I don’t think so. The usual rules of thumb still apply. Never respond directly to any ‘cold’ (unsolicited and unexpected) call / text / email – that is, don’t call a phone number, go to a web address, send to an email address, etc given in the message.
If it does seem to be from a business / other entity you deal with that might have reason to contact you, contact them via their published contact details to ask what it’s about.
The challenge will be many mobile message bank users use redial functions within the message bank. If for example, the message appears to be from a known and used business or organisation (Telco, bank, government agency etc), it is highly likely redial function will be used. The redial will use the number attached to the message.
As it is ringless voicemail, a missed call with number won’t be left. The only way to do a search is if one listens to the voicemail, separately records the number if it is provided (e.g. with pen or while multitasking) and then checks the veracity of the number. Not an as easy process.
Scams are more successful when it is a cold call from a business one is dealing with. For example, around tax time when scammers masquerade as the ATO, a bank ringing up about a recent transfer or payment… when one has just made a transfer or payment etc. Coincidence maximises success.
The challenge will be saying to the masses that they should not believe voicemails.
Imagine if there is a AI synthesised voice someone knows. Ringless voicemails means these need to be dismissed as potential scams until one verifies by different means. Ring up the person using known phone numbers to check the voicemail is authentic. It means voicemail will no longer be able to be replied upon, even from known or where one recognises the voice of the caller. Many will struggle with this as it is a huge change.
Possibly the government needs to ban ringless voicemail. I can see why it might be needed - for political advertising or in the event of an emergency… but the risks potentially outweigh the benefits.
I guess that only works with a mobile number as recipient. And the Albo Government has got that one covered for me by bricking my mobile phone.
There’s no inherent reason why you can’t have a voice mailbox for a fixed line but is anyone using that?
While that is 100% possible from a technical point of view, I don’t see that happening widely in the foreseeable future because it requires getting hold of a lot more info for scam purposes. Associated with your mobile phone number, the scammer has to find the identity of someone you know (and not just anyone that you know but someone with an appropriate relationship to you) and then get a voice sample.
As a targeted attack, definitely doable, but as a robodialer going through 0400000000 to 0499999999 … that’s a lot more work.
Scammers can get a voice sample by ringing a person up. That’s one reason not to play funny buggers with the scammers, trying to waste their time. While you are keeping them on the line, they can be recording your voice, in order to train an AI to mimic you.
As a thought experiment … consider the Hi Mum scam. Works enough of the time when the scammer has essentially no information (other than guessing the gender of the recipient, and of course gambling that the recipient even has kids). Now imagine that the scammer has to find the identity of an actual kid and then get a voice sample.
I would think that “less is more” … except as a targeted attack.
Phishing scam emails using DocuSign have been around for a while, but I’d never received one until this morning. It went straight to the junk mail folder because Outlook decided it looked like a scam message, but because I have no reason to expect to need to digitally sign anything, I wasn’t at risk of being fooled by it anyway.
However, if it hadn’t been caught by the junk mail filter, the fully-formatted version probably could look convincing to anyone used to interacting with DocuSign, clicking the link, and supplying personal identification details.
It shows how evil outsourcing is. Emails arrive from random suppliers (like DocuSign) not from the actual party that you are expecting to be dealing with.
But it’s a two-edged sword because if each individual actual party tried to implement that kind of signing functionality, I’m sure some of them would mess up the security anyway.
From recent experience, the actual party will often send a warning email so that you know to look out for an email from a random supplier that will in fact be legitimate.
In an ideal world, all these outsourcing arrangements would be re-architected so that the email arrives from the actual party.
My bad that I did not keep or screen shot it, but one I encountered recently from a google product search presented as an Aldi branded ecommerce web site. The scammer was a lazier than type. Their scam site still had a US style phone contact shown as 123-456-7890 with a contact email ‘[email protected]’.
Not all of them are equally clever. Some are incredibly not smart.