What is Nostr?
BrianKrebs /
npub1rfd…t9xk
2025-02-25 20:38:18
in reply to nevent1q…84nv

BrianKrebs on Nostr: I keep getting financial industry people reaching out about this story to say how ...

I keep getting financial industry people reaching out about this story to say how much fraud they are now seeing from peoples' payment card data being phished and loaded onto mobile wallets just by also phishing a one-time code out of victims.

One thing I think a lot of people are missing with this type of fraud is that while it is ideal for the phishers to coax that one-time code out of victims at the same time they are phishing the card data, it doesn't have to be that way.

What I'm getting at here is that this method of turning phished data into mobile wallets essentially allows card data that was previously only good for online transactions (i.e. it was stolen from an ecommerce vendor) to be "enriched" at any point going forward and turned into a mobile wallet.

In other words, the phishing of the one-time code sent by the victim's bank in response to a request to link their card to a mobile wallet can happen out of band, well after the fact, and under any pretext.
Author Public Key
npub1rfdvtvmesnz7x7s3hjg5q2dgrup9xfh209gvj36angljrfy5edtq25t9xk