social engineering at its finest…
it’s amazing to me how gullible some people can be if the person trying to scam them comes off as “official” enough by whatever standard people use to judge these things. someone called our office last friday pretending to be from the phone company and talked to one of our users. this person told my co-worker that he was from the phone company and needed the password to their account so they could “do some testing” of the line. so what does said co-worker do? promptly gives this stranger their password and doesn’t mention it until monday when we discover that an outsider has been making thousands of dollars of international calls from our phone system. well, it took us over a day to lock this hacker out of the phones and sure enough they called another person and asked them the same thing. even worse, this other person gave out their password too!
luckily this person remembered the company wide email that went out the day before warning everyone not to give out their passwords to ANYONE not part of the IT department and we were able to lock their account before any damage could be done.
or so we thought…
about 30 minutes after this scenario, our phones were *flooded* with calls from an asian/oriental sounding person claiming to be part of some phone company and/or phone software vendor asking everyone for their passwords. luckily this time nobody gave out their password to this guy, but it got kind of comical near the end because he would call one extension, get rejected, and then that person’s neighbor’s phone would ring with the same guy with the same story. hopefully this is the end of the story from our side, but i do believe the FBI are now involved in the case since the numbers this guy was calling from were also hijacked phone systems.
but i do believe the lesson was learned by all: NEVER give out personal information over the phone to ANYBODY, no matter how trustworthy. even the companies who already have your personal data are willing to let you give a partial password since you’re just verifying what you already share between you. but they should never push you into revealing more than you’re willing to reveal, and if they do you should hang up and call back and hope you get someone else on the phone. just remember to keep your info safe and secure at all times or else you never know what might happen….