WEBVTT
1
00:00:01.399 --> 00:00:05.000
This program is designed to provide general information with regards
2
00:00:05.000 --> 00:00:08.000
to the subject matters covered. This information is given with
3
00:00:08.039 --> 00:00:12.400
the understanding that neither the hosts, guests, sponsors, or station
4
00:00:12.640 --> 00:00:19.480
are engaged in rendering any specific and personal medical, financial, legal, counseling,
5
00:00:19.679 --> 00:00:23.839
professional service, or any advice. You should seek the services
6
00:00:23.879 --> 00:00:28.480
of competent professionals before applying or trying any suggested ideas.
7
00:00:30.600 --> 00:00:34.000
The information contained in this podcast is intended for informational
8
00:00:34.000 --> 00:00:37.479
purposes only and is not a substitute for individual professional
9
00:00:37.600 --> 00:00:41.359
legal advice. The podcast information was carefully compiled from vetted
10
00:00:41.439 --> 00:00:45.600
sources and references. However, Rose Resources outreach to safeguard the
11
00:00:45.640 --> 00:00:48.560
elderly cannot guarantee that you will not fall victim to
12
00:00:48.600 --> 00:00:54.079
a scam. Let's talk about scams. It's the must listen
13
00:00:54.159 --> 00:00:57.359
show for anyone who wants to protect themselves and their
14
00:00:57.439 --> 00:01:01.640
loved ones from scams. Every twoesdayday at eight am Pacific
15
00:01:01.679 --> 00:01:06.120
time on K four HD Radio, Joyce Petrowski, founder of Rose,
16
00:01:06.239 --> 00:01:11.120
and her guests will provide valuable insights and practical tips
17
00:01:11.120 --> 00:01:15.000
on how to recognize and protect yourself from scams.
18
00:01:15.280 --> 00:01:19.719
And now here is your host, Joyce Petrowski.
19
00:01:20.159 --> 00:01:25.519
Good Morning, everybody, welcome to let's talk about scams. I
20
00:01:25.560 --> 00:01:29.159
am Brian Watson. I am a community outreach specialist for Rose.
21
00:01:30.040 --> 00:01:32.519
I have been filling in for Joyce and I've really
22
00:01:32.640 --> 00:01:35.840
enjoyed it. Joyce will be back in two weeks, that's
23
00:01:35.879 --> 00:01:40.599
the plan. So she's given me the microphone and letting
24
00:01:40.640 --> 00:01:45.040
me tell some fraud prevention tips with everybody out there.
25
00:01:45.439 --> 00:01:49.359
So thanks for tuning in today. Today's message is phishing
26
00:01:49.439 --> 00:01:53.680
and smishing continue to be a problem, so we're kind
27
00:01:53.680 --> 00:01:57.000
of getting back to the basics here today. Fishing and
28
00:01:57.079 --> 00:02:01.959
smishing are the two scams that we see on a
29
00:02:02.120 --> 00:02:07.079
daily basis. If you have a computer, and you have email,
30
00:02:07.599 --> 00:02:10.599
and you have a cell phone, you are being bombarded
31
00:02:10.719 --> 00:02:13.759
daily by phishing and smashing. So we're going to talk
32
00:02:13.800 --> 00:02:17.599
about both of them today, both the two scams, and
33
00:02:17.599 --> 00:02:21.439
I'm gonna show some examples as well. Because we've talked
34
00:02:21.479 --> 00:02:25.919
about a lot of really complex stuff, things like cryptocurrency
35
00:02:26.000 --> 00:02:31.919
and pig butchering and account takeovers and malware and all
36
00:02:31.919 --> 00:02:35.479
these like big words, but today we're going to get
37
00:02:35.479 --> 00:02:38.159
back to the basics. Fishing and smishing have been around
38
00:02:38.159 --> 00:02:43.599
for a long time. So remember phishing is via email
39
00:02:44.000 --> 00:02:48.319
and think of it as a phony email. The phishing
40
00:02:49.080 --> 00:02:53.919
emails try to trick you into thinking you are dealing
41
00:02:54.080 --> 00:02:57.919
with a company that you know, like a large company,
42
00:02:57.960 --> 00:03:02.360
a store, or a service, or a government agency. So
43
00:03:02.360 --> 00:03:04.120
I want to tell you a story about a scam
44
00:03:04.159 --> 00:03:08.120
that recently happened to a friend of mine. He received
45
00:03:08.280 --> 00:03:14.439
an email purporting to be from Exfinity, and it sounded
46
00:03:14.520 --> 00:03:18.800
very legitimate. It looked legitimate. It had the Exfinity logo,
47
00:03:18.879 --> 00:03:23.400
and it said your your payment was rejected. And you
48
00:03:23.439 --> 00:03:26.439
know a lot of people use a credit card or
49
00:03:26.479 --> 00:03:29.400
a bank account to make that automatic payment every month,
50
00:03:29.479 --> 00:03:32.840
which is what we recommend. We're not fans around here
51
00:03:32.840 --> 00:03:36.800
of writing checks unless you absolutely have to. And it
52
00:03:36.879 --> 00:03:40.319
said click on this button to update your payment information.
53
00:03:40.840 --> 00:03:43.080
So one, if we could pull that first slide number
54
00:03:43.080 --> 00:03:48.280
one up, please This is an example of the actual well, actually,
55
00:03:48.319 --> 00:03:53.240
this is the actual email. See how the Exfinity logo
56
00:03:53.319 --> 00:03:57.319
looks good and it says action required update your payment information.
57
00:03:58.319 --> 00:04:02.159
Your payment was rejected and if you want to keep service,
58
00:04:02.879 --> 00:04:07.439
update payment information. Seems pretty legitimate, right, No, no, no,
59
00:04:07.840 --> 00:04:12.599
this is a phishing email. That purple button right in
60
00:04:12.639 --> 00:04:16.319
the middle is something you never want to click on.
61
00:04:17.600 --> 00:04:20.519
And my friend clicked on that button and it asked
62
00:04:20.600 --> 00:04:24.879
him to start putting in credit card information, which he did,
63
00:04:25.360 --> 00:04:28.079
and when I found out about it, I said, you
64
00:04:28.199 --> 00:04:30.560
need a new credit card because your credit card just
65
00:04:30.600 --> 00:04:35.800
got compromised. This is a classic phishing email. I received
66
00:04:35.800 --> 00:04:38.720
the same one a couple days later. One of the
67
00:04:38.759 --> 00:04:41.040
things you can do I'm not going to do right here,
68
00:04:41.120 --> 00:04:43.360
but if you see what I've done with my mouse,
69
00:04:43.439 --> 00:04:46.040
I don't know if it's showing, but if I were
70
00:04:46.079 --> 00:04:49.720
to hover my mouse over that button, not click on it,
71
00:04:49.759 --> 00:04:53.639
but hover only, it'll show the actual website it's going to.
72
00:04:53.920 --> 00:04:58.759
It's not Exfinity. So this is a classic phishing email.
73
00:04:58.920 --> 00:05:03.360
So why does this scam work? Well, it works because
74
00:05:03.519 --> 00:05:08.160
most people, responsible, responsible adults, pay their bills in a
75
00:05:08.199 --> 00:05:13.240
timely manner and quickly. So my friend pays his bills
76
00:05:13.360 --> 00:05:18.319
every month on time, trust me. And you know he
77
00:05:18.480 --> 00:05:21.720
was busy doing stuff. He saw this. He wanted to
78
00:05:21.759 --> 00:05:24.360
just take care of his obligations. He clicked on it,
79
00:05:24.519 --> 00:05:26.759
so you could see how anybody could fall for this.
80
00:05:27.480 --> 00:05:30.399
So I'm showing you this not to embarrass my friend,
81
00:05:31.160 --> 00:05:35.600
but to it's a lesson for all this So what happens.
82
00:05:36.120 --> 00:05:39.480
So if you click on a link like this, my
83
00:05:39.560 --> 00:05:43.480
friend was asked to fill in credit card information, but
84
00:05:43.560 --> 00:05:46.720
they could also ask for things like your social Security number,
85
00:05:47.040 --> 00:05:51.480
your date of birth, passwords, user names, other financial information.
86
00:05:52.160 --> 00:05:57.560
And these sophisticated criminals could also install malware, which is
87
00:05:57.759 --> 00:06:02.000
malicious software or spyware on your computer without knowledge, and
88
00:06:02.040 --> 00:06:05.040
they could use that to commit identity theft. They could
89
00:06:05.160 --> 00:06:07.680
use that to get all of your passwords, all your
90
00:06:07.720 --> 00:06:11.800
bank account information. So it's very you've got to be
91
00:06:11.879 --> 00:06:13.920
very careful. And here's the other thing. I'm holding up
92
00:06:13.959 --> 00:06:18.319
my phone here. If you get an email like this
93
00:06:18.439 --> 00:06:23.120
from Infinity or Amazon or something similar, don't use this.
94
00:06:23.560 --> 00:06:27.879
This is far too small. The screen is too small.
95
00:06:27.920 --> 00:06:30.319
You can't see what's going on. Only do this stuff
96
00:06:30.360 --> 00:06:33.920
from your home computer where you have a big screen.
97
00:06:35.639 --> 00:06:39.800
So we've basically come to the point where you have
98
00:06:39.839 --> 00:06:44.240
to assume every email you receive is a scam. I
99
00:06:44.279 --> 00:06:46.360
don't like living in a world like that, but that's
100
00:06:46.399 --> 00:06:48.839
the world we live in. I mean, I can get
101
00:06:48.839 --> 00:06:51.240
on the computer right now and have something delivered this
102
00:06:51.319 --> 00:06:54.759
afternoon or tomorrow at the latest, anything I want, pretty much.
103
00:06:55.519 --> 00:06:58.879
But the downside is the criminals can use that information
104
00:06:58.959 --> 00:07:01.439
as well. All right, So here's some common sense tips
105
00:07:01.519 --> 00:07:08.279
on phishing. Re exist the urge to act quickly. See
106
00:07:08.279 --> 00:07:10.519
this email in front of us. It says it's got
107
00:07:10.560 --> 00:07:13.360
ale exclamation point, and they're threatening to shut you off
108
00:07:13.920 --> 00:07:19.759
within twenty four hours. You never have to rush. Read
109
00:07:19.800 --> 00:07:23.360
the email carefully, look for typos, look for incorrect grammar.
110
00:07:24.480 --> 00:07:28.879
Scammers want to use urgency. That's how they get you
111
00:07:29.000 --> 00:07:31.360
to make a bad decision. My friend made a quick,
112
00:07:31.439 --> 00:07:37.040
rash decision and cause an inconvenience. Go for a break,
113
00:07:37.199 --> 00:07:39.399
Take a break, go for a walk. Look at the
114
00:07:39.439 --> 00:07:43.560
email the next day, ask someone else, and I'll mention again.
115
00:07:43.839 --> 00:07:46.920
Just don't use your cell phone. The screen's too small.
116
00:07:47.639 --> 00:07:51.240
Look carefully at the email address, and that's why you
117
00:07:51.319 --> 00:07:53.879
need to use a big computer, because you can't. Usually
118
00:07:53.879 --> 00:07:56.120
you can't do this on your cell phone. Look at
119
00:07:56.120 --> 00:07:58.040
the email where it came from. And I'm going to
120
00:07:58.120 --> 00:08:01.480
show you an example next. So one can we go
121
00:08:01.519 --> 00:08:06.480
to slide too. This is an Exfinity email that I
122
00:08:06.560 --> 00:08:12.399
also received. It was similar and I only highlighted or
123
00:08:12.480 --> 00:08:19.120
only copied a small portion of it. It says from Exfinity.
124
00:08:19.160 --> 00:08:23.319
But look at the email I copied customer service at
125
00:08:23.480 --> 00:08:28.439
wosanitation dot com. That's not coming from Exfinity. That is
126
00:08:28.480 --> 00:08:32.480
a complete scam. And then look at even the title
127
00:08:32.519 --> 00:08:36.480
of this email. The subject line deadline looming your financial
128
00:08:36.559 --> 00:08:41.759
commitment is due. Does that sound like Exfinity would write that. No,
129
00:08:42.240 --> 00:08:46.559
that's probably written by someone living in a foreign country
130
00:08:46.679 --> 00:08:51.519
English second language. And there's some weird font issues there too,
131
00:08:51.600 --> 00:08:54.799
that the eyes are too big. There's some goofy stuff
132
00:08:54.840 --> 00:09:01.639
going on. But classic fishing email. Anytime you have these
133
00:09:01.960 --> 00:09:05.960
phishing emails, don't click on the links. That's what gets
134
00:09:05.960 --> 00:09:09.399
you in trouble. We never click on links. Okay, So
135
00:09:09.480 --> 00:09:12.279
what is what is the safest option? If you're not sure,
136
00:09:12.679 --> 00:09:18.200
just delete it? Okay? You know what's the worst thing
137
00:09:18.240 --> 00:09:23.879
that could happen your email? I mean your cable could
138
00:09:23.879 --> 00:09:26.879
be shut off, But and that's not going to happen
139
00:09:26.919 --> 00:09:28.840
because the whole thing's a scam. So what you want
140
00:09:28.840 --> 00:09:31.159
to do if you're not sure and you want to
141
00:09:31.200 --> 00:09:33.919
sleep at night and you're worried your your cables can
142
00:09:33.960 --> 00:09:38.840
be shut off, contact Exfinity or whatever company directly, and
143
00:09:38.879 --> 00:09:42.000
you never use the number that the scammers provide because
144
00:09:42.480 --> 00:09:44.960
you're going to end up talking to a scammer sitting
145
00:09:45.000 --> 00:09:47.799
in a call center somewhere. You go on the internet
146
00:09:47.879 --> 00:09:52.559
and find Exfinity's legitimate site on your own expinity dot
147
00:09:52.600 --> 00:09:57.600
com or whatever it is, contact customer service and see
148
00:09:57.600 --> 00:10:00.480
if there's an issue with your account. You can also
149
00:10:00.559 --> 00:10:04.679
log into your account using your username and password, and
150
00:10:04.759 --> 00:10:09.120
again never use a link provided by a phishing email,
151
00:10:09.799 --> 00:10:12.279
and you can log in and see what's going on,
152
00:10:13.399 --> 00:10:15.600
you know. And for example, when we always talk about
153
00:10:15.679 --> 00:10:19.200
verified numbers, Let's say you got an email and it
154
00:10:19.240 --> 00:10:22.519
claimed to be from your bank, so I bek it
155
00:10:22.559 --> 00:10:25.080
Wells Fargo. And if I got an email saying there
156
00:10:25.120 --> 00:10:30.120
was something wrong with my account, update my information. Nope,
157
00:10:30.159 --> 00:10:32.879
I delete it. What I do? I flip over my
158
00:10:35.039 --> 00:10:38.840
ATM card here, I call the service customer service number
159
00:10:38.919 --> 00:10:41.440
right on the back. That's a legitimate number we always
160
00:10:41.480 --> 00:10:47.440
call from verified numbers. And then I know, Joyce and
161
00:10:47.480 --> 00:10:50.240
I beat this like a dead horse. But you got
162
00:10:50.279 --> 00:10:53.440
to have a phone a friend. Who is your phone
163
00:10:53.440 --> 00:10:58.440
a friend? Everyone's sitting here right now listening watching our
164
00:10:58.519 --> 00:11:02.480
radio show this morning. Who is your phono friend? Is
165
00:11:02.519 --> 00:11:05.559
it a family member, is it a friend, is it
166
00:11:05.600 --> 00:11:08.799
a neighbor? You know, when you get a phishing email
167
00:11:08.799 --> 00:11:11.840
and you're not sure who would you talk to. Sometimes
168
00:11:12.360 --> 00:11:15.279
phone a friend might be the local police department, you
169
00:11:15.320 --> 00:11:19.039
know what. They would rather help you out and prevent
170
00:11:19.080 --> 00:11:21.279
you from getting scammed than try to track down money
171
00:11:21.360 --> 00:11:25.759
later on. But and you also have someone who's very
172
00:11:25.759 --> 00:11:28.519
tech savvy. Hopefully your phono friend is tech savy, but
173
00:11:28.759 --> 00:11:32.799
sometimes they're like two different people. When I was doing
174
00:11:32.799 --> 00:11:38.720
fraud prevention presentations twenty years ago, phishing was in its infancy,
175
00:11:40.720 --> 00:11:43.720
but a lot of the phishing emails were really, really bad.
176
00:11:44.320 --> 00:11:46.360
They were almost like a joke, you know, it was
177
00:11:46.399 --> 00:11:49.879
almost comical how bad they are. But with artificial intelligence
178
00:11:50.480 --> 00:11:54.960
and with criminals being more organized and sharing information, these
179
00:11:55.399 --> 00:11:59.919
phishing emails look more and more legitimate. The problem of
180
00:12:00.000 --> 00:12:03.320
phishing is only going to get worse before it gets better.
181
00:12:04.080 --> 00:12:07.279
I want to show you another phishing email, number three,
182
00:12:07.320 --> 00:12:12.559
please one. This one purports to be from Norton LifeLock,
183
00:12:14.360 --> 00:12:19.960
and the scammers basically just copied the image from Norton
184
00:12:20.039 --> 00:12:24.120
LifeLock and put it on there. Dear customer, your subscription
185
00:12:24.639 --> 00:12:27.600
is set to renew today and it's going to charge
186
00:12:27.600 --> 00:12:30.440
you over five hundred dollars So this is a classic
187
00:12:30.480 --> 00:12:33.919
fishing email. They want you to panic and say I
188
00:12:33.960 --> 00:12:39.080
didn't order a five year Norton LifeLock renewal. That's ridiculous.
189
00:12:39.279 --> 00:12:43.240
I need to cancel it right away. And the scammers
190
00:12:43.279 --> 00:12:46.320
are so nice they provide a phone number for you. Well,
191
00:12:46.399 --> 00:12:49.600
what happens when you call that phone number, you're calling
192
00:12:49.639 --> 00:12:53.320
a scammer. Okay, what we do is we delete this
193
00:12:53.480 --> 00:13:01.480
email and you contact Norton LifeLock or contact Norton LifeLock
194
00:13:01.639 --> 00:13:06.519
and make sure it's it's to reassure yourself that it
195
00:13:06.600 --> 00:13:10.799
was a phishing email. We never call the number. I
196
00:13:10.879 --> 00:13:13.120
was over at my mom's house helping her with her
197
00:13:13.159 --> 00:13:16.799
email the other day. I went into her email account
198
00:13:16.960 --> 00:13:22.759
and she had about ten emails just like this from
199
00:13:22.799 --> 00:13:26.919
all different companies. These the scammers are sending these things
200
00:13:26.960 --> 00:13:30.399
out in the thousands, if not millions. And then I
201
00:13:30.480 --> 00:13:32.639
have one more phishing email. I want to show you
202
00:13:32.720 --> 00:13:36.879
slide for please one. So this is one a phishing
203
00:13:36.919 --> 00:13:41.759
email that purports to be from Social Security Administration. And
204
00:13:41.840 --> 00:13:45.639
look at this, it's real nice. Your social Security statement
205
00:13:45.720 --> 00:13:48.919
is streamlined and easier to read than ever before. We
206
00:13:49.120 --> 00:13:53.080
encourage you to view your statement once a year. Sounds legitimate.
207
00:13:53.240 --> 00:13:57.159
The government is here to serve you and help you out. Unfortunately,
208
00:13:57.200 --> 00:14:00.519
this is a phishing email. Don't click on that blue
209
00:14:00.559 --> 00:14:03.960
link at the bottom. You're falling right into the trap
210
00:14:04.039 --> 00:14:07.559
of a scammer. What we do is we delete this,
211
00:14:08.279 --> 00:14:13.519
go directly to SSA dot gov and either log in
212
00:14:13.720 --> 00:14:16.360
or talk to someone. This is a complete scam. And
213
00:14:16.519 --> 00:14:19.519
just think about this. The scammers send thousands of these emails,
214
00:14:20.000 --> 00:14:22.399
millions of these emails, and they only need to get
215
00:14:22.480 --> 00:14:25.799
lucky one percent of time or zero point one percent
216
00:14:25.840 --> 00:14:27.799
of the time, and they're going to make money. And
217
00:14:27.840 --> 00:14:31.960
then one other clue here, look where it's from Social
218
00:14:32.080 --> 00:14:37.159
Security statement and the email is no reply at Greek
219
00:14:38.279 --> 00:14:44.240
coproad dot com. That is not Social Security Administration. All right,
220
00:14:44.279 --> 00:14:47.960
So next we are going to be talking about texting.
221
00:14:49.360 --> 00:14:52.320
There is a new text now where criminals claim you
222
00:14:52.440 --> 00:14:57.200
owe money for unpaid road tolls and they're pretending to
223
00:14:57.240 --> 00:15:00.840
be state agencies and they send text message is demanding money,
224
00:15:00.879 --> 00:15:02.399
and they don't ask for a lot of money. It's
225
00:15:02.720 --> 00:15:05.840
usually a small amount of money. So these text messages
226
00:15:06.240 --> 00:15:10.000
are a form of what we call smishing, a social
227
00:15:10.039 --> 00:15:14.679
engineering attack using fake text messages to trick people into
228
00:15:14.720 --> 00:15:18.039
sending money to cyber criminals, trick you into sharing personal
229
00:15:18.080 --> 00:15:22.399
information or downloading malware. So why do we call it smishing?
230
00:15:22.519 --> 00:15:28.120
So a text message is an SMS, a short message service,
231
00:15:28.159 --> 00:15:32.320
that's the technical word for it. So instead of calling SMS,
232
00:15:32.320 --> 00:15:35.480
we call it smishing, and it rhymes with phishing. So
233
00:15:35.759 --> 00:15:41.080
smashing is fake text messages. So next slide one, please,
234
00:15:41.879 --> 00:15:46.039
this is an example of a text, a smishing text
235
00:15:46.519 --> 00:15:49.679
that claims to be from the Arizona Department of Transportation.
236
00:15:51.200 --> 00:15:55.159
Little side note, in Arizona, we don't have any toll roots,
237
00:15:55.360 --> 00:15:58.879
so that's the number one clue. But look at this.
238
00:15:58.879 --> 00:16:03.240
This is a classic smishing email. You have an outstanding toll.
239
00:16:04.440 --> 00:16:06.759
If you don't pay it by the end of March,