from Hacker News

I Fell for a Scam

by unsignednoop on 5/6/23, 7:54 AM with 5 comments

So here's what happened

I received a text at 4 am telling me that my account balance hadn't been paid (been drinking)

I clicked the link and it was a site of the payroad I regularly drive on

I have also noticed that my paytag hadn't been beeping so it all seemed legit

If you don't pay in 3 days the fine will be $500

I entered my card details and nothing happened. I tried on my phone and nothing happened. Check console and theres 404 errors in the req

Woke up the next day and tried again, noticed that the home button doesn't work, the social media buttons don't work. The site says it's a 200 fine if you don't pay. Holy shit this is a scam website

I look at the console logs and it turns out that scammers sent their xhr requests to //api/card_confirm.php (Double slashes)

Holy shit lads, I am on cloud 9 right now, I almost got scammed but due to a simple typo my data is safe. (They fixed the site shortly after when I sent a test card no). This is the luckiest day of my life lmao

  • by elnatro on 5/6/23, 9:37 AM

    If you entered your card details in that site you should cancel it.

    Double-check suspicious sites that asks for your bank or cards information.

    Glad you were lucky and they did not ended up with your money.

  • by quickthrower2 on 5/7/23, 2:04 AM

    Everything that is wrong with security and expectations set by banks and merchants. SMS links are normal (should they be?). Non 2FA online card txns normal (should they be?). Weird domains to pay for things are normal.

    But then when I legit want to send $1000 my bank makes me go through a rat maze of a quiz where I need to answer correctly (rather than honestly/accurately) in order to send the money!

  • by is_true on 5/6/23, 11:51 AM

    Cancel the card.

    They could've been logging the requests anyway

  • by KomoD on 5/6/23, 3:32 PM

    > Holy shit lads, I am on cloud 9 right now, I almost got scammed but due to a simple typo my data is safe. (They fixed the site shortly after when I sent a test card no). This is the luckiest day of my life lmao

    Yeah no, it isn't safe... The request was most likely logged in the webserver logs

    Cancel the card immediately.

  • by Aperocky on 5/6/23, 1:43 PM

    Even if you did, I assume the credit card company will be able to reverse/cancel the transaction as long as you report in a reasonable time.