A Warning About Telephone Tech Support Scams And How They Tried To Target My Parents
Introduction
It is a sad fact of life that as more and more business and financial transactions move online a greater number of conmen and criminals are taking advantage of this.
These people are growing more sophisticated and rely on the fact that not everyone is as tech savvy as they are.
Even if you keep all your software up to date and properly secured, the weakest security link on your network can be the human element - as we are all susceptible to social engineering to various degrees.
Those who are from older generations and did not grow up with computers tend to be most susceptible.
Recently my parents have received a number of phone calls claiming to be from their ISP and saying that there is a problem which needs to be fixed (the actual problem seems to vary).
I have an agreement with my parents where I have instructed them to pass such phone calls on to me or ask them to call back when I am around.
These scammers are so brazen that they have called multiple times.
The funny thing is they don't actually even seem to be that good at what they do but obviously they are not afraid of getting caught from halfway across the world.
I have only spoken to them a couple of times and despite them being quite obviously found out the first time it did not seem to deter them from trying again.
The Calls
Here are how the phone calls went. I have tried to recall the conversation to the best of my ability but obviously it will not be exact:
Me: What seems to be the problem?
John: Sir this is John Smith. I am calling from [ISP Name Here] as you may know there are some problems with your parent's internet connection which I am calling to fix. Can you access this with a laptop or a desktop?
He doesn't really sound like a John Smith - his accent indicates he is likely calling from the Indian subcontinent. Nothing surprising about that, although the fake Western name thing has been abandoned by most legitimate companies nowadays as it just sounds dishonest.
Me: I can but I am not aware of a problem.
John: Sir there is a problem with the channels on your router [insert some technobabble gibberish that is complete nonsense here].
Me: Really that sounds serious?
John: Yes sir I will take you through the steps but I need you to log into your computer now. Do you have a laptop or a desktop? Is it a Mac or a PC?
Me: Mac.
John: OK I will need to hand you over to my colleague James who will take you through the steps on a Mac.
Pause as "John" whispers something unintelligible to "James".
James: Yes hello sir, this is James. Could you please turn your computer on?
James also has a very Indian accent - but OK maybe this place only hires people that have western names.
Me: It's already on. Do you want me to switch it off?
James: No please keep it on and log in.
Me: I'm already logged in, do you want me to log out. OK I just logged out.
James: No, no sir please log in. Can you log in now?
Me: OK I'm logged in now.
James: OK please now open your Safari browser.
Me: I can't do that.
James: Why not?
Me: I don't use Safari.
James: What browser do you use?
Me: Chrome.
James: OK open Chrome then. Is the window open?
Me: OK it's open.
James: OK I need you to type in this address in the top address bar. Can you do that?
Me: Yes.
James: Please type in this address - I will spell it out - www - dot - t-e-a-m....
Me: www - dot - x-c-a-n......
So what basically proceeds is "James" trying to get me to enter the address to download the Teamviewer software so he can take over my computer and me "mishearing" the address as many times as I can.
After a while I get bored with this:
Me: OK James you are obviously an idiot. I know exactly what you are trying to do and I know exactly what Teamviewer is. I'm not going to download it and I will be passing your information on to the authorities.
James hangs up once he realises he isn't going to get what he wants.
It seems this did not scare them because my father received a few more calls and as per my instructions he told them to call back when I was around.
The second call I received was a lot shorter. Once again there was a similar spiel. This time the guy was saying there was a problem with my [ISP issued] router.
This is complete BS as my router is fine and I also don't use the ISP issued router since they are complete crap - I always buy my own and make sure it is kept up to date.
I couldn't be bothered to go through the same rigamarole as before so I straight up asked the guy on the other end for "reference number" so I could confirm he was from my ISP.
He immediately hung up.
That was yesterday and I would not be surprised if someone else from the same group rings back. They are obviously not scared of being caught.
The Modus Operandi For This Type of Scam
The basic idea for the scammer is to hope that they will get through to someone who is older and less computer literate.
They will then try to scare them by telling them there is an urgent problem that they need to fix (and they will help them to do it over the phone).
Part of this involves speaking very quickly and bamboozling the person on the other end of the phone with terms and language they don't understand.
By barking out instructions rapidly the person on the other end of the phone doesn't get a chance to think.
All they know is that there is a problem with their computer (or router) and that they are at risk unless they get it fixed immediately.
The scammer will also keep suggesting that the problem is serious and that they are at grave risk if the victim tries to resist.
They prey on people's fears and their ignorance and then use them to get the person to download a piece of software like Teamviewer.
Teamviewer is remote access software that lets you administer multiple computers remotely and is available for free - hence why scammers like to use it. Basically it allows you to completely control another computer from a distance.
It is a very useful tool when you have multiple machines but the average home user should not need to install it - further if someone else is instructing you to install it or any other software during a phone call you should be very suspicious.
Although I refused to install the software I have heard from various online sources what happens when people do comply:
Once they have installed the software the scammer will take over the victim's computer and put on a show that "fakes" some kind of malware infection.
They may then ask them to make a payment for removing it. If the person pays they will put on a show of removing it.
If the victim is very lucky that is all they will do and they will have been ripped off for removing something that likely wasn't there in the first place.
However the big risk here is that these people have taken over the person's computer and they could well have installed all kinds of software without them knowing.
This can include key-loggers and other tools for stealing their passwords and vital information so they can steal money from bank accounts etc.
Basically it is the equivalent of handing over all your information to a complete stranger who is already scamming you and hoping that they behave honourably.
How to fight this
There is no foolproof way to deal with this. The scams continue to evolve and they tend to get more sophisticated with time.
The people I dealt with were very inept and not very convincing but I can imagine there are some people who are more sophisticated.
I think it would be very difficult for these sorts of people to fool someone who is tech savvy and knows a bit about computers.
Those are not the kind of people these scammers are looking for though. They are looking for people who can use computers but aren't 100% confident with them.
Often these people will be older individuals - parents and grandparents.
I think one of the best forms of protection is to educate your parents/grandparents about these sorts of scams.
Here are some potential methods I can think of:
Instruct your parents/grandparents to tell any such callers that they do not deal with computer issues and ask them to call you or someone else who is more technically competent.
Get the full details of the problem from the person on the other end of the phone and write them down. They will normally disguise their caller ID but if not make sure you record it.
Ask them for a reference number - most legitimate calls will have one or an equivalent.
DO NOT download any software. Do not do anything on your computer. Get the details of the problem and then dig out the details for your ISP or whoever the call is meant to be from and contact them DIRECTLY yourself to discuss the phone call. You will soon know if there is a problem or not.
With most ISPS or other online services you can usually check on their website if there is a problem. They will also notify you of any issues using their internal messaging system. Do not trust emails though.
Even if you are having service issues with your ISP/other technology do not believe a phone call. I have heard stories of these calls by chance coinciding with someone actually having technical issues - don't lower your guard because of this. As far as I know it is not common for ISPs to call people when their connection goes down - these issues happen so often that it would be impossible for them to do that. Normally they wait for people to contact them. Similarly Microsoft do not call people when they are having problems with Windows. You call them.
If there is a really serious problem that needs to be fixed most legitimate companies will send out an engineer to do it. They will also be able to provide you with evidence that they are who they say they are. In cases where they won't send someone out, you might be able to pay a fee for them to do that. If they aren't helpful change your ISP/Tech service provider.
Finally if you yourself are unsure of anything discuss it with a more tech savvy friend or family member.
I'm sure there are other things I haven't thought of - please give your suggestions in the comments.
Conclusion
As a greater proportion of people rely on their computers for the purposes of banking, sending money and managing their finances, a greater and greater number of criminals will try to capitalise on this.
We should all be wary and on our guard for these scams. If you have older family members please make sure that you educate them about these issues.
What might seem obvious to you may not be so obvious to someone who is not as comfortable with technology.
I would be interested to hear if any of you have run across these type of scammers yourself or with family members?
Let me know in the comments.
I prevented my mom from a hacker who was talking to her on Facebook messenger. It was really creepy because the hacker had assumed the identity of one of her real world friends. The hacker had made a duplicate FB account, using the identity of her friend, so she immediately accepted the friend request. As she was telling us what her friend was saying, she thought it was strange, but she almost fell for the scam. The "friend' was promising large amounts of money from a gov. program. Scary thing though is she was conversing with the scammer via messenger, and she believed it was her friend!!!!!
Once I started thinking about what she was doing, I knew it was a scammer. Then we reported this account to Facebook, and also tracked down the others who had befriended the scammer account. It was really spooky, but after we did all this, Facebook banned them.
I have also not allowed my parents to do anything without me reviewing everything first. I am on the extremely paranoid/cautious spectrum, and i just assume everything is a scam. Having an obsessive-compulsive personality actually comes in handy with security issues.
They are a lot smarter now, because I live by this rule:
Assume everyone is a scammer. Find evidence pointing otherwise. Trust very seldom. Even FB friends can be fake.
That's quite scary. I've seen similar things happen to older people that I know. These people would never have fallen for such scams when they were younger.
It looks like this is just something which happens to us as we get older. Us steemit users wouldn't fall for any scams like this right now, but I wonder if we'll be more vulnerable after we're retired...
Wow that is even more scary than the call centre thing. Do you have any idea what he was trying to do - this sounds a lot more sinister than the usual cold call method?
I think sadly nowadays it is best to assume everyone is a scammer until proven otherwise.
given it was "money from a gov program" they were offering, they were probably the more... dark... kind of scammer.
I imagine they were aiming for full-on identity theft, by getting her to give social security number, bank details, etc... (seeing as government forms need so much information, it would seem "reasonable" to provide it to them)
Right so maybe cloning the identity to take out loans and things, make false papers etc?
Yup, and, being the little malicious monsters that they are, proceed to scam all her friends and family too if they can.
a friend of mine has the same experience as Leah's parents - the worst part is they got to hack her FB and have asked a few of her friends to send money to that hackers account using her FB tsk tsk
modus operandis like this have no souls
It's scary!
.... Having an obsessive-compulsive personality actually comes in handy with security issues.(smiles) it sure dose my dear. am sure you still don't think that steemit is scam..? lol nice comment @stellabelle,this is the fifth comment of yours am reading in various posts and they have been really engaging. hope you don't mind if i follow you.
i never thought steemit was a scam. I did my homework for 2 weeks solid (and slept very little).
abi..is alright dear,was just being funny.
My elderly father has been scammed by the guys claiming to be from Microsoft. He had to pay them for some ridiculous antivirus software. Fortunately I found out soon after and managed to immediately get his computer cleaned of potential viruses and scanning software. I also complained to the payment processor (some variant of paypal) and managed to get them to refund the purchase. They still regularly phone him to try to scam him again, but he is now wiser. It is unbelievable what devious tricks people will resort to.
Thanks for sharing your experience. Yes they are scumbags. I hope it didn't hit him too badly mentally.
Brilliant post! someone tried to scam my Mum one day, she let the other person get to the end of the call and then said okay, can you pop that all in a letter and once it comes i will confirm with customer support, the line went dead...
Excellent! Good thing she wasted their time too.
She is quite sensible when it comes to these things. Thankfully.
I joined a company like this as a part time job while I was in college. Initially I was told this is a tech support job which I believed. But on the very first day I found what they actually do and my conscience did not allow me to pursue with it and left it immediately.
They used to run the TREE command on CMD after getting the remote access, since the TREE command takes some time to execute they type something like LICENSE EXPIRED. PLEASE RENEW in the mean time.
Thats how they loot money from other people and the worst part is they have no sense of guilt for what they do.
Well done for not joining in. Sadly some people do not have enough of a conscience.
Thats really sad!
Unfortunately even the most intelligent people can get caught out on this. As former tech support, I try to warn my customers about this... But even then it may not be enough until they get done in the first time. One of my customers now had to lock their Web Bank and credit card because they took 10,000 from his account, and would have taken the whole near 80,000 over time if he hadn't noticed and put a hold on it.
Remember: Microsoft and your ISP will never call you and offer to fix your computer. Even at worst of times this is a paid service you should never allow anyone who is calling you to do. This article is dead on about how to protect yourself.
Put the proof of identity on them! They called you, they should be able to tell you your reference number and your IP Address at least. When in doubt, ask them for a call back number. Hang up, and do a search for that number. Call your provider directly and ask if it from them. At least then you know your talking to the real deal.
Thank you. Those are excellent points. As in my case it doesn't take asking for much to get them to just hang up.
nice post @thecrypto,well here in Nigeria,we don't normally get scammer telling you to repair your PC rather what they normally do here is to go after your ATM pin and its the older people that also falls pry to this. i think the best way to cube this as you have rightly said is to educate and as much time as possible,waste their time over the phone if you have the time...still a newbie,will like to follow and tap from your wealth of experience.
Cool thanks for commenting. So are these ATM scams big in Nigeria?
yes kind of,but since most of them don't succeed,the numbers have reduced pulse ,there were and still is a lot of sensitization about it in many platforms;churches,schools,Facebook etc and i think such awareness can help in the united states.
Yeh it's something you do worry about with your parents. They've even tricked a couple of friends of mine with very clever sincere tactics. Sometimes I'm slightly fooled but I know generally not trust anyone calling or by email unless you contact them through official recognised means.
Yes it is easy for people to get tricked.
Is it worth storing phone numbers on their phone from family and friends so that when they ring the name of the person displays? Anything else that displays without a pre-stored name...they can safely ignore. If it's a genuine call, they can leave a message for review later on with your help :-)
That is a good point. Unfortunately sometimes legitimate businesses block their numbers too.
My attitude these days is to screen every call. I never pick up when the landline phone rings and always wait for a review of messages at my own convenience. Chances are if it's a cold call, it's something you don't need.
Pests.
Yes and I suspect if it is important they will leave a message.
This is very important advice. In Indo scammer makin a phone calls sayin that receiver won a contest. Ridicilous actions, sometimes they goin into trap.
If your parents need me to choke someone, I gladly will. Even if they don't need me to, I still gladly will.
Thank you:)