Data science

Your phone rings, but you don’t hear a voice from the other end? This is how scammers target their victims.

When your phone rings with no voice, it’s often scammers using automated systems to check if your number is active (reconnaissance), building lists for future scams like AI voice cloning to impersonate loved ones or urgent pleas for money, or trying to get personal data, so hang up, don’t engage, and block the number to prevent building lists of active numbers for targeted fraud. 

Why Phone Fraud Starts With A Silent Call

When you answer your phone and there’s no one on the other end, it could be a computer that’s gathering information about you and your bank account. Here’s an experience some of us have had. The phone rings. You pick it up and say “Hello. Hello. Helloooo.” But nobody answers.

It turns out there could be someone on the other end of the line: an automated computer system that’s calling your number — and tens of thousands of others — to build a list of humans to target for theft.

Build A List

Vijay Balasubramaniyan, CEO of Pindrop Security, a company in Atlanta that detects phone fraud, says that in any number of ways, the criminal ring gets your 10 digits and loads them into an automated system. Maybe you gave your number to Target or some other big retailer that got hacked. Maybe you entered an online raffle to win a free iPhone.

How to Stop Unwanted Calls

Why are you getting so many calls? Often, it’s scammers calling. Here’s what to know about blocking unwanted calls, dealing with robocalls, avoiding phone scams, and signing up for the National Do Not Call Registry.

Blocking Unwanted Calls

Scammers can use the internet to make calls from all over the world. They don’t care if you’re on the National Do Not Call Registry. That’s why your best defense against unwanted calls is call blocking. Which type of call-blocking or call-labeling technology you use will depend on the phone — whether it’s a mobile, traditional landline, or a home phone that makes calls over the internet (VoIP).

Robocalls

If you answer the phone and hear a recorded message instead of a live person, it’s a robocall. If you’re getting a lot of robocalls trying to sell you something, odds are the calls are illegal. Many are also probably scams.

Phone Scams

Any scam can happen over the phone. But phone scammers often use common stories. Knowing their tricks will help you spot and avoid the scam. Hang up on phone scammers and hang on to your money.

National Do Not Call Registry

The National Do Not Call Registry was created to stop sales calls from real companies. It’s free to register your home or mobile phone number.

That initial call you get, with silence on the other end, “[is] essentially the first of the reconnaissance calls that these fraudsters do,” Balasubramaniyan says. “They’re trying to see: Are they getting a human on the other end? You even cough and it knows you’re there.”

Gather Account Information

The next step is gathering information about your bank or credit card account. You get a call with a prerecorded voice that tells you, for example, “[we’re] calling with an important message about your debit card. If you are the cardholder please stay on the line and press 1.

How Silent Calls Lead to Scams

Information Gathering: Scammers use these calls to gather data, which can be fed into advanced AI to clone voices or create convincing scenarios. 

Number Verification: A silent call confirms a human answered, marking the number as active for later, more direct attacks (vishing).

What is ‘vishing’?

Have you ever encountered a strange email coming from your bank, a company, social media, or a government agency—but something about it was just odd. Perhaps the wording was odd or the format of the entire email seemed foreign. The act of sending an email to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft is called “phishing”.

If It helps you understand it any better, take the word “phishing” literally. Cyber criminals are ‘fishing’ for your private information posing as an established organization.

How can you detect a phishing email? Below are a few things to look out for that are dead giveaways.

Check The Header

Welcome Longhorn Community!

Enterprise Technology powers the University’s digital ecosystem—delivering tools and services that help the UT Austin community learn, discover, and succeed. What is Duo?

Duo is a Multi-Factor Authentication (MFA) security product that provides an extra layer of protection when accessing online services.

To increase security at the university, MFA will now be required to access online services such as Canvas, Zoom, UT Box, the Qualtrics Survey Tool, and most other services that require you to sign on with your UT EID and EID password.

Why is the University Using MFA?

MFA helps stop cyber-security attacks like phishing. Cyber-security attacks are on the rise with 20% more accounts being compromised in 2019 as compared to 2018. This is the third year in a row of growth in compromised accounts and forecasting predicts this growth will only continue. Compromised student and guest accounts have risen 51% since 2018. MFA makes a difference in reducing compromised accounts.  

Why Duo? Infographic

How Do I Use MFA?

When you sign on to a university web service with your UT EID and EID password, you will automatically be prompted to sign on using MFA, as well. Duo Help Video from Enterprise Technology

In the video below, UT’s Enterprise Technology (ET) introduces Duo, a multi-factor authentication service. Duo is used as an extra layer of security to make logins more secure.

To learn more about Duo and how to use it, you can view the videos below. Closed captioning is available via the [CC] button.

Registration Steps for New Users

The first step in registration is to enroll your device using your UT EID. The device you enroll will be used when you are prompted to authenticate by university web applications protected by MFA.

Follow the instructions below to register your mobile phone or landline. 

Registering Backup Devices

The university strongly recommends that you register more than one device.

In the event that your primary device is lost/stolen/broken, you can use your backup device to add a new one. In the event that your smartphone or tablet is reset to factory settings, you can use your backup device to that smartphone or tablet. If you do not configure a backup device, you will need to contact only device becomes lost, stolen, broken, or reset.

How Do I Register My Devices?

The university strongly recommends that you register more than one device for multi-factor authentication. This way, if your primary device becomes lost, stolen, replaced, or reset to factory conditions, you will be able to use a backup device to re-register the affected device.

Notes: 

  • As of August 9th, 2023, for ITT and affected staff: SMS passcodes will no longer be allowed, and Duo Push will automatically.
  • As of September 26th, 2023, for all UT Austin affiliates: SMS passcodes will no longer be allowed, and Duo Push will automatically be replaced.

About Our Identity Provider

The University of Texas at Austin maintains the Enterprise Authentication service which implements the Service Provider key component of any organisation’s identity management, the Service Provider is designed to work alongside a vast range of web applications. Through integration with popular web servers, this product prioritises privacy and offers a wide range of authorisation features. 

A variety of policy-oriented features

Supports a wide range of platforms including Windows, OSX and more

Automated management of Identity Providers

A flexible Single Sign-On solution for any organisation with complex identity management requirements. With excellent scaling capabilities and highly customisable authentication and data manipulation features, the Identity Provider equips workforces with a tailored SSO experience.

Handles millions of authentication requests per day

Widely adaptable to support custom scenarios

Built-in support for a range of authentication systems

The Identity Provider software allows users to authenticate to a third-party SAML 2.0 Service Provider (SP). Our Identity Provider is also extended to support OpenID Connect (OIDC) through the OIDC OP Plugin. Metadata Aggregator

Built to speed up the process of consuming and querying metadata, the Metadata Aggregator is a relatively general tool that can be easily customised by developers based on your organisation’s needs. This product is especially useful to organisations operating multiple identity providers. 

Provides a web service for querying consumed and processed metadata

Verifies digitally signed metadata

Embedded Discovery Service

Installed alongside a Service Provider, this product grants the user the ability to select their chosen Identity Provider from a smaller list. Through side-by-side installation with the SP, the Embedded Discovery Service enables consistent branding across products.

  • Simple installation and configuration
  • Provides users with an easy-to-navigate list of Identity Providers
  • Supports assistive technologies such as screen readers

Need help with your Shibboleth products?

We have a range of support options for members of the Consortium and general users. Click to find out what support is available to you.

Can filter information by specified elements

All service providers and relying parties must be part of a  or sponsored by a department at The University of Texas at Austin.

For more information, see the below:

Shaping the future of Shibboleth Software

The Shibboleth Consortium is committed to ensuring the longevity of Shibboleth systems. Thanks to the support of our Consortium Members, our team of dedicated developers are able to keep the software freely available to users all over the world. Shibboleth has been at the forefront of identity management software since the early 2000s. Since then, academic institutions, identity federations, and commercial organisations around the world have adopted it as their identity solution. But as reliance on Shibboleth products continues to increase, so does the responsibility to keep it open-source and operational. The Shibboleth Consortium generates vital funding to ensure continuity and helps shape the future of the systems.

Get exclusive access to technical support

As a Consortium member, you will have quick and easy access to the core development team, helping you to promptly troubleshoot your organisation’s queries as and when they arise. Voice phishing, or vishing, is a scam where fraudsters use phone calls (Voice over IP or traditional) to trick people into revealing sensitive personal or financial information, like passwords, bank details, or Social Security numbers, by impersonating trusted entities such as banks, government agencies, or tech support. These urgent calls create fear or offer fake prizes to manipulate victims into divulging confidential data for identity theft or financial fraud. 

How To Recognize a Phone Scam

Phone scams come in many forms, but they tend to make similar promises and threats, or ask you to pay certain ways. Here’s what to know.

There is no prize

The caller might say you were “selected” for an offer or that you’ve won a lottery. But if you have to pay to get the prize, it’s not a prize.

You won’t be arrested

Scammers might pretend to be law enforcement or a federal agency. They might say you’ll be arrested, fined, or deported if you don’t pay taxes or some other debt right away. The goal is to scare you into paying. But real law enforcement and federal agencies won’t call and threaten you.

You don’t need to decide now

Most honest businesses will give you time to think their offer over and get written information about it before you commit. Take your time. Don’t get pressured into making a decision on the spot.

Only scammers demand you pay certain ways

Scammers will often insist you pay in a way that makes it hard to get your money back How Gift Card Scams Work

Gift card scams start with a call, text, email, or social media message. Scammers will say almost anything to get you to buy gift cards — like Google Play, Apple, or Amazon cards — and hand over the card number and PIN codes. Here are some common tactics scammers use in gift card scams:

  1. Scammers will say it’s urgent. They will say to pay them right away or something terrible will happen. They don’t want you to have time to think about what they’re saying or talk to someone you trust. Slow down. Don’t pay. It’s a scam.
  2. Scammers will tell you which gift card to buy (and where). They might say to put money on an eBay, Google Play, Target, or Apple gift card. They might send you to a specific store — often Walmart, Target, CVS, or Walgreens. Sometimes they’ll tell you to buy cards at several stores, so cashiers won’t get suspicious. The scammer also might stay on the phone with you while you go to the store and load money onto the card. If this happens to you, hang up. It’s a scam.
  3. Scammers will ask you for the gift card number and PIN. The card number and PIN on the back of the card let the scammer get the money you loaded onto the card — even if you still have the card itself. Slow down. Don’t give them those numbers or send them a photo of the card. It’s a scam.

Common Gift Card Scams

Scammers tell different stories to get you to buy gift cards so they can steal your money. Here are some common gift card scams: Scammers pretend to be from government agencies like the FTC, Social Security Administration, and IRS — or say they’re calling about your Medicare benefits. They contact you and say that, if you don’t pay or give them your personal information, something bad will happen. Or maybe you’ll miss out on some government benefit. But it’s a scam. Learn the signs and avoid the scam.

What To Know About Government Impersonation Scams

A government impersonation scam often starts with a call, email, text, or social media message from someone who says they’re with a government agency. They might give you their “employee ID number” to sound official. And they might have information about you, like your name or home address.

They often say they work for the FTC, Social Security Administration, IRS, or Medicare — but sometimes they give you fake agency names, like the non-existent National Sweepstakes Bureau. They’ll also give you some reason why you need to send money or give them your personal information immediately. If you get a call or message like this, hang up or ignore it. It’s a scammer.

Government agencies will never call, email, text, or message you on social media to ask for money or personal information. Only a scammer will do that.

 How to avoid the scam

Social Security Administration Impersonation Scams

The scam: You get a call, email, text, or message on social media that says it’s from the Social Security Administration. They say your Social Security benefits will end, or your Social Security number will be suspended, unless you pay immediately. They insist the only way you can fix the problem is to pay with gift cards, a wire transfer, cryptocurrency, or a payment app. They may even threaten that you’ll be arrested if you don’t pay. But it’s not the Social Security Administration calling. Your benefits won’t be suspended, and you don’t owe anything. What Is Identity Theft?

Identity theft is when someone uses your personal or financial information without your permission.

They might steal your name and address, credit card or bank account numbers, Social Security number, or medical insurance account numbers. And they could use them to

  • buy things with your credit cards
  • get new credit cards in your name
  • open a phone, electricity, or gas account in your name
  • steal your tax refund
  • get a job
  • get medical care
  • pretend to be you if they’re arrested

How To Know if Someone Stole Your Identity

It pays to know how to tell if someone stole your identity. Here’s how to tell if identity theft has already happened:

Get and review your credit reports. Accounts in your name that you don’t recognize could be a sign of identity theft. 

Track what bills you owe and when they’re due. If you stop getting a bill, that could be a sign that someone changed your billing address and may be misusing your information as an identity thief.

Review your bills. Charges for things you didn’t buy could be a sign of identity theft. So could a new bill you didn’t expect.

Check your bank account statement. Withdrawals you didn’t make could be a sign of identity theft.

How To Get Your Free Annual Credit Reports

How do I order my free annual credit reports?

The three nationwide credit bureaus — Equifax, Experian, and TransUnion — have a centralized website, toll-free telephone number, and mailing address so you can order your free annual reports in one place. Do not contact the three credit bureaus individually. 

About Credit Reports

What is a credit report?

What’s Your Credit, and Why Does It Matter?

When people talk about your credit, they mean your credit history. Your credit history describes how you use money. For example:

  • How many credit cards do you have?
  • How many loans do you have?
  • Do you pay your bills on time, or are you late on payments?

How you’ve handled your money and bills in the past helps lenders decide if they want to do business with you. Your credit history also helps them determine what interest rate to charge you.

Who cares about your credit history?

Lenders, landlords, insurance companies, and potential employers are a few examples of who might look at your credit history. Your credit history can make a big difference when you

  • apply for a loan or credit card
  • look for a job
  • rent an apartment
  • buy or lease a car
  • apply for rental or home insurance

How Do You Know If Your Credit Is Good?

“Good” or “bad” credit is based on your credit history. You probably have “good” credit if your credit history shows that you paid your bills on time and didn’t borrow more than you could afford to pay back. You might have “bad” credit if your credit history shows few or no bills paid back, that you paid your bills late, or that you couldn’t afford to pay back the full amount you borrowed. If a Business Denies You Credit or Offers Less Favorable Terms Disputing Mistakes on Your Credit Report

If you get one of these notices and think there’s a mistake with your credit report Credit bureaus sell the information in your report to businesses that use it to decide whether to loan you money, give you credit, offer you insurance, or rent you a home. Some employers use credit reports in hiring decisions. The strength of your credit history also affects how much you will have to pay to borrow money.

The credit bureaus must

give you a free copy of your report once every 12 months

make sure that the information they collect about you is accurate

Is Your Credit Report Accurate?

The information in your credit report can affect your buying power and your chance to get a job, rent or buy a place to live, and buy insurance. Credit bureaus sell the information in your report to businesses that use it to decide whether to loan you money, give you credit, offer you insurance, or rent you a home. Some employers use credit reports in hiring decisions. The strength of your credit history also affects how much you will have to pay to borrow money. You’ll want to be sure the information in your report is both accurate and complete. Find out by regularly checking your credit report. You have the right to get free copies of your credit report from each of the three major credit bureaus once every 12 months. Protect documents that have personal information

Keep your financial records, Social Security and Medicare cards, and any other documents that have personal or financial information in a safe place. When you decide to get rid of them, shred them before you throw them away. If you don’t have a shredder, look for a local shred day in your community, or use a marker to block out account numbers.

If you get statements with personal information in the mail, take your mail out of the mailbox as soon as possible.

Ask questions before you give out your Social Security number

Some organizations need your Social Security number to identify you — like the IRS, your bank, and your employer. But those organizations won’t call, email, or text you to ask for it. If they do, it’s a scammer.

Other organizations that might ask you for your Social Security number might not really need it. For example, a medical provider, a company you’re doing business with, or your child’s school. Ask these questions before you give them your Social Security number:

  • Why do you need it?
  • How will you protect it?
  • Can you use a different identifier?
  • Can you use just the last four digits of my Social Security number?

If you’re not satisfied with their answers, don’t share your Social Security number.

Protect your information from scammers online and on your phone

1. Lock Your Phone

Set your phone to lock when you’re not using it and create a PIN or passcode to unlock it. Use at least a 6-digit passcode. You also might be able to unlock your phone with your fingerprint, your retina, or your face.

Secure Your Home Wi-Fi Network

Your router is the access point between your devices and the internet. If malware gets onto any device connected to your home network, it can spread to other devices connected to the same network. 

Protect Your Online Accounts with Strong Passwords and Two-Factor Authentication

Your online accounts may contain a lot of your personal information. Protect them with a strong password that’s hard to guess and turn on two-factor authentication.

Passwords

When it comes to passwords, you have a few options:

  • create your own password
  • choose an automatically generated password
  • use a password manager

Create your own password. If you create your own password, make it long. Aim for at least 15 characters. Use a combination of uppercase and lowercase letters, numbers, and symbols.

Since a long password can be hard to remember, you may find it easier to use a passphrase. A passphrase is a series of words separated by spaces. If you use a passphrase

  • make sure it consists of random words
  • avoid using common phrases, song lyrics, or movie quotes that are easy for a hacking program to guess

Choose an automatically generated password. Studies show that people aren’t good at creating and remembering strong passwords.

Why a Password Alone Isn’t Enough

Like most people, you probably use a strong password to protect your accounts. But hackers use different tactics to steal or guess your passwords. How To Recognize Phishing

Scammers use email or text messages to try to steal your passwords, account numbers, or Social Security numbers. If they get that information, they could get access to your email, bank, or other accounts. Or they could sell your information to other scammers. Scammers launch thousands of phishing attacks like these every day — and they’re often successful.

Scammers often update their tactics to keep up with the latest news or trends, but here are some common tactics used in phishing emails or text messages:

Phishing emails and text messages often tell a story to trick you into clicking on a link or opening an attachment. You might get an unexpected email or text message that looks like it’s from a company you know or trust, like a bank or a credit card or utility company. Or maybe it’s from an online payment website or app. The message could be from a scammer, who might

  • say they’ve noticed some suspicious activity or log-in attempts — they haven’t
  • claim there’s a problem with your account or your payment information — there isn’t
  • say you need to confirm some personal or financial information — you don’t
  • include an invoice you don’t recognize — it’s fake
  • want you to click on a link to make a payment — but the link has malware
  • say you’re eligible to register for a government refund — it’s a scam
  • offer a coupon for free stuff — it’s not real

Here’s a real-world example of a phishing email:

Image

Netflix phishing scam screenshot

Imagine you saw this in your inbox. At first glance, this email looks real, but it’s not. Scammers who send emails like this one are hoping you won’t notice it’s a fake.

Here are signs that this email is a scam, even though it looks like it comes from a company you know — and even uses the company’s logo in the header:

  • The email has a generic greeting.
  • The email says your account is on hold because of a billing problem.
  • The email invites you to click on a link to update your payment details.

While real companies might communicate with you by email, legitimate companies won’t email or text with a link to update your payment information. Phishing emails can often have real consequences for people who give scammers their information, including identity theft. And they might harm the reputation of the companies they’re spoofing.

How To Get Fewer Spam Emails

  • Use an email filter. Check your email account to see if it has a tool to filter out unwanted emails or to funnel them into a junk email folder. Many email providers (like Gmail or Yahoo) have strong spam filters turned on by default. But there are ways to make them work even better. For example, if any spam makes it through to your inbox, mark it as spam or junk. Filters aren’t perfect, so even emails that make it past the filter might still be spam. Also, check your spam or junk folders occasionally to make sure non-spam email didn’t end up in there.
  • Block unwanted emails. Check your email provider’s settings for steps to block unwanted emails. Try blocking specific email addresses or email domains (the part of the address after the @). 

Check to see how companies will use your email address.

  • When you give a company your email address, it might share or sell it to third parties. Checking a company’s privacy policy might help you see how they’ll share your contact information. 
  • Unsubscribe from unwanted emails. Many email providers have features that help you unsubscribe from email lists. They may show up as a banner or as a button when you open the email. To find out what options your email provider has, search online for the name of your email provider, plus “how to unsubscribe from unwanted emails.” 

How To Protect Your Device from Spammers

Protecting your device is another way to cut down on spam by keeping spammers from using it to send you still more spam. Hackers and spammers scan the internet looking for computers, phones, tablets, and other connected devices that aren’t protected by up-to-date security software. 

What Is Malware?

Malware is harmful software that’s installed on your device without your knowledge. Viruses, spyware, and ransomware are common types of malware.

Criminals use malware to steal your personal information, like your usernames and passwords, bank account numbers, or Social Security number. 

Criminals may also install malware and use it to

  • send you unwanted or inappropriate ads
  • demand payment to unscramble data encrypted by ransomware
  • make your device vulnerable to even more malware

Protect Against Malware

Use security software keep Your Software Up to Date criminals look for weak points to exploit before software companies can fix them. 

3 Comments On “Your phone rings, but you don’t hear a voice from the other end? This is how scammers target their victims.”

Leave a Reply

Your email address will not be published. Required fields are marked *