The Bank of Hawaii early alert of scam phone calls spoofing caller ID

Caller-ID-Spoofing1In an early-alert sign, The Bank of Hawaii is warning of a spate of scam phone calls that are spoofing the caller ID of the bank’s real call center, the Honolulu Star-Advertiser reports. The bad guys are likely to repeat scams like this nationwide or even worldwide, so it pays off to watch for this.

The scammers are posing as the bank’s fraud center and asking recipients to verify their Social Security number, date of birth, and debit card PIN. The Bank of Hawaii emphasizes that it doesn’t ask for personal information via phone calls, emails, or text messages, and recommending that anyone receiving such a call should hang up the phone immediately.

Caller ID spoofing is easy, and can be done with many free tools online, so the caller ID display shouldn’t be treated as a verification that the person on the other end is who they say they are. You should immediately be on guard if someone begins asking for information over the phone. If a company or government agency calls you and asks for information, you should hang up and call the company or agency using the contact number on their website or the number printed on the back of the card. In most cases, the call will turn out to be a scam.

Organizations should have processes in place to prevent sensitive data from being exfiltrated over the phone. New-school security awareness training can teach your employees to be extremely suspicious the moment someone asks for personal or sensitive information over the phone. The Honolulu Star-Advertiser has the story:

Can hackers spoof an email address of your own domain?

DSTAre you aware that one of the first things hackers try is to see if they can spoof the email address of your CEO? If they are able to commit "CEO Fraud", penetrating your network is like taking candy from a baby.

Now they can launch a "CEO fraud" spear phishing attack on your organization, and that type of attack is very hard to defend against, unless your users are highly ‘security awareness’ trained.

Find out now if your domain can be spoofed. The Domain Spoof Test (DST) is a one-time free service. Run this test so you can address any mail server configuration issues that are found.

Try To Spoof Me!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

Subscribe To Our Blog

Comprehensive Anti-Phishing Guide

Get the latest about social engineering

Subscribe to CyberheistNews