{"id":2087,"date":"2021-06-24T08:49:11","date_gmt":"2021-06-24T08:49:11","guid":{"rendered":"https:\/\/osintme.com\/?p=2087"},"modified":"2021-06-24T11:17:17","modified_gmt":"2021-06-24T11:17:17","slug":"vishing-attacks-in-ireland-and-some-resources-to-help-investigate-them","status":"publish","type":"post","link":"https:\/\/osintme.com\/index.php\/2021\/06\/24\/vishing-attacks-in-ireland-and-some-resources-to-help-investigate-them\/","title":{"rendered":"Vishing attacks in Ireland &#8211; and some resources to help investigate them"},"content":{"rendered":"\n<p>In the last two weeks or so users in Ireland have been subject to vishing attacks on a large scale.<\/p>\n\n\n\n<p>The modus operandi is random phone calls from unknown mobiles, predominantly 087 numbers that appear to belong to Vodafone.<\/p>\n\n\n\n<p>It&#8217;s unclear if these are real or spoofed &#8211; but from research that I carried out into the numbers confirmed to be part of this scam, none of them belong to any identifiable real persons.<\/p>\n\n\n\n<p>Multiple users reported being targeted over and over, which suggests that the scammers don&#8217;t just pick random numbers to call &#8211; they actually verify that the victim&#8217;s number is valid and is in active use.<\/p>\n\n\n\n<p>This &#8220;due diligence&#8221; is probably done using breach data dumps like the Facebook one, which I previously discussed <a href=\"https:\/\/osintme.com\/index.php\/2021\/04\/05\/the-facebook-data-dump-privacy-lessons-for-users-in-ireland\/\">here<\/a>.<\/p>\n\n\n\n<p>The vishing callers impersonate Irish government organisations, from the Department of Social Protection to An Garda Siochana. <\/p>\n\n\n\n<p>The content of the message will vary, but usually it will employ some degree of urgency (&#8220;your PPS number has been invalidated&#8221; or &#8220;there is an outstanding warrant in your name&#8221;, etc.).<\/p>\n\n\n\n<p>In some cases, an unanswered call will result in an automated voicemail message being left &#8211; like the one below:<\/p>\n\n\n\n<figure class=\"wp-block-audio\"><audio controls src=\"https:\/\/osintme.com\/wp-content\/uploads\/2021\/06\/SocialProtectionScamVoiceMail.mp3\"><\/audio><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Other variations of this message sound like this:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>I was calling from the department of social protection we have got in order to suspend your PPS number on immediate basis because your PPS number is found suspicious for illegal and criminal activities it is very time-sensitive and urgent to hear back from you before we proceed further with suspension of your assets bank accounts, so please press&nbsp;one.<\/em><\/p><\/blockquote>\n\n\n\n<p>For some unclear reason, on this occasion the scammers favour using 087 numbers belonging to Vodafone.&nbsp;<\/p>\n\n\n\n<p>Multiple users who were targeted also use 087 numbers, so perhaps this MO stems from the abuse of free calls between Vodafone numbers?<\/p>\n\n\n\n<p>The company itself issued a warning on this topic, containing the following advice:<\/p>\n\n\n\n<p>\u2022 Don&#8217;t engage with the caller<br>\u2022 Hang up the call, don&#8217;t return the call<br>\u2022 Don&#8217;t follow the automated instructions, don&#8217;t press 1 etc<br>\u2022 Never disclose personal\/financial information<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">*Public Service Announcement*<br> <br>1\/3<br><br>We are aware of a phone call phishing scam currently circulating in Ireland. The calling number will look like an Irish mobile number and in many cases, the first six digits, including the 08X prefix, will be the same as your own phone number<\/p>&mdash; Vodafone Ireland (@VodafoneIreland) <a href=\"https:\/\/twitter.com\/VodafoneIreland\/status\/1405927409417867264?ref_src=twsrc%5Etfw\">June 18, 2021<\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div><\/figure>\n\n\n\n<p>It&#8217;s unclear what Vodafone is doing to detect, prevent and report such scams (other than what we see publicly on their Twitter). <\/p>\n\n\n\n<p>It&#8217;s also unclear if there is anything Vodafone, or any other company can actually do in cases like this. After all, spoofing a phone number or using a prepaid, unregistered one is all too easy.<\/p>\n\n\n\n<p>During my research into this topic I gathered a sample of numbers confirmed to have been used in this scam. <\/p>\n\n\n\n<p>The real count of vishing numbers is expected to be exponentially larger &#8211; but pasting some of them here will expose them &#8211; and if somebody searches for a specific number, they might as well find this post and confirm that it is indeed a scam.<\/p>\n\n\n\n<p><strong>NOTE:<\/strong> This might change in 6 or 12 months time and there is a chance that a particular number will get recycled back into the pool of available numbers, to be given to a genuine unsuspecting user. But right now, the only digital footprint for those numbers is this scam.<\/p>\n\n\n\n<p>So here we go:<\/p>\n\n\n\n<p>+353874251297<br>+353874125566<br>+353795866029<br>+353879244427<br>+353874850324<br>+353874465749<br>+353874445068<br>+353874692559<br>+353877691231<br>+353879824745<br>+353879248980<br>+353853875132 <em>&#8211; [the only non 087 number on my list]<\/em><\/p>\n\n\n\n<h3 class=\"has-text-align-center wp-block-heading\">Irish phone number lookup resources<\/h3>\n\n\n\n<p>Unless you work in law enforcement or directly for a telecommunications company, identifying unknown phone numbers will require relying on OSINT. <\/p>\n\n\n\n<p>In the cases of phone number lookups in general, a lot of this comes down to using community driven sites where people report suspicious phone numbers.<\/p>\n\n\n\n<p>Last year I wrote a post on <a rel=\"noreferrer noopener\" href=\"https:\/\/osintme.com\/index.php\/2020\/05\/10\/a-guide-to-investigating-scam-text-messages-and-websites-fake-revenue-online-page\/\" target=\"_blank\">investigating scam text messages<\/a>, some of which methods can be applied in this case, like for example using <a href=\"https:\/\/www.truecaller.com\/\">Truecaller<\/a>, <a href=\"https:\/\/sync.me\/\" target=\"_blank\" rel=\"noreferrer noopener\">Sync Me<\/a> or some Google search operators for phone numbers of interest:<\/p>\n\n\n\n<p><strong>\u201c+12568417086\u201d OR \u201c256-8417086\u2033 OR \u201d 1 2568417086\u2033<\/strong><\/p>\n\n\n\n<p><strong>intext:\u201d+12568417086\u2033<\/strong><\/p>\n\n\n\n<p><strong>allintext:\u201d+12568417086\u2033<\/strong><\/p>\n\n\n\n<p><strong>site:\u201d&lt;<em>whatever site you search<\/em>&gt;\u201d intext:\u201d+12568417086\u2033<\/strong><\/p>\n\n\n\n<p>However, for looking up Irish numbers specifically, we have the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>IE Tellows: <a rel=\"noreferrer noopener\" href=\"https:\/\/ie.tellows.net\/\" target=\"_blank\">https:\/\/ie.tellows.net\/<\/a><\/li><li>Free Lookup: <a rel=\"noreferrer noopener\" href=\"https:\/\/free-lookup.net\/ireland\" target=\"_blank\">https:\/\/free-lookup.net\/ireland<\/a><\/li><li>Phone Numbers IE: <a rel=\"noreferrer noopener\" href=\"https:\/\/www.phonenumbers.ie\/\" target=\"_blank\">https:\/\/www.phonenumbers.ie\/<\/a><\/li><li>Should I Answer: <a rel=\"noreferrer noopener\" href=\"https:\/\/ie.shouldianswer.net\/\" target=\"_blank\">https:\/\/ie.shouldianswer.net\/<\/a><\/li><\/ul>\n\n\n\n<p><strong>BONUS: <\/strong>There are some landline scams doing the rounds too. For example, one of the readers recently received a call from <a rel=\"noreferrer noopener\" href=\"https:\/\/free-lookup.net\/35312528641\" target=\"_blank\">+35312528641<\/a>. <\/p>\n\n\n\n<p>The scammer purported to work for Vodafone and promised his victim a new discounted plan &#8211; in exchange for credit card details&#8230;<\/p>\n\n\n\n<h6 id=\"wp-block-themeisle-blocks-advanced-heading-9c313803\" class=\"wp-block-themeisle-blocks-advanced-heading wp-block-themeisle-blocks-advanced-heading-9c313803\"><em>Received a scam call or message recently? Let me know via <a href=\"https:\/\/twitter.com\/osintme\" target=\"_blank\" rel=\"noreferrer noopener\">DM on Twitter<\/a> or email me on mattaios@protonmail.com.<\/em><\/h6>\n","protected":false},"excerpt":{"rendered":"<p>Explaining the MO of the most recent vishing scam hitting users in Ireland &#8211; and how to search for &#038; identify these scam phone numbers.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"neve_meta_sidebar":"","neve_meta_container":"","neve_meta_enable_content_width":"","neve_meta_content_width":0,"neve_meta_title_alignment":"","neve_meta_author_avatar":"","neve_post_elements_order":"","neve_meta_disable_header":"","neve_meta_disable_footer":"","neve_meta_disable_title":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[18],"tags":[56,105,82,102,81,137],"class_list":["post-2087","post","type-post","status-publish","format-standard","hentry","category-digital-privacy-security","tag-ireland","tag-mobile","tag-phishing","tag-phones","tag-scam","tag-vishing"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/2087","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/comments?post=2087"}],"version-history":[{"count":16,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/2087\/revisions"}],"predecessor-version":[{"id":2109,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/2087\/revisions\/2109"}],"wp:attachment":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/media?parent=2087"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/categories?post=2087"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/tags?post=2087"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}