{"id":10066,"date":"2022-07-06T18:30:15","date_gmt":"2022-07-06T23:30:15","guid":{"rendered":"http:\/\/blog.jlbn.net\/?p=10066"},"modified":"2022-07-06T18:30:16","modified_gmt":"2022-07-06T23:30:16","slug":"anyone-can-fall-for-online-scams-even-you-heres-how-to-avoid-them","status":"publish","type":"post","link":"http:\/\/blog.jlbn.net\/?p=10066","title":{"rendered":"Anyone can fall for online scams \u2014 even you. Here\u2019s how to avoid them."},"content":{"rendered":"\n<p><strong><em><a rel=\"noreferrer noopener\" href=\"https:\/\/www.gobankingrates.com\/category\/investing\/real-estate\/?utm_campaign=1171552&amp;utm_source=yahoo.com&amp;utm_content=1&amp;utm_medium=rss\" target=\"_blank\">From spam texts to payment app fraud to crypto tricks.<\/a><\/em><\/strong><\/p>\n\n\n\n<p>Alison Giordano just wanted to help out a friend, but instead, she almost lost her Instagram account.<\/p>\n\n\n\n<p>The scam was pretty sneaky: A friend messaged Giordano (who, full disclosure, is a friend of mine) on Instagram asking if she could help her win a contest. The friend would send her a text with a link, and all Giordano had to do was take a screenshot of the text and send it back to her friend. Giordano did as instructed. Moments later, she got an email from Instagram saying someone logged into her account from a different location on a different device.<\/p>\n\n\n\n<p>A screenshot that causes your account to be hacked sounds like a lower-stakes but higher-tech version of&nbsp;<em>The Ring<\/em>, but what happened to Giordano is actually quite simple. There was no contest, and the text didn\u2019t come from her friend. Giordano\u2019s friend (or, almost certainly, someone who took over her friend\u2019s account and was pretending to be her friend) went to Instagram\u2019s password reset page and requested a reset link for Giordano\u2019s account. That prompted Instagram to send a text to Giordano with a link to access her Instagram account. The URL of the link was in the text, so when Giordano took the screenshot and sent it back, the scammer simply entered the URL in their device, and that let them access Giordano\u2019s account \u2014 no password or supernatural curses necessary.<\/p>\n\n\n\n<p>Fortunately for Giordano, she saw Instagram\u2019s email almost immediately and was able to get back into her account before the scammer took it over. She blocked her friend\u2019s account, changed her password, and enabled\u00a0<a href=\"https:\/\/www.vox.com\/recode\/22419794\/authenticator-apps-and-you-authy-google-authenticator\">two-factor authentication<\/a>.<\/p>\n\n\n\n<p>\u201cI was just very naive and trusting,\u201d Giordano tells me. \u201cI felt pretty stupid when all was said and done.\u201d<\/p>\n\n\n\n<p>She shouldn\u2019t have. The Instagram messages came from what appeared to be a friend, and Giordano\u2019s other friends have asked for her help with (real) social media-based contests in the past, so of course she didn\u2019t think much of it. She certainly didn\u2019t think sending a screenshot could compromise her account. Until we spoke, she didn\u2019t even know how it happened \u2014 it took me a while to figure it out too, until&nbsp;<a href=\"https:\/\/mobile.twitter.com\/tallpoppyhq\/status\/1530584650975936513\">this tweet<\/a>&nbsp;warning about this kind of scam clarified things. If Giordano hadn\u2019t seen that email from Instagram, her account might have been lost to her forever, probably going on to try to scam all of her friends.<\/p>\n\n\n\n<p>We\u2019d like to think that scams happen to other people who aren\u2019t as smart or savvy as we are. Many people who get scammed believe this, which is why the\u00a0<a href=\"https:\/\/papers.ssrn.com\/sol3\/papers.cfm?abstract_id=3852323\">vast majority<\/a>\u00a0of them will never report it: Either they don\u2019t know they were scammed or they\u2019re ashamed to admit that it happened to them.<\/p>\n\n\n\n<p>But it could happen to anyone, including you.<\/p>\n\n\n\n<p>\u201cThe reason why these scams work is because some of them are good,\u201d Yael Grauer, content lead for Consumer Reports\u2019&nbsp;<a href=\"https:\/\/securityplanner.consumerreports.org\/\">Security Planner<\/a>, tells Vox. \u201cEven though I think education is important, there\u2019s a reason social engineering is a thing. You can\u2019t be perfect and on guard all the time.\u201d<\/p>\n\n\n\n<p>Scammers prey on our biggest fears and strongest desires. They get better all the time, so it\u2019s worth your time to learn how to recognize their tactics. The mediums scammers use may change, but many of the underlying strategies stay the same \u2014 which means the recommendations for how to protect yourself from them do too.<\/p>\n\n\n\n<h3>Don\u2019t panic &#8230;<\/h3>\n\n\n\n<p>When I got an email saying there was a new login to my Twitter account from Moscow, my initial response was abject terror (My checkmark! My DMs! My reputation!). At first glance, the email looked a lot like the login confirmation emails that Twitter actually sends. Even the email address it was sent from was very close to the one Twitter uses for such notifications. I admit that I almost clicked on the account restoration link. Then the adrenaline wore off, and I realized that the email came from \u201ctwitter-act.com\u201d and not \u201ctwitter.com.\u201d It was sent to my work email, which isn\u2019t attached to my Twitter account, and it had a typo. Most importantly, I remembered that some of\u00a0<a href=\"https:\/\/twitter.com\/pkafka\/status\/1506068606152548357\">my co-workers<\/a>\u00a0had gotten similar phishing emails only a few days before. I\u00a0<a href=\"https:\/\/twitter.com\/SaraMorrison\/status\/1506072154894393347\">actually knew<\/a>\u00a0to expect this one, but all of that fell out of my head for a few seconds \u2014 which was exactly the point.<\/p>\n\n\n\n<p>\u201cIt\u2019s really, really hard for us to access logical thinking when we\u2019re in a heightened emotional state, and it\u2019s so hard to get out of that state once you\u2019ve engaged,\u201d says Kathy Stokes, director of fraud prevention at the AARP. \u201cIf you feel an immediate sort of visceral, emotional reaction to something coming your way, try to let that be your red flag.\u201d<\/p>\n\n\n\n<p>Scammers know that emotions make their job easier. People get careless or let their guard down, which is why so many scams start with urgent messages asking you to do something immediately: dispute an erroneous charge on your&nbsp;<a href=\"https:\/\/www.abcactionnews.com\/money\/consumer\/taking-action-for-you\/scammers-discover-new-way-to-trick-amazon-customers-tampa-bay-woman-loses-2-000\">Amazon account<\/a>, fix your hacked social media account, avoid being arrested by the IRS police by settling a bill that for some reason can only be&nbsp;<a href=\"https:\/\/www.irs.gov\/newsroom\/holiday-scam-reminder-gift-cards-are-never-used-to-make-tax-payments\">paid off in gift cards<\/a>. In almost every case, a legitimate message doesn\u2019t need you to respond within the next 30 seconds. So take that 30 seconds to calm down and think before you click anything.<\/p>\n\n\n\n<h3>\u2026 and don\u2019t engage<\/h3>\n\n\n\n<p>If you get a message or call you weren\u2019t expecting and don\u2019t know, the best thing to do is ignore it. Even what appears to be a perfectly innocent wrong number text could be something more insidious: someone\u00a0<a href=\"https:\/\/www.wrtv.com\/news\/wrtv-investigates\/wrong-number-text-scam-popping-up-on-hoosier-phones-could-have-dire-consequences-if-you-respond#:~:text=When%20you%20respond%20%E2%80%9Csorry%2C%20wrong,money%2C%20or%20even%20explicit%20pictures.\">trying to scam you<\/a>\u00a0by starting up a conversation. I\u2019ve gotten a few of those wrong number texts, and while I\u2019d like to think they kept texting me back because of my sparkling wit and impeccable conversation skills, that almost certainly wasn\u2019t the reason.<\/p>\n\n\n\n<p>\u201cSomeone texts something important enough for you to tell them it\u2019s a wrong number and suddenly they\u2019re like, \u2018You sound like a great person,\u2019\u201d Grauer says. \u201cFor the most part, it\u2019s almost always a scam.\u201d<\/p>\n\n\n\n<p>Find your meet-cute somewhere else.<\/p>\n\n\n\n<p>That\u2019s especially true for the texts and calls you know are scams. You may think it\u2019ll be cathartic to respond to those by cursing out the people who are trying to steal your money, but the best thing you can do is block the number and move on with your life. Engaging with a scammer tells them your phone number or email address has a real person on the other end of it, which will only set you up to get more texts and calls and emails.<\/p>\n\n\n\n<p>\u201cThe basic rule of thumb is simply hang up, and call whatever enterprise you think called you directly,\u201d Alex Quilici, CEO of robocall-blocking software company YouMail, explains. For example, if your \u201cbank\u201d calls, you should hang up, find the number of your bank on your debit card (or another official source, like its website), and call that number back. \u201cThat\u2019s the 100 percent safe way to deal with the issue.\u201d<\/p>\n\n\n\n<p>Even better is stopping scam calls and texts from reaching you at all. Phone companies&nbsp;<a href=\"https:\/\/www.vox.com\/recode\/22882647\/robocalls-robotexts-scams-stir-shaken-voip-extended-warranty\">now offer<\/a>&nbsp;free spam-blocking services, which can identify and stop potential scam or spam calls. Some services can block potential spam texts: iOS devices have&nbsp;<a href=\"https:\/\/support.apple.com\/guide\/iphone\/block-filter-and-report-messages-iph203ab0be4\/ios\">built-in text filters<\/a>, and Google\u2019s Messages app can&nbsp;<a href=\"https:\/\/www.pcmag.com\/how-to\/block-robotexts-and-spam-messages\">warn you<\/a>&nbsp;if a text seems suspicious.<\/p>\n\n\n\n<h3>Don\u2019t give out your password<\/h3>\n\n\n\n<p>This should be obvious by now, right? Clearly not, since it\u2019s believed that&nbsp;<a href=\"https:\/\/www2.deloitte.com\/my\/en\/pages\/risk\/articles\/91-percent-of-all-cyber-attacks-begin-with-a-phishing-email-to-an-unexpected-victim.html\">90 percent<\/a>&nbsp;of cyberattacks are the result of successful phishing schemes, where a hacker or scammer tricks victims into thinking they\u2019re a trusted or known source to give their sensitive information to. Some are better than others. I\u2019ve seen some knowledgeable people in my own life fall for&nbsp;<a href=\"https:\/\/www.graphus.ai\/blog\/one-in-three-employees-will-fall-for-phishing\/\">email-from-your-employer<\/a>&nbsp;attacks (they clicked the links, but I hope they all stopped short of giving out their passwords).<\/p>\n\n\n\n<p>That\u2019s why most businesses will tell you that they will never ask for your password, and authentication texts will usually say something like \u201c[Company] will never ask you for this code.\u201d Also, you should really stop using two-factor authentication with texts, which are\u00a0<a href=\"https:\/\/www.cnet.com\/news\/privacy\/do-you-use-sms-for-two-factor-authentication-heres-why-you-shouldnt\/\">much less secure<\/a>\u00a0\u2014 use an\u00a0<a href=\"https:\/\/www.vox.com\/recode\/22419794\/authenticator-apps-and-you-authy-google-authenticator\">authenticator app<\/a>\u00a0instead. Google makes a popular one for both\u00a0<a href=\"https:\/\/apps.apple.com\/us\/app\/google-authenticator\/id388497605\">iOS<\/a>\u00a0and\u00a0<a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.google.android.apps.authenticator2&amp;hl=en_US&amp;gl=US\">Android<\/a>.<\/p>\n\n\n\n<p>Scammers love to use social media to find victims, too. If you\u2019ve ever so much as tweeted the word \u201chack,\u201d you\u2019ll get a series of what I like to call Twitter Scam Reply Guys, who will usually recommend that you contact someone they claim to know who can get your account back, as long as you give them your login credentials and\/or pay them (<a href=\"https:\/\/www.vice.com\/en\/article\/k7w39x\/account-recovery-service-twitter-hacked-instagram-coinbase\">don\u2019t do this<\/a>).<\/p>\n\n\n\n<h3>Know where links are taking you<\/h3>\n\n\n\n<p>A common way people get hacked or scammed is through malicious links, often in their email, texts, or DMs. Always check where a link is taking you before you click on it, and only go to websites you trust. That\u2019s easier said than done, of course; it can be hard to see where a link is directing you on a smaller mobile device, and shortened link services may make it impossible to know where you\u2019ll end up. If you get a text from FedEx about a package delivery with a link, for example, you may not realize that the website it\u2019s sending you to&nbsp;<a href=\"https:\/\/www.cbsnews.com\/news\/fedex-scam-text-message-package-phishing-smishing-tracking-number\/\">isn\u2019t FedEx<\/a>.<\/p>\n\n\n\n<p>The best thing to do is go to a company\u2019s website directly, rather than through a random link in a text you weren\u2019t expecting in the first place. If you get a text that claims to be FedEx or Wells Fargo, go to FedEx.com or WellsFargo.com; don\u2019t click the link on the text. And definitely don\u2019t enter any of your sensitive information \u2014 like your credit card, social security number, or your password \u2014 on a site if you aren\u2019t absolutely sure that it\u2019s the site you think it is.<\/p>\n\n\n\n<h3>Be very careful with payment apps<\/h3>\n\n\n\n<p><a href=\"https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2004\/12\/ftc-warns-consumers-about-check-overpayment-scams\">Overpayment scams<\/a>&nbsp;\u2014 when someone sends you more money than you were expecting and then asks you to give them back the difference \u2014 have stood the test of time. Once it was paper checks and wire transfers. Payment apps have made it even easier.<\/p>\n\n\n\n<p>In fact, peer-to-peer payment apps like Venmo, Zelle, and Cash App have made a lot of scams easier because it\u2019s fairly seamless to send money through them, and those transfers are instantaneous. There\u2019s a reason why those apps tell you over and over again to be sure that the person you\u2019re sending money to is who you think they are: Once your money is sent, you often can\u2019t get it back. These services&nbsp;<a href=\"https:\/\/www.nytimes.com\/2022\/03\/06\/business\/payments-fraud-zelle-banks.html\">don\u2019t have the same protections<\/a>as, say, a credit card or, in&nbsp;<a href=\"https:\/\/www.paypal.com\/c2\/webapps\/mpp\/paypal-safety-and-security?locale.x=en_C2\">some cases<\/a>, PayPal.<\/p>\n\n\n\n<p>One example of how scammers exploit these apps (and human decency) is to send money to random accounts (like yours), then claim they sent it to the wrong person and ask you to please send the money back. Being nice, you send the money back, only to later discover that the money that was sent to you came from a stolen credit card. Now\u00a0<a href=\"https:\/\/www.bbb.org\/article\/news-releases\/22128-scam-alert-this-venmo-scam-sends-you-money-by-accident\">you have to pay it back<\/a>\u00a0\u2014 all of it.<\/p>\n\n\n\n<p>If you\u2019re the recipient of extra or unexpected funds, don\u2019t just send the money back to wherever it came from, even if the sender gives you a convincing sob story for why you should. The best thing to do is contact the payment app and deal with the matter through them, rather than directly with whoever sent you the money.<\/p>\n\n\n\n<p>There are ways to protect yourself to a certain extent on these apps. Most will give you a way to verify that you\u2019re sending money to the right person by confirming their email address or phone number first. Use these safeguards. Consumer Reports&nbsp;<a href=\"https:\/\/www.consumerreports.org\/digital-payments\/how-to-protect-peer-to-peer-payments-a1478958356\/\">suggests<\/a>&nbsp;connecting your peer-to-peer payment apps to a credit card instead of a bank account, as credit cards have more protections for fraudulent transactions. If the app won\u2019t protect you, your credit card company might, though most payment apps make you pay a 3 percent fee on credit card transactions.<\/p>\n\n\n\n<p>It\u2019s also a good idea to put a PIN code on those apps, so even if someone gets into your phone \u2014 say, if they\u00a0<a href=\"https:\/\/www.wral.com\/charlotte-man-warns-of-venmo-cell-phone-scam-after-losing-2-200\/19913906\/\">ask to borrow it<\/a>\u00a0to make an emergency call \u2014 they can\u2019t get into your apps and send your money away. This will add an extra step to using your payment app, but an easily remembered four-digit PIN takes about a second to enter and could save you a lot of money.<\/p>\n\n\n\n<h3>Don\u2019t use crypto<\/h3>\n\n\n\n<p>Even in the best of circumstances, crypto is a loosely (or barely) regulated market that\u2019s&nbsp;<a href=\"https:\/\/www.vox.com\/the-goods\/23071245\/bitcoin-price-crypto-ethereum-nfts-defi-stablecoin\">as volatile as it is hard to understand<\/a>. That has helped make it a prime target for scammers and hackers. The decentralized aspect of crypto may be part of its appeal, but it\u2019s a lot less appealing when you check your wallet one day and discover&nbsp;<a href=\"https:\/\/www.vice.com\/en\/article\/y3v3ny\/all-my-apes-gone-nft-theft-victims-beg-for-centralized-saviors\">all your apes are gone<\/a>. Maybe you\u2019ll get lucky and OpenSea will freeze trading of your stolen NFT in time, or Coinbase will&nbsp;<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-rob-thousands-of-coinbase-customers-using-mfa-flaw\/\">reimburse you<\/a>&nbsp;if your crypto was stolen through its own security flaw. But don\u2019t&nbsp;<a href=\"https:\/\/www.fox35orlando.com\/news\/couples-digital-coinbase-account-hacked-24000-stolen\">count on it<\/a>.<\/p>\n\n\n\n<p>\u201cThe advice I give people is that if you don\u2019t understand how it works, don\u2019t get involved in it,\u201d Sean Gallagher, a senior threat researcher at Sophos, says. \u201cConsidering that many people who consider themselves educated about crypto still manage to get scammed, it\u2019s probably not a good idea for most people to get into cryptocurrency investing.\u201d<\/p>\n\n\n\n<p>While crypto is relatively new, many people are getting scammed through some of the oldest tricks in the book. Stokes, of the AARP, says she has seen \u201ca ton\u201d of scams where someone gains a victim\u2019s trust and claims they can help\u00a0<a href=\"https:\/\/www.aarp.org\/money\/scams-fraud\/info-2019\/cryptocurrency.html\">invest their money<\/a>\u00a0in crypto for a big return. The Federal Trade Commission\u00a0<a href=\"https:\/\/www.vox.com\/recode\/23153469\/bitcoin-crypto-scam-report-ftc\">recently reported<\/a>\u00a0that consumers lost $1 billion to crypto-based fraud between January 2021 and March 2022, with most of those losses coming from bogus investment scams \u2014 and most of those came from social media posts or ads. And those are just the losses people told the FTC about; again, most people don\u2019t report being defrauded. These days, it\u2019s\u00a0<a href=\"https:\/\/www.vox.com\/the-goods\/23148474\/crypto-celebrities-ftx-kim-kardashian-larry-david\">easy<\/a>\u00a0<a href=\"https:\/\/www.cnn.com\/2022\/05\/12\/investing\/luna-terra-stablecoin-explained\/index.html\">enough<\/a>\u00a0to lose money in \u201clegitimate\u201d crypto investments. Why make it even riskier?<\/p>\n\n\n\n<h3>Protect yourself from yourself<\/h3>\n\n\n\n<p>One way to avoid getting scammed is to preemptively protect your accounts from your mistakes as much as possible. If Giordano had two-factor authentication on her Instagram account, the scammers wouldn\u2019t have been able to get into it through the URL \u2014 they\u2019d need the code from her authenticator, too.<\/p>\n\n\n\n<p>There are&nbsp;<a href=\"https:\/\/www.vox.com\/recode\/2020\/1\/28\/21080122\/avoid-hack-hacker-theft\">a few ways<\/a>&nbsp;you can protect your accounts from getting hacked, including setting up two-factor authentication and using different passwords for everything via a password manager. You can lock things down even more by using&nbsp;<a href=\"https:\/\/www.theverge.com\/2019\/2\/22\/18235173\/the-best-hardware-security-keys-yubico-titan-key-u2f\">hardware authenticators<\/a>&nbsp;and&nbsp;<a href=\"https:\/\/www.nytimes.com\/wirecutter\/guides\/online-security-built-in-antivirus-software\/\">anti-malware software<\/a>, which you can get for mobile devices too.<\/p>\n\n\n\n<p>\u201cThat\u2019s what security software is supposed to do,\u201d Mark Ostrowski, head of engineering at cybersecurity company Check Point, says. It should protect you from \u201ca lapse in judgment or if the scam is really, really, really, really good.\u201d<\/p>\n\n\n\n<p>At a certain point, your security measures might feel like more trouble than they\u2019re worth. I have to admit, things were easier when I didn\u2019t have to juggle my password manager, two different authenticator apps, and text messages for the accounts where authenticator apps aren\u2019t available. But I\u2019d rather have to take an extra step to log into an account than go through getting hacked and (temporarily) losing $13,000, like I did&nbsp;<a href=\"https:\/\/www.vox.com\/recode\/2020\/1\/28\/21080122\/avoid-hack-hacker-theft\">that time<\/a>hackers got into my bank account. You never know who has your password or how they got it.<\/p>\n\n\n\n<p>\u201cThere\u2019s an ongoing usability versus security thing where it\u2019s not fun, it\u2019s time-consuming, it\u2019s annoying,\u201d Grauer, of Consumer Reports, says.<\/p>\n\n\n\n<p>It\u2019s up to you to decide where the balance between usability and security should be, keeping in mind what you would lose if someone took over your accounts. After that, all you can do is try to keep these tips in mind, hope for the best, and don\u2019t be too hard on yourself if you fall victim to the worst.<\/p>\n\n\n\n<p>\u201cHaving a healthy paranoia, I think, is important,\u201d Ostrowski says, before confessing that even he has slipped up and clicked on a few links he shouldn\u2019t have. \u201cI hate to admit it, but I think everybody has, right?\u201d<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>From spam texts to payment app fraud to crypto tricks. Alison Giordano just wanted to help out a friend, but<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3423,254,3421],"tags":[888,3530,3531],"_links":{"self":[{"href":"http:\/\/blog.jlbn.net\/index.php?rest_route=\/wp\/v2\/posts\/10066"}],"collection":[{"href":"http:\/\/blog.jlbn.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/blog.jlbn.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/blog.jlbn.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/blog.jlbn.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10066"}],"version-history":[{"count":1,"href":"http:\/\/blog.jlbn.net\/index.php?rest_route=\/wp\/v2\/posts\/10066\/revisions"}],"predecessor-version":[{"id":10068,"href":"http:\/\/blog.jlbn.net\/index.php?rest_route=\/wp\/v2\/posts\/10066\/revisions\/10068"}],"wp:attachment":[{"href":"http:\/\/blog.jlbn.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10066"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/blog.jlbn.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=10066"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/blog.jlbn.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=10066"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}