Stopping the Scam

We’ve had a handful of conversations recently with people who were close to being victims of fraud, either targeted themselves or by watching it happen to someone they know. The interesting part is that the people involved are not the sort you’d expect to fall for anything. They are intelligent, sharp, and financially literate. But perhaps that in and of itself is the point: anyone can fall victim to these tactics (they’re becoming more and more elaborate), and that’s why we need to talk about this.

Many people have heard of or experienced the IRS scam. You get a phone call or text that says you owe the IRS this much money because of [insert random reason here]. By now, that one’s well enough known that it barely works anymore, which means the scammers have upgraded.

So what about this? You get a text from your credit card company, which also happens to be the company you bank with, let’s say it’s Chase. The text is familiar, it says something like, “Chase Security: Corey, your credit card ending in 1234 was used at: Costco, $273.25, 07/22. Did you authorize this activity? Reply YES or NO.” You don’t recognize the purchase because you didn’t go to Costco that day, and when you do, you always spend at least $400 (at least that’s how it seems to work for me), so you reply no. You then get a subsequent text that says to call the number provided to discuss this with the fraud department. Now you’re nervous someone has your credit card info, and you call immediately.

The person on the other end is calm and professional and asks you to log into your account so you can confirm whether the fraudulent charge has cleared. From there, they build a story that sounds almost logical: because the charge originated from a compromised account, your account was now flagged, and not only is the credit card an issue but the funds sitting in your bank account were at risk too. They tell you an electronic transfer won’t work for fraud compliance issues (making you trust them more perhaps?). What you need to do instead is withdraw a cashier’s check and send it to Chase’s secure holding address while the fraud department sorts things out.

Now, you read this on a page and, yes, the steps in that sequence may start to sound a bit odd. But instead, read it in a voice that sounds like a bank employee while you’re starting to feel the pressure of a security breach, and perhaps you make a different decision. And while none of the people we spoke to lost any money, they did get further into the conversation than they’d like to admit. Moreover, they said some version of the same thing afterward: they knew better, and still almost did it.

The Rule That Requires No Judgment

Before we go any further, I think this is imperative. Make yourself this one rule. And the rule is that nobody legitimate will ever ask you to send them money over the phone or by text. Not your bank, not the IRS, not a sheriff’s deputy, not Amazon or Microsoft or your utility company, not a grandchild in trouble, and not a federal agent of any description. Not by cashier’s check, not by wire, not by gift card, not by crypto ATM, and certainly not by handing an envelope to a courier in a parking lot.

Just don’t do it. Ever. There’s no version of this where you happen to be the exception.

What I like about an absolute rule is that it requires nothing from you in the moment, and the moment is exactly when you’re least equipped to evaluate anything. You don’t have to decide whether this particular caller sounds legitimate, or whether the purchase seems familiar, or whether the fraud department procedure they’re describing might actually be a thing. You hang up. If there’s a chance it was real, you find the institution’s number yourself from a statement or the back of your card, never the number they gave you or the one in the text, and you call them. And if the caller gets angry or urgent when you say you’re going to verify independently, that’s all the confirmation you need. Legitimate organizations are delighted when you verify.

The Lock Nobody Checks

But beyond the phone scams, it’s also important to discuss another piece. Your personal information. And here’s the part of this that I think gets underappreciated, and it’s the reason I want to spend the rest of this piece on a couple of boring, free actions.

So that you know, your personal information is already out there. Your Social Security number, date of birth, address history, previous employers, your mother’s maiden name, the make and model of the car you financed in 2018, all of it has probably leaked in some breach or another over the last decade. Equifax alone exposed roughly 147 million people. Add in the health insurers, the credit unions, the hotel chains, the background check companies most of us have never heard of, and the honest conclusion is that the train left the station a long time ago. You cannot un-leak any of it, and no amount of vigilance recovers it.

Which means the useful question isn’t how to keep the information private. It’s what happens when someone shows up at the door holding all of it. And for most people, the answer is that the door is unlocked, because we’ve all been taught to think about identity theft as a monitoring problem rather than an access problem. Credit monitoring services tell you after someone has opened an account in your name. That’s a security camera pointed at a door that doesn’t lock. What you actually want is a deadbolt.

The Deadbolt

For those who don’t know, there are three credit bureaus: Equifax, Experian, and TransUnion. These are the companies that produce the dreaded credit score. But they’re where the deadbolt goes. And the process you need to undertake is to “freeze” your credit at all three bureaus. It’s free by federal law (remember this as they will try to sell you stuff), it takes about fifteen minutes total, and it is the only protection on this list that still works when the person on the other end already knows everything about you.

And how it works is quite simple, which is why it holds up. When someone applies for credit in your name, the lender pulls your file from one or more of the bureaus before approving anything. A freeze means the file doesn’t come out. It doesn’t matter how convincing the applicant is, how complete their information is, or how good the forged documents look, because the lender can’t complete the step that comes before the approval. The fraudster’s information advantage becomes irrelevant when there’s nothing to pull.

The objection I hear most often is convenience, and while it’s not what you want to spend your time doing, I promise it’s worth it. Think honestly about how often you need access to new credit. A mortgage every decade or so, a car every five or six years, a new credit card occasionally when a signup bonus is too good to pass up. And in every one of those cases, you know well in advance that it’s coming. Nobody accidentally applies for a mortgage.

When the day does come, you don’t undo the freeze permanently either; you thaw it. A temporary thaw unlocks your file for a window you set, usually a day or two, and then it refreezes automatically without you having to remember to do anything. If the lender tells you which bureau they use, and most will if you ask, you only have to thaw that one. The whole process takes about two minutes online through each bureau’s website. Compare that to the hassle, headache, and time people spend proving they didn’t open a $40,000 auto loan in a state they’ve never visited.

Another Layer

While we’re on security, passwords sit there as the one thing most people know they should fix and haven’t.

When a service you use gets breached, change that password immediately rather than eventually. For the replacement, length beats cleverness by a wide margin. Every additional character multiplies the number of combinations an attacker has to work through, while clever substitutions mostly make the thing harder for you to remember. Something like “P@ssw0rd!” satisfies every complexity requirement on the signup form and falls to a modern cracking rig almost instantly, because the substitution patterns are completely predictable. Use upper and lower case, use numbers, use special characters, but above all use length. Sixteen characters is a reasonable floor, and more is better if the site allows it.

Now here’s a piece of advice that even I, admittedly, don’t follow. However, that doesn’t mean it’s not the right thing to do, quite the contrary. And that is to use a different password everywhere. I know this sounds impossible, which it would be without a password manager. However, there are plenty of options, either through your browser, phone, or a dedicated service. The realistic failure source isn’t someone guessing your password. It’s someone buying it from the breach of a retailer you forgot you had an account with, and then trying it against your bank.

Fifteen Minutes

If you only do one thing after reading this, freeze your credit. It’s free, it takes fifteen minutes, and unlike almost every other security measure, it doesn’t depend on you being alert at the right moment or recognizing a scam while your pulse is up. It works 24/7, 365 days a year.

However, if you ever find yourself on the receiving end of one of those texts or phone calls, just stop and hang up. No legitimate person is going to ask you to send them money over the phone or by text. And even if you hang up on a legitimate call, what is the worst thing that will happen? You annoy a legitimate customer service agent? I think they’ll be ok. Don’t make yourself rely on your judgment holding up under pressure in a situation that was engineered specifically to break it.

Recognize that there are bad actors out there, and so is your personal information. What’s left is deciding whether you lock the door or leave it wide open for someone to walk right in.

Scam
Markets / Economy
  • We saw some “sell the news” reactions this week as Alphabet reported earnings. The S&P finished the week down -0.6%, the Nasdaq down -2.1%, and the small-cap Russell 2000 down -1.1%.
  • The S&P Global U.S. Services PMI rose to 53.6 in July from 51.2 in the previous month, marking the fastest expansion in services sector activity so far this year, according to a flash estimate.
  • The S&P Global U.S. Manufacturing PMI edged down to 53.8 in July from 53.9 in June, falling short of market expectations of 54.3, according to the preliminary estimate.
Stocks
  • U.S. equities were in negative territory. Consumer Discretionary and Communication Services led the decline, while Energy and Utilities outperformed. Value stocks led growth stocks, and large caps beat small caps.
  • International equities closed higher for the week. Emerging markets fared better than developed markets.
Bonds
  • The 10-year Treasury bond yield increased 14 basis points to 4.69% during the week.
  • Global bond markets were in negative territory this week.
  • High-yield bonds led for the week, followed by government bonds and corporate bonds.
Weekly Market Data

Leave a Reply

Your email address will not be published. Required fields are marked *