Yesterday, I answered a call from an unknown number 🚩
The caller said they worked in my bank’s fraud department. According to them, the bank had detected and blocked suspicious charges from Samsung on my credit card.
They kept asking me whether I made these charges and if I was in Vancouver, if I was buying a Samsung TV, etc. Filling the silence, distracting me 🚩
While they were yapping, I logged into my account and saw the charges they were talking about:

I immediately locked my card and told the caller I would hang up and call the bank using the number on the back of my card, because it’s sus that they’re calling me from an unknown number.
They said they knew it was weird, but this line is a non-callback number, which is why it’s unlisted. They told me I could call back, but it would be faster to continue on this call, and we could make sure the charges were refunded. They were trying so hard to keep me on the phone. 🚩
I hung up.
They called me back four times… 🚩
Eventually, I answered on the fourth because I wanted to see what their game was. /me sips tea

They knew almost everything
The scammer began confirming my personal information. They rattled off my:
- First and last name
- Full address
- Phone number
- Email address
- Last four of my Credit card number
They sounded professional. It was a generic verification spiel, and the conversation followed the kind of script you would expect from an actual fraud department. In a normal scam call, you’d expect them to be phishing for this information, but they knew everything, convincing you they were indeed from your bank.
The audio was extremely clear 🚩 That clarity, made me suspect the voice may have been AI-generated or possibly a voice changer?
I became even more suspicious of this when they read my postal code; the letters and numbers came out jumbled and glitchy 🚩 It was one of the only obvious breaks in an otherwise convincing performance.
At this point, I knew someone, somewhere, had obtained and sold my credit card info. /me is very annoyed that I’m going to have to get a new card.
The one-time code
Then the caller moved on to “verifying” my identity so they could “stop and refund these fraudulent transactions”.
When I contact my bank legitimately, it sends me a one-time passcode for authentication. As an example, the legitimate security message from my bank is very clear about what to do if someone else initiated the conversation:
If you DID NOT initiate contact with MBNA, do not share this code and call the number on the back of your MBNA Card. Your one-time passcode is [REDACTED].
During this call, they sent a text message 🚩 that appeared to come from the bank’s number:
MBNA: The one-time passcode you requested is [REDACTED]. It is valid for 3 min. Std msg rates apply.
I refreshed my bank and saw a bunch more authorizations show up on my card:

I seached Google for Consensys Software inc, turns out it’s Consensys is the company behind MetaMask, and MetaMask lets people buy crypto using a credit or debit card.
So, my best guess is that they were trying to use my card to buy crypto and send it to a wallet they controlled. Once they moved the crypto out of that wallet, getting the money back would become a giant pain in the ass.
To be clear, this doesn’t mean Consensys was involved or compromised. The scammers were most likely just using a legitimate crypto service to turn my available credit into something they could move around more easily.
The “refund”
Next, the scammer said they would send me a text so I could approve a refund for the fraudulent charge.
They told me to reply Y.
While the message arrived, they kept talking. They gave me instructions, repeated details about the supposed refund, and filled every moment of silence. Basically, they made sure I didn’t have time to read the message. 🚩
The actual message said:
MBNA FRAUD ALERT: Transaction of $210.45 @ DOLLARAMA #116 on Amazon.ca Credit Card ending in [REDACTED]. Reply Y if this was authorized; N if not.
They were not asking me to approve a refund.
They were tricking me into telling my bank that their fraudulent transaction was authorized so it would go through.
I told the caller that I had “approved the refund.”
At this point in the call, they asked me to confirm my details and asked for the card balance. I was like, what do you mean? The available credit or the total credit limit; they said either one. 🚩
Basically, they were trying to figure out why the payment wasn’t working and how much money they could potentially scam me out of. Apparently, the $210 Dollarama shopping spree wasn’t ambitious enough. lol
There was some silence…them waiting for the charges on my card to go through.
After some time…and failed transaction attempts, they then asked if I had locked my card.
I said yes. I had locked it as soon as they called the first time.
They told me I needed to unlock the card so they could process the refund, cancel the transactions, and send me a new card 🚩
When I refused, they offered several more explanations for why unlocking the card was supposedly necessary.
Eventually, I said:
“Bro, if you work at MBNA, you can do that yourself. ”
Apparently, that was the moment they realized I was wasting their time. 😂
They hung up.
What was really happening
The scammers already had enough of my personal information to attempt a transaction.
They called me and used my personal information and knowledge of their own fraudulent activity to prove they were from the fraud department.
Their goal was not to help me reverse the charges. Their goal was to manipulate me into authorizing them.
When they learned that I had locked the card, they needed me to unlock it so they could successfully take my money.
When I refused, I like to think they reacted like this:

Where I think they got my information
I clean malware from compromised websites for a living, so I have a fairly specific theory about where the scammers got my information.
My best guess is that I made a purchase from a website infected with a credit card skimmer.
These skimmers are essentially malicious scripts embedded in a website’s checkout flow. They capture the information you enter into forms during checkout, before it is securely sent to the payment processor.
The purchase goes through normally, and from the customer’s perspective, nothing looks suspicious. Meanwhile, a copy of everything entered at checkout is sent to a remote server controlled by a threat actor.
Typically, this information is sold on illegal websites to scammers like this who call and try the last little bit of social engineering to get your money.
Anyway, that would explain why these scammers had the exact combination of information used for an online purchase, e.g. first and last name, billing and shipping address, credit card details, phone number, and email address.
Looking back, I even have a suspicion about which website it was. But in my defense, I really wanted that Dungeon Crawler Carl T-shirt, and I regret nothing 😂

TL;DR
If someone unexpectedly calls about fraudulent charges on a specific card, just hang up, log in to your account, lock your card, and call your bank’s official number.
…or lock your card and waste their time? jk


Leave a Reply