Using Asterisk to Scam Credit Cards

Received a news tip that fraudsters are using Asterisk as a "collection tool" for their credit card scam. While that's nothing new by itself, since there are plenty of scammers leveraging Asterisk, I found it fascinating to be able to actually call into the scammer's system.

Asterisk has become hacker's tool of choice because it's free, flexible, and feature-rich. Just install Asterisk on an inexpensive PC and you have yourslf a powerful PBX that can war dial hundreds of phone numbers while forging the outbound CallerID. Often referred to as "vhishing" or voice phishing, a vishing attack is easy to do using Asterisk.

You can war dial and leave a recorded message to hundreds of people, telling them that their credit card number has been stolen and that they need to call a specific phone number to resolve the issue.

Anyway, a reader told me today he just received an email "from" Capital One asking to call (866) 473-0719 for fraud verification. He believes that this number is routed to an Asterisk box since he recognized that the scammer is using Festival text-to-speech (TTS) to ask the questions. It certainly sounds like Festival to me as well. Yeah, like a credit card company would 100% TTS for their credit card verification system. Well, a sucker is born every minute, so some people might fall for it.

here's the email he received:
We detected irregular activity on your debit card on 08/03/2008.
We have attempted to contact you to verify your account information, and unfortunately all methods of contact have been unsuccessful.

For your protection, your account has been disabled until we are able to verify your information to prevent any misuse of your account.

Please call customer service at (866) 473-0719 to activate your account.

Interestingly, the scammer is not checking if the credit number entered is valid or not - you can enter 16x 0 and the system will accept it.

What's odd is that the autoattendant is saying stuff about "credit card activation" not credit card fraud verification. So who is going to call this number and activate a CapitalOne card that they've owned (& already activated)? I guess we need to see P.T. Barnum's "there's a sucker born every minute" again to answer that question.

Also, the VoIP or TTS quality on their line stinks. Very choppy. Some of the TTS words were garbled or completely cut off. Maybe the mass blast spam they're sending out is using all their VoIP bandwidth?

Well, nothing like having some fun with dumb criminals. So go have some fun and pester the scammer with invalid credit card numbers.
| 0 Comments | 0 TrackBacks

Listed below are links to sites that reference Using Asterisk to Scam Credit Cards:

Using Asterisk to Scam Credit Cards TrackBack URL : http://blog.tmcnet.com/mt/mt-tb.cgi/36895

Leave a comment

Recent Activity

Today

  • Tom Keating queued The Blind Side

Sunday

Sunday

  • Tom Keating tweeted, "Moving a Data Center: Moving a data center can be fun. Yes, if you enjoy being up from 6am (Friday) to 2am (Satur... http://bit.ly/cX6L0j"
  • Tom Keating posted Moving a Data Center

Friday

  • Tom Keating tweeted, "Tearing down TMC's entire network infrastructure. My sweet beautiful network! [sniff] [sniff]"

Thursday

  • Tom Keating tweeted, "why the heck am I still awake when I have an all-nighter tomorrow moving the entire #TMCNet data center? (www.tmcnet.com) fun fun!"
  • Tom Keating tweeted, "No, Gremlins Didn't Eat TMCNet's Web Servers: Starting tomorrow around 7am, TMC will be shutting down its entire d... http://bit.ly/bS3OOn"

More...

Recent Comments

  • Peter Radizeski: I'm not certain that is accurate. The staff for VON read more
  • טכנאי מחשבים: Fast, organized, thorough, non-intrusive, and free! THANKS AVG. read more
  • SomeGuy: I've had sipgate setup for less than 24 hours on read more
  • Uverse instaler: Being a uverse installer in the StL area, I can read more
  • Roger: Dan did you find out what the music is?? I read more
  • VoIP Spear: I don't think this site is active anymore. You can read more
  • Mamrez: Hi guys , I'm looking for cracked MOBILELOG for iphone read more
  • Symplicity: Works amazing thanks :) read more
  • wirefly customer: I got my phone from wirefly and it turned out read more
  • Maher: Dear Sir, I am looking for a slim credit card read more

Subscribe to Blog

Recent Entry Images

  • apple-ipad.jpg
  • google-nexus-one.jpg
  • freetalk-connect.jpg
  • freetalk-connect.jpg
  • calliflower-skype.jpg
  • itexpo-logo.jpg

Entry Archives

Around TMCnet Blogs

  • Communications and Technology Blog - Tehrani.com:
    Apple Antitrust Issues
  • On Rad's Radar?:
    Endstream Plans
  • VoIP & Gadgets Blog:
    Moving a Data Center
  • Communications and Technology Blog - Tehrani.com:
    IfByPhone Interview ITEXPO East 2010 Miami
  • First Coffee:
    Frost & Sullivan Webcast, LCEC and ENERGYprism, IDC for
  • On Rad's Radar?:
    Freeside's new CEO
  • The Readerboard:
    Tune In, Call in (And Donate), 'Hope for Haiti
  • VoIP & Gadgets Blog:
    No, Gremlins Didn't Eat TMCNet's Web Servers
  • Latest Whitepapers

    TMCnet Videos