HUNTSVILLE, Alabama — ATT is warning customers to be wary of spoofing and
phishing scams after a Huntsville man was contacted early this week by a con
artist claiming to be a security representative with the telecommunications company.
Ron Schneider, a retired St. Louis police officer and
consultant to GM Dealerships for Maritz, Inc., said he received a phone call
Monday on his wireless home phone from a man with a far Eastern accent, stating
he was with ATT’s security department.
The caller, who knew Schneider’s email address, said Schneider’s
account had been compromised by an entity in Russia and that his username and
password needed to be reset after ATT shut down his account for his
security.
The scammer asked Schneider if he had received an email
from ATT the night before confirming the issue.
“I was sitting at my computer and could not find any
notification from ATT and asked him to send it again while I was at the
computer,” he said. “He said he sent it again and after several attempts to
refresh my inbox, it had not come through. He stated that my email address had
apparently been taken off the server.”
Schneider, who lives in the
Hampton Cove area, said he became really suspicious when the man asked if he had used
his email account to make purchases, access online banking services or for
gaming within the last two months.
Schneider, who believes the
incident might be related to the recent Target breach, said his email account
was set up by his employer and is not used for any of those services. When
Schneider told the scammer that he didn’t believe his story and asked for a
1-800 number to call ATT back, the fraudster apparently gave him a bogus
number.
After Schneider hung up the phone, he dialed the number that
was listed on his caller ID.
“My phone listed the number as 661-748-0240,” he said. “When
I dialed it back, a recording stated that this number was disconnected. I
waited a little longer and called it a second time and another recording stated
that this call could not be completed as I was trying to reach a ‘Skype user.'”
Since the incident, Schneider has contacted ATT, the
Better Business Bureau and the Federal Trade Commission about his experience. “I think it’s important to let the public know
about the new twist in scams as they are uncovered,” he said.
ATT spokesman Lance Skelly
said Schneider’s experience isn’t an isolated incident, as they are hearing
similar reports in Georgia. He said there is no way to determine exactly how or
where Schneider’s information was initially obtained.
Skelly said all wireless
customers, regardless of carrier, should stay on top of spoofing and phishing
scams because criminals are always changing their tactics.
“Caller ID spoofing
is a technique used by criminals to falsify the telephone number and/or name
that appears on a person’s Caller ID so it appears as if the calls are coming
from another source, like a well-known company,” he said. “These criminals then
use another tactic called phishing to trick customers into sharing personal
information over the phone, allowing them to gain access to wireless accounts.”
Skelly said
victims of phishing scams are usually asked to reveal personal information, such as
a Social Security number, password, address or last name.
Michele Mason, president and CEO of the Better Business Bureau of North Alabama in Huntsville, said she works with similar scams every day.
“While
it’s possible this is connected to the Target breach, it sounds like the only
information the caller had was an email account and phone number, which can be
found other ways — especially if it is a business account that may be
advertised on a website along with a number,” she said.
Mason said Schneider’s incident
sounds like a scam the BBB has been seeing where a fraudster pretends to be a tech-support
employee from a well-known company, like Microsoft, saying there has been an
issue with the victim’s account.
“Typically, this scenario is used to get the consumer to provide access to their computer,
as well as possibly an email account, which the scam artist will use to scam
others in their address book, as well as scan files or monitor their keystrokes
to steal financial/account information,” she said.
ATT
provides the following tips:
- Never give out personal
information in response to an incoming call. Identity thieves are clever –
they often pose as representatives of banks, credit card companies,
creditors, or government agencies to get people to reveal their account
numbers, Social Security numbers, mother’s maiden names, passwords and
other identifying information.
- If
you get a call from a company or government agency seeking personal
information, don’t provide it. Instead, hang up and call the phone
number on your account statement, in the phone book, or on the company’s or
government agency’s website to find out if the entity that supposedly called
you actually needs the requested information from you.
- Please
let the FCC know about ID spoofers by calling 1-888-CALL-FCC or filing a
complaint at www.fcc.gov/complaints.
