Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Banks in my country send all sorts of emails with "scammy" subjects, and then when you open them their banner says "Don't fall for such scams" or "Scams start this way". Maybe if they added an option to opt-out of such emails, it would be pretty nice! Now it's just more inbox noise.

And of course, their "scam-like" emails end up in the inbox, while real scammers emails would end up in the Spam folder.



Banks in the UK do all sorts of scammy things, not for that purpose, but as part of their usual business

Judging by their frequent and long lectures about how I'd be liable for any fraud, it sounds like they've absolved themselves of responsibility too well to need to improve fraud protection

They send email from an unfamiliar domain, not the one customers know from their website, nor a subdomain thereof

They call customers and ask for security information

They ask for one-time codes on some calls from customers, but they also separately say it's something that only fraudsters do

All of the above risk causing customers to lower their guard to fraud

They fail to recognise repeat payees to validate payment details when taking international transfer instructions by phone, which risks fraud (if an invoice seeming to be from a regular supplier is actually from a fraudster) or other loss (if the payment details are misheard)

They also fail to recognise repeat payees when using transaction history to flag unusual activity, which only increases false positives, so it isn't as bad, but it's still annoying


> They send email from an unfamiliar domain, not the one customers know from their website, nor a subdomain thereof

Prime example, Santander

From: Santander <santander@email2.yoursantander.co.uk>

Subject: Know more about Facebook Scams

Congratulations Santander, you've now trained your customers to trust emails from domains like "email2.your<business>.co.uk"


I thought that only in my country the banks' "security" turned fucking retarded but it seems it's a global trend. Recently I received legit email from my bank with warning against scammers and the title was "The first step of the scammer will be will be sending an email, text message, or calling you". Is it a double intelligence test or they just admitted to being scammers?


> And of course, their "scam-like" emails end up in the inbox, while real scammers emails would end up in the Spam folder.

Perhaps you meant this the other way around?

Either way, I have received quite a steady stream of rather obvious phishing attempts directly to my inbox on Outlook.com. Once our twice a month I have a missed Amazon package, or some horrible debt, or an being investigated for tax fraud or other such.


No I mean that if my bank sends me an email with a scammy subject, it won't get caught in the spam filter because everything else is legit, like the From field, their verified domain, email signatures, and the body content. They use the same domain and presumably the same email address to send such emails and other important emails too.

But if a scammer sends me a fake email, it'll probably get caught in the spam filter of my email provider (hopefully).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: