If it sounds fishy

Posted by Common Sense Security on 19. September 2012as

Last night I got a call from my friend Jane. She said, “I need your advice. I called my credit card’s customer service number and they immediately offered me a voucher to $100 which I can spend any way I want. The only thing they want me to pay is $4 for shipping and handling. They ask for my credit card number and I am not sure if I should give it to them. It’s unusual behavior for my card’s customer service. What should I do?”

I answered, “Is it possible that you misdialed that customer service number? On the internet crooks will often register a web address that is a common typo of a legitimate business web address. Then they can steal information and maybe money too by pretending to be that legitimate business. They can do the same thing with a phone number.”

Later, Jane called me and said that yes, the numbers on the card were so small, she misread that toll-free number. I was very proud of her: most people in her situation would be thrilled to get free $100, would not get suspicious, and would provide lots of their private information to the fraudsters.

When we call someone ourselves, we feel confident that we are talking to the right party. When we misdial a number or mistype a web address, it does not occur to us to check for possible mistakes. I learned a lesson today: double-check a phone number you dial if you are calling your bank, your credit card provider or any other place where you have to provide substantial private information. And if it sounds fishy, triple check before doing something you may regret later.

Be safe!

Leave a Reply