Do you Know what Spoofing is? And 5 Questions to Test Your Knowledge on Fraud Awareness

 

Headlines these days are full of stories of people being taken advantage of by scammers or people trying to commit fraud. A few weeks ago, the small town where is family is from was hit hard by a flood – and while the community outreach in the aftermath was heartwarming, it was heartbreaking to hear how fast scammers and bad actors mobilized to take advantage of those in a vulnerable situation.

Awareness is key, and the more we talk about what’s going on, the better prepared we can be to take the necessary precautions.

To that end, let’s talk about the term “spoofing”.

Do you know what the term “spoofing” means?

Bad actors make use of technologies and, specifically, Artificial Intelligence (AI) as one of the main tricks of their trade –  it’s particularly bad because they use them to imitate someone or a program -Spoofing – to pretend to be a trusted friend, boss, or company – with the intention to trick you into giving them money or personal data.

In the spirit of sharing knowledge, and in honor of all the kiddos heading back to school this time of year, I thought it might be fun to share a quiz to test your fraud awareness knowledge!

So, without further ado… grab a cup of coffee or tea, and let’s get set.

Quiz:  How Fraud Savvy are You?

1. Your bank is calling.

Your phone rings and Caller ID shows the name of your bank. The person on the other end tells you there’s been suspicious activity on your account and they need to verify some information.

What do you do?

A. Give them the information. Caller ID says it’s my bank.
B. Ask them a few questions first to make sure they really work there.
C. Hang up and call my bank using a number I know is legitimate.
D. Stay on the phone, but don’t give them my Social Security number.

The answer: C

Unfortunately, we can’t trust always trust Caller ID because bad actors/scammers can “spoof” a phone number so the call appears to be coming from your bank, a government agency or even someone you know.

If someone unexpectedly contacts you about your financial accounts, hang up and independently verify the information by contacting the institution yourself using the number on your card, statement or official website.  Never call a number the caller gives you.

Remember: Verify the person contacting you and not just the story they’re telling you.

2. Your grandson needs help. NOW.

You get a frantic call from someone who sounds remarkably like your grandson. He’s traveling, and he’s been arrested. He needs bail money immediately and insists you do not call his parents.

What’s the biggest red flag?

A. He’s traveling.
B. He needs money.
C. He sounds panicked.
D. He wants you to act immediately and keep it a secret.

The answer: D

The combination of urgency, emotion, and secrecy signals they may be trying to get you do something in the moment that you would not normally do given a few minutes to think it through.

Additionally, the use of AI in these age-old “grandparent scams” is unsettling because they can use the technology to imitate someone’s voice.

So even if it sounds like someone you love, stop and give yourself some time to think.  Then, call your family member directly using the number already stored in your phone, and/or call their parent, and ask a question only they would know.

Remember:  When someone desperately wants you to act before you have time to think, pause and give yourself time to think.

3. How many passwords do you have?

Which of these is the best password strategy?

A. One incredibly complicated password that I use everywhere.
B. Unique passwords for my accounts, plus multi-factor authentication when available.
C. Basically the same password everywhere, but I change a number at the end.
D. Easy passwords I can remember. Life is complicated enough.

The answer: B

A unique password will help contain any damage that may be caused by compromised access.  If you reuse the same, or similar, password for all your accounts, one compromised account could potentially give a bad actor access to several others.

The use of tools like multi-factor authentication and a reputable password manager add additional layers of protection.

Remember: One stolen password should not unlock your entire digital life.

4. The email looks completely legitimate.

You receive an email that looks very real, with the right logo, your name is spelled correctly, and the grammar is perfect. And, it looks exactly like emails you have received from this company before.

Is it safe to click?

A. Yep. Scammers make obvious mistakes.
B. Yes, because they know my name.
C. Not necessarily. I should verify the sender and go directly to the company’s website or app.
D. If the company logo is there, I’m good.

The answer: C

Traditionally, we have told people to look for misspellings and awkward language to spot scam emails. This is still solid advice, but once again, AI use helps bad actors and scammers create convincing emails, texts, and websites as well as imitate voices.

If you receive an unexpected message asking you to log in, make a payment or provide information, don’t use the link in the message.  Again, verify the information independently by opening the app, typing the website into your browser or calling the company directly (via a phone number found on their actual website browser).

Remember: Looks can be deceiving.  Always verify where the information is coming from.

5. Microsoft is calling about that virus on your computer.

Someone calls and says they’re from Microsoft, and they’ve found a virus on your computer, but they will need remote access to fix it.

What should you do?

A. Let them in but watch closely.
B. Ask them to prove they work for Microsoft.
C. Let them in as long as they don’t ask for banking information.
D. Hang up.

The answer: D

Please hang up.  Legitimate companies will not random call you because they’ve detected a virus on your computer and need remote access.

Remember: If someone you didn’t contact wants access to your computer, the answer is no.

BONUS:  Your mom says, “I think I did something stupid.”

She tells you she may have given a scammer access to her computer.  You can tell she’s embarrassed and scared.

What’s the best response?

A. “Mom! Why would you do that?”
B. Help her stop communication with the scammer and quickly contact the appropriate financial institutions.
C. Wait a few days and watch her accounts.
D. Tell her she can’t manage her finances anymore.

The answer: B

I included this question very intentionally.  When my mom called me after her scam experience, I will never forget the fear in her voice.

For older adults, admitting they’ve made a financial mistake can feel like admitting they’re losing their independence. If they think the response will be anger, judgment or having control taken away from them, they may be less likely to tell us when something happens.

Remember:  Open communication is part of fraud protection too.  Create an environment where people you love can say “Something happened and I need help”.

Given all this doom and gloom about AI and the use of technology by bad actors, it may be tempting to believe that AI is bad – I suspect we’ll be debating the use of AI for years and years to come – but right now, I don’t believe that AI is inherently bad.  In the world of “AI everything”, it’s important to remember that as humans, we have something that technology doesn’t offer – judgement, common sense and the ability to interpret our experiences.

I hope this quiz was at least a little fun to read through, if not a meaningful, yet friendly reminder that we need to be intentional about these conversations.  Talk about fraud.   Talk about it with your parents. Your kids. Your friends. Your spouse. Share the ridiculous scam text you received. Tell someone about the email that almost fooled you. Make these conversations normal.

Because none of us are immune.  And the more we talk about how these scams work, the harder we make it for the bad actors to succeed.

Additional Resources Available Online:

TOPICS: Fraud

Leave a Reply

Your email address will not be published. Required fields are marked *