{"version":1,"type":"rich","provider_name":"Libsyn","provider_url":"https:\/\/www.libsyn.com","height":90,"width":600,"title":"After You Log In to the Fake Bank, They Send You to the Real One","description":"The detail that makes this scam land is not the fake website. It's what happens two seconds after you use it. Craig walks the whole sequence. Attackers use AI to build a pixel-accurate copy of a bank's site \u2014 he uses Bank of America as the example and is careful to say he's picking on the scammers, not the bank. They send a wide net of email claiming fraudulent activity on your account, knowing that some fraction of any list banks there. You click, you land on the copy, you enter your username and password. Then the clever part. They immediately redirect you to the real bank's site, which naturally says the login failed and asks you to try again. You assume you fat-fingered it. You log in properly, everything works, you get on with your day \u2014 and you never form the thought that anything went wrong. Your credentials are gone and nothing about the experience told you so. The FBI's figure for the Phantom Hacker scam, which leans on this and related techniques against older Americans, is over a billion dollars since last year. Craig's defence is one habit, stated plainly: never click the link. If an email about your bank worries you, go to the bank's own site yourself. If there is a genuine problem the message will be waiting for you when you log in, and you can ask their support directly whether the thing you received was real. Two further pieces of practical advice, both concrete:  Multi-factor authentication matters, but not the text-message kind. Something you know plus something you have is the right shape, and an authenticator app is the right implementation. Text messages are easy to fake and easy to intercept, and Craig notes they have been used to steal hundreds of millions. He is genuinely surprised how many banks still rely on them. Use a credit card, not a debit card. Fraud on a credit card is not your liability. Fraud on a debit card means the money has already left your account and you are now arguing to get it back, under policies that vary bank to bank. Craig went decades using only a debit card and no longer does.  Also in this segment:  The tech support imposter version, which caught Craig's own father \u2014 and the IRS variant, where Craig personally took six calls in half an hour demanding Amazon gift certificates to avoid jail Why the young are not the safe bet people assume: a study found Gen Z will hand over an email address for a donut, on the reasoning that everything about them is already out there anyway Both men on refusing to give a Social Security number \u2014 Craig uses a passport card instead, and notes drily the original promise that the number would never be used for anything but Social Security and would never become a national ID Craig's newsletter that week on business AI projects, against the MIT finding that 95% of them fail Rush trivia to open: the band's biggest-charting song was &quot;Take Off&quot; with Bob and Doug McKenzie, and Rick Moranis and Geddy Lee went to school together  Free newsletter: CraigPeterson.com ","author_name":"Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity","author_url":"https:\/\/cptt.libsyn.com\/podcast","html":"<iframe title=\"Libsyn Player\" style=\"border: none\" src=\"\/\/html5-player.libsyn.com\/embed\/episode\/id\/42908642\/height\/90\/theme\/custom\/thumbnail\/yes\/direction\/forward\/render-playlist\/no\/custom-color\/88AA3C\/\" height=\"90\" width=\"600\" scrolling=\"no\"  allowfullscreen webkitallowfullscreen mozallowfullscreen oallowfullscreen msallowfullscreen><\/iframe>","thumbnail_url":"https:\/\/assets.libsyn.com\/secure\/item\/42908642"}