The fraudster called from a number that appeared as 800 302 302. This is the real helpline number of PKO BP bank. However, she was not a bank employee but a fraudster. Unfortunately, criminals can spoof a genuine number.
This time, however, the criminals reached a journalist who immediately realized it was a scam because he does not have an account with PKO BP and the woman had an Eastern European accent. He nevertheless said that he had an account with the bank because he was curious to see what the conversation would be like and how people are defrauded.
– The woman said that a PLN 500 transfer had been made from my account and asked whether that was actually the case. I replied that it was not, and the whole procedure began, designed to frighten and disorient the customer. It is a form of psychological manipulation. I continued the conversation while pretending to be an unaware customer who did not know much about smartphones and banking systems. In the end, the woman wanted me to install the AnyDesk application. I know this program and understand that it would allow the scammers to connect to my phone and take control of it. So I provided a nonexistent device address. When I finally told the fraudster whom she had actually reached, she hung up without saying goodbye – says the istotne.pl portal journalist
Below, you can listen to the entire conversation between the fraudster and the journalist.
In connection with the attempt to take over the phone and account, we immediately contacted PKO BP bank.
– Unfortunately, for more than a year, attempts at this type of fraud have become quite frequent. Fortunately, customers are increasingly alert to them. Criminals exploit weaknesses in GSM infrastructure and can spoof any telephone number – a bank helpline, but also that of the police or prosecutor’s office. Both we and other banks warn about these scams on the bank’s website, login pages, mobile applications, social media and helplines – writes Magdalena Lejman from the PKO BP press team.
– Criminals call people whose data most often comes from social media or leaks from various websites and introduce themselves as bank employees or representatives of another trusted public institution. They often use the pretext of securing an account – informing the victim about an allegedly blocked transfer of a large amount or a suspicious loan or card payment. Taking advantage of the victim’s anxiety, they obtain online banking login details, payment card details and BLIK codes, urge them to install an application or transfer or deposit money into a “technical account”. In reality, the data obtained during the conversation allows them to rob the victim, while an application installed on the victim’s phone is used to steal, for example, authorization codes. We continually warn against situations of this kind. A bank employee will never ask a customer for login details and will never persuade them by phone to install software. We will also never ask anyone to transfer money to a “safe account” or provide BLIK codes. If we have doubts about the caller’s identity, we should hang up and call the bank’s helpline ourselves – adds Magdalena Lejman.
The Polish Bank Association and the police have published relevant warnings: