novaleaf
5 hours ago
I know of a Thai person who fell for an "e-work" scam over the last year.
The hook was that you pre-pay some amount, do some trival work, then get like 500% return on your "investment". So they filter+train their mark by having them sign up for whatever financial transfer workflow, and figure out how gullable they are by giving them some payouts. A big part of this is some chat-group where lots of other fake-workers post comments saying how nervious/risky it seems and how sometimes the payment is delayed but they all eventually get paid. Eventually they let the mark sign up for some high-value amount, like equivalent of a few thousand USD. When the mark doesn't get paid, they contact the "technical support" team that then tries to social engineer the victim to loose even more money transferring funds the wrong direction (the scammers picked financial apps that make this mistake easiest).
I kind of find it unbelievable that people fall for this stuff, but the obvious proof is that enough people do :(
thephyber
4 hours ago
> I kind of find it unbelievable that people fall for this stuff
I remember reading a headline that being poor is equivalent to losing about 5 IQ points. Don’t know how true that is, but my intuition tells me that most people financially struggle, spend a lot of extra time worrying about money, and in general act a little more desperate and would be a little more aware/skeptical if their stress + financial situation allowed it.
After a few years working in cybersecurity, I viewed EVERYTHING through the lens of “is someone lying to me?”. Emails, text messages, downloading software from a website/App Store, job offers, investment opportunities, etc.the surface area is limitless. There’s exactly zero chance that even an experienced professional with excellent eyesight, who reads up on the newest scams, who doesn’t have lots of family / social events to care for, etc will never get hacked/scammed.
Even in the cybersecurity industry, almost all companies have abandoned the idea that there will never be a breach, and have moved towards thinking about resiliency, where any breaches that do happen are minimized or closed quickly/automatically.
That’s a lot of words to say: even though I thought I would never get scammed, once I spent more time educating myself about how it happens, it seems obvious to me that scams work a percentage of the time and the scale of attempts is enormous.
netsharc
3 hours ago
> is someone lying to me?”. Emails, text messages, downloading software from a website/App Store
And incredibly, someone usually is. Most software download sites have so many UI elements saying "Download", on their downloads page, but only one of them is the legit software you want, and others are some random software that paid money to the website to be there to... probably try to get themselves installed and scam you some more.
I just checked the Google "play" store: searching for "Temu" (I know, dumb, but there was an ad on the main screen of the store), in the page of search results, the first install button is for the sponsored Alibaba app...
Even billion dollar businesses are... trying to scam you. "Don't be evil" no more indeed.
PS "full self-driving", also a scam..
thephyber
2 hours ago
I think the subtext of what I wrote in that paragraph was about the additional cognitive load of having to worry about every little action. For most people who are less informed about scams/cybersecurity, there is a lower cognitive load tax on their mind/attention (but that lower cognitive load results in less skepticism and more susceptibility to scams). Or put another way, the heuristics they use are at a different point on the tradeoff curve between effort/resources and accuracy.
miduil
2 hours ago
> After a few years working in cybersecurity, I viewed EVERYTHING through the lens of “is someone lying to me?”
Oh thank you for highlighting that, I've had some instance where I'd suddenly have the urgent feeling that something I'm experiencing is a hoax and I couldn't tell why this suddenly surfaced back then, but I guess years of exposure to security does that to one.
thephyber
an hour ago
I think initially I did it because I had high network privileges in my position at a company which had an immense amount of sensitive data on important companies. Kind of a deep thought exercise to be hyper vigilant in my position of responsibility.
Later, I think I stretched the thought exercise to start identifying new business opportunities (trying to find value in protecting against each of those things I identified).
At the same time I grew “professionally paranoid”, I was learning about epistemology and skepticism (to try to understand the cultural and political changes of the last decade). It’s been a wild ride.
bsder
2 hours ago
> I remember reading a headline that being poor is equivalent to losing about 5 IQ points.
Poor people also spend a lot of time using cash equivalents rather than credit.
There is a big advantage to using credit. For example, I don't worry too much about fraud on my credit card as the reversibility means that the banking system is taking care of it. If a suspicious transaction hits my ATM card, the bank absolutely jumps on it since it simply doesn't match my patterns of usage.
On the other hand, if you are using your ATM card or cash transfer apps all the time, you're a ripe target for getting scammed. The protections are much weaker and the reversibility (if any) is much worse.
This doesn't even get into the fact that, as a poor person, the people you are transacting with are also stuck in the same system for various reasons of various levels of dubiousness.
bdangubic
4 hours ago
exactly this. anyone - regardless of who they are - can fall for a scam. and for exact reason stated in your last sentence!
ChrisMarshallNY
4 hours ago
A few years ago, I wrote a blog post about my approach to risk management[0].
I generally look at risk as a two-dimensional graph, with the axes being Probability and Severity, and the action strategies as being Prevention, Mitigation, and Remedy.
If we get realistic about likelihood and impact, we can figure out how to reduce the damage.
One trick a wealthy friend of mine uses, is keeping a small checking account, that he fills with just enough cash from his brokerage, so that even if his cards/accounts get pwned, he can't lose that much.
bdangubic
2 hours ago
I have followed one simple principle for the last 16 years and have been incident-free. The communication with every business I am affiliated with in any way is one-way - I contact them. I never answer any calls or texts and I never answer any emails. no exceptions. It is amazing how much this simple rule just works. To fall for most scams you have to make a mistake which almost always involves you getting something, call, text, email…
thephyber
40 minutes ago
This is one of the best heuristics (because it’s such an short+easy to memorize). I learned it from my mother who is kinda low tech, but understood risk.
But ultimately, it’s a heuristic and is imperfect.
One example thing which bypasses weakness to this heuristic: when you import a programming language library or a “curl pipe bash”: how much research do you do to verify the authenticity of the library, the security of the package and contributors, that you didn’t typo and accidentally install a lookalike malware, etc? And then every time you take an action which updates the same thing, are you equally as rigorous and vigilant as the first time?
walterbell
2 hours ago
Also applies to computers: no open inbound ports, and outbound only to known destinations.
nradov
44 minutes ago
Can anyone really fall for a scam? I'm not particularly smart or wealthy and I've never fallen for a scam despite numerous attempts. Maybe I've just gotten lucky but scams seem quite easy to avoid.
(I have had a few fraudulent charges on my credit cards but I don't really consider those to be scams and they're easy to resolve.)
crooked-v
25 minutes ago
Being average makes it easier, because nobody's specifically targeting you using information scammed out of your less canny family or coworkers.
thephyber
4 hours ago
Different take:
At the risk of accidentally demonizing the poor, I remember reading a think piece that could be summarized as “morals/ethics are a luxury only the rich can afford.” The gist is that if you can’t afford to quit your job on the spot and not worry about paying rent this month, you will always be victim to your boss’s unethical actions lowering your ethical standards.
As an engineer, I have frequently challenged myself to empathize with the VW emissions scandal engineers, who were pressured to meet unrealistic emissions and deadlines. The managers didn’t have to explicitly tell them to build emissions testing defectors — they came up with that as an engineering solution to the requirements they were given. I ask myself: at what point would you have quit, and hopefully told the authorities?
Also more recent example is the staff of the submarine that went down to the site of the Titanic and imploded. The CEO was apparently an unbelievable bully and took extraordinary risks, but the staff didn’t quit. One of them was a Scottish immigrant who moved his whole family to take the job. He was also worried about being blacklisted from the entire private sector submarine industry. There was a lot of friction to being able to exercise his highest ethical standards.
Thailand is more or less at war with Cambodian war lords, who have tens of thousands of poor English speakers from around the world living in captivity, their passports taken away, running long term scams over the internet. When they have no money and no power to run, is it fair to blame the low level scammers for having fallen for a job scam months or years ago?
The more financial pressure you are under, the more likely you are to tolerate an unethical environment.
derefr
4 hours ago
Always seemed to me that the correct response to this scam is to recruit everyone you know to go through just the first step of the scam and then quit while they’re ahead. Like taking a casino’s offer of free food and then leaving without gambling.
novaleaf
4 hours ago
IIRC they chat group was using LINE, where the scammers can delete messages / kick people at will. So more people joining just to make a few bucks from the initial payout just increases the credibility of the operation.
Also the initial "tasks" the mark performs are worth only like a few USD. not worth anybody's time except for certain types of vulnerable people who not-coincidentally make good victims.
veeti
3 hours ago
Just an anecdote but this happens in the west too. I literally woke up today to some spam Telegram "job offer" group that was vibrating my phone like crazy. And all of this in my native language of just a few million speakers. I wish I took some screenshots before trashing it, but the messages were just as you described.
duxup
3 hours ago
There was a post on HN where someone followed through with a scam like this. It was very weird, the scammer walked the victim through some setup on their computer. They may have actually been selling video views and likes and other social media and advertising engagement fakery ... the process was surprisingly complex and the victim had an account page tracking their activity and payouts.
thisisit
4 hours ago
Even the best of people can fall for scams. It depends on how much you need the money. No one starts off thinking they are going to be scammed. The design ensures people enter this trap slowly. When people are hesitant they are given a taste of success - the 500%. Some people tap out here. Others want to continue to try their luck. But often they are stopped with reverse psychology that there are no low pay jobs and they need to pitch in more money.