One of the most striking examples of social engineering can be found in the hundreds of fake call centers in India and other countries that seek to deceive Western users lacking sufficient technical knowledge. The problem for those call centers is that sometimes they aren't so lucky, and they run into experts who, besides taking control of the situation, record the event and publish it on YouTube.
The Classic Scam Script
The process almost always starts the same way: the victim’s computer gets infected with partial or full scareware that alerts them to a serious issue with Windows and presents a phone number to contact the “Microsoft support service.” On the other end is a supposed “IT expert” who calls himself John, George, Sean, Michael, or something similar, very friendly at first, but speaking English with such a thick Indian accent that his words are barely comprehensible. This is where things start to vary. Most commonly, the “expert” escalates the fear tactic, guiding the user to tools like Event Viewer or System Information and suggesting that each entry there “is an error caused by a malware infection.”
Next, the scammers instruct the victim to download TeamViewer or a direct equivalent, and share both the ID and password. From that moment, the “expert” becomes an attacker, capable of all kinds of damage—unless the user pays or enters their credit/debit/PayPal/etc. credentials into a special page. Considering that TeamViewer is free, Skype calls are free, and fear is an extremely cheap weapon, keeping these call centers full of fraudsters is easy and relatively inexpensive.
When Scammers Meet Their Match
…the villains are becoming victims, courtesy of a group of users with far more advanced knowledge. Several of those users are also YouTubers, and they’ve created channels where they share their adventures ruining the scammers’ day. Most of these “technicians” basically follow a script and lack the skill to respond to a counterattack. Add to that the use of outdated machines running obsolete operating systems, and the Western vigilantes can do things like install RAT software, trojans, and keyloggers, delete their “tools”, and even change the operating system password.
Of course, the owners of these channels have often been accused of faking calls , given the disturbing level of ignorance shown on the other end, but let’s not fool ourselves: at this very moment there is some nefarious entity on a Skype call tricking a person into putting their credit card number into a browser.
The second video is one of the best examples of the impact these scammers have when they find the right victims. It runs more than 38 minutes, and at the end we can see that they stole nearly half a million dollars. Some of the YouTubers focus their efforts on getting refunds for the victims, but unfortunately that doesn’t always work. How sustainable is this kind of fraud over time? I wouldn’t bet on it. Slowly, they are realizing their new role as clowns in front of a Western audience, and that the weapons thrown at them are getting more sophisticated. A solid example is the case of The Jolly Roger Telephone Company, which has an entire army of bots to jam their phone lines.
Still, it’s obvious they will squeeze the orange dry, and we as communicators need to keep warning about this activity. All legitimate Microsoft phone numbers are published in this link, divided by country. Anyone who needs to contact the company should start there.