FA-4.1 - Scam Psychology, Phishing & wrong Support

shedontluv-U

shedontluv-U

Busy rn , off my notifications for 1-2 hours
Joined
Feb 21, 2026
Posts
10,991
Reputation
28,948

FINANCIALLY AESTHETIC · GUIDE 19/37
SCAM PSYCHOLOGY, PHISHING & FAKE SUPPORT

FA-4.1 · Scamproof & Financial Security
━━━━━━━━━━━━━━━━━━━━





Phishing: A Threat Based on Deception

A phishing attack is a deceptive tactic used by threat actors that aims to send emails that appear legitimate to users. It represents the most common threat to email security. While relatively easy to detect in the past, phishing attacks have become more sophisticated over time. With the advent of artificial intelligence (AI), phishing emails contain fewer and fewer spelling errors, clichés, or typical red flags. They are now well-written and their content appears legitimate, making them even harder to detect.

Phishing attacks can be generic or targeted. In the case of targeted attacks - also known as spear phishing - threat actors conduct in-depth research on specific individuals or groups who have privileged access to valuable information, and then craft relevant emails that will not arouse suspicion.

Whaling is a specific form of spear phishing in which threat actors target high-ranking individuals within an organization and impersonate trusted authorities. The primary objective, however, remains the same: to manipulate users into revealing sensitive information, such as usernames, passwords, and banking details. Threat actors may also trick users into clicking on malicious links, opening dangerous attachments, or making unauthorized changes to a system they have access to. It is therefore essential to remain vigilant and understand the evolving nature of phishing attacks in order to protect your organization from these threats.

Phishing is a form of social engineering and fraud in which threat actors attempt to trick you into opening a malicious email containing attachments or links that download malware onto your device. Phishing attempts can result in the compromise of your organization and its sensitive information. Stay vigilant and review your emails before opening them.

Phishing is a fraudulent technique designed to trick internet users into disclosing personal information (login credentials, passwords, etc.) and/or banking information by impersonating a trusted third party. This may take the form of a fake message, text message, or phone call purporting to be from a bank, social network, telecommunications provider, energy supplier, e-commerce site, government agency, etc. The goal is to steal personal or professional information (accounts, passwords, banking information, etc.) for fraudulent purposes.


Identity Theft and Email Spoofing

Email impersonation is a deceptive tactic in which threat actors manipulate the sender’s details in an email’s header to make it appear as though the email comes from a trusted source. This practice is primarily intended to deceive recipients into believing the email is legitimate, thereby encouraging them to open it and interact with its content.

The inherent danger of email impersonation is that these deceptive messages typically contain malware, viruses, or malicious links that redirect users to fake websites or services. Simply opening the email can expose the recipient’s device to threats and make it vulnerable to further exploitation. Email impersonation is commonly used in phishing attacks and fake wire transfer scams. The ramifications of these attacks extend far beyond the immediate damage. The disclosure of sensitive information resulting from a spoofed email can lead to identity theft.

Threat actors use identity theft to exploit trust, make a profit, or gain access to sensitive information via electronic mail. For example, in wire transfer fraud schemes, threat actors impersonate trusted individuals, such as employees, to steal money from companies or their customers and partners. An attack involving identity theft is another example. In this context, the attacker pretends to be a legal representative and often targets staff members who lack the knowledge or authority to verify the legitimacy of the request. Similarly, threat actors sometimes impersonate authoritative entities, such as regulatory agencies, government departments, and law enforcement agencies.

Brand impersonation is another tactic used by threat actors. They falsely associate themselves with a well-known brand to deceive the recipient into disclosing confidential information. There are many identity theft techniques, such as posing as internal staff to commit financial fraud or exploiting the credibility of reputable brands for illicit purposes. It is therefore very important to adopt security practices focused on vigilance when handling electronic mail.


Social Engineering: Exploiting Urgency and Authority

Fake bank transfer scams are a growing concern for organizations of all sizes and across all industries. This sophisticated attack model often targets companies that offer bank transfer services. Threat actors attempt to defraud organizations by impersonating senior executives or business partners in order to deceive staff members, with the ultimate goal of having their targets transfer funds to fraudulent accounts.

These targeted and carefully planned attacks involve large sums of money and thus represent one of the most financially damaging threats to electronic mail security. Although perpetrators of fake transfer scams may exploit and steal data, their primary goal is to enrich themselves; to do so, they attempt to deceive organizational staff by employing social engineering tactics, such as identity theft.


The Fake Tech Support Scam: The Precise Mechanics of the Manipulation

The fake tech support scam (or computer repair fraud) involves frightening the victim with an alarming warning message that appears to lock up their computer, informing them of a serious technical problem and the risk of data loss or being unable to use their device, in order to pressure them into contacting a purported official tech support service (Microsoft, Apple, etc.).

The alert message typically appears after the victim clicks a link in a phishing email or a malicious ad, or while browsing fraudulent websites. This message is by no means an alert from the victim’s operating system or antivirus software; it is an aggressive, fraudulent web page. In some cases, victims are even contacted directly by phone by fake technicians.

Once contact is established with the victim, the fake tech support representative will then convince them to grant remote access to their computer and to pay for a bogus IT repair service and/or to purchase unnecessary - or even harmful - software, backed by invoices and contracts that appear official.

If the victim refuses to pay, the criminals may threaten to destroy their files, render their computer unusable, or disclose their personal information - which they will have stolen during their “intervention.”

In an increasing number of reported cases, the fake technicians manage to convince the victim to allow them access to their supposedly hacked bank accounts and, under the pretext of securing them, steal the funds.

The reported financial losses for victims of this type of scam can range from a few hundred euros to tens of thousands of euros.

The goal is to extort money from the victim by persuading them to let the scammer take control of their computer to pretend to fix it, install software, and/or sign them up for subscriptions for which they will be billed.

A Victim’s Account

“I was online when suddenly a siren started blaring and a window popped up on my screen telling me I had a virus and that I had to call a number to remove it or risk losing all my files. My computer was completely frozen, and it was very distressing. So I called the number, and a technician asked for remote access to my computer to fix it. He then asked me to pay €350 for the repair and a one-year support contract. He seemed confident and professional, and since I don’t know much about these things, I trusted him. He “logged into my computer remotely,” as he put it. When I told my son this story, he told me I’d been scammed. I called my bank to cancel my card and filed a police report, but I don’t think I’ll ever see my money again.”

This account illustrates the entire manipulation process: the sudden and intense fear, the urgency of the threat of data loss, the trust placed in someone posing as a professional, and the lack of independent verification before taking action.

Protecting Yourself from Fake Tech Support Scams

No official technical support team will ever contact you or ask you to contact them to resolve an issue following an alleged security alert.

To protect yourself against this scam, you should:

  • regularly and systematically install system security updates and updates for the software installed on your computer, especially your web browsers;
  • use antivirus software and keep it up to date;
  • avoid unsafe or illegal websites, such as those hosting pirated content (music, movies, software, etc.) or certain pornographic sites that may infect your computer or host questionable ad networks;
  • Do not install any “pirated” applications or programs, or those of dubious origin or reputation;
  • Do not open any attachments or click on any links in unexpected or suspicious messages;
  • Be cautious when clicking on advertising links (ads on websites and social networks, sponsored articles with “clickbait” headlines, advertising links that appear at the top of search engine results, etc.);
  • Back up your data and system regularly so you can restore it to its original state if there is a need to do so.

What to Do If You’re a Victim?

If you encounter this type of scam, regardless of its source, do not respond to any requests and do not call the number provided. If you’re at work, immediately alert your IT department or service provider - if you have one - so they can intervene and take the necessary steps if needed. Keep all evidence for reporting the incident or filing a complaint with the authorities; take a screenshot of your screen if necessary.

Close the fake alert window. If necessary, press the Esc or F11 key on your keyboard to exit full-screen mode. If that doesn’t work, restart your computer to regain control. Once you’ve regained control of your browser, clear the cache, delete cookies, reset to default settings, and, if that’s not enough, delete and recreate your profile.

Do not grant remote access to your computer in response to a request you did not initiate yourself, and without having definitively verified the legitimacy of the operator requesting access. If a fake technician has taken control of your computer, uninstall the remote access software (AnyDesk, TeamViewer, ConnectWise, etc.) and change all your passwords. Run a thorough scan of your device with your antivirus software.

If you provided your credit card numbers, immediately report them as lost or stolen to your bank. If a payment has been charged to your account, request a refund from your bank and explain your situation. If you paid the fake support provider via transfer, ask your bank to cancel the transaction.


SMS Phishing or “Smishing”

You receive a text message that appears to come from a government agency, your bank, a delivery service, or any other organization or company. This message, which is often alarming, urges you to take immediate action - such as logging in, confirming something, updating your information, or making a payment - under threat of service restrictions or fees to your account. Be careful - you may be facing an SMS phishing attempt, also known as “smishing”!

SMS phishing is also known as “smishing,” a portmanteau of “SMS” and “phishing.” It is a method used by cybercriminals to deceive their victims by impersonating a well-known third party (government agencies, banks, delivery services, online services, etc.) via text message.

Under this false identity and using a false pretext, SMS phishing involves sending a short message that generally prompts victims to disclose personal information and/or bank card details, or even login credentials (passwords). Cybercriminals may also use this type of cyberattack to infect the victim’s mobile phone (smartphone) with a malicious app (virus) designed to steal personal and banking data or to take control of the device. Another type of smishing involves tricking the victim into calling back a number provided in the message in order to defraud them. The goal of cybercriminals is to fraudulently use the stolen information and gain access to compromised accounts or phones.

Why Smishing Works So Well

Cybercriminals have a particular interest in smishing because it is harder to identify fraudulent text messages than phishing emails. In fact, text messages allow cybercriminals to communicate concisely, using language that is less “formal” and more terse - a style often characteristic of this type of message - while minimizing the risk of spelling or grammatical errors that might raise suspicion. Also, the sender can only be identified by a standard phone number (from France or abroad), a short code, or a brief description - none of which make it easy to determine the authenticity of the message sender. Also, people are generally less suspicious because smishing is a relatively new phenomenon compared to traditional email phishing. Similarly, victims may mistakenly believe that a received text message is inherently legitimate because they assume their phone number can only be used by known third parties.

The brevity of text messages, their credible nature, the difficulty in easily identifying their sender, and the relatively recent phenomenon of smishing tend to pique curiosity rather than arouse suspicion.

Also, it is more difficult to identify a malicious website on a cell phone after clicking on a link received via text message. Indeed, due to the small screen size and depending on the web browser used, the information on the website you’re visiting is not immediately and fully visible, and the website address is usually truncated.

Finally, smishing exploits our habit of receiving all kinds of notifications on our cell phones - validation messages, confirmation messages, or other alerts - and, generally, of reacting to them instantly.

How the fraudulent message works

The message consistently prompts the victim to take action under various pretexts. These may include resolving an issue such as a blocked online or bank account, a payment incident, regulatory compliance, canceling an order the victim did not place, obtaining a refund from a government agency, finalizing the delivery of a package, updating or confirming personal information, and so on.

The message is generally alarming, even anxiety-inducing or cryptic. It often states that action must be taken immediately, or else the account will be suspended, a penalty will be imposed, or an unauthorized payment will be charged, etc. The brevity of the message - and thus the limited information it contains - also adds to its alarming nature, prompting the victim to act on it without delay.

Smishing messages can serve various purposes: stealing personal information, bank card details, and/or login credentials; infecting the device with a virus; or prompting the victim to call back a phone number. In the latter case, the text message does not contain a link but urges the victim to call a specific phone number under various pretexts, such as to block a fraudulent bank transaction or online purchase. The victim, convinced that they are calling an official organization, will be all the more susceptible to falling for scams such as “fake adviser fraud.” In some cases, the number provided may be a premium-rate number that generates income for the scammers with every call made and is billed to the victim.

How to Respond to a Suspicious Text Message

Never disclose sensitive information in response to a text message, as no legitimate government agency or company will contact you via text to ask for your personal information, banking details, or passwords.

If you have even the slightest doubt, verify the information in the message yourself by contacting the organization directly or by logging into your personal account on its official website or mobile application.

Before clicking on a suspicious link, check its authenticity. If you have any doubts or just to be safe, go directly to the organization’s website using your usual methods - for example, via a bookmark you’ve created yourself or through its mobile application.

Never download an app from anywhere other than official websites or app stores. If, after clicking on a link in a text message, an alert appears prompting you to download or update an app, do not proceed and close the page.

Report the fraudulent message on the 33700 platform or forward it via text message to 33700 (free service). This service will block the sender of the message.


Verification practices common to both traditional phishing and smishing

Never share sensitive information via email or phone: no legitimate government agency or business will ask for your banking information or passwords via email or phone.

Before clicking on a suspicious link, hover your mouse cursor over it (without clicking) - this will display the actual URL it points to, allowing you to verify its authenticity - or go directly to the organization’s website using a bookmark you’ve created yourself.

Check the website address displayed in your browser. If it does not exactly match the organization’s official site, it is most likely a fraudulent site. Sometimes, just a single character in the website address may be altered to deceive you. If you have even the slightest doubt, do not provide any information and close the page immediately.

If in doubt, contact the organization directly, if possible, to confirm the message or call you received.

To mitigate the risks associated with email impersonation, make it a habit to always hover your mouse over links in an email before clicking on them. This will allow you to verify the actual URL and ensure that it matches the expected domain and is legitimate. Avoid clicking on links that seem suspicious or unfamiliar. Always consult your organization’s IT security team if you have any doubts. You should also scrutinize any email containing unusual requests, such as an urgent financial transaction or a request for sensitive information. It’s prudent to verify these requests using other communication channels, such as calling the sender or manually visiting the website in question in your browser to confirm the claims made in the email.

Another important point to consider involves homograph attacks, where threat actors use characters from other alphabets - such as Cyrillic or Greek - that resemble Roman characters to create deceptive email addresses or URLs. Pay close attention to subtle differences in characters that may indicate an attempt at impersonation of an email address.


If You Are a Victim of Classic Phishing

If you have even the slightest doubt, contact the relevant organization to verify the message or call you received. Immediately report the incident to your bank or financial institution if you have inadvertently disclosed information about your payment methods or if you have noticed fraudulent charges on your account. Keep all evidence, especially the phishing message you received.

Change your passwords immediately if you have inadvertently disclosed a password on the affected website or service, as well as on all other websites or services where you used that compromised password.

If you’ve received a suspicious message, do not click on any attachments or suspicious links. Report these suspicious messages to Signal Spam, which works with the CNIL to identify the main sources of spam and take the necessary action to combat it. If you have received a suspicious message via SMS or MMS, report it on the 33 700 platform or by sending an SMS to 33700 (free service).


Awareness and Verification: The First Line of Defense

Employees are the first line of defense within an organization. It is therefore important to provide them with regular, thorough security training to mitigate the risks associated with human error. The more aware staff members are of the security risks associated with emails, the less likely they are to be fooled by the tactics and attacks of threat actors.

Here are some key topics to include in training on this subject:

  • techniques for identifying and avoiding phishing, ransomware, and wire transfer scams;
  • strategies for avoiding security threats, such as malware, malicious links, and malicious attachments;
  • tips for protecting passwords;
  • guidelines on how to respond to an electronic mail account compromise and promptly report suspicious emails and security incidents;
  • risks associated with the compromise of a phone number (subscriber identification module or SIM card swapping);
  • techniques for detecting social engineering attempts and knowing what not to share via email or other communication channels.

You should exercise caution before clicking on a hyperlink in an email or downloading an attachment, especially when the email comes from an unknown or suspicious source. Take the time to verify the legitimacy of the links and assess the sender’s credibility by ensuring the domain name is correct or by hovering your mouse over the link to view the actual address. This simple but essential step can help you avoid falling victim to phishing attacks or malware and protect your personal information and your organization’s data from related security risks.




RESPONSE RULE

Break the pressure loop: stop, verify through an independent channel and never use the contact route in the message.


 
  • +1
  • Ugh..
Reactions: ZygoRR, Tesarossa and Aezac

FINANCIALLY AESTHETIC · GUIDE 19/37
SCAM PSYCHOLOGY, PHISHING & FAKE SUPPORT

FA-4.1 · Scamproof & Financial Security
━━━━━━━━━━━━━━━━━━━━





Phishing: A Threat Based on Deception

A phishing attack is a deceptive tactic used by threat actors that aims to send emails that appear legitimate to users. It represents the most common threat to email security. While relatively easy to detect in the past, phishing attacks have become more sophisticated over time. With the advent of artificial intelligence (AI), phishing emails contain fewer and fewer spelling errors, clichés, or typical red flags. They are now well-written and their content appears legitimate, making them even harder to detect.

Phishing attacks can be generic or targeted. In the case of targeted attacks - also known as spear phishing - threat actors conduct in-depth research on specific individuals or groups who have privileged access to valuable information, and then craft relevant emails that will not arouse suspicion.

Whaling is a specific form of spear phishing in which threat actors target high-ranking individuals within an organization and impersonate trusted authorities. The primary objective, however, remains the same: to manipulate users into revealing sensitive information, such as usernames, passwords, and banking details. Threat actors may also trick users into clicking on malicious links, opening dangerous attachments, or making unauthorized changes to a system they have access to. It is therefore essential to remain vigilant and understand the evolving nature of phishing attacks in order to protect your organization from these threats.

Phishing is a form of social engineering and fraud in which threat actors attempt to trick you into opening a malicious email containing attachments or links that download malware onto your device. Phishing attempts can result in the compromise of your organization and its sensitive information. Stay vigilant and review your emails before opening them.

Phishing is a fraudulent technique designed to trick internet users into disclosing personal information (login credentials, passwords, etc.) and/or banking information by impersonating a trusted third party. This may take the form of a fake message, text message, or phone call purporting to be from a bank, social network, telecommunications provider, energy supplier, e-commerce site, government agency, etc. The goal is to steal personal or professional information (accounts, passwords, banking information, etc.) for fraudulent purposes.


Identity Theft and Email Spoofing

Email impersonation is a deceptive tactic in which threat actors manipulate the sender’s details in an email’s header to make it appear as though the email comes from a trusted source. This practice is primarily intended to deceive recipients into believing the email is legitimate, thereby encouraging them to open it and interact with its content.

The inherent danger of email impersonation is that these deceptive messages typically contain malware, viruses, or malicious links that redirect users to fake websites or services. Simply opening the email can expose the recipient’s device to threats and make it vulnerable to further exploitation. Email impersonation is commonly used in phishing attacks and fake wire transfer scams. The ramifications of these attacks extend far beyond the immediate damage. The disclosure of sensitive information resulting from a spoofed email can lead to identity theft.

Threat actors use identity theft to exploit trust, make a profit, or gain access to sensitive information via electronic mail. For example, in wire transfer fraud schemes, threat actors impersonate trusted individuals, such as employees, to steal money from companies or their customers and partners. An attack involving identity theft is another example. In this context, the attacker pretends to be a legal representative and often targets staff members who lack the knowledge or authority to verify the legitimacy of the request. Similarly, threat actors sometimes impersonate authoritative entities, such as regulatory agencies, government departments, and law enforcement agencies.

Brand impersonation is another tactic used by threat actors. They falsely associate themselves with a well-known brand to deceive the recipient into disclosing confidential information. There are many identity theft techniques, such as posing as internal staff to commit financial fraud or exploiting the credibility of reputable brands for illicit purposes. It is therefore very important to adopt security practices focused on vigilance when handling electronic mail.


Social Engineering: Exploiting Urgency and Authority

Fake bank transfer scams are a growing concern for organizations of all sizes and across all industries. This sophisticated attack model often targets companies that offer bank transfer services. Threat actors attempt to defraud organizations by impersonating senior executives or business partners in order to deceive staff members, with the ultimate goal of having their targets transfer funds to fraudulent accounts.

These targeted and carefully planned attacks involve large sums of money and thus represent one of the most financially damaging threats to electronic mail security. Although perpetrators of fake transfer scams may exploit and steal data, their primary goal is to enrich themselves; to do so, they attempt to deceive organizational staff by employing social engineering tactics, such as identity theft.


The Fake Tech Support Scam: The Precise Mechanics of the Manipulation

The fake tech support scam (or computer repair fraud) involves frightening the victim with an alarming warning message that appears to lock up their computer, informing them of a serious technical problem and the risk of data loss or being unable to use their device, in order to pressure them into contacting a purported official tech support service (Microsoft, Apple, etc.).

The alert message typically appears after the victim clicks a link in a phishing email or a malicious ad, or while browsing fraudulent websites. This message is by no means an alert from the victim’s operating system or antivirus software; it is an aggressive, fraudulent web page. In some cases, victims are even contacted directly by phone by fake technicians.

Once contact is established with the victim, the fake tech support representative will then convince them to grant remote access to their computer and to pay for a bogus IT repair service and/or to purchase unnecessary - or even harmful - software, backed by invoices and contracts that appear official.

If the victim refuses to pay, the criminals may threaten to destroy their files, render their computer unusable, or disclose their personal information - which they will have stolen during their “intervention.”

In an increasing number of reported cases, the fake technicians manage to convince the victim to allow them access to their supposedly hacked bank accounts and, under the pretext of securing them, steal the funds.

The reported financial losses for victims of this type of scam can range from a few hundred euros to tens of thousands of euros.

The goal is to extort money from the victim by persuading them to let the scammer take control of their computer to pretend to fix it, install software, and/or sign them up for subscriptions for which they will be billed.

A Victim’s Account

“I was online when suddenly a siren started blaring and a window popped up on my screen telling me I had a virus and that I had to call a number to remove it or risk losing all my files. My computer was completely frozen, and it was very distressing. So I called the number, and a technician asked for remote access to my computer to fix it. He then asked me to pay €350 for the repair and a one-year support contract. He seemed confident and professional, and since I don’t know much about these things, I trusted him. He “logged into my computer remotely,” as he put it. When I told my son this story, he told me I’d been scammed. I called my bank to cancel my card and filed a police report, but I don’t think I’ll ever see my money again.”

This account illustrates the entire manipulation process: the sudden and intense fear, the urgency of the threat of data loss, the trust placed in someone posing as a professional, and the lack of independent verification before taking action.

Protecting Yourself from Fake Tech Support Scams

No official technical support team will ever contact you or ask you to contact them to resolve an issue following an alleged security alert.

To protect yourself against this scam, you should:

  • regularly and systematically install system security updates and updates for the software installed on your computer, especially your web browsers;
  • use antivirus software and keep it up to date;
  • avoid unsafe or illegal websites, such as those hosting pirated content (music, movies, software, etc.) or certain pornographic sites that may infect your computer or host questionable ad networks;
  • Do not install any “pirated” applications or programs, or those of dubious origin or reputation;
  • Do not open any attachments or click on any links in unexpected or suspicious messages;
  • Be cautious when clicking on advertising links (ads on websites and social networks, sponsored articles with “clickbait” headlines, advertising links that appear at the top of search engine results, etc.);
  • Back up your data and system regularly so you can restore it to its original state if there is a need to do so.

What to Do If You’re a Victim?

If you encounter this type of scam, regardless of its source, do not respond to any requests and do not call the number provided. If you’re at work, immediately alert your IT department or service provider - if you have one - so they can intervene and take the necessary steps if needed. Keep all evidence for reporting the incident or filing a complaint with the authorities; take a screenshot of your screen if necessary.

Close the fake alert window. If necessary, press the Esc or F11 key on your keyboard to exit full-screen mode. If that doesn’t work, restart your computer to regain control. Once you’ve regained control of your browser, clear the cache, delete cookies, reset to default settings, and, if that’s not enough, delete and recreate your profile.

Do not grant remote access to your computer in response to a request you did not initiate yourself, and without having definitively verified the legitimacy of the operator requesting access. If a fake technician has taken control of your computer, uninstall the remote access software (AnyDesk, TeamViewer, ConnectWise, etc.) and change all your passwords. Run a thorough scan of your device with your antivirus software.

If you provided your credit card numbers, immediately report them as lost or stolen to your bank. If a payment has been charged to your account, request a refund from your bank and explain your situation. If you paid the fake support provider via transfer, ask your bank to cancel the transaction.


SMS Phishing or “Smishing”

You receive a text message that appears to come from a government agency, your bank, a delivery service, or any other organization or company. This message, which is often alarming, urges you to take immediate action - such as logging in, confirming something, updating your information, or making a payment - under threat of service restrictions or fees to your account. Be careful - you may be facing an SMS phishing attempt, also known as “smishing”!

SMS phishing is also known as “smishing,” a portmanteau of “SMS” and “phishing.” It is a method used by cybercriminals to deceive their victims by impersonating a well-known third party (government agencies, banks, delivery services, online services, etc.) via text message.

Under this false identity and using a false pretext, SMS phishing involves sending a short message that generally prompts victims to disclose personal information and/or bank card details, or even login credentials (passwords). Cybercriminals may also use this type of cyberattack to infect the victim’s mobile phone (smartphone) with a malicious app (virus) designed to steal personal and banking data or to take control of the device. Another type of smishing involves tricking the victim into calling back a number provided in the message in order to defraud them. The goal of cybercriminals is to fraudulently use the stolen information and gain access to compromised accounts or phones.

Why Smishing Works So Well

Cybercriminals have a particular interest in smishing because it is harder to identify fraudulent text messages than phishing emails. In fact, text messages allow cybercriminals to communicate concisely, using language that is less “formal” and more terse - a style often characteristic of this type of message - while minimizing the risk of spelling or grammatical errors that might raise suspicion. Also, the sender can only be identified by a standard phone number (from France or abroad), a short code, or a brief description - none of which make it easy to determine the authenticity of the message sender. Also, people are generally less suspicious because smishing is a relatively new phenomenon compared to traditional email phishing. Similarly, victims may mistakenly believe that a received text message is inherently legitimate because they assume their phone number can only be used by known third parties.

The brevity of text messages, their credible nature, the difficulty in easily identifying their sender, and the relatively recent phenomenon of smishing tend to pique curiosity rather than arouse suspicion.

Also, it is more difficult to identify a malicious website on a cell phone after clicking on a link received via text message. Indeed, due to the small screen size and depending on the web browser used, the information on the website you’re visiting is not immediately and fully visible, and the website address is usually truncated.

Finally, smishing exploits our habit of receiving all kinds of notifications on our cell phones - validation messages, confirmation messages, or other alerts - and, generally, of reacting to them instantly.

How the fraudulent message works

The message consistently prompts the victim to take action under various pretexts. These may include resolving an issue such as a blocked online or bank account, a payment incident, regulatory compliance, canceling an order the victim did not place, obtaining a refund from a government agency, finalizing the delivery of a package, updating or confirming personal information, and so on.

The message is generally alarming, even anxiety-inducing or cryptic. It often states that action must be taken immediately, or else the account will be suspended, a penalty will be imposed, or an unauthorized payment will be charged, etc. The brevity of the message - and thus the limited information it contains - also adds to its alarming nature, prompting the victim to act on it without delay.

Smishing messages can serve various purposes: stealing personal information, bank card details, and/or login credentials; infecting the device with a virus; or prompting the victim to call back a phone number. In the latter case, the text message does not contain a link but urges the victim to call a specific phone number under various pretexts, such as to block a fraudulent bank transaction or online purchase. The victim, convinced that they are calling an official organization, will be all the more susceptible to falling for scams such as “fake adviser fraud.” In some cases, the number provided may be a premium-rate number that generates income for the scammers with every call made and is billed to the victim.

How to Respond to a Suspicious Text Message

Never disclose sensitive information in response to a text message, as no legitimate government agency or company will contact you via text to ask for your personal information, banking details, or passwords.

If you have even the slightest doubt, verify the information in the message yourself by contacting the organization directly or by logging into your personal account on its official website or mobile application.

Before clicking on a suspicious link, check its authenticity. If you have any doubts or just to be safe, go directly to the organization’s website using your usual methods - for example, via a bookmark you’ve created yourself or through its mobile application.

Never download an app from anywhere other than official websites or app stores. If, after clicking on a link in a text message, an alert appears prompting you to download or update an app, do not proceed and close the page.

Report the fraudulent message on the 33700 platform or forward it via text message to 33700 (free service). This service will block the sender of the message.


Verification practices common to both traditional phishing and smishing

Never share sensitive information via email or phone: no legitimate government agency or business will ask for your banking information or passwords via email or phone.

Before clicking on a suspicious link, hover your mouse cursor over it (without clicking) - this will display the actual URL it points to, allowing you to verify its authenticity - or go directly to the organization’s website using a bookmark you’ve created yourself.

Check the website address displayed in your browser. If it does not exactly match the organization’s official site, it is most likely a fraudulent site. Sometimes, just a single character in the website address may be altered to deceive you. If you have even the slightest doubt, do not provide any information and close the page immediately.

If in doubt, contact the organization directly, if possible, to confirm the message or call you received.

To mitigate the risks associated with email impersonation, make it a habit to always hover your mouse over links in an email before clicking on them. This will allow you to verify the actual URL and ensure that it matches the expected domain and is legitimate. Avoid clicking on links that seem suspicious or unfamiliar. Always consult your organization’s IT security team if you have any doubts. You should also scrutinize any email containing unusual requests, such as an urgent financial transaction or a request for sensitive information. It’s prudent to verify these requests using other communication channels, such as calling the sender or manually visiting the website in question in your browser to confirm the claims made in the email.

Another important point to consider involves homograph attacks, where threat actors use characters from other alphabets - such as Cyrillic or Greek - that resemble Roman characters to create deceptive email addresses or URLs. Pay close attention to subtle differences in characters that may indicate an attempt at impersonation of an email address.


If You Are a Victim of Classic Phishing

If you have even the slightest doubt, contact the relevant organization to verify the message or call you received. Immediately report the incident to your bank or financial institution if you have inadvertently disclosed information about your payment methods or if you have noticed fraudulent charges on your account. Keep all evidence, especially the phishing message you received.

Change your passwords immediately if you have inadvertently disclosed a password on the affected website or service, as well as on all other websites or services where you used that compromised password.

If you’ve received a suspicious message, do not click on any attachments or suspicious links. Report these suspicious messages to Signal Spam, which works with the CNIL to identify the main sources of spam and take the necessary action to combat it. If you have received a suspicious message via SMS or MMS, report it on the 33 700 platform or by sending an SMS to 33700 (free service).


Awareness and Verification: The First Line of Defense

Employees are the first line of defense within an organization. It is therefore important to provide them with regular, thorough security training to mitigate the risks associated with human error. The more aware staff members are of the security risks associated with emails, the less likely they are to be fooled by the tactics and attacks of threat actors.

Here are some key topics to include in training on this subject:

  • techniques for identifying and avoiding phishing, ransomware, and wire transfer scams;
  • strategies for avoiding security threats, such as malware, malicious links, and malicious attachments;
  • tips for protecting passwords;
  • guidelines on how to respond to an electronic mail account compromise and promptly report suspicious emails and security incidents;
  • risks associated with the compromise of a phone number (subscriber identification module or SIM card swapping);
  • techniques for detecting social engineering attempts and knowing what not to share via email or other communication channels.

You should exercise caution before clicking on a hyperlink in an email or downloading an attachment, especially when the email comes from an unknown or suspicious source. Take the time to verify the legitimacy of the links and assess the sender’s credibility by ensuring the domain name is correct or by hovering your mouse over the link to view the actual address. This simple but essential step can help you avoid falling victim to phishing attacks or malware and protect your personal information and your organization’s data from related security risks.




RESPONSE RULE

Break the pressure loop: stop, verify through an independent channel and never use the contact route in the message.


About to read but genuinely seems like it’s the holy grail of scam
 
  • +1
  • JFL
Reactions: shedontluv-U, ZygoRR, Tesarossa and 1 other person
nigga wholehandely ruining his whole rep and wont even get a contributor badge

1787097014905
 
  • JFL
  • +1
Reactions: shedontluv-U, BigBallsLarry and ZygoRR
  • JFL
  • +1
Reactions: ZygoRR and vexd

FINANCIALLY AESTHETIC · GUIDE 19/37
SCAM PSYCHOLOGY, PHISHING & FAKE SUPPORT

FA-4.1 · Scamproof & Financial Security
━━━━━━━━━━━━━━━━━━━━





Phishing: A Threat Based on Deception

A phishing attack is a deceptive tactic used by threat actors that aims to send emails that appear legitimate to users. It represents the most common threat to email security. While relatively easy to detect in the past, phishing attacks have become more sophisticated over time. With the advent of artificial intelligence (AI), phishing emails contain fewer and fewer spelling errors, clichés, or typical red flags. They are now well-written and their content appears legitimate, making them even harder to detect.

Phishing attacks can be generic or targeted. In the case of targeted attacks - also known as spear phishing - threat actors conduct in-depth research on specific individuals or groups who have privileged access to valuable information, and then craft relevant emails that will not arouse suspicion.

Whaling is a specific form of spear phishing in which threat actors target high-ranking individuals within an organization and impersonate trusted authorities. The primary objective, however, remains the same: to manipulate users into revealing sensitive information, such as usernames, passwords, and banking details. Threat actors may also trick users into clicking on malicious links, opening dangerous attachments, or making unauthorized changes to a system they have access to. It is therefore essential to remain vigilant and understand the evolving nature of phishing attacks in order to protect your organization from these threats.

Phishing is a form of social engineering and fraud in which threat actors attempt to trick you into opening a malicious email containing attachments or links that download malware onto your device. Phishing attempts can result in the compromise of your organization and its sensitive information. Stay vigilant and review your emails before opening them.

Phishing is a fraudulent technique designed to trick internet users into disclosing personal information (login credentials, passwords, etc.) and/or banking information by impersonating a trusted third party. This may take the form of a fake message, text message, or phone call purporting to be from a bank, social network, telecommunications provider, energy supplier, e-commerce site, government agency, etc. The goal is to steal personal or professional information (accounts, passwords, banking information, etc.) for fraudulent purposes.


Identity Theft and Email Spoofing

Email impersonation is a deceptive tactic in which threat actors manipulate the sender’s details in an email’s header to make it appear as though the email comes from a trusted source. This practice is primarily intended to deceive recipients into believing the email is legitimate, thereby encouraging them to open it and interact with its content.

The inherent danger of email impersonation is that these deceptive messages typically contain malware, viruses, or malicious links that redirect users to fake websites or services. Simply opening the email can expose the recipient’s device to threats and make it vulnerable to further exploitation. Email impersonation is commonly used in phishing attacks and fake wire transfer scams. The ramifications of these attacks extend far beyond the immediate damage. The disclosure of sensitive information resulting from a spoofed email can lead to identity theft.

Threat actors use identity theft to exploit trust, make a profit, or gain access to sensitive information via electronic mail. For example, in wire transfer fraud schemes, threat actors impersonate trusted individuals, such as employees, to steal money from companies or their customers and partners. An attack involving identity theft is another example. In this context, the attacker pretends to be a legal representative and often targets staff members who lack the knowledge or authority to verify the legitimacy of the request. Similarly, threat actors sometimes impersonate authoritative entities, such as regulatory agencies, government departments, and law enforcement agencies.

Brand impersonation is another tactic used by threat actors. They falsely associate themselves with a well-known brand to deceive the recipient into disclosing confidential information. There are many identity theft techniques, such as posing as internal staff to commit financial fraud or exploiting the credibility of reputable brands for illicit purposes. It is therefore very important to adopt security practices focused on vigilance when handling electronic mail.


Social Engineering: Exploiting Urgency and Authority

Fake bank transfer scams are a growing concern for organizations of all sizes and across all industries. This sophisticated attack model often targets companies that offer bank transfer services. Threat actors attempt to defraud organizations by impersonating senior executives or business partners in order to deceive staff members, with the ultimate goal of having their targets transfer funds to fraudulent accounts.

These targeted and carefully planned attacks involve large sums of money and thus represent one of the most financially damaging threats to electronic mail security. Although perpetrators of fake transfer scams may exploit and steal data, their primary goal is to enrich themselves; to do so, they attempt to deceive organizational staff by employing social engineering tactics, such as identity theft.


The Fake Tech Support Scam: The Precise Mechanics of the Manipulation

The fake tech support scam (or computer repair fraud) involves frightening the victim with an alarming warning message that appears to lock up their computer, informing them of a serious technical problem and the risk of data loss or being unable to use their device, in order to pressure them into contacting a purported official tech support service (Microsoft, Apple, etc.).

The alert message typically appears after the victim clicks a link in a phishing email or a malicious ad, or while browsing fraudulent websites. This message is by no means an alert from the victim’s operating system or antivirus software; it is an aggressive, fraudulent web page. In some cases, victims are even contacted directly by phone by fake technicians.

Once contact is established with the victim, the fake tech support representative will then convince them to grant remote access to their computer and to pay for a bogus IT repair service and/or to purchase unnecessary - or even harmful - software, backed by invoices and contracts that appear official.

If the victim refuses to pay, the criminals may threaten to destroy their files, render their computer unusable, or disclose their personal information - which they will have stolen during their “intervention.”

In an increasing number of reported cases, the fake technicians manage to convince the victim to allow them access to their supposedly hacked bank accounts and, under the pretext of securing them, steal the funds.

The reported financial losses for victims of this type of scam can range from a few hundred euros to tens of thousands of euros.

The goal is to extort money from the victim by persuading them to let the scammer take control of their computer to pretend to fix it, install software, and/or sign them up for subscriptions for which they will be billed.

A Victim’s Account

“I was online when suddenly a siren started blaring and a window popped up on my screen telling me I had a virus and that I had to call a number to remove it or risk losing all my files. My computer was completely frozen, and it was very distressing. So I called the number, and a technician asked for remote access to my computer to fix it. He then asked me to pay €350 for the repair and a one-year support contract. He seemed confident and professional, and since I don’t know much about these things, I trusted him. He “logged into my computer remotely,” as he put it. When I told my son this story, he told me I’d been scammed. I called my bank to cancel my card and filed a police report, but I don’t think I’ll ever see my money again.”

This account illustrates the entire manipulation process: the sudden and intense fear, the urgency of the threat of data loss, the trust placed in someone posing as a professional, and the lack of independent verification before taking action.

Protecting Yourself from Fake Tech Support Scams

No official technical support team will ever contact you or ask you to contact them to resolve an issue following an alleged security alert.

To protect yourself against this scam, you should:

  • regularly and systematically install system security updates and updates for the software installed on your computer, especially your web browsers;
  • use antivirus software and keep it up to date;
  • avoid unsafe or illegal websites, such as those hosting pirated content (music, movies, software, etc.) or certain pornographic sites that may infect your computer or host questionable ad networks;
  • Do not install any “pirated” applications or programs, or those of dubious origin or reputation;
  • Do not open any attachments or click on any links in unexpected or suspicious messages;
  • Be cautious when clicking on advertising links (ads on websites and social networks, sponsored articles with “clickbait” headlines, advertising links that appear at the top of search engine results, etc.);
  • Back up your data and system regularly so you can restore it to its original state if there is a need to do so.

What to Do If You’re a Victim?

If you encounter this type of scam, regardless of its source, do not respond to any requests and do not call the number provided. If you’re at work, immediately alert your IT department or service provider - if you have one - so they can intervene and take the necessary steps if needed. Keep all evidence for reporting the incident or filing a complaint with the authorities; take a screenshot of your screen if necessary.

Close the fake alert window. If necessary, press the Esc or F11 key on your keyboard to exit full-screen mode. If that doesn’t work, restart your computer to regain control. Once you’ve regained control of your browser, clear the cache, delete cookies, reset to default settings, and, if that’s not enough, delete and recreate your profile.

Do not grant remote access to your computer in response to a request you did not initiate yourself, and without having definitively verified the legitimacy of the operator requesting access. If a fake technician has taken control of your computer, uninstall the remote access software (AnyDesk, TeamViewer, ConnectWise, etc.) and change all your passwords. Run a thorough scan of your device with your antivirus software.

If you provided your credit card numbers, immediately report them as lost or stolen to your bank. If a payment has been charged to your account, request a refund from your bank and explain your situation. If you paid the fake support provider via transfer, ask your bank to cancel the transaction.


SMS Phishing or “Smishing”

You receive a text message that appears to come from a government agency, your bank, a delivery service, or any other organization or company. This message, which is often alarming, urges you to take immediate action - such as logging in, confirming something, updating your information, or making a payment - under threat of service restrictions or fees to your account. Be careful - you may be facing an SMS phishing attempt, also known as “smishing”!

SMS phishing is also known as “smishing,” a portmanteau of “SMS” and “phishing.” It is a method used by cybercriminals to deceive their victims by impersonating a well-known third party (government agencies, banks, delivery services, online services, etc.) via text message.

Under this false identity and using a false pretext, SMS phishing involves sending a short message that generally prompts victims to disclose personal information and/or bank card details, or even login credentials (passwords). Cybercriminals may also use this type of cyberattack to infect the victim’s mobile phone (smartphone) with a malicious app (virus) designed to steal personal and banking data or to take control of the device. Another type of smishing involves tricking the victim into calling back a number provided in the message in order to defraud them. The goal of cybercriminals is to fraudulently use the stolen information and gain access to compromised accounts or phones.

Why Smishing Works So Well

Cybercriminals have a particular interest in smishing because it is harder to identify fraudulent text messages than phishing emails. In fact, text messages allow cybercriminals to communicate concisely, using language that is less “formal” and more terse - a style often characteristic of this type of message - while minimizing the risk of spelling or grammatical errors that might raise suspicion. Also, the sender can only be identified by a standard phone number (from France or abroad), a short code, or a brief description - none of which make it easy to determine the authenticity of the message sender. Also, people are generally less suspicious because smishing is a relatively new phenomenon compared to traditional email phishing. Similarly, victims may mistakenly believe that a received text message is inherently legitimate because they assume their phone number can only be used by known third parties.

The brevity of text messages, their credible nature, the difficulty in easily identifying their sender, and the relatively recent phenomenon of smishing tend to pique curiosity rather than arouse suspicion.

Also, it is more difficult to identify a malicious website on a cell phone after clicking on a link received via text message. Indeed, due to the small screen size and depending on the web browser used, the information on the website you’re visiting is not immediately and fully visible, and the website address is usually truncated.

Finally, smishing exploits our habit of receiving all kinds of notifications on our cell phones - validation messages, confirmation messages, or other alerts - and, generally, of reacting to them instantly.

How the fraudulent message works

The message consistently prompts the victim to take action under various pretexts. These may include resolving an issue such as a blocked online or bank account, a payment incident, regulatory compliance, canceling an order the victim did not place, obtaining a refund from a government agency, finalizing the delivery of a package, updating or confirming personal information, and so on.

The message is generally alarming, even anxiety-inducing or cryptic. It often states that action must be taken immediately, or else the account will be suspended, a penalty will be imposed, or an unauthorized payment will be charged, etc. The brevity of the message - and thus the limited information it contains - also adds to its alarming nature, prompting the victim to act on it without delay.

Smishing messages can serve various purposes: stealing personal information, bank card details, and/or login credentials; infecting the device with a virus; or prompting the victim to call back a phone number. In the latter case, the text message does not contain a link but urges the victim to call a specific phone number under various pretexts, such as to block a fraudulent bank transaction or online purchase. The victim, convinced that they are calling an official organization, will be all the more susceptible to falling for scams such as “fake adviser fraud.” In some cases, the number provided may be a premium-rate number that generates income for the scammers with every call made and is billed to the victim.

How to Respond to a Suspicious Text Message

Never disclose sensitive information in response to a text message, as no legitimate government agency or company will contact you via text to ask for your personal information, banking details, or passwords.

If you have even the slightest doubt, verify the information in the message yourself by contacting the organization directly or by logging into your personal account on its official website or mobile application.

Before clicking on a suspicious link, check its authenticity. If you have any doubts or just to be safe, go directly to the organization’s website using your usual methods - for example, via a bookmark you’ve created yourself or through its mobile application.

Never download an app from anywhere other than official websites or app stores. If, after clicking on a link in a text message, an alert appears prompting you to download or update an app, do not proceed and close the page.

Report the fraudulent message on the 33700 platform or forward it via text message to 33700 (free service). This service will block the sender of the message.


Verification practices common to both traditional phishing and smishing

Never share sensitive information via email or phone: no legitimate government agency or business will ask for your banking information or passwords via email or phone.

Before clicking on a suspicious link, hover your mouse cursor over it (without clicking) - this will display the actual URL it points to, allowing you to verify its authenticity - or go directly to the organization’s website using a bookmark you’ve created yourself.

Check the website address displayed in your browser. If it does not exactly match the organization’s official site, it is most likely a fraudulent site. Sometimes, just a single character in the website address may be altered to deceive you. If you have even the slightest doubt, do not provide any information and close the page immediately.

If in doubt, contact the organization directly, if possible, to confirm the message or call you received.

To mitigate the risks associated with email impersonation, make it a habit to always hover your mouse over links in an email before clicking on them. This will allow you to verify the actual URL and ensure that it matches the expected domain and is legitimate. Avoid clicking on links that seem suspicious or unfamiliar. Always consult your organization’s IT security team if you have any doubts. You should also scrutinize any email containing unusual requests, such as an urgent financial transaction or a request for sensitive information. It’s prudent to verify these requests using other communication channels, such as calling the sender or manually visiting the website in question in your browser to confirm the claims made in the email.

Another important point to consider involves homograph attacks, where threat actors use characters from other alphabets - such as Cyrillic or Greek - that resemble Roman characters to create deceptive email addresses or URLs. Pay close attention to subtle differences in characters that may indicate an attempt at impersonation of an email address.


If You Are a Victim of Classic Phishing

If you have even the slightest doubt, contact the relevant organization to verify the message or call you received. Immediately report the incident to your bank or financial institution if you have inadvertently disclosed information about your payment methods or if you have noticed fraudulent charges on your account. Keep all evidence, especially the phishing message you received.

Change your passwords immediately if you have inadvertently disclosed a password on the affected website or service, as well as on all other websites or services where you used that compromised password.

If you’ve received a suspicious message, do not click on any attachments or suspicious links. Report these suspicious messages to Signal Spam, which works with the CNIL to identify the main sources of spam and take the necessary action to combat it. If you have received a suspicious message via SMS or MMS, report it on the 33 700 platform or by sending an SMS to 33700 (free service).


Awareness and Verification: The First Line of Defense

Employees are the first line of defense within an organization. It is therefore important to provide them with regular, thorough security training to mitigate the risks associated with human error. The more aware staff members are of the security risks associated with emails, the less likely they are to be fooled by the tactics and attacks of threat actors.

Here are some key topics to include in training on this subject:

  • techniques for identifying and avoiding phishing, ransomware, and wire transfer scams;
  • strategies for avoiding security threats, such as malware, malicious links, and malicious attachments;
  • tips for protecting passwords;
  • guidelines on how to respond to an electronic mail account compromise and promptly report suspicious emails and security incidents;
  • risks associated with the compromise of a phone number (subscriber identification module or SIM card swapping);
  • techniques for detecting social engineering attempts and knowing what not to share via email or other communication channels.

You should exercise caution before clicking on a hyperlink in an email or downloading an attachment, especially when the email comes from an unknown or suspicious source. Take the time to verify the legitimacy of the links and assess the sender’s credibility by ensuring the domain name is correct or by hovering your mouse over the link to view the actual address. This simple but essential step can help you avoid falling victim to phishing attacks or malware and protect your personal information and your organization’s data from related security risks.




RESPONSE RULE

Break the pressure loop: stop, verify through an independent channel and never use the contact route in the message.


[/


ChatGPT write me some bs
 
  • +1
Reactions: shedontluv-U and BigBallsLarry

Similar threads

shedontluv-U
Replies
2
Views
19
niggawhat
niggawhat
shedontluv-U
Replies
2
Views
28
RJ_ascends
RJ_ascends
shedontluv-U
Replies
4
Views
39
shedontluv-U
shedontluv-U
shedontluv-U
Replies
9
Views
122
Brava
Brava
shedontluv-U
Replies
4
Views
60
shedontluv-U
shedontluv-U

Users who are viewing this thread

Back
Top