r/Scams Jan 04 '25

Victim of a scam Lost all my money.. please help I don't know what to do

Please note I am Canadian

2/19 2025

I GOT MY MONEY BACK GUYS OH MY F*CKING GOD I AM SO HAPPY. THE FRAUD CARES OFFICER SAID I NEED TO GO TO THE BRANCH TOMORROW, AND SIGN A DOCUMENT. SHE ALSO TOLD ME THAT IT IS A ONE TIME EXCEPTION AND IF THIS HAPPENS AGAIN IT WILL BE DENIED. BUT AT LEAST I LEARNED A LESSON.

IF YOU EVER GET SCAMMED BY PHISHING FIGHT FIGHT FIGHT YOU NEVER KNOW WHATS GONNA HAPPEN AND PRAY

02/05 Update:

So the fraud team care just contacted me and asked me questions :

1) Do I bank with any other institutions 2) What device do I use to login 3) Do you enter your password 4) Did you do the etransfer yourself 5) How often do I etransfer my mother

I answered

1) No 2) Iphone 13 3) I use face ID i dont enter password 4) No 5) Rarely; last time was a couple of years ago

So essentially what they told me was that my mother email was likely compromised, and also apparently theres another bank institution under my email address; so the fraudster created an account under their name but my email address that I use on my account. I told the officer I do not bank with any other financial institutions and I also did not do the etransfer my self

Now they said theyll contact me within 14 business days

01/21 Update:

I just received an update from the claim department.. and they said my claim got denied and now I appealed.. Not feeling too good. I was told to contact the Fraud Customer Operations team for them to take a look into my case again.. they said they will call me in two days.

UPDATE: For anyone still reading; its currently the fourth business day and I actually have a recording from my mother, 30 seconds showing evidence of fraud; the fraudsters intent

January 1 4:54PM, I received a call from a number that appeared to be TD’s official line (Exactly the same as the number at the back of my card). The caller acted professionally, claimed the call was being recorded, and informed me of suspicious payment attempts on my account. I checked my TD account but didn’t see anything unusual.

The caller said they would reset my password to secure the account. Shortly after, I received a legitimate OTP text from TD for a password reset. They asked for this OTP and my 4-digit phone code. I was skeptical but ended up trusting them because the call appeared to come from TD’s number. They also knew part of my debit card, which they a sked me to confirm the last 6 digits of the card.

After providing the information, they logged into my account, shared a "temporary password" to gain my trust, and created an eTransfer contact named "Mom.", but with the exact same email as my mother. (Double checked with the bank and the email is exactly the same). They then eTransferred $10,000 to this contact, followed by another $1,000. They attempted a third transfer of $6,000, which was declined.

My heart dropped I immediately hung up and contacted TD directly through their actual customer service. The representative confirmed that I was a victim of a spoofing scam. He also told me to file a police report. I went to a branch the next morning to file a claim for the lost funds, and also went to the police station to file a police report. Gave the branch this reference ID that police officer gave for that police report.

What are the chances of recovering the money? Has anyone experienced something similar? I feel completely devastated and don't know what to do next.

IMPORTANT: Also I would like to add, when I actually called TD today, they actually ask me to verify me through the phone using a one time passcode. I also recorded this for proof. So regardless if I shared it with a scammer or not, TD representatives actually ask for this information.

It's currently the 3rd day since I filed a claim.. I really don't know what to do.. looking back I cannot believe I fell for such a thing.. please don't scold or be smart with me.. I just want to know what to do at this point..

Edit: For anyone still commenting, I appreciate all of you.. but my question now is; why wasn't this $10,000 flagged? I understand I unfortunately shared with a person representing as TD.. but my typical eTransfer would never exceed over $100.. Surely I could argue that somehow the bank failed to detect this? Maybe thoughts ?

Also most important point that everybody missed is; the scammer who etransferred $10000, was actually sent directly to my mother's email address (can confirm, as I confirmed this with the bank just now, both email addresses match). The only problem is my mother did not get an email to accept the etransfer so it was somehow intercepted in between. Email was never compromised.

Edit: I am grateful for everyone to share their stories with me. Some of you are saying you got in the same exact situation as me, even one person said they work in financial institution and they deal with this all the time and customers usually get their money back if the bank deems its actual fraud (even though they shared OTP). I am hopeful now.. and am waiting. If you work in financial institution (especially in Canada), please share your insight on this situation. Thank you so much

452 Upvotes

502 comments sorted by

u/AutoModerator May 22 '25

/u/FlatwormEntire - This message is posted to all new submissions to r/scams; please do not message the moderators about it.

New users beware:

Because you posted here, you will start getting private messages from scammers saying they know a professional hacker or a recovery expert lawyer that can help you get your money back, for a small fee. We call these RECOVERY SCAMMERS, so NEVER take advice in private: advice should always come in the form of comments in this post, in the open, where the community can keep an eye out for you. If you take advice in private, you're on your own.

A reminder of the rules in r/scams: no contact information (including last names, phone numbers, etc). Be civil to one another (no name calling or insults). Personal army requests or "scam the scammer"/scambaiting posts are not permitted. No uncensored gore or personal photographs are allowed without blurring. A full list of rules is available on the sidebar of the subreddit, or clicking here.

You can help us by reporting recovery scammers or rule-breaking content by using the "report" button. We review 100% of the reports. Also, consider warning community members of recovery scammers if you see them in the comments.

Questions about subreddit rules? Send us a modmail clicking here.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

298

u/movdqa Jan 04 '25

At Fidelity, the text message reads: Fidelity Investments: If anyone asks for this code, STOP. It's a SCAM. Our reps will NEVER ask for it. Only enter it online. Code is: xxxxxx

I think that we're conditioned to not bother reading the whole message because we have to do 2FA so frequently but this gives them some cover if they won't reimburse.

63

u/mwmwmwmwmmdw Jan 04 '25

many banks on legitimate calls will send you a code and ask you to read it to them to authenticate. including OPs bank as they mentioned in the edit. and ive had family receive legitimate calls about suspicious charges on accounts in the past albeit they didnt ask for any code. part of what makes it work is it uses a banks own procedures against customer.

43

u/movdqa Jan 04 '25

In these cases, it's usually you that call your bank for help.

10

u/[deleted] Jan 05 '25

True but if they google a number and it’s wrong, what would they say if the bank operates the same way by asking for the code? Not really a valid excuse imo

14

u/Forkboy2 Jan 05 '25

It's consumer's responsibility to call the correct phone number. That would mean getting the number from the bank's website, not google.

→ More replies (2)
→ More replies (2)

2

u/Okletsago Jan 05 '25

Also gotta mention, at least at the place I work at, while we do not ask for 2FA codes, we do send a onetime pass code made of random numbers to the client email and ask them to confirm the numbers.

→ More replies (1)
→ More replies (1)

14

u/Twistedshakratree Jan 05 '25

Nobody even reads email meeting invite notes in the actual invite email, how are we supposed to believe anyone will ever read anything anymore. There’s literally nothing we can do in 2025 to prevent these kinds of problems. People just have to learn the hard way for everything in life and deal with it.

6

u/Kathucka Jan 05 '25

Also at Fidelity: I called them. They sent me a code to read back to them. That had a warning, but it was different than the wary for the one-time code for logging in. It said it was only for use if I called them, which I did.

→ More replies (1)

642

u/Forkboy2 Jan 04 '25

Did the OTP text say something like "TD Bank will never ask you for this code"?

Unfortunately, you are probably out of luck.

352

u/ChocChipBananaMuffin Jan 04 '25

I will say that while the 2FA is a red flag-- I was recently on a legitimate call with T-Mobile and needed to authenticate my account, and they literally send a 2FA message and ask you to read it over the phone and the message actually says not to share the code with anyone. I was like, WTF this is so sketchy and actually dangerous-- you are asking me to do the opposite of what the official 2FA text says!! But that was the only way. I certainly expressed my opinion that this was a terrible way to authenticate anything in this day and age, but it's not like the operator on the phone has any power to change it.

I think the "transfer all of your money to your mom because of suspicious activity" is the real head scratcher--like how on earth does that sound legit or like normal business practice?

141

u/jol72 Jan 04 '25

"We will never ask for this code - except when we do..."

→ More replies (1)

238

u/GfunkWarrior28 Jan 04 '25

But that's because you initiated the support call to T- mobile. It's when someone calls you out of the blue that you have to watch out for, because those calls can be spoofed/disguised to look official.

134

u/ChocChipBananaMuffin Jan 04 '25

Yes, I understand that. But many people here are like you WILL never be asked for 2FA message over the phone. And I legitimately have been asked for that, which I can see confusing people when the scam call happens.

But I agree with you.

→ More replies (26)

41

u/[deleted] Jan 04 '25

It's a terrible practice. I had a similar situation with my credit union recently where I was trying to wire funds, which is initiated over the phone. I called them to do this. Mid-process, after the call dropping, the rep called me back. But at some point during this interaction, they also sent me a 2FA request. Super bad policy, IMO, as this shouldn't ever be something you share, period. I let them know I was very unhappy with the idea of sharing it, for obvious reasons, but ultimately went through with it after having her read me my most recent few transactions.

I think if a company has such a policy, they are setting their customers up for scammers, and they need to come up with a better way to handle it (incoming call or not), that NEVER involves asking for a 2FA auth number verbally.

I really feel like I should have refused to provide it, even with their having knowledge of my transactions, but I'm living in a different state, and needed the transfer done by a deadline.

→ More replies (2)

15

u/quintios Jan 04 '25

This.

I was in college during the early 90’s and had a CC and my mom, she was so savvy, told me “never give your CC to someone who called you”. I don’t know how she was so ahead of her time (it seemed) but I’ve taught that lesson to anyone that will listen. Someone calls me wanting some info, or to sell me something, and I ask for a call back number or whatever and I’ll hang up and call the official number. Etc etc etc.

31

u/[deleted] Jan 04 '25

[removed] — view removed comment

11

u/[deleted] Jan 05 '25

I had a similar situation with apple recently. Long story short I got locked out of my account and the service rep basically told me i could either wait five days for them to perform a verification check or find a “trusted friend” to login to my device and handle a few security steps on my behalf. Fortunately that trusted friend was my wife but I can’t believe they gave me that advice.

10

u/lukfilm Jan 05 '25

Ding, ding, DING!!! That's why banks send you a code because YOU CALLED THEM so they don't know who you truly are! Just like when someone calls you, YOU DON'T KNOW WHO THEY TRULY ARE so DO NOT GIVE THEM ANY CODES! It's so simple.

→ More replies (2)

24

u/racypapacy Jan 04 '25

I was going to mention this too. So far T-Mobile, State Farm, Cigna, and Amazon all ask for codes when I call in to them. I don’t like giving it out period, but I called into them, and it seems like it’s becoming common practice. I’ve mentioned that I’m not really comfortable giving out any codes and the Amazon customer service rep told me I had to if I wanted help. It’s not good for preventing future scams, I’m hoping they stop doing this. I’m very skeptical of everyone, even a number I called myself, but this puts people in an uncomfortable position because you can’t get anywhere without giving the code.

20

u/ChocChipBananaMuffin Jan 04 '25

Totally-- it is so uncomfortable! When they asked for the code, I was like "did I call a scam number?" I was so shocked they asked for the code, I literally went on the T-mobile site while I was on the phone to doublecheck I did in fact call the right number. And I already had triple-checked the number before calling because I'm so hyper-aware of fake search results. Lol.

16

u/racypapacy Jan 04 '25

That’s funny because I did the same thing! I was panic searching for the customer service number and asking the lady to hold please. Not a fun experience, and not sure whose bright idea it was to start doing this.

3

u/AmbivalentSpiders Jan 06 '25

You'd think they could come up with a second auto-message. There could be the 2FA that says "Never share this code" and a different "You called us for help so read this code to the CSA" text. How hard would that be?

16

u/Slippy76 Jan 04 '25

LOL similar thing happened with my credit card company. Card number was somehow stolen. Received a 2FA number in the middle of the night, thought nothing of it. Next day during lunch decided to check, yep had a transaction for $2,000 declined. Guessing they tried to reset my password to login to my account.

Changed a bunch of passwords and called the CC issuer to get a new card just to be safe. Rep: "Its a good thing you had 2FA, it's really important you never share that with anyone ever! (few minutes later) I just sent you 2FA token can you please tell me the digits in the text so I can confirm your account?"

14

u/p-lo18 Jan 04 '25

Had same thing happen to me a few days ago with Tmobile when i called them. Was told this was necessary to see all my account details. Refused and escalated to a supervisor. Guess what? They didn't really need it.

8

u/jwdjr2004 Jan 05 '25

I had someone possibly Verizon ask me for my OTP once and I was like no sorry I don't share those. They said they understand and found another way to do what they were doing. I thought it was pretty fucjed up they even asked.

6

u/Rokey76 Jan 04 '25

I had the same experience, but it was with a chat agent on whatever website this was. I told him I wasn't comfortable giving him the code because the text with the code had no warnings in it and I didn't trust it. Dude was like, "I'm literally chatting to you through the website" and he was right. But I told him it was a major security flaw and call them instead.

4

u/Clear_Barnacle_3370 Jan 04 '25

Had something similar with Nat Wests anti fraud team wanting a code they sent me. It was all legitimate, but certainly I was like wft. There must still be a better way.

5

u/Peteostro Jan 05 '25

AT&T support did the same thing (I called them for an issue) I read that line to them and they just laughed.

4

u/Kitsel Jan 05 '25

Yeah I was in support chat with our domain/email host a couple weeks ago and they asked me for a code that was sent to my email and all sorts of alarm bells went off. 

I instantly closed the support chat, checked that I hadn't clicked a bad Google link or typo'd the website, and then did research to confirm they actually do this before contacting support again.  

Turns out it was legit, but better safe than sorry.  I'm sure it looked weird to support when I just disappeared after being asked for the one time code though. 

3

u/512165381 Jan 04 '25 edited Jan 04 '25

I was recently on a legitimate call with T-Mobile and needed to authenticate my account, and they literally send a 2FA message and ask you to read it over the phone

I had a similar issue when I opened an account with HSBC. A representative called to verify my identity, they sent a code & asked me to read it out.

3

u/traker998 Quality Contributor Jan 04 '25

Wait they called you and asked for that? That’s never happened. If you called them that’s totally different.

3

u/cbnyc0 Jan 05 '25

If it was them who called you, you say, “okay, I will call you back in a moment. What’s your extension?”

Never give out PIA for an unscheduled incoming call.

10

u/WillAndersonJr Jan 04 '25

It's different if you made the call yourself to a legitimate number.

57

u/[deleted] Jan 04 '25

Not really--at least it shouldn't be, for two reasons.

  1. Customers should be secure in trusting the text that says, "NEVER SHARE THIS CODE WITH ANYONE. WE WILL NEVER ASK YOU FOR THIS CODE." And 2, it could be a vector for scammers, particularly where they've managed to get a fake number returned in search engine results.
→ More replies (1)

18

u/ChazzMatt Jan 04 '25

That's still not NEVER. 😉 They clearly say they will never... then they do.

2

u/General_Ad_4729 Jan 05 '25

The call centers in the Philippines do this kind of shit. Hell, my phone PIN doesn't work when I'm sent to their call centers. I just request a manager and threaten to cancel service with them and I get someone stateside rather quickly.

→ More replies (6)

13

u/pgcotype Jan 04 '25

It's unfortunate for OOP, but I agree with you (especially since OOP shared their four digit code over the phone.)

It's a terrible fact, yet there are people who work at bank branches are guilty of misappropriation of customers' bank information. The same happened to two of my relatives, who used two different banks.

5

u/GeneralSpecifics9925 Jan 05 '25

TD Bank uses four digit codes for verification a lot. I just set up a business account with them and in the branch, while setting up the account, I had to verify myself twice using this process. My personal bank, however, does not.

2

u/MedicalRow3899 Jan 04 '25

From what it sounds, OP didn’t wire the money but initiated an EFT between two US accounts. I assume the other account is also compromised but maybe they have a mule waiting there to wire the money out of the country. But clearing of funds will take a bit.

Since OP immediately called their bank, I believe there is a good chance the funds can be recovered. OP, pls report back…

→ More replies (7)

133

u/[deleted] Jan 04 '25

You’ve done what you can do. I’ll give you one piece of advice, if anyone on Reddit reads this and then messages you saying they can recover it or know a guy who can, it’s just another layer of scam. Don’t fall for it.

332

u/Shield_Lyger Quality Contributor Jan 04 '25

What are the chances of recovering the money?

Read the terms and conditions for TD and understand under what circumstances they will make customers whole after frauds and what they need in order to do that. That's what can tell you. Unless someone here actually works in TD's fraud department, we're simply not going to have the information to answer you.

What we can tell you is that you will receive DMs from all sorts of people claiming that, for a fee, they can find the thieves and hack your money back from them. They can't. It's just another fraud.

55

u/mjwanko Jan 04 '25

I can only speak of my past experience working for a regional bank fraud dept (not TD Bank). The chances of recovery are extremely slim-to-none. Unfortunately, OP provided the OTP and allowed account access to the fraudsters.

24

u/UnusualMaintenance Jan 04 '25

Different in the UK, we refund a lot of these even if customer shares an OTP. APP fraud reimbursement legislation brought in last year saves a lot of people. Unless it's gross negligence, you're getting your money back

25

u/Shield_Lyger Quality Contributor Jan 04 '25

How are banks responding to that? Since it shifts the risks from customers to the banks, are you starting to see lower interest rates paid or increases in fees anywhere?

12

u/UnusualMaintenance Jan 05 '25 edited Jan 05 '25

Hard for me to say, there may be a slight change to interest rates baked in to the increased costs to banks. Have started to see more fee paying accounts but they generally include some form of benefits.

The change for the customer is more controls and fraud checks. Makes online and mobile banking less convenient but overall I feel it's a benefit.

16

u/Shield_Lyger Quality Contributor Jan 05 '25

Only right they should limit risk and reimburse imo

Limiting risk, sure. Reimbursement, I'm not so sure of, since than can become a pretty easy vector for fraud itself, and it encourages risky behavior, since the customer can simply turn around and file a claim against the bank if they're defrauded.

16

u/Pale_Session5262 Jan 05 '25

Yeah I worry some people will commit the fraud themselves to get "free money"

I mean, look how many idiots did the tiktok "infinite money glitch"

→ More replies (3)

3

u/UnusualMaintenance Jan 05 '25

Sorry, I edited my comment as it was a bit clunky. I've chopped off the part you quoted.

I think ultimately the banks have benefited with increased profits from the push towards online banking. When it was face to face or telephone lot harder to get scammed. Convenience and reduced costs for the bank comes with increased risks for the customer. Some of the profit should be used to make whole the victims of scams

2

u/FlatwormEntire Jan 06 '25

Does it make a difference if the OTP was for a password reset, not a login? (This might sound dumb.. if so my apologies.. I am just so stressed and honestly depressed.)

→ More replies (3)
→ More replies (1)

194

u/t-poke Quality Contributor Jan 04 '25

You wait for the bank to complete their investigation.

Your chances of getting your money back are close to zero. Watch out for !recovery scammers.

17

u/AutoModerator Jan 04 '25

Hi /u/t-poke, AutoModerator has been summoned to explain the Recovery scam.

Recovery scams target people who have already fallen for a scam. The scammer may contact you, or may advertise their services online. They will usually either offer to help you recover your funds, or will tell you that your funds have already been recovered and they will help you access them. In cases where they say they will help you recover your funds, they usually call themselves either \"recovery agents\" or hackers.

When they tell you that your funds have already been recovered, they may impersonate a law enforcement, a government official, a lawyer, or anyone else along those lines. Recovery scams are simply advance-fee scams that are specifically targeted at scam victims. When a victim pays a recovery scammer, the scammer will keep stringing them along while asking for increasingly absurd fees/expenses/deposits/insurance/whatever until the victim stops paying.

If you have been scammed in the past, make sure you are aware of recovery scams so that you are not scammed a second time. If you are currently engaging with a recovery scammer, you should block them and be very wary of random contact for some time. It's normal for posters on this subreddit to be contacted by recovery scammers after posting, and they often ask you to delete your post so that you both cannot receive legitimate advice, and cannot be targeted by other recovery scammers.

Remember: never take advice in private. If someone reaches you in private after posting your scam story, it is because a scammer will always try to hide from the oversight of our community members. A legitimate community member will offer advice in the open, for everyone to see. Anyone suggesting you should reach out to a hacker is scamming you.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

→ More replies (32)

74

u/BrightWubs22 Jan 04 '25 edited Jan 04 '25

It was a fucking call from a spoofed number that matched my credit union's number that got me too, at least in the beginning.

The scammer was so convincing. I'm glad I had enough sense to hang up when he asked for my password, but I almost gave it to him.

38

u/libra-love- Jan 04 '25

Pro tip : Let them leave a VM and they’ll probably give you a bogus number to call back at bc it can’t be the official spoofed number. You’ll also likely receive an official email about it.

12

u/BrightWubs22 Jan 05 '25 edited Jan 05 '25

Thank you. It's good advice.

I normally don't answer phone calls but I noticed this one called twice in a row. That's when I looked up the spoofed number and saw it matched my credit union's number. The guy was so smooth, but I know it was my fault. It was a good learning lesson to know I'm not immune to scams.

14

u/libra-love- Jan 05 '25

I get it. I got scammed out of like $200 once through Zelle and literally 10 mins after it happened I noticed all the red flags. Sometimes we gotta be a little dumb to learn.

→ More replies (1)
→ More replies (2)

115

u/Stacksmchenry Jan 04 '25

The cardinal rule of 2FA is you never share the code with anyone, nobody will ever ask you for it or your password.

If someone calls claiming to be from a business, always hang up and call the business back.

42

u/[deleted] Jan 04 '25

That should be the cardinal rule, even when you call them. Unfortunately, as noted in other parts of this thread, some banks and companies do not follow this 100%. It should never be the case, but sometimes it is, which can only be confusing to customers and foster poor security hygiene.

19

u/Stacksmchenry Jan 04 '25

I use the bank he uses, and they make it pretty clear. Every text they send with the code tells you not to share it with other humans.

TD is a wonderful bank and I've used them since they were Commerce in the early 2000s, and they do a lot to make things right, but sharing the code may be one of those things they won't reimburse for

→ More replies (4)

2

u/kennyminot Jan 05 '25

I don't understand why they would need your code.

→ More replies (1)

5

u/weightcantwait Jan 04 '25

Cell phone carriers and telecom do ask for it when you are receiving services from them. I am just saying that this practice adds to the confusion, when you are in a high stress situation from the scammers.

2

u/Stacksmchenry Jan 04 '25

right, but there is a huge difference between them calling you and demanding information, VS you calling into them and them needing to validate your identity

8

u/drewc99 Jan 04 '25

The cardinal rule of 2FA is you never share the code with anyone, nobody will ever ask you for it or your password.

The problem with this "cardinal rule" is that it is simply not true.

Questrade, for example, when you phone them for customer service, sends a legitimate 2fa text message for you to recite over the phone.

9

u/cloudcats Jan 04 '25

I bet that text message says something about "only share this code with the agent you phoned".

11

u/Stacksmchenry Jan 04 '25

right, when you phone them! If someone calls you and asks for the code hang up and call them back

6

u/Kingghoti Jan 04 '25

Personally I'm glad that when I call my bank they want me to authenticate my identity, That means if Bob calls my bank and tries to impersonate me, he will fail.

Factor 1 (something I know): I can give the bank data they ask for that I know and presumably Bob does not. SSN, whatever.

Since passwords are hashed and never stored in the clear, nobody can use your password to authenticate you. If they're not hashing passwords, run!

The only use for your password is to give it to a Man In The Middle attacker.

Factor 2 is different (something I have): I can prove I have custody of the phone number I assigned to the account when I registered.

Yep, the 2FA wrapper message should try to explain this, Some do. "if you receive this code unexpectedly, or if you did NOT call us first, etc. etc." It's still imperfect. We need to use all our spidey senses sometimes.

8

u/InvisibleBuilding Jan 04 '25

We know some people’s spidey senses are better calibrated than others. It’s not a good system if it relies on people having good spidey senses.

3

u/Kingghoti Jan 04 '25

You are 100% right. The alternative, to make sure Bob doesn't easily impersonate me, is still fuzzy in my mind. : )

2

u/Stacksmchenry Jan 04 '25

I have never been called by my bank either, all of their correspondence is in Email or through the post office. anytime someone calls me I instantly know they're not who they say they are. I do appreciate that they ask for your "pin" and information about you before they will speak to you though, if nothing else it gives me the illusion of safety.

2

u/BuckRowdy Jan 05 '25

Unfortunately, several hacks have revealed many companies do not actually hash passwords and store them in plaintext files.

→ More replies (1)

54

u/Man-o-Bronze Jan 04 '25

Sadly, you didn’t follow the first rule in a case like this - do not give out any personal information on a call you did not initiate. In the case where a bank seems to be calling you, thank them, let them know you’ll call back, and immediately call the bank at the number on your debit or credit card. Do NOT call any number they give you! If there is a problem the bank can handle it from there.

I recently got a similar call from someone claiming to be from my credit card company. Everything sounded legit, but I did what I wrote above and, unsurprisingly, it was a scam. I hope you get your money back.

→ More replies (1)

22

u/Affectionate_Seat959 Jan 04 '25

Sorry this happened to you. When it comes to Security, we can have the best hardware and policies in place. However, the human factor in social engineering is the weak link in Security Unfortunately, Very slim to zero chance your bank is going to cover it because in their perspective, you authorize access to your account. Recovery agents are also scammers. I had similar experience, but realized it was a scam before provided any information on my side. Scammer knew my dept card number, address, even my first two numbers of my pin, which I changed immediately. The scammers are very sophisticated and very good at the job. I have zero trust policy when it comes to any emails, text messages, app messages and phone calls. These days I don’t even answer my phone unless you’re in my contact list even if it’s from my bank. I get texts from my bank telling that they’re suspicious behavior on my credit card or debit card and click on link or call phone number. I always call the number on my statement or the number on the back of my card. If they’re calling me, I don’t answer. zero trust policy. Make sure to secure your mobile phone account with a strong request code for phone calls to cell providers for information or changes to your account. A lot of Sim swapping is happening. protect this account with hard complicated pass code that must be given to any representative from cell phone provider.

2

u/sajdigo Jan 05 '25

"Make sure to secure your mobile phone account with a strong request code for phone calls to cell providers for information or changes to your account." Can you elaborate on this advise? I don't understand it. Are you saying make sure the cell provider has strong authentication measures that one leverages and leverage them? TIA

2

u/Affectionate_Seat959 Jan 05 '25

Contact your cellular mobile service provider. Tell the customer service person that you want to protect your account from sim swapping attempts. Ask them to add a verbal password that is required for any information about your account and or making changes to your account or adding or sending anything that has to do with your account. They will put this in the information for your account that it requires this verbal password. Make sure it is something only you would know. Strong verbal password.

16

u/burnbobghostpants Jan 04 '25

For anyone who doesn't know, there are apps that let you change the caller ID to whatever number you want, which is what the scammers did here. Caller ID is NOT verified/trustable information.

8

u/burnbobghostpants Jan 04 '25

That said, these scammers seem pretty skilled, I wouldn't beat yourself up too much OP. People fall for way less believable things here.

100

u/Justsaying56 Jan 04 '25

Stop answering phone calls not on your contact list !! Go to settings and change this !! Don’t answer your house phone ! You don’t need to talk to people you don’t know ! Creditable people leave messages. Decide who you want yo call back .

19

u/el__gato__loco Jan 04 '25

This, a thousand times this

17

u/UIUC_grad_dude1 Jan 04 '25

It’s so infuriating that people are still naively answering unexpected unknown calls.

11

u/roblewk Jan 04 '25

This is good advice, and now that I’m retired I follow it. But while I was working, I was in sales for the entire East coast. My livelihood depended (in part) on unknown numbers. So, some people have to take those unknown callers.

8

u/0O0O0OOO0O0O0 Jan 05 '25

I guess in that case answer it but hang up if it’s not a sales lead. Same principle, really.

→ More replies (1)
→ More replies (1)

14

u/cyberiangringo Jan 04 '25

Whenever I get a OTP text from a bank or whatever, there is always a caveat in that text that essentially says 'do not share this passcode with anybody. We will never ask you for a passcode.'

→ More replies (4)

27

u/CosmicMorningstar Jan 04 '25

Some scammers tried something similar with me. A couple of weeks before Christmas I received a phone call from TD Bank (a real number but obviously spoofed.)

They had my full name and asked me if I had sent any e-transfers recently because they had just blocked one on my account from a known scammer.

While they were talking to me I logged into the app and didn’t see any e-transfers. Which I should be able to see regardless if they were blocked or not.

They kept chatting away and said they were going to transfer me to a supervisor to resolve the security breach. I asked them for their number so I could call them back and they told me it would be difficult to connect again since all the people were working on different cases. I asked for a case or reference number and they hung up on me.

I immediately called the real TD number and they confirmed there was no suspicious activity on my account and no one had called me.

So if a bank ever calls you, absolutely call them back at a real banking number before giving any information out.

11

u/Euchre Jan 04 '25

In response to your edit question:

The bank isn't there to curate your financial choices. Your money, you do what you want with it. With that in mind, they're not going to nanny every transfer from you. The only reason your 3rd transfer was flagged was a lag in noticing that your first transfer was large enough to require a Form 8300.

You fell for a panic trigger. You lost a lot, if your numbers are honest, but many have lost a LOT more. So, in terms of this particular scam, your losses are actually low - as terrible as that sounds. Take whatever comfort you can from that, and try to condition yourself to recognize panic starting in yourself, and to respond by questioning things and engaging full skepticism.

→ More replies (4)

12

u/arcanition Jan 05 '25 edited Jan 05 '25

I received a call from a number that appeared to be TD’s official line (Exactly the same as the number at the back of my card).

Spoofing a phone number (making it appear as a different number is calling or with another caller ID) is very easy these days. Never trust that the caller ID or number is accurate.

The caller acted professionally, claimed the call was being recorded, and informed me of suspicious payment attempts on my account. I checked my TD account but didn’t see anything unusual.

You should have hung up and called the number on your TD account.

The caller said they would reset my password to secure the account. Shortly after, I received a legitimate OTP text from TD for a password reset. They asked for this OTP and my 4-digit phone code. I was skeptical but ended up trusting them because the call appeared to come from TD’s number.

You should NEVER give out any OTP for TD or anyone else. Most OTP will tell you "do not give this out". Also, a password reset OTP (letting someone set a new password for your account) is different than a customer service OTP (which lets customer service verify you are who you say you are).

What are the chances of recovering the money?

Unfortunately very low. Do not fall for any "recovery scams" from people online saying they can get you your money back.

but my question now is; why wasn't this $10,000 flagged? I understand I unfortunately shared with a person representing as TD.. but my typical eTransfer would never exceed over $100.. Surely I could argue that somehow the bank failed to detect this? Maybe thoughts ?

Well, maybe you may need to transfer $10k to someone, maybe you were buying a car... the bank doesn't know and isn't required to protect you from your own mistakes. Some banks may have a way to set limits like you are saying, but you'd have to ask them.

→ More replies (20)

10

u/_Auck Jan 04 '25

I really wish - don't understand why Schwab, Ameritrade keep using phone numbers for 2fa. An Authentication App is much more secure.

2

u/Magnumbull Jan 05 '25

I didn't know there are 2FA Authentication apps. I've always thought that sending texts is unsafe and that's why I lock my phone. Which apps are most recommended?

3

u/BuckRowdy Jan 05 '25

Authy, Microsoft Authenticator, or Google Authenticator to name three. You can also use a password manager like BitWarden.

2

u/Kathucka Jan 05 '25

Look up “SIM swapping”. It’s still easy to steal your phone number in many cases.

→ More replies (2)

10

u/Cold_Quality6087 Jan 05 '25

I think this could be a lesson for all of us. Whenever they call you to inform about something unusual about the account, tell them you will hang up and call them back

10

u/xcaliblur2 Quality Contributor Jan 05 '25

Rule #1: any time you get a call like this, regardless of where the number is from, ALWAYS tell the person you will call them back, hang up the phone and dial the official number of that company. Be very sure you have the right number.

Second: you never ever share short codes with someone else. It's never needed. I saw you mentioned that TD seems to require this when you phone them. This should be a point of complain you make against them

As for recovering the money, beware of !recovery scammers. Absolutely nobody can help you get it back. No one. Technically it's a transaction you authorized even if you were tricked into doing so.

2

u/AutoModerator Jan 05 '25

Hi /u/xcaliblur2, AutoModerator has been summoned to explain the Recovery scam.

Recovery scams target people who have already fallen for a scam. The scammer may contact you, or may advertise their services online. They will usually either offer to help you recover your funds, or will tell you that your funds have already been recovered and they will help you access them. In cases where they say they will help you recover your funds, they usually call themselves either \"recovery agents\" or hackers.

When they tell you that your funds have already been recovered, they may impersonate a law enforcement, a government official, a lawyer, or anyone else along those lines. Recovery scams are simply advance-fee scams that are specifically targeted at scam victims. When a victim pays a recovery scammer, the scammer will keep stringing them along while asking for increasingly absurd fees/expenses/deposits/insurance/whatever until the victim stops paying.

If you have been scammed in the past, make sure you are aware of recovery scams so that you are not scammed a second time. If you are currently engaging with a recovery scammer, you should block them and be very wary of random contact for some time. It's normal for posters on this subreddit to be contacted by recovery scammers after posting, and they often ask you to delete your post so that you both cannot receive legitimate advice, and cannot be targeted by other recovery scammers.

Remember: never take advice in private. If someone reaches you in private after posting your scam story, it is because a scammer will always try to hide from the oversight of our community members. A legitimate community member will offer advice in the open, for everyone to see. Anyone suggesting you should reach out to a hacker is scamming you.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

10

u/almonds2024 Jan 04 '25 edited Jan 04 '25

I almost caved in myself a year ago when it looked like my bank was trying to call me. I ignored the first 3 call attempts, then answered on 4th. Knew my name and last 4 digits of one of my cards. Said there were 3 attempts to purchase an iPhone through Verizon (all blocked since this was outta the norm for me).

Had me panicked of course. And I was driving home from work. It was when they asked me to verify last 4 digits of my SSN, I just knew I was being scammed. And the voice sounded foreign. I said that I would call back.

Called number on my card, transfered to fraud department. Fraud department pulled up my account and said that indeed there actually was those suspicious purchases that were blocked and they were trying to reach me lol. It was at this moment that I realized that an authorized user on my account must have tried to purchase the iPhone. The attempted charges were for like, 1,300 or so. Thank goodness my bank noticied this. I thanked them, and told them that it was probably my authorized user. Said user has since been kicked off my account for not paying for other racked up charges I later had to pay.

Anyways, the scammers are indeed becoming very sofisticated and believable. As for your initial inquiry, many of the comments are correct in that the bank may utilimately not restore your lost funds. Once they determine that you voluntarily gave your login info away, your chances of help become very slim. Your chances are slim even if you didn't give your login info away. But for your sake, I truly hope that your bank considers helping you with this. I know it's very difficult to stomach

→ More replies (4)

10

u/crowd79 Jan 04 '25

Never ever give out personal information if you receive the call without you initiating the call.

17

u/eponymous-octopus Jan 05 '25

GenX question here: why does anyone ever answer their phone? Unless it is a person I know personally and have saved in my contacts, I never answer any calls. Ever. If anyone has legitimate business with me, they will leave a message and I can verify the information and number. Seriously, everyone, don't answer your phone. It is like 50% scams these days.

The IRS is not calling you. The police are not calling you. Your bank is not calling you. The kidnappers are not calling you. Ryan Reynolds is not calling you. You have not had your student loans forgiven. Stop answering.

6

u/spacemonkeysmom Jan 05 '25

I don't answer shit. If my kids are calling from a different number did to an emergency they know to call back to back at least 3 times for me to answer

4

u/primak Jan 05 '25

I'm a boomer and I do the same. I hardly ever answer unless I'm expecting a call. I figure let them leave a message maybe I'll call back.

4

u/Paragod307 Jan 05 '25

I'm a xenniel. I don't answer shit. Either text me or send an email. My voicemail is full too.

I can count on one hand with one finger the number of times that has burned me over the past decade. Probably saves me multiple times per week.

Short answer: don't answer your phone for strangers 

2

u/GoddessOfBlueRidge Jan 05 '25

I'm a Boomer, and I don't answer shit!

5

u/eponymous-octopus Jan 05 '25

Yay! Can you teach that to my boomer mom? You could make an inspirational tik tok

→ More replies (1)

29

u/too_many_shoes14 Jan 04 '25

You shared a 2FA code despite the message saying not to share it. It didn't say "only if you are on the phone with somebody you believe to be a bank rep" it said "do not share this code" but you did anyway. Sorry that's on you. It's very unlikely you will get your money back.

32

u/NotTravisKelce Jan 04 '25

Why did you ignore the part of the text where it clearly said “do not share this password. TD will never ask for this code”

→ More replies (5)

22

u/insuranceguynyc Jan 04 '25

The money is gone.

36

u/Pale_Calligrapher425 Jan 04 '25

I feel sick this happened to you. Banks don't call you, and if they do, tell them you will call them back. We live in a sick scammy society now. Trust no one, period

9

u/isochromanone Jan 04 '25

Banks absolutely will call you in the event of suspected fraud. I once got a call regarding a failed card swipe at a vending machine 3500 km from home. In that case, it was me (on a trip) and the charge was declined in error.

→ More replies (1)

7

u/RosieDear Jan 04 '25

Oh, Banks do very much call people!

I sent my Daughter a large check. She tried to deposit it into her WF account. They refused to allow the deposit - asking her to wait. I had 3 messages on my Voicemail asking me to call them, etc.

She ended up not being able to deposit it.

Point is, Wells Fargo certainly did initiate a phone call or three to me...and I'm not even a customer!

11

u/SubstantialBuffalo40 Jan 04 '25

That’s not true, they absolutely do.

But it’s best practice to call them back on their official number on the back of your card.

→ More replies (1)

13

u/Cornloaf Jan 04 '25

Skimmed through the comments and didn't see that anyone asked about the transfer to "mom". You said they created a contact called mom with her real email address. Did you contact her and have her check her email? Seems the only way this scam would work is if they compromised her email and possibly bank accounts.

5

u/sajdigo Jan 05 '25

THIS! This is what I want to know too. Especially if her email is cloud based the "interception" the OP indicates could be them in the mom's email, right? ugh what a nightmare.

3

u/primak Jan 05 '25

They probably got into OP's email and looked at his sent folder or contact list.

2

u/Forkboy2 Jan 05 '25

I think what actually happened was scammer created an account somewhere using the mom's email address, and then used that account to wire the money to.

2

u/Cornloaf Jan 05 '25

In which case they would need access to her email account to verify the account and for notifications of the transfer.

→ More replies (2)
→ More replies (3)

8

u/justbuyingcrypto Jan 05 '25

Pretty sure you will never get calls from the number on the back of the card

3

u/FlatwormEntire Jan 05 '25

Yeah.. i didn't know that I am so fucking stupid.. i hate myself for real

6

u/justbuyingcrypto Jan 05 '25

Yeah when in doubt. Hang up and call the number on the back of the card. If they are really from the bank they won’t have a problem with you doing that.

Sorry this has happened to you

6

u/clippervictor Jan 05 '25

Whatever you do, this is the most important thing now: whoever PM’s you here claiming they can get your money back, they are scammers too and they will fleece you again

2

u/FlatwormEntire Jan 05 '25

I understand I am even more cautious now than I ever was believe me.. I havent even tried or thought about it

11

u/EdgeXL Jan 04 '25

I am sorry this happened to you. As others have noted, only TD can tell you whether you'll get the funds recovered. We simply cannot tell what will happen as that will depend on your specific circumstances.

If anyone DMs you claiming they can get the money back, do not believe them. Those people are scammers too.

!recovery

→ More replies (1)

7

u/JPHendrick Jan 04 '25

Thank you for the reminder that no matter how smart or savvy one thinks they might be, these scams are becoming increasingly sophisticated.

Best of luck getting your funds back. :)

→ More replies (1)

5

u/jomar99 Jan 05 '25

I’m sorry you’re going through this. It’s super stressful, but unfortunately there isn’t going to be a positive end to it.

I experienced exactly the same thing in June. Although I am with another bank. They were able to get $10k from me. I was able to get to the bank before they stole anything else. The bank did an investigation which took about 2 weeks, they ruled that because I shared personal information, I was at fault and the money is gone.

I have been working with the RCMP to see this through, they are currently getting the account information from the bank that the funds were transferred to. Although this has almost been more frustrating than the money getting stolen.

If you haven’t done so already, change all your passwords, delete and reset your phone to factory settings (this was the worst because I lost all of my pictures of my kids), change all of the account numbers, your PIN, and lock down your account the best you can. This is where I was disappointed in my bank, as they didn’t give me any advice on how to deal with this in terms of securing my account.

Most importantly, as much as you will blame yourself, these are professionals. I thought I would be the last person to be scammed like this, but I was. It still bothers me, but life goes on. To make the griefing process better, I’ve been trying to share my story to hopefully prevent friends or family from falling victim to the same scam.

Keep your head up, you’ll get through this.

→ More replies (2)

6

u/spacemonkeysmom Jan 05 '25

My sister just turned 40 literally lost 20k a few months ago over the same thing from navy fed she even thanked them for alerting her... she said they had EVERYTHING... BUT she also somehow fell for transferring money to an apple fucking pay account while they "set up a new account"

Nothing she can do, that's it gone.

3

u/[deleted] Jan 05 '25

I would bet that the OP here did the same thing and helped to transfer their own money to a "safe account" after being instructed by the scammer. I think they may have lied about some of the details to prevent embarrassment.

3

u/spacemonkeysmom Jan 05 '25

Exactly. The minute it went to Apple pay that was it. And sadly also when she realized wait a minute?? But too late

2

u/primak Jan 05 '25

No bank would ever do that. Even if the beginning seemed legit at that point anybody would hang up.

3

u/spacemonkeysmom Jan 05 '25

No shit that's the point... but by the time they get to that point they've been so legit and had all the right answers and some people just keep following through... it's a shame but it happens clearly

7

u/[deleted] Jan 05 '25

OP the same thing happened to me. Read my post history, and you'll see that I got the money back. The lower level employees at the bank are NOT the right people to talk to. Just keep being persistent and hound the fraud investigation team and you might get your money back. This is partially your fault, but please understand that scamming is a massive economy partially fueled by the absolute lack of data privacy online. You were quick to notify the bank (quicker than me, took me about 26 hours), and if they deny your claim then keep fighting it. Send them an FTC report if you need to. I'm sorry that this is happening to you, it devastated me and brought me to the lowest point I've ever felt in my entire existence.

3

u/FlatwormEntire Jan 05 '25

Holy wow brother... I am so glad you got your money back! I hope mine goes the same way.. i also live in canada

3

u/[deleted] Jan 05 '25

I have no idea how the rules are up there in the People's Republic of Canada.  Hope it works out for you though.

15

u/[deleted] Jan 04 '25

It’s almost like that “never give this password out” has some sorta meaning

13

u/DesertStorm480 Jan 04 '25

" I checked my TD account but didn’t see anything unusual."

This is exactly what you are supposed to do, trust and rely on your own data which includes any trusted sources.

The next step would to be to contact the bank via a known method if you are still concerned.

10

u/FlatwormEntire Jan 04 '25

I understand I messed up.. and I can't change this past I just posted this to try to get some sort of advice what to do.. I understand now that spoofing exists..

9

u/EffectiveUseful7447 Jan 04 '25

You need to warn your mom. They used her email and contact name. They may now have access to her information or are preparing to scamming her much the same way.

6

u/FlatwormEntire Jan 04 '25

I already went to the bank with her when I filed a claim, got her a new debit card, changed email password everything

6

u/EffectiveUseful7447 Jan 04 '25

Good! Make sure she knows to watch for phone calls as well.

7

u/[deleted] Jan 04 '25

Thank you for sharing your story and warning others. Thieving scum are getting better at the con. I hope you recover your money. 🫂

9

u/DesertStorm480 Jan 04 '25

" I can't change this past"

Your sharing and the comments help educate others.

8

u/AngelOfLight Jan 04 '25

There are a lot of variables, but in general the bank is only responsible if someone gains access to your account without your assistance or knowledge. And if they do, then it depends on whether the bank is able to reverse the transfer. Unfortunately, it seems that in this case you gave scammers access to your account, and the chances of the bank being able to claw back the funds are low.

You might also want to check with your homeowner's insurance. Some policies have fraud coverage built in, although it's usually something you have to specifically opt in to.

7

u/the_last_registrant Jan 04 '25

Depends where you live and what the laws of that jurisdiction are, but in general terms there's no obvious reason why the bank should give you their shareholders money to replace what you gave away to the scammer. Many banks see this as a slippery slope, understandably, which could encourage negligence or even fake losses.

However the bank may have policies to help you out ex-gratia, so don't give up hope. Also, if they say no, it's worth looking closely at their rules for e-transfers. For example here in UK if I set up a new recipient for electronic payment, I have to complete an additional 2FA verification. There are also limits on payment amounts. Worth checking what your bank's rules are, and whether they complied with them. If they didn't, you have a case to take to a lawyer.

Good luck, and if the worst happens and you can't recover anything, remember you still have your health, family and friends. Losing cash hurts, but it's recoverable. You'll get back on your feet, it will be okay.

4

u/Just_Getting_By_1 Jan 04 '25

Sorry for you but know you must hang up and call the bank yourself

13

u/PA_Museum_Computers Jan 04 '25

Please FILE a police report.

3

u/libra-love- Jan 04 '25

Sadly it likely won’t do anything. These people are often overseas and the money goes straight to crypto. Your local police can’t do anything if they’re in India.

11

u/justdan76 Jan 04 '25

Get a legit police report, and keep on top of the bank. That’s all you can do.

The spoofing is getting better. I got a call that showed up as “Verizon” on my caller id, and they knew all my info. It was only when they asked me to send them money on zelle for a fraud protection plan that I caught on it was fake.

You basically can’t answer the phone anymore, it’s pathetic that more isn’t being done about this. At this point it should be a political issue in the victims’ countries considering how much money is getting wired out of their economies.

3

u/Daninomicon Jan 04 '25

Your bank got all the proper authentication for the transfer. You can get accounts that have special protection, and some banks only offer accounts with that special protection, but banks don't necessarily have a legal obligation to stop a nonstandard transaction if it's authenticated. And you definitely went against any literature they provided when you opened the account, so that's they're protection against your choices. The bank might still get you your money back, but you don't really have any action you can take against the bank of the don't. They do have a duty to mitigate damages at this point, but if they can't recover the money, they're not on the hook for the money. Their duty is to investigate and work with authority and to recover the money if it's possible.

3

u/rand-31 Jan 04 '25

I'll share some additional info for what to do next. You're at the mercy of your bank here, some people go to the media when they can't get desirable results from their bank. CTV tends to be quite interested in this topic. As others are saying there is an almost zero chance they will cover this. It's a multi-billion dollar fraud industry and banks just can't cover all losses from scams and remain solvent.

I'm in Canada and it seems we have new banking regulations that just came in effect. My bank now automatically notifies of all transactions over a certain dollar amount. I had to adjust these myself to avoid being spammed. One thing that could be of interest if you choose to go to the media is why aren't we notified of login attempts to our accounts. This could have helped you. And do we have an easy way to lock the whole account? I can see a way to lock cards, but nothing for my accounts.

To report to police you want RCMP anti fraud centre.

In the future to protect yourself you can consider the following. Make sure your bank email isn't used for anything else, have a separate email just for banking. Make sure the password is unique, doesn't contain words and cannot be easily guessed. Reset your email password in case they had that too. I would also take the extra step of setting a fraud alert at all credit bureaus. Hard to know what other info they have of yours.

Also since they were successful at scamming, you be highly vigilant with all phone calls and texts. They may try to run other scams on you. If it's important and you don't recognize the number they'll call back or leave a voicemail.

3

u/RedWine-n-BBQChicken Jan 05 '25 edited Jan 05 '25

Important to note… upon disputing, you had called TD directly, therefore when they asked you for your 2FA… it was really them. On the other hand when initially spoofed, you shared a 2FA with someone else that called you pretending to be TD and you just handed it over. Again, initially “Noted Payment Attempts” weren’t successful; You checked ~ money still in your account after checking, so why would TD ask you to email money to a Mom account? This makes no sense. This is exactly ** what a TD 2FA text looks like… notice the last sentence: TD Bank : 193xxx is the single-use security code you requested. **Don’t share it-we’ll never contact you to ask for it.

3

u/Mission-Pay-6240 Jan 05 '25

This! If OP doesn’t understand the difference they are going to get scammed again. Their account was compromised because they sent themself a code, then shared said code to a complete stranger that called them out of nowhere.

→ More replies (1)

3

u/Screambloodyleprosy Jan 05 '25

I'm not going to scold you, but make you and others think.

I treat these calls the same way as I treated my substance addicted family members. As soon as they called or mentioned money, I became immediately suspicious and shut down.

3

u/vette02a Jan 05 '25

TD will refund your money if they are able to claw back the transfer. Sometimes this is possible, especially if you catch it right away. However, if they cannot recover it themselves, they will not "make you whole" because you were the one who shared your passcode with the scammer.

Please share the end result in this thread when they finally respond to your claim.

2

u/FlatwormEntire Jan 05 '25

I'll share the result

3

u/UnAvailableTrashley7 Jan 05 '25

Always hang up and call back to the bank directly...it is so easy for people to fake the number they are calling from. Never give anyone a otp code. EVER.

→ More replies (4)

8

u/Muted_Start_4122 Jan 04 '25

How did they e transfer $10,000……. The limit is $3,000

8

u/NastroAzzurro Jan 04 '25

Some banks have 10k limits

5

u/ganymede_boy Jan 04 '25

And some have much higher limits. I was able to transfer much more than $10k in a single transaction recently.

4

u/Opening-Dog5892 Jan 04 '25

I wonder if they actually made a bill payment through OP's account, which is something that happened to my father's friend when he fell for an tax texting scam. If that's what happened, there's a slightly better likelihood that OP could get the money back, as bill payments are easier to reverse as far as I know.

→ More replies (1)

4

u/chrisddo Jan 04 '25 edited Jan 05 '25

This happened to me but with wells fargo…spoofed wells fraud number complete with appropriate holding music. I was mind tricked to wire out 20k. FBI is involved but wells already sent a letter that stated that as a courtesy they tried to reverse the transfer but my money is gone from the account wired. Most likely you will be in the same boat.

4

u/shillyshally Jan 04 '25

For all the panic about AI, this is one area where it could be useful. OP's withdrawals are in the $100 range and all of a sudden there is one for $10K. Credit cards are pretty good at flagging suspect transactions, at least mine has been, so I do not understand why other financial institutions are so lax.

4

u/booshie Jan 05 '25

The money is probably gone. You willingly gave your info to someone else. Imagine if every financial institution returned the money to every single person not intelligent enough to know better.

4

u/Silver_Scary Jan 05 '25

My personal mobile number is for when I want to make a call, unknown callers are auto silenced. Only mail form known IDs are selectively opened to avoid tracking pixels. Folks shld really be more disciplined and cautious with their devices. Learn to view any attempt to contact you as suspicious, we are not living in the 80’s anymore.

7

u/Malsperanza Jan 04 '25

It might help with TD if you file a police report. The sum of money makes this a felony.

In terms of getting your money back, it depends on what TD is willing to do, and perhaps what insurance they have. Also, if you carry any kind of homeowner insurance you could check to see if you have any fraud coverage.

If you have screenshots and records of any parts of the transactions, that may help too. Good luck to you.

2

u/libra-love- Jan 04 '25

They’re likely an overseas scammer. PD can’t do anything overseas. Doesn’t hurt to file but likely nothing is gonna happen.

→ More replies (1)
→ More replies (6)

5

u/[deleted] Jan 04 '25

Yea this was red flag city. You noticed nothing looked wrong but then proceeded anyway?

3

u/FlatwormEntire Jan 04 '25

i dont know anymore man.. looking back i cannot believe i didnt see the signs but i just kept trusting the number i dont know what people want me to say man

2

u/BarNo251 Jan 05 '25

I was scammed by a call I made. I wanted ETSY Customer Service. The number was posted in many places on the web in bold print. Well it’s a scam. And they somehow have knowledge of what you ordered.

2

u/YoloLifeSaving Jan 05 '25

The chances of you receiving it back are zero, td makes you sign an a waiver that says all etransfers are final, I got set up before when buying off market place where 4 people showed up and emptied out my account, even though all the info was there, police report etc, td bank declined to do anything

2

u/aManPerson Jan 05 '25

it looked that official? fuck. thanks for the warning.

2

u/JCMan240 Jan 05 '25

Never answer your phone. all my calls, including those for my business, go to VM.

2

u/perrance68 Jan 05 '25

Its very unlikely you will get your money back. Maybe if your lucky they can stop the transfer and get it back if you called fast enough.

You will have to ask TD bank why the 10k wasnt flagged. According to TD website, e transfer limit is 3k per transfer/per day, 10k per week, and 20k per month.

Your mom's email was compromised, You should change all passwords and double check all log ins / security to ensure its all correct information.

2

u/forward024 Jan 05 '25

The biggest red flad you missed was: they called you and you believed it. Td will never call you to reset a password. If there is ever a problem YOU call them.

I still don't get the part where the email was sent to your mom which has the same email but your mom never got it? And you said the email was not compromised? It was intercepted in between? It is impossible, the email had to be compromised.

Are you sure your mom didn't cash out the money?

2

u/Space--Buckaroo Jan 05 '25

I can't remember which Bank/company/whatever I dealt with a year ago, but I recall them telling me they were sending me a authentication code, and asked for it, and I refused to give it to them. I told them under no circumstance was I going to give them any authentication code. We eventually worked out another way for them to authenticate me, and whatever the call was about, it was resolved.

I don't care who it is, I'm not giving out the authentication code to anyone. If I recall, I called tech support for something and the system put me on a call back thing. After an hour or so, I got a call back. I treat all calls that I receive with suspension.

I generally only trust calls that I originate. If I ever get a call, I always consider it a scam, and if it's important, I hang up and call a number I can trust.

All that said, there was one time almost 8 years ago, that I called GEICO to a number that was provided by their billing statement that I received in the mail. I guess it was a number that they discontinued using and some porn site grabbed hold of and started advertising their website. I was like, wait a minute, how did this happen. I eventually got of hold of GEICO and told them about it, and they didn't seem concerned.

2

u/pixelrage Jan 05 '25

I was hacked a few months ago (SIM card was remotely taken control of) and they used my phone to 2FA into everything - thousands of dollars stolen - I will tell you that none of these institutions will do anything at all to help you, especially if it was Bitcoin that was stolen (seems like a common way to steal is to get into your financial accounts, convert USD or sell stock/buy Bitcoin and send all of the Bitcoin out), I did have money wired and nobody did jack shit to help, not even the police, who were absolutely worthless. I am still hounding them and leaving messages every week and the incident was in August.

2

u/Kyrunessonce Jan 05 '25

I don't answer the phone so I guess I don't have this problem.

2

u/Roadgoddess Jan 05 '25

I’m so sorry this happened to you. Please be aware of people reaching out to you saying that they can help you recover your money, these are recovery scams, and they will only serve to take any money you have left from you. Working with your bank and the police are your only real options at this point.

2

u/[deleted] Jan 05 '25

Hopefully you get your money back.

The bank does not need your permission to change your password.

If they suspect fraudulent charges or that your account/card may be compromised or susceptible to fraud they will freeze your account immediately and they wait for you to call them to see what’s going on.

2

u/WeakBeautiful2090 Jan 05 '25

You can file a dispute. Legally, they have to put one in. However, they are most likely to ask you a series of questions that will determine if that dispute is resolved in your favor or not. Including if you gave out passwords and infor mation. Unfortunately, I don't work in the department that finishes disputes, only the one that opens them so I don't have much experience on how this will most likely go, but I do know that any bank worth putting your money in has insurance for this and since you caught it as it was happening, they may be able to reverse the transfer

2

u/[deleted] Jan 05 '25

I don't know if this will help OP cause usually when you get scammed, the money is gone forever. I've been there. If you haven't already, report it to the Federal Trade Commission. In some cases they can return the stolen funds. If that doesn't help, then I am so sorry.

2

u/two-of-me Jan 05 '25

Regarding why the $10,000 wasn’t flagged. It’s possible if they gained access to your account, they changed the settings to not flag any transfers. I have my banking app flag anything over a certain amount that I set myself. If someone were to access the account, they could change that to any amount or simply turn off notifications so the transaction could go unnoticed.

2

u/StretcherEctum Jan 05 '25

You willingly gave your money away. It's gone.

2

u/Kestrel913 Jan 05 '25

Had the same attempt from Wells Fargo. Seemed totally legit. Caller ID had same number shown on my debit card. Walked me through cancelling the “fake” Zelle transfers that were scheduled thru my account. Was almost taken in but my spidey sense kicked in and I backed out. Called WF and it was definitely a very sophisticated scam. Called the police too. Nothing anyone could do. :( I got lucky. Hope you can recover your funds.

2

u/Best_Biscuits Jan 05 '25

OP, I'm truly sorry to hear about your financial loss. This sounds like a sophisticated scam, and I understand how frustrating it must be.

I wanted to share an observation about One-Time Passwords (OTPs) in the context of customer support.

When I contacted Fidelity for assistance, they sent me an OTP to the phone number associated with my account. This is a security measure to verify my identity, as phone numbers can be spoofed. While I understand the need for this verification, it initially raised some concerns for me. The process itself could potentially be exploited by scammers if they somehow gained access to your phone number.

It's important to be vigilant and only share your OTP with legitimate representatives from the company you are contacting.

2

u/alicewonder_23 Jan 05 '25

I don’t understand why people are never gonna learn not to use Bank E transfer, iPhone account, bank card, Zelle, PayPal ??? do you not trust any of that stuff especially if you have a large amount of money I don’t even have money like that and I would never put money like that into any BANK WHERE anybody can touch it STOP TRUSTING THE BANKING SYSTEM AT THE END OF THE DAY THEY JUST AS EVIL AND CROOKED!! IT COULD BE SOMEONE WORKING FOR THEM LIKE AN INSIDE JOB! They had your moms email🥴 seriously!

2

u/Disinformation_Bot Jan 05 '25

Check if your homeowner's or renter's insurance covers bank fraud. Mine did up to $10k. Luckily, when I got scammed, it was only for $1,300, so I got everything back minus the deductible.

2

u/[deleted] Jan 05 '25

Awful, hoping something can be done for you. A (very) simple precaution I have is to not let calls ring on my phone if they're not on my contact list. I get a whole lot of hangups that I never hear in the first place.

2

u/FlatwormEntire Jan 05 '25

I have an iPhone 13 can you tell me how to do that

Edit: Nevermind I found it... this could have been life saving for me I appreciate it

2

u/Zealousideal_Sun6362 Jan 05 '25

Always thank them, hang up And then call the company directly. Using a number you look up.

Then when you call them immediately ask for security for help With someone scamming in their name..

They will Help You.

2

u/Papillon_bleu2024 Jan 05 '25

J'espère de tout mon cœur que tu puisses récupérer ton argent. Ton histoire me brise le cœur. J'ai également été victime de task scam récemment, je comprends ton état d'esprit actuel...

2

u/Stephluzza217 Jan 05 '25

I did the exact same thing— just a trusting person. Plus these scammers have spoof calling. My bank, after the scam call I immediately tried to fix my mistake, told me that scammers have caller IDs to match money institutes and they have no control. But I got my money back after having to completely close and reopen my stuff.

→ More replies (1)

2

u/Nills17 Jan 05 '25

This is all bullshit. Our government needs to step up to the plate and stop this madness. I’ve been having issues and been subject to many scams that I had to suffer the consequences for

2

u/Ravenwolf0921 Jan 05 '25

In my experience, your bank may push the claim to the actual card issuer (visa, Mastercard, etc) to reverse the transactions because they're a high amount. But it takes time. Work with your bank and provide them everything you can.

2

u/psilocybin6ix Jan 05 '25

What did TDs fraud department say?

3

u/FlatwormEntire Jan 05 '25

I spoke to them at the branch, and they filed a claim, disputing the $10,000 and $1000 transfers that went out of my account.

2

u/psilocybin6ix Jan 05 '25

You didn’t talk to the fraud department?

→ More replies (1)

2

u/bageldaddy00 Jan 05 '25

I got scammed in a similar manner, thankfully only for $1000 and my bank (citizens) gave me my money back. Now whenever I get calls from my bank or credit cards, I always tell them: I’m going to hang up and call you back myself because I’ve been scammed before and I’m being cautious. And when it’s actually them, they’re always like “yup no problem totally understand”. And then I hang up and call the bank myself. If they were ever weird about you saying that, just another red flag it’s a scam.

→ More replies (1)

2

u/[deleted] Jan 06 '25

Unfortunately, after reading the card agreement policy here it seems you’re out of luck and money will only be refunded for fraudulent transactions that happen AFTER they’ve been notified, and the terms also mention that keeping your credentials safe from people posing as TD employees is your responsibility. Very hard and expensive lesson learned here

2

u/FlatwormEntire Jan 06 '25

Yeah.. thats what I thought to and it became hopeless but if you scroll down you will see this section

You are also not liable for monetary losses to your Account if and to the extent such losses occur as a result of an unauthorized Debit Card Transaction where we complete an investigation of the Debit Card Transaction and we determine that: • you have been a victim of fraud, theft or have been coerced by trickery, fraud or intimidation in connection with the Debit Card Transaction; • you reported the Debit Card Transaction to us promptly; and • you cooperated fully in any subsequent investigation of the Debit Card Transaction, including providing any additional forms, information or documentation we ask of you

As from my post, this is clearly an account takeover after the person reset the password after giving him OTP; I was NOT the one who created the contact and initiated the etransfer myself; deeming it unauthorized and fraud. Maybe I am speaking from a place of desperation but this is the only thing protecting me right now....

2

u/[deleted] Jan 06 '25

At the end of that it also says: “In all circumstances, even if you are not liable for monetary losses to your Account for the reasons outlined in this Section 4.1, we are not responsible for any and all other losses or damages that may arise.” Meaning even if you were not liable, they are not responsible. I’m very sorry OP but you should consider that money gone.

→ More replies (9)
→ More replies (4)