{"id":4733,"date":"2015-03-24T15:00:36","date_gmt":"2015-03-24T19:00:36","guid":{"rendered":"http:\/\/www.kaspersky.co.in\/blog\/?p=4733"},"modified":"2020-02-26T20:28:38","modified_gmt":"2020-02-26T14:58:38","slug":"skype-fraud-story","status":"publish","type":"post","link":"https:\/\/www.kaspersky.co.in\/blog\/skype-fraud-story\/4733\/","title":{"rendered":"Fraudsters hacked Skype and tricked victim&#8217;s friends to send them about $5000"},"content":{"rendered":"<p><em>Editorial note: <a href=\"https:\/\/www.facebook.com\/SergeyDolya.ru\" target=\"_blank\" rel=\"noopener nofollow\">Sergey Dolya<\/a>, the author of this post is one of the most popular Russian bloggers. This story recently involved\u00a0one of his friends. The victim was <a href=\"https:\/\/www.facebook.com\/eturtseva\" target=\"_blank\" rel=\"noopener nofollow\">Katya Turtseva<\/a>, a high-ranking employee of an\u00a0<a href=\"http:\/\/en.wikipedia.org\/wiki\/Acronis\" target=\"_blank\" rel=\"noopener nofollow\">international IT company<\/a>. We mention this to make it clear that in this specific case, the victim knew a thing or two about security.<\/em><\/p>\n<p>Recently a friend of mine had her Skype account hacked. Scammers decided to use this opportunity to trick people from her contact list out of their money, and in just one hour they received more than 100,000 rubles (about $1,500)!<\/p>\n<p>To the thieves benefit, there were a lot of people in her contact list: about 300 of them. The scammers decided to ask her friends to borrow relatively small sums of money, 15,000 rubles (about $250) \u2019till tomorrow\u2019. In fact, this is the maximum amount <a href=\"http:\/\/en.wikipedia.org\/wiki\/Yandex.Money\" target=\"_blank\" rel=\"noopener nofollow\">Yandex Money<\/a> (a popular Russian payment system) allows to transfer at a time.<\/p>\n<p>The plan was simple: \u2018Katya\u2019 wanted to buy some goods online but had no money on her Yandex Money account. This approach had credibility and made people believe that they were speaking with the victim. They decided to transfer money without a call to their friend; some of them even sent money twice.<\/p>\n<p>This is one of the conversations fraudsters (F) had\u00a0with one of the victim\u2019s friends (V):<\/p>\n<p>F: OK. I\u2019ll get straight to the point: I need your help.<br>\nV: What\u2019s happened? Spill it! And send me a photo.<br>\nF: I wanted to borrow money till tomorrow<br>\nV: How much? I can send you money, if I have enough in my account.<br>\nF: 15 thousands (rubles)<br>\nV: OK, sure. Where do I send it?<br>\nF: Thanks<br>\nV: How should I send it?<br>\nF: I need to pay with a card but my account is empty. Can you pay?<br>\nV: No problem<br>\nF: http.yandex\u2026. (the link to payment page)<br>\nV: I need a recipient\u2019s bank account<br>\nF: hey! where are you?<br>\nV: was changing nappy<br>\nF: oh. here it is: (number of fraudsters\u2019 account)<br>\nV: I\u2019ll take a photo of the invoice and lull Vanya asleep. He is crying.<br>\nF: OK, I\u2019ll be online<br>\nV: OK<br>\nF: Oh, Lena, coming to think of it. Do you have another 15,000? If not, it\u2019s OK you\u2019ve already helped a lot! But if you have, I\u2019ll send you back 30,000 tomorrow + commission at my expense<\/p>\n<p><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/36\/2015\/03\/05092819\/skype01.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/36\/2015\/03\/05092819\/skype01.jpg\" alt=\"Fraudsters hacked Skype and tricked victim's friends to send them about $5000\" width=\"2000\" height=\"641\" class=\"aligncenter size-full wp-image-4735\"><\/a><\/p>\n<p>When everything came to light, it was\u00a0very difficult\u00a0to do almost anything to fix this problem.<\/p>\n<p>A few days were spent communicating with the Skype support service: employees needed more than 24 hours to understand what had happened. When they figured out that Katya\u2019s account had been hacked, they sent her a link to a password recovery form, totally ignoring the part of the letter in which Katya explained that scammers had changed the associated e-mail as well.<\/p>\n<p>Next, the support service asked Katya to fill in the verification form, twice. It was the three\u00a0days since the start of this scamming affair and fraudsters were still persistently sending their requests through the contact list. Support service refused to block Katya\u2019s account until they were able to clarify the situation through-and-through.<\/p>\n<p>In the end, Katya correctly answered all questions from verification form except one: when was your Skype account created. The support service decided that the whole situation was too complicated and recommended that she\u00a0create another account! By that time, the fraudsters had already stolen about $5,000.<\/p>\n<blockquote class=\"twitter-pullquote\"><p>Sergey Dolya @dolyasergey tells how his friend had her #Skype hacked and used for money scamming<\/p><a href=\"https:\/\/twitter.com\/share?url=https%3A%2F%2Fkas.pr%2FL4oa&amp;text=Sergey+Dolya+%40dolyasergey+tells+how+his+friend+had+her+%23Skype+hacked+and+used+for+money+scamming\" class=\"btn btn-twhite\" data-lang=\"en\" data-count=\"0\" target=\"_blank\" rel=\"noopener nofollow\">Tweet<\/a><\/blockquote>\n<p>Meanwhile, one of Katya\u2019s friends tried to get a refund. She blocked her card and asked her bank to cancel the payment. Her request was formally accepted. The bank confirmed that she had never worked with this shop before and asked her to file a complaint at the local police department. Her bank requested a copy of this complaint to initiate the investigation of the\u00a0case.<\/p>\n<p>The police sent her back to the bank: in addition to\u00a0a whole bunch of different documents, they needed a document from her bank saying that the investigation had been launched. There was a lot of back and forth at that point. They were dealing with a local police department that had no\u00a0experience in a situation like this. At the local police department, Katya\u2019s friend was told that she should send her request to a main police office in Moscow.<\/p>\n<p><post href=\"https:\/\/www.facebook.com\/eturtseva\/posts\/10203835876233948\"><\/post><\/p>\n<p>After that, Katya\u2019s friend called her bank once again. Her card was blocked as well as the money transfer, but it would be tied-up until the merchant applied for it. When the investigation actually starts, they will ask for a money refund from the merchant\u2019s bank. The possibility of a successful solution to this problem seems to an unlikely dream.<\/p>\n<p>When other users tried writing to the fraudsters,\u00a0directly. The fraudsters did not believe that police would do anything substantial on this case. Obviously they clearly understood the imperfection of Russian legal system combined with the Skype security policy:<\/p>\n<p>\u2014 ***, guys, give us an interview, at least in chat<br>\n\u2014 ***, f*** off, don\u2019t f*** my brain)<br>\n\u2014 Come on, we do wonder. Katya says you\u2019ve already gathered 100,000 rubles<br>\n\u2014 They say she has gone to the police. And let God bless her there\u2026 I\u2019m blessed with my anonymity<br>\n\u2014 It\u2019s unlikely that I can break your anonymity by chat<br>\n\u2014 You\u2019re just disturbing me<\/p>\n<p><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/36\/2015\/03\/05092818\/skype03.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/36\/2015\/03\/05092818\/skype03.jpg\" alt=\"Fraudsters hacked Skype and tricked victim's friends to send them about $5000\" width=\"1578\" height=\"1006\" class=\"aligncenter size-full wp-image-4736\"><\/a><\/p>\n<p>It seems that the only one thing that you can do in this case is to secure your accounts. Here are a few tips:<\/p>\n<ul>\n<li>The best, most obvious and at the same time the most ignored tip is to <a href=\"https:\/\/www.kaspersky.com\/blog\/false-perception-of-it-security-passwords\/\" target=\"_blank\" rel=\"noopener nofollow\">use a reliable password<\/a>! Everybody knows it but there is still <a href=\"https:\/\/www.kaspersky.com\/blog\/25-worst-passwords-2014\/\" target=\"_blank\" rel=\"noopener nofollow\">a lot of thoughtless people<\/a>.<\/li>\n<li>Don\u2019t use the same password for different accounts. If you do, when one of web-services is compromised <a href=\"https:\/\/www.kaspersky.com\/blog\/primary-webmail-protection\/\" target=\"_blank\" rel=\"noopener nofollow\">you can lose all your accounts<\/a>.<\/li>\n<li>Use <a href=\"https:\/\/www.kaspersky.com\/blog\/what_is_two_factor_authentication\/\" target=\"_blank\" rel=\"noopener nofollow\">two-factor authentication<\/a> to protect your accounts. In this case you\u2019ll receive a short code via SMS or e-mail to use as a second password.<\/li>\n<li>Don\u2019t click suspicious links: there are a lot of <a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-avoid-phishing\/\" target=\"_blank\" rel=\"noopener nofollow\">pages on the web that steal your data<\/a>. It\u2019s called phishing. Also, do not reply to letters and messages from unknown contacts.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Fraudsters hacked Skype and tricked people from a contact list to send them about $5,000 over the course of a few days. Skype support, local banks and the police refused to do anything.<\/p>\n","protected":false},"author":590,"featured_media":4734,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,9],"tags":[1897,189,80,82,344,187,363,43,701,97,345,1898],"class_list":{"0":"post-4733","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-tips","9":"tag-advice","10":"tag-data-security","11":"tag-fraud","12":"tag-hacking","13":"tag-online-protection","14":"tag-passwords","15":"tag-personal-data","16":"tag-privacy","17":"tag-scam","18":"tag-security-2","19":"tag-skype","20":"tag-tips"},"hreflang":[{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/skype-fraud-story\/4733\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/skype-fraud-story\/5246\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/skype-fraud-story\/7247\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/skype-fraud-story\/8043\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/skype-fraud-story\/7144\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/skype-fraud-story\/7247\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/skype-fraud-story\/8043\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/skype-fraud-story\/8043\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.co.in\/blog\/tag\/advice\/","name":"#advice"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/posts\/4733","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/users\/590"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/comments?post=4733"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/posts\/4733\/revisions"}],"predecessor-version":[{"id":19265,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/posts\/4733\/revisions\/19265"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/media\/4734"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/media?parent=4733"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/categories?post=4733"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/tags?post=4733"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}