2 - next day they then rang amazon back again saying they had forgotten their password. Amazon asked for the number of a credit card associated with the account.
3 - Hacker gave the credit card number that they gave in (1). Amazon gave the password out for the victim's account
4 - Hacker logs in to the Amazon account. What they are after are the last four digits of the victim's real credit card...and which is available on screen when you log in
5 - Armed with these four digits, hacker then rings Apple support to say they have lost their Apple ID/password. As part of the security check carried out by Apple support they ask for, guess what....the last four digits of the credit card.
6 - Et voila. Hacker now has the victim's Apple login details. Bingo.

Masterful. Scary. But masterful.
 
Roger,

That's not social engineering - its good old fashioned fraud. Probably fraud by misrepresentation.

Brian
 
finneyb":988azuav said:
Roger,

That's not social engineering - its good old fashioned fraud. Probably fraud by misrepresentation.

Brian

Brian, within the orbit of IT security it is referred to as 'social engineering' which is to differentiate it from direct hacking attempts etc.
 
RogerS":j4nooywl said:
Brian, within the orbit of IT security it is referred to as 'social engineering' which is to differentiate it from direct hacking attempts etc.

Roger, I don't care what they call it, it's fraud and subsequently no doubt theft, if only our courts dealt with these people the way they should be dealt with we wouldn't have this problem. I've made a concious effort to reduce my 'on line' dealings and feel a lot better for doing so.
 
Back
Top