pwshub.com

An ex-Mastercard executive was nearly scammed of $100,000. Here's how she spotted it.

hacking

A former MasterCard vice president of product shared her tips for avoiding account takeovers after almost falling victim to one.Peter Dazeley/Getty Images

  • A former Mastercard executive almost lost $100,000 to an account takeover scam.

  • Scammers accessed her real-estate agent's email and impersonated a title company.

  • Account takeover fraud surged 354% in 2023, causing $13 billion in losses, researchers say.

It can happen to anyone, it seems. Even those who work in the finance industry.

A former Mastercard executive told Business Insider she nearly lost $100,000 to an account takeover scam last year.

Catherine Woneis, former vice president of CipherTrace, a service owned by MasterCard that helps secure crypto transactions, says she almost lost most of her life savings after scammers accessed her real-estate agent's email.

Account takeover fraud is when scammers gain access to your social media, email, banking, or other personal accounts. Criminals usually gain access to accounts with stolen credentials that they purchase through the dark web or social engineering tactics that trick you into sharing your password, Woneis said. They then use these accounts to siphon away your hard-earned cash.

The number of known account takeover scams grew by 354% year over year in 2023, resulting in $13 billion in losses, according to AI fraud detection service Sift Science.

In Woneis's case, Scammers accessed her real-estate agent's email using "credential stuffing," a tactic that uses AI bots to try every possible username and password until they fall on the correct answer.

The fraudsters used information found in emails about Woneis's transactions to impersonate the title company for her home. The fake title company then emailed Woneis, asking for an "accelerated" payment.

"This is a very typical thing that criminals use in frauds: They try to implement some time piece," Woneis said.

Woneis said she checked to see if the email address was real and noticed it was appended with another address, but she assumed it was part of the company's automated email system.

"They sent me wire instructions that perfectly mimicked the wire instructions from the title company. They had an example of what that looked like," Woneis said. "It was the exact same typography, the exact same letterhead, and everything else."

The only differences from the real wire instructions were a fake phone number and email, along with incorrect bank information. Woneis said she thankfully called the phone number she originally received from the title company, who informed her the bank account information was incorrect on the form.

"Had I been in a rush and called the phone number on the form, that would have been them, and they would have pretended to be the real estate company saying, 'Yes this is authentic, and it's come from us,'" she said. "We could have potentially been caught in wire fraud."

Woneis said she would have lost about $100,000 if the transaction went through.

Woneis now works for a cybersecurity company called Fingerprint, which she says is developing tools to combat the rise of account takeovers. Some of the keys to fighting this kind of fraud are algorithms that can determine where a website visitor is located (if they're using a VPN) and systems to identify when bots are trying to access a website through brute force, Woneis said.

If you think any of your accounts may be compromised, Woneis says to quickly change all of your usernames and passwords, set up two-factor authentication for any sensitive accounts, and report any fraud to the FTC fraud reporting website.

Read the original article on Business Insider

Source: finance.yahoo.com

Related stories
1 month ago - The US has focused on building domestic supply chains for advanced semiconductors. Now, China is rapidly expanding its own manufacturing capacity for less advanced but more widely used chips.
3 weeks ago - Dividends that can grow above the rate of inflation for years can be huge wealth-builders over time.Although artificial intelligence (AI) stocks...
1 month ago - These are the upcoming stock splits for the week of September 9 to September 13, based on TipRanks’ Stock Splits Calendar. A stock split is a corporate action in which the company issues additional common shares to increase the number of...
3 weeks ago - These are the upcoming stock splits for the week of September 16 to September 20, based on TipRanks’ Stock Splits Calendar. A stock split is a corporate action in which the company issues additional common shares to increase the number of...
3 weeks ago - History shows that Eli Lilly tends to do something special with its stock toward the end of the year.
Other stories
2 minutes ago - Photo: xPACIFICA (Getty Images), NurPhoto (Getty Images), Apu Gomes (Getty Images), A statue of Satoshi Nakamoto, a presumed pseudonym used by the...
2 minutes ago - Cathie Wood is well known for her aggressive investing style. She's poured billions of dollars into electric car manufacturers like Tesla and BYD,...
1 hour ago - One figure points to a significant change that could spark considerable stock price growth.
1 hour ago - The stock market recently hit another all-time high. The S&P 500 is up more than 30% over the past year, driven by a strong economy and falling...
1 hour ago - CRISPR Therapeutics (NASDAQ: CRSP) and Moderna (NASDAQ: MRNA) have much in common. They're both innovative biotechs working in relatively newer...