Geen Opslag Crisisbescherming: Geüploade bewijzen worden uitsluitend in het vluchtige geheugen geanalyseerd en direct gewist. Geen logs, geen back-up.

Financial IVR SpoofDreigingsniveau: Kritiek

Bank Fraud Department Voice Spoof: Identifying Synthetic IVR Phone Scams

Auditing conversational AI phone agents impersonating major banks to steal one-time passcodes.

"This is the Chase Fraud Prevention automated alert system. A suspicious charge of $1,420 was attempted on your debit card in Miami, FL. To block this charge, press 1 now..."

Authenticiteit verifiëren met Sealed Rose

Directe Neurale Analyse · Gratis · Geen Account Vereist · Geen Opslag · Direct in Geheugen

Nummer- & Provider-Check

Financial fraud syndicates deploy AI interactive voice response (IVR) systems that mimic the exact tone, hold music, and menu options of major banks (Chase, Wells Fargo, Bank of America, Barclays). When you answer, an articulate synthetic voice alerts you to an urgent unauthorized charge. To "reverse" the transaction, the automated system prompts you to enter your debit card PIN or read back a one-time passcode (OTP) sent to your phone, which the scammers use in real-time to drain your account.

Kritieke Waarschuwingssignalen

1Automated Bot Prompting for 2FA SMS Code

Banks explicitly state: "We will NEVER call you and ask for your one-time passcode or password." Any call asking for an SMS code is 100% fraudulent.

2Perfect Caller ID Spoofing of the Bank’s Real Customer Service Number

The number displayed on your caller ID matches the 1-800 number printed on the back of your credit card.

3Synthetic Voice Agent Adjusting Script Based on Your Spoken Answers

The bot uses an LLM speech-to-speech agent to answer your questions in a polished, corporate American tone.

Telephony & AI Voice Agent Mechanics

  • Spoofed Caller ID via Asterisk / VoIP: Attackers inject arbitrary caller ID numbers via SIP headers (`P-Asserted-Identity`) that carriers fail to validate.
  • Conversational Voice Agents (Vapi / Retell / Bland AI): Criminals abuse commercial conversational voice APIs configured with bank customer service prompts to automate phone phishing.
  • Real-Time OTP Harvesting: While the voice bot speaks with you, an automated backend script enters your credentials on the real bank website and triggers the 2FA SMS to your device.

Hoe uzelf te beschermen en handelen

STAP 1

1. Hang Up Immediately — Never Press Numbers or Speak

Do not follow automated prompts or give any information.

STAP 2

2. Call the Real Number on the Back of Your Physical Card

Manually dial the customer service phone number printed on your actual debit or credit card and ask if any fraud alert was triggered.

STAP 3

3. Trace the Spoofed Carrier on Sealed Rose Phone Lookup

Inspect the caller number on Sealed Rose Phone Lookup to check for high-risk carrier origins.

STAP 4

4. Change Your Online Banking Password and Enable Authenticator 2FA

Replace SMS 2FA with hardware keys or authenticator apps (Google Authenticator, 1Password) that cannot be phished over the phone.

Veelgestelde Vragen

Why did my phone display the real name of my bank?

Scammers spoofed the caller ID. Telephony networks traditionally trusted sender-provided caller ID information. Always hang up and dial the bank back directly.

What if I already entered my PIN on the call?

Call your bank’s official fraud hotline immediately to lock your debit card and freeze online banking access before funds are withdrawn at an ATM.

Beschikbaar in 23 Talen: