
Amy Nofziger, director of Victim Support for the AARP Fraud Watch Network, and Rachel Tobac, co-founder and CEO of SocialProof Security, join us to discuss how to identify a scam.
Loading summary
A
Listener support WNYC Studios.
B
This is all of this. I'm David Fuerst in for Alison Stewart for part of the show today. I'll be with you for the first hour. Alison will be here for the second. Coming up on the show, we'll speak with the director of a new documentary about the Vaselka, the beloved Ukrainian restaurant in the East Village. The restaurant's owners will join us as well. We'll finish our full bio conversation about the life of tennis great Althea Gibson. And we'll speak with Joy Reid about her new book, Medgar and Medgar Evers and the Love story that Awakened America. That's the plan. So let's get started with scams and how to avoid being the victim of one. Last week, an article in the Cut went viral. Here's the the day I put $50,000 in a shoebox and handed it to a stranger, I never thought I was the kind of person to fall for a scam. The author, Charlotte Coles, the Cut's own financial advice columnist. If you haven't read the story, here is a very brief Charlotte received a call from someone who claimed to be an Amazon employee. This person said that someone had been ordering laptops and iPads on Charlotte's account. Charlotte was then transferred to someone who claimed to be an investigator with the Federal Trade Commission, who told Charlotte that her identity had been stolen and might have even been connected with a crime. Things escalated and Charlotte was instructed not to tell anyone what was going on or face the threat of jail time. At the end of it all, she says she put $50,000 in a shoebox, handed it over to a stranger, and never saw it again. If you're thinking, well, this would never happen to me, you might want to think again. Scams like this are more common than you might imagine, and they don't just target the elderly, as some people assume, and as our next guests will explain. Amy Nofziger is the director of Victim Support for the AARP Fraud Watch Network. She says their hotline, rece, receives anywhere from 400 to 450 calls a day from people who suspect they might have been scammed. And Rachel Toback is the CEO and co founder of Social Proof Security. She also uses hacking skills, friendly hacking skills, to show companies where their security weaknesses are. Between the two of them, Amy and Rachel have heard of almost every scam in the book, and they join us now to discuss what types of frauds are common, how to recognize the signs of a scammer, and how to protect yourself. Amy And Rachel, welcome.
C
Hi. Thanks for having me.
A
Thanks for having me too.
B
And listeners, please join the conversation. Have you or someone you know been the victim of a scam? What happened? Did you understand in the moment that it was happening, that something wasn't right? This is a judgment free zone. We want to hear your scam stories. Give us a call at 212 433-9692. That's 212-433-WNYC. Amy, you see so many scams a day. What are some of the most common at this moment? And what seems to be really effective at convincing people right now?
C
Well, I will say the ones that we see are the ones that you're hearing about, right? This Amazon imposter scam bank imposter scams. You know, any of the imposter scams are very popular on the helpline. Also, romance scams, right? This is one that people think only happens around Valentine's Day, but it doesn't. It happens all year round. This is always in our top 10. This is where you meet someone online, start a friendship, a relationship, doesn't even have to have romantic intentions. The next thing you know, they have an emergency and need money. But one of the things that is really popular right now, and actually the FTC just released some data about this, is the way that scammers want to be paid. And it just bypassed prepaid gift cards, which was the most common and preferred method of criminals. But it's crypto ATM machines and cryptocurrency. So that's one thing that's very new right now, is that the scammers are asking their victims to go to these crypto ATM machines and deposit their money. Once you do that, the money is virtually gone and untraceable.
B
Wow. Rachel. I think some of us have this idea that getting scammed is something that usually happens to older, perhaps less tech savvy people. How true is that?
A
Well, we do see scams hit older folks, but it might surprise you that actually Gen Z is falling for more scams than older folks right now. Older folks and Gen Z are neck and neck every single day with falling for these scams. So a lot of times people think I would never fall for a scam like, when in reality they probably would.
B
Hmm. I mean, if someone told me to do something involving cryptocurrency, I wouldn't know where to begin. So does that mean, does that help?
A
These scammers oftentimes will walk you through exactly what you need to do. Staying on the line with you the entire Time. And so even if you don't know how to, say, go to a cryptocurrency atm, they will walk you through that process step by step to ensure you know exactly what to do. And that's what we saw in this Cut article as well. They didn't use one of those Bitcoin currency ATMs, but they stayed on the line with this individual in the cut article, taking her to the bank, Helping, helping all the way through.
B
Amy, how do hackers and scammers tend to pick their victims?
C
Well, let's just first and foremost put it out there that all of us have a tard on our back. And that's not to scare anyone. That's really to empower people to know that you might be the next person that gets this Amazon imposter phone call and so to be aware that it might be you. But they can certainly just do a whole random dialing. They'll dial 10,000 people at 1 time and hope that the next person, you know, picks up or we're seeing a lot of these scams come in via text message now. Same way, they just have a bunch of numbers. I received one of these yesterday and it's kind of pretends like it's a wrong number scam, like, hey Jenny, you want to go to dinner this weekend? Me, as a nice person, will write back and say, I'm sorry, you have the wrong number. Then the conversation ensues and it ultimately turns into some sort of scam. So it is pretty random, we will say in some of the higher dollar amount scams that we're hearing about, you know, they are targeting, you know, admin at a large tech company, right. And they're trying to do some, you know, I'm your boss and need you to wire this money right away. So some of those, they are gathering a bit more information. But in this cut article, you know, they could have gotten Charlotte on the phone and then, right then and there, their team is working to find out other pieces of information about her, to, to really give the impression that it was her, that they were dialing.
B
There's a whole team involved.
C
A whole team, absolutely. We know that about these criminals as they do work in team, and that's how quickly they were able to put the pieces of the puzzle together about what Charlotte, what her birthday was, what her last four digits were, where she lived, et cetera.
B
And we'd like to have you join this conversation. We're getting some calls in already. Have you been a victim of a scam of some Kind. Or perhaps somebody you know, let us know. 212-433-9692. That's 212-433-WNYC. Let's hear from Joe in New York City. Welcome to all of it.
D
Hi, how are you?
B
Great. Tell us about what happened to you.
D
Well, it happened five years ago, and I still can't talk to anybody. It's. I know it wasn't me. And I got a phone call. And they just led you down the rabbit hole? And they kept giving me more information and scaring me. In the back of my mind, I knew it was a scam because I'm a smart person. But you just need to stop believing you. And then you get more scared. And then it just goes on and on and on and, And, I mean, I lost a bunch of money and they, you know, it still affected me five years later, but it can happen to anybody. And it's so scary how much information this was five years ago. I can only imagine how much more information people have now.
B
Joe, Joe, you say it's affecting you five years later. Do you mean financially or emotionally?
D
Financially and emotionally. Financially, of course. I never, I'll never get that money back emotionally. I read the article and cried because I nobody, I saw the bad people with the bad comments people were writing. And until you're in, until you're in the shoes, you will never learn to accept. And you blame yourself and you're just like, how'd this happen?
B
So, Rachel, Rachel, do you want to speak to that?
A
Absolutely. We really see these attackers trying to build a sense of shame, fear, urgency to make you take these actions, telling you they're from Apple support or your bank or, or Amazon support. And oftentimes the caller ID matches what they're saying they're from. And so I'm curious if people out here are listening and thinking, I didn't realize that they could display my bank's phone number on the caller id, when in reality that's easy for us to do. It takes less than 30 seconds with an app available on the App Store, and it costs less than a dollar. So just like this caller is saying, they build that sense of shame and they blame you so that you stay quiet, quiet. And they can continue these types of scams without you talking about them.
B
What about what Joe was just saying there about feeling so upset reading the comments, people saying, essentially, how could you fall for that?
C
Yeah, David, if I could jump in really quick. This is something with my 22 years of experience with working with victims at ARP that we hear all the time. And, you know, we in society put shame on these people. And that's one thing that ARP is really trying to do, is take away that shame and stigma. And thank you, Joe, for sharing your story because it really is important to share. You need a safe place to share these stories. You were a victim of a crime. There really is no difference than if they stole $10,000 from you off of the street or stole $10,000 off of the phone. You need to share your story. The difference is, is how we in society then treat that victim. Right? The victims of financial crimes, we say, oh, my gosh, like you were a professor. I can't believe that happen. You know, someone steals $10,000 on the street, you're baking them a casserole and setting up a GoFundMe account. Right. So we need to just remember that if anyone comes to us, a friend, a family member, a neighbor, and shares their story with you, that we lead that conversation with kindness and empathy. I'm so sorry that happened to you.
B
Well, join this conversation and share your story. Again, the number 212-433-9692. Let's hear from Rebecca in Montclair, New Jersey. Good afternoon.
E
Hi. Yeah, you know, this topic is so interesting. And just recently, I got a phone call from individuals who were claiming to be from U.S. customs and Border Patrol. Border protection. Border Protection. And they were inquiring about my travel long and short. They had said that they intercepted packages and parcels containing everything you could imagine that they were intercepting parcels with meth and cocaine and heroin and that it was crossing over from Mexico. They were asking about my travel to Texas, asking addresses in El Paso. And I had just happened to be in the car when I took this phone call. And it just didn't seem right to me. I kept asking them to verify their information because, you know, they're pretending to be from the government. And so how do I know if this is real or not? And the long and short of it is I basically said to the individual on the phone, we're going to drive to the police station and continue the phone call with a police officer in the room. Because if you are who you are.
D
I want to comply.
E
Right. Because obviously isn't me. I'm not doing this. But I also. This doesn't feel right. Because then they started to ask about international bank transfers, and it started to get a little hairy. And the information that they were giving, you know, they kept saying, go on the Internet if you want to verify our badge. Numbers, go log into the Internet. And so my advice would be, if you have the ability, if you can take the phone call to a police officer if you're not sure of it. That was my advice. They ended up hanging up the phone call. But I would like to think of myself as pretty savvy, and it was intense, you know, I just, I didn't know what to do on the call.
B
Rachel, what about that advice?
A
Absolutely. Taking this to the police is not a bad idea at all because these attackers are often pretending to be from a government agency. They might say, hey, you have been a part of a cybercrime that you didn't know you were a part of. You have been involved in money laundering or drug trafficking. That's what we saw with the Cut article. We also often hear people saying, your nephew or your grandchild has been a part of a crime. And they often pretend to be from a bail agency saying, hey, you got to stay on the phone because you have to pay.
B
So scary.
A
Bail it is so this nephew can be released. Sometimes we even see voice cloning where the nephew's voice is voice cloned and saying, hey, please help me, Grandpa. I'm so scared. These types of scams are only going to get more complex, more urgent, and more fearful as we're able to see AI leveraged within those attacks.
B
That's what's happening right now. So what's going to be happening down the line?
A
It's going to be even scarier, potentially. The use of deepfakes with video in addition to audio. We're just going to have it become more and more convincing, which is why it's so important that we use another method of communication. Communication to confirm this is authentic. Talking to the police is an example. Talking to your nephew, calling them back to thwart spoofing. There's a lot of examples of using multiple methods of communication to ensure that we make sure this person is who they say they are.
B
We're speaking with Rachel Toback and Amy Nofziger, and thank you so much for your call, Rebecca. If you'd like to join this conversation. 212-433-9692. Let's go to Jay in Yonkers. Good afternoon and welcome to all of it.
F
Good afternoon. One of my favorite pastimes is messing with these guys because I constantly get phone calls. Hello, Grandpa. So right away, I put on my old man voice.
G
Harold, is that you? I haven't seen you a long time.
F
Then they give me the whole story. And it's always the same Script that they were at a party, they had one drink, they got into a car and the woman hit them with her car and she was pregnant. And now I've got in jail and I have an $8,000 or $5,000 bond to be posted. And they give me the name of their lawyer, and it's always Mr. Green. And having nothing better to do, I call Mr. Green and he gives me this whole schmear story. And then I tell him, you know, my usual thing is, does your mother know you do these bad things? He hangs up. But I have his phone number and I keep on calling him and he finally has to shut off that number. So this happens quite often. And same thing has happened. I get a phone call from the bogus irs, and once again, I was at my office and we have optimum. So it's unlimited, unlimited phone service. I just kept on calling the agent back until they shut down their number. So they're out there and nobody, of course a government agency is going to call you.
B
What about that?
F
One hour after my grandpa's phone call, I get another phone call from hello, Grandma. So I put on my high falsetto voice and mess with them for a while.
B
What about that, though, Amy? Messing with people, prolonging these conversations, is it. Is it better to sort of move on?
C
Yeah, I get that you're having a lot of fun with that shame, but I do recommend that you don't. And the reason is, is because oftentimes that will show that you're staying on the phone. Right. And so we do know that these criminals do share phone numbers of people who pick up their phone and stay on. So even though you might be messing with them for 20 minutes, that might indicate why you're continuously getting more phone calls. So my best recommendation is don't pick up the phone unless you absolutely know who's calling. And there's even some technology in some of the smartphones today where you can silence unknown callers, meaning anyone that's not in your contacts list will go directly to voicemail. But just know that your phone number and your personal information is big business with these scammers, and it's shared among them. So the longer you're on the phone, another scammer might think, ooh, that's a good target to go after.
B
Wow. Amy Nofziger, director of Victim support for AARP Fraud Watch Network, and Rachel Toback, co founder and CEO of Social Proof Security, will continue this conversation on all of it here on wnyc. Coming up in just a moment. We're talking about phone scams and online scams here on all of it on wnyc. I'm David, first in for Alison Stewart. Have you been the victim of a scam of some kind? Let us know with a phone call. 212-433-9692. That's 212433, WNYC. And I want to read a text that we just received. Since looking for jobs on various sites, I have been contacted by scam job recruiters via text. I have almost fully set up a profile before they start asking for personal or financial information before I got suspicious. What about that text scam, Rachel?
A
Very common. Right now we are seeing attackers pretending to be even the real organizations on these job sites where folks are going to apply to fake jobs or receiving outreach from fake jobs. Because of the layoffs happening right now, a lot more people are falling for these scams and the attackers often will say, hey, you're going to be working from home. Please send us $500 so we can send you a laptop so we can send you your microphone or your speakers that you'll be using while you work from home. And these people think, well, I guess that does sound reasonable. I'll go ahead and do that. But oftentimes this is a scam. These types of organizations will not ask you to send money. That's not going to happen. They will provide those tools for you.
B
And I want to get to another phone call in just a moment. But Amy, I want to read this other text to you. Very upsetting. My 25 year old high functioning autist son is desperate for a girlfriend. He responded to someone on Instagram. Next thing we knew she had drained his bank account of everything. I say she because it was obviously a group of people doing this. Thank goodness we banked together. So I was able to fix was very painful for him as well. Tell us about that.
C
Yeah, unfortunately we hear these stories every single day on the helpline whether you're younger or older. We all want companionship and we all want to share our life with. Just know that wherever you are online so is a criminal and just be aware and, and I'm, you know, proud of the mother for, for taking a stand and getting involved. But it's unfortunate that there's a lot of people out there that don't have someone that they can turn to and trust. So you know, whether it's your, your minister, your, you know, a police officer, someone that you trust, if you're involved in a scam right now, reach out for help, you can certainly call us on the helpline, but you're going to need someone support in this, in this fraud recovery journey.
B
And let's get to another phone call right now if you'd like to. We have a lot of calls coming in right now. 212-433-9692. William from Brooklyn, welcome to all of it.
F
Hi.
G
About five years ago, I wanted to contact PayPal and I googled their number, called the number, and the person who answered the call said, are you aware that somebody has used your account recently in an airport? I said, no. They were like, okay, we're going to send you a code. I read them the code and then they told me that I can't remember how they did it, but they convinced me that I had to go get a Google Play card. And I'm 37 and I feel that I'm pretty savvy, but I had never heard of a Google Play card. And my emotions, I was getting quite angry by the whole thing and I thought it was absurd that I had to go out of my way to go get a Google Play card. And I hung up the phone and then they kept calling back and I was seeing that they were doing little activity on my PayPal account. So I went to a CVS and I got the Google Play cards and I was at the cash register and I said to the woman checking me out, listening to this crazy story, I have to buy these Google Play cards. And she was like, that's a scam. And I hung up and didn't buy the cards, thankfully. But it was so jarring to me because I sought out them and, and I thought that Google, you know, the number that appeared on the top would be the correct number. And I reported it to Google and I never heard back from them. But now whenever I'm trying to contact a company, I'm super cautious about finding it on ebay's website or Instagram's website, as opposed to just trusting any number.
B
Rachel Toback, good advice there.
A
Yeah. So unfortunately, any phone number can be spoofed and display on your caller ID. That's possible for almost every phone number in the U.S. in addition, I really want to highlight what happened in that specific scam. When they asked you to read that code out, they were stealing your Multi Factor Authentication code or your two factor code from that site you were using. So they likely had your password. That means they logged into the site. They were able to generate a Multi Factor Authentication code, send it to you, and siphon it out from you on the phone. Do not give your codes out to people over the phone. And recognize that spoofing can happen to anyone. And any phone number can be displayed on caller id.
B
Amy, what are some of the real concrete steps we can do to protect ourselves? I mean, I'm just ready to hide under the blanket. Never answer the phone, never look at email. I shouldn't be talking to you right now. What can we do?
E
Right?
C
I might be a scammer. First and foremost, have awareness. And don't be scared. Be empowered, because when you're in a state of fear, you're less likely to act and use your cognitive thinking. In the story that, you know, we just heard from William, you know, he thought he was doing his due diligence and going on and googling the phone number. But the criminals can place fake phone numbers. So use his, you know, example for a good step. If you're ever looking for a customer service phone number, go directly to the website of the company you want to call and go to their contact Us page. Do not just take the first number that comes up on a Google or Bing return. Additionally, other steps to take if you're on social media, lock your page down tightly. Most social media pages will show you how. Whether it's LinkedIn, Facebook, Instagram, they'll take you through the steps. You do not want to have these open pages where people can get information about you. And then finally, a great step that everyone can do today, I mentioned it earlier, is if you have a smartphone, pull it out right now. Make sure your contacts are up to date. Go into your phone settings and hit the toggle that says, says silence unknown callers that will have anybody that's not in your contacts list, go directly to your voicemail. So you'll still get the phone call, but it will not ring and catch you off guard. And that's what we hear about. And that's what happened in that cut article. She's at her desk, it's Halloween, it's busy. Her mind is somewhere else. The phone rings, she's caught off guard, her defenses are not up, and that's how they were able to criminalize her.
B
Rachel, what about, what kind of information should we be careful about posting online? You know, we all sometimes, sometimes overshare a little bit online. What should be. What should we really be careful about? Things that might leave us more vulnerable to being scammed?
A
Yeah. A lot of times people will post on social media that you. They use specific tools and the attacker can pretend to be from that specific tool and Give you a call to trick you. I also want to highlight that it's really important that you use long, random and unique passwords on every single site and apply. When we reuse our passwords, attackers can find that in a data breach online, log into our account and siphon out additional codes or information from us. So it's important to make sure we don't reuse our passwords and turn on multi factor authentication for every site and tool we use. And recognize that spoofing is easy. Caller ID can show anything on our phone. So it's really important that we don't just trust our caller ID and we make sure that we use another method of communication to confirm that's authentic. Also, if you Google a site, sometimes those ads at the top of Google can be malicious. A lot of times these malicious actors will take out an ad telling you that the phone number that they want you to call is right there at the top, when in reality that's not actually the bank or Amazon support or Google support. So it's important that you use trusted phone numbers and like Amy mentioned, go directly to a known trusted site, their Contact Us page, and ensure that you do not get tricked by spoofing, by calling them back. If you call them back, you're going to go to the real person or the real organization, not the attacker.
B
Yeah. Then you're initiating the phone call to what you know is the trusted place. Let's hear another phone call. This will in Brooklyn. Thanks for joining us this afternoon.
C
Hi.
H
Good to talk to you.
G
I was in the middle of a.
H
Long job search and I was on the phone with your screener. And when I finished telling them about my situation, I was hearing the end of the description of the same thing that happened to me. I actually had a Google Meet interview with someone who kept pressing me for bank details to get the get the money over for the home office equipment. And I wound up saying I had to take a break. And I called the company that they were purported to be calling from and they said they'd never heard of the person. They didn't have that job open and it was new to them. So I avoided paying for this bogus office equipment. But I had a couple of other instances where the same scam was brought up and the companies already knew about it. They knew that their LinkedIn pages had been spoofed and they were ready for it, but they couldn't really do anything preemptively. It seems like an easy way to keep reaching out to vulnerable people.
B
Amy.
C
You hit the nail on the head when you said vulnerable. So even though we all have targets on our back, we have to remember that in our life stages that we do might have more vulnerability. So when you are unemployed or looking for a new job, you are a target for job scams, right? If you are a grandparent, you are a target for a grandparent scam. If you are recently widowed, you are a target for a lot of these scams. So just know that when you're out there looking for employment, the scammers are looking for you. But I think again, bottom line, regardless what scam, it is one of the classified 100 that are out there right now. Listen to for the key things. And you said it again. Will they asked for your bank account information. No legitimate employer that is interviewing you is going to ask you that until you have a signed offer in front of you and you need your check direct deposited. No government agency is going to ask for payment and prepaid gift cards, cryptocurrency or a peer to peer app. No law enforcement agency is going to call you and basically give you a heads up that they're coming to arrest you unless you pay. So again, don't get caught up in all of the scams that are out there. Listen for those key red flags.
B
And just to wrap up, Rachel, if it's too late, if you believe you are the victim of a scam, who should you report it to? What else should you do?
A
If you believe that you are a victim of a scam, it's important that you talk to your bank or your credit card and let them know what happened. Sometimes they can shut it down. Oftentimes the money is lost. But it's important to at least try.
B
It's important to at least try. Okay, Rachel Toback, the CEO and co founder of Social Proof Security, and Amy Nofziger, the director of Victim support for the AARP Fraud Watch Network. Thank you both for joining us on all of it today. And thank you for all of your calls and your texts and sharing your personal stories with us.
I
NYC now delivers breaking news, top headlines and in depth coverage from WNYC and Gothamist every morning, midday and evening. By sponsoring our programming, you'll reach a community of passionate listeners in an uncluttered audio experience. Visit sponsorship wnyc.org to learn more.
Podcast: All Of It (WNYC)
Host: David Furst (filling in for Alison Stewart)
Guests: Amy Nofziger (AARP Fraud Watch Network), Rachel Toback (Social Proof Security)
Date: February 22, 2024
This episode addresses the surge of modern scams, debunking myths about who scammers target and equipping listeners with practical strategies to recognize and avoid becoming a victim. Using the viral case of a financial columnist who gave $50,000 to a scammer as a springboard, guest experts discuss the psychology, technology, and methods behind prevalent scams and respond to listener stories and questions.
Recent Viral Example: The show opens with the story of Charlotte Coles, who was conned into handing over $50,000 in cash to a stranger under an elaborate ruse involving fake Amazon charges and fake law enforcement threats.
Prevalence and Reach:
Generational Misconceptions:
Victim Selection:
Creating Urgency, Fear, and Shame:
Listener Story Highlights:
Advanced Scams Using Technology:
Taunting Scammers:
Trusting Phone Numbers from Search Engines:
Text and Job Scams:
Romance Scams:
Customer Service Scams:
Stay Alert, Not Afraid:
Verify Contact Information:
Control Your Digital Footprint:
Password Hygiene:
Limit Incoming Calls:
Listen for Red Flags:
Reporting:
Seek Support:
The conversation is empathetic and empowering, striking a supportive note for victims and emphasizing that anyone—regardless of age or expertise—can be targeted and manipulated. The guests use clear, nonjudgmental language and real-life examples to illustrate their advice.
This episode demystifies the tools and tactics of modern scammers, reminds listeners that anyone can be a target, and offers actionable steps to protect oneself. At its core, the message is one of vigilance, compassion, and community support: don’t let fear keep you silent, and always verify before you trust.