Catch Of The Week: The Friendly Face That Wants Your Bank Password

By REBECCA RUTHERFORD
Los Alamos
For the Los Alamos Daily Post

There’s a new twist on an old con making the rounds, and this one comes with a face. Scammers have started using Apple’s FaceTime to pose as your bank, and it is working alarmingly well. Apple and the FTC have both put out warnings, because people who would never fall for a sketchy email are getting taken in by a live video call. That is the whole trick. A face feels honest in a way a text message never does.

Here is how the bait gets set. You get a text saying there is suspicious activity on your account or your card. It tells you to call a number, or a few minutes later your phone rings on its own (literally my worst nightmare, please just text me!). The “representative” on the line sounds calm and official, and says they just need a little more verification. Then they ask to move the call over to FaceTime.

Once you are on video, the ask gets bigger. They want you to share your screen while you log into your online banking, “just to confirm everything looks right.” And that is the moment the trap springs. While you type, the scammer is watching every keystroke in real time; your username, your password, your account numbers, and even the one-time security code your bank texts you. They do not need to hack anything. You hand it all over, live, because a friendly face asked nicely.

What makes this so effective is that nothing on your phone is technically broken. As one security firm put it, the exploit here is human trust, not software. That is exactly why it slips past people.

So let me give you the tells, because they are simple once you know them:

  • Your bank will not FaceTime you. Neither will Apple, or for that matter any legitimate business. If a video call comes in claiming to be a business, that alone tells you it’s a scam.
  • Never share your screen with someone who called you out of the blue. A legitimate business does not need to watch you log in.
  • Urgency is the red flag that never fails. Anyone rushing you to move money “to protect it” or verify “right now” is running a script.
  • Do not call the number in a scary text. If you want to check on your account, flip your card over and dial the number printed on the back, or type your bank’s website in yourself.

And if you do get one of these suspicious FaceTime calls, Apple actually wants to know. You can take a screenshot of the call info and email it to reportfacetimefraud@apple.com. Any scam is also worth reporting at ReportFraud.FTC.gov.

The bottom line: a face on a screen is not proof of anything anymore. When someone reaches out to you asking for passwords or screen access, hang up and reach out on a number you trust, or go directly to the website. The safest move is almost always the slowest one, pause and think before you react.

Stay sharp out there, and I’ll see you next week with another catch of the week.

Editor’s note: Rebecca Rutherford works in information technology at Los Alamos National Laboratory.

Search
LOS ALAMOS

ladailypost.com website support locally by OviNuppi Systems