<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Phishing calls in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Phishing-calls/m-p/23274#M2936</link>
    <description>&lt;P&gt;LOL VISA cards in Canada start with 45.&amp;nbsp; Rob is in BC and I am in Ontario....so making an assumption that all banks that issue VISAs in Canada use 45 as the first two numbers.&amp;nbsp; I have two cards with two different banks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe they have a different number that they start with in other countries but have no proof of that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BTW: I may be off the forum for a while.....My phishing call was from the CRA (Canada Revenue Agency) telling me that I owe the government a lot of money and unless I pay using my credit card, the police will arrest me....funny thing was when I told them that I would be happy to be arrested that I would finally get three meals a day, THEY HUNG UP.........&lt;/P&gt;&lt;P&gt;so if I am not replying to anything or saying things, send packages to the Vanier Centre for Women in Milton.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jun 2019 20:45:02 GMT</pubDate>
    <dc:creator>dcontesti</dc:creator>
    <dc:date>2019-06-05T20:45:02Z</dc:date>
    <item>
      <title>Phishing calls</title>
      <link>https://community.isc2.org/t5/Industry-News/Phishing-calls/m-p/23271#M2934</link>
      <description>&lt;P&gt;Was awakened by a phone call this morning.&amp;nbsp; Obviously recorded, probably computer generated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Telling me that there were spurious charges on my Visa card.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Right off there were indications that this was a fraud.&amp;nbsp; First off, it didn't identify the issuing bank, and identified the card by saying the number started with 45.&amp;nbsp; (&lt;STRONG&gt;All&lt;/STRONG&gt; Visa cards start with 45 ...)&amp;nbsp; Also, while the message was recorded or generated, there was no change in tone when the message got to identifying the charges.&amp;nbsp; Recorded calls using something out of a database usually have a slight change in tone at that point.&amp;nbsp; (I figured it was a bit of a gamble telling me that I had a charge from Amazon for $300 and one from Google Play for $1,000, since I might deal with those entities, but I suppose the risk is small.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was supposed to stay on the line for a security agent, but I didn't feel like playing games with them.&amp;nbsp; I assume someone would have been trying to get info that they could then use to actually perpetrate a fraud on my card.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A bit later I went to the bank.&amp;nbsp; They obviously knew about the calls and the script.&amp;nbsp; (And confirmed that there were no charges or flags on our card.)&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2019 18:58:44 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Phishing-calls/m-p/23271#M2934</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-06-05T18:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing calls</title>
      <link>https://community.isc2.org/t5/Industry-News/Phishing-calls/m-p/23272#M2935</link>
      <description>&lt;P&gt;I have several Visa cards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NONE start with "45".&amp;nbsp; They start with "4", but that's it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2019 19:51:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Phishing-calls/m-p/23272#M2935</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2019-06-05T19:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing calls</title>
      <link>https://community.isc2.org/t5/Industry-News/Phishing-calls/m-p/23274#M2936</link>
      <description>&lt;P&gt;LOL VISA cards in Canada start with 45.&amp;nbsp; Rob is in BC and I am in Ontario....so making an assumption that all banks that issue VISAs in Canada use 45 as the first two numbers.&amp;nbsp; I have two cards with two different banks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe they have a different number that they start with in other countries but have no proof of that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BTW: I may be off the forum for a while.....My phishing call was from the CRA (Canada Revenue Agency) telling me that I owe the government a lot of money and unless I pay using my credit card, the police will arrest me....funny thing was when I told them that I would be happy to be arrested that I would finally get three meals a day, THEY HUNG UP.........&lt;/P&gt;&lt;P&gt;so if I am not replying to anything or saying things, send packages to the Vanier Centre for Women in Milton.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2019 20:45:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Phishing-calls/m-p/23274#M2936</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2019-06-05T20:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing calls</title>
      <link>https://community.isc2.org/t5/Industry-News/Phishing-calls/m-p/23312#M2939</link>
      <description>&lt;P&gt;BIN ranges should be well understood:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://en.wikipedia.org/wiki/Payment_card_number" target="_blank"&gt;https://en.wikipedia.org/wiki/Payment_card_number&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://binlist.net/" target="_blank"&gt;https://binlist.net/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 09:32:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Phishing-calls/m-p/23312#M2939</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2019-06-06T09:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing calls</title>
      <link>https://community.isc2.org/t5/Industry-News/Phishing-calls/m-p/23321#M2941</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/715155969"&gt;@dcontesti&lt;/a&gt;&amp;nbsp;wrote:&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BTW: I may be off the forum for a while.....My phishing call was from the CRA (Canada Revenue Agency) telling me that I owe the government a lot of money and unless I pay using my credit card, the police will arrest me....funny thing was when I told them that I would be happy to be arrested that I would finally get three meals a day, THEY HUNG UP.........&lt;/P&gt;&lt;P&gt;so if I am not replying to anything or saying things, send packages to the Vanier Centre for Women in Milton.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Sounds like a variant of the IRS calls people get here in the US, often times made by people with an Indian accent.&amp;nbsp; Hadn't heard they were doing the same thing in other countries, but guess it's the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 14:47:00 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Phishing-calls/m-p/23321#M2941</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2019-06-06T14:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing calls</title>
      <link>https://community.isc2.org/t5/Industry-News/Phishing-calls/m-p/23322#M2942</link>
      <description>&lt;P&gt;Folks will do anything to try to defraud you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 16:15:48 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Phishing-calls/m-p/23322#M2942</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2019-06-06T16:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing calls</title>
      <link>https://community.isc2.org/t5/Industry-News/Phishing-calls/m-p/23323#M2943</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/783051913"&gt;@Steve-Wilme&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;BIN ranges should be well understood:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://en.wikipedia.org/wiki/Payment_card_number" target="_blank" rel="noopener"&gt;https://en.wikipedia.org/wiki/Payment_card_number&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://binlist.net/" target="_blank" rel="noopener"&gt;https://binlist.net/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Very true, but if I were a scammer and trying to defraud someone in Canada, I would probably use this list:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://stevemorse.org/ssn/List_of_Bank_Identification_Numbers.html#Visa_.2845.2A.2A.2A.2A.29" target="_blank"&gt;https://stevemorse.org/ssn/List_of_Bank_Identification_Numbers.html#Visa_.2845.2A.2A.2A.2A.29&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Or something similar.....and see that most banks in Canada use 45 as the first two numbers....otherwise their scam would not go very far.&amp;nbsp; Can you imagine a call that says "I am calling about your credit card that starts with 4.".&amp;nbsp; They would not get very far and most would hang up on them at that point.&amp;nbsp; However with the first two numbers folks might pay more attention to them (especially the elderly).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first six numbers of any&lt;SPAN&gt;&amp;nbsp;Visa and Mastercard are code numbers for the issuing institution. By these 6 digits anyone can know which institution issued the card, and what type of card it is (debit/credit, premiere or not, etc).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I think the lesson here, is that if your bank calls you regarding a potential fraud on a credit card, they have much more information than the first number or the first two numbers, they identify themselves clearly (actually they allow you to call them back for verification), they know your entire credit card number, they know your address, etc.....there is usually no mistaking these calls.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And the CRA or the IRS will never all you at home.....their communication is done electronically or via snail mail.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It is actually that these folks existed and continue try to rob people.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But then such is life.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards on a Thursday&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;d&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 16:47:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Phishing-calls/m-p/23323#M2943</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2019-06-06T16:47:16Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing calls</title>
      <link>https://community.isc2.org/t5/Industry-News/Phishing-calls/m-p/23331#M2944</link>
      <description>&amp;gt; emb021 (Contributor I) posted a new reply in Industry News on 06-06-2019 10:47&lt;BR /&gt;&lt;BR /&gt;&amp;gt; &amp;nbsp; &amp;nbsp; Sounds like a variant of the IRS calls people get here&lt;BR /&gt;&amp;gt; in the US, often times made by people with an Indian accent.&amp;nbsp; Hadn't heard they&lt;BR /&gt;&amp;gt; were doing the same thing in other countries, but guess it's the same. &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The phone calls are relatively new (recall how old I am ...), but, over the years,&lt;BR /&gt;I've had tax phishing spam email from the IRS, Revenue Canada, and the UK&lt;BR /&gt;revenue office ...&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;Separation of test and production environments is one of those&lt;BR /&gt;things that is such basic common sense that it wouldn't occur to&lt;BR /&gt;me to have to point to something that says to do it. The first&lt;BR /&gt;time you test something on your production network and it breaks&lt;BR /&gt;something else which breaks something else, etc etc etc is the&lt;BR /&gt;LAST time they will ask you why it has to be done on a separate&lt;BR /&gt;network. - Mim Britt, CISSPforum 20090126&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Thu, 06 Jun 2019 18:52:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Phishing-calls/m-p/23331#M2944</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-06-06T18:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing calls</title>
      <link>https://community.isc2.org/t5/Industry-News/Phishing-calls/m-p/23349#M2947</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;, in response to your randomly chosen quote "&lt;SPAN&gt;Separation of test and production environments is one of those&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;things that is such basic common sense..."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 448px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/3255i13BE5FE4D671F14F/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 02:13:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Phishing-calls/m-p/23349#M2947</guid>
      <dc:creator>vt100</dc:creator>
      <dc:date>2019-06-07T02:13:41Z</dc:date>
    </item>
  </channel>
</rss>

