So you think anyone in their right senses will reveal an otp for a transaction or action that they didn't perform.A typical OTP bot attack works like this:
- An attacker first obtains a victim’s username and password (often through phishing or a data breach).
- They attempt to log in, which triggers an OTP challenge.
- The bot immediately calls or texts the victim while impersonating a bank, company, or support team.
- If the victim reveals the OTP, the attacker uses it before it expires to complete the login.
The important point is that the bot doesn’t generate or crack OTPs—it relies on social engineering to trick people into giving them away.
Hey Emma although ur correct, there are stil some dummies that actually send the OTP, very small success rate though, i have build my own bank otp bot, and i packed it in because the success rate was so low, out of 100 calls about 2 would send the ''security'' pin, the other 98 would ignore itSo you think anyone in their right senses will reveal an otp for a transaction or action that they didn't perform.
The first instinct of a right thinking human is to suspect foul play. Cos they literally aren't on their bank or using the app or performing any action in their account and all of a sudden, they receive an impersonating text or email or call with otp and they'll just reveal that? Just like that?Y'all crack me up so much in this forum.
Well said bro..it's a thing to note that banks now are getting rigid with their security system hence why it's harder now penetrating accounts using otp bots.Hey Emma although ur correct, there are stil some dummies that actually send the OTP, very small success rate though, i have build my own bank otp bot, and i packed it in because the success rate was so low, out of 100 calls about 2 would send the ''security'' pin, the other 98 would ignore it
exactly, i think rather than using a bot, SE'ing would probably work out with a better success rate, also getting a reliable sip trunk provider that actually spoofs the correct caller ID can drastically increase success rates. But as it stands just like you said a few years ago it was rampant and easily done, im from the UK and the OFCOM regulator has made some major changes and has enforced all UK carriers to block or use a no caller id if the incoming caller ID even resembles a financial institution, this cam into effect last year and has made it near impossible to be able to spoof uk caller ID's.Well said bro..it's a thing to note that banks now are getting rigid with their security system hence why it's harder now penetrating accounts using otp bots.
It wasn't like this few years back, a good standard bot has atleast 90% success rate. That probability has dropped drastically now cos banks are taking their security serious.
Originally, UK is not the kind of country you wanna trifle with when it comes to fraud. Little wonder there are very limited fraud plays in the UK.exactly, i think rather than using a bot, SE'ing would probably work out with a better success rate, also getting a reliable sip trunk provider that actually spoofs the correct caller ID can drastically increase success rates. But as it stands just like you said a few years ago it was rampant and easily done, im from the UK and the OFCOM regulator has made some major changes and has enforced all UK carriers to block or use a no caller id if the incoming caller ID even resembles a financial institution, this cam into effect last year and has made it near impossible to be able to spoof uk caller ID's.
exactly, these Americans dont know how good they got it! For us in the UK is near impossible and extremely difficult, thats why ive exported my work to usa, using americans and teaching them how to do things and getting 50%, only way forwards, in uk im carding transactions of £20 maybe 3 times from a cc, so total £60, but usa one transaction is hitting 1/200$! massive difference, and the fact that usa is real non-vbv, and the uk is auto vbv doesnt help that shift towards america aswell. And no offence to the american audience but they aint as clued up as the UK public, much easier to se americans than ukOro
Originally, UK is not the kind of country you wanna trifle with when it comes to fraud. Little wonder there are very limited fraud plays in the UK.
Aside the fact that it's almost impossible spoofing stuffs in the UK, laundering funds in that region or any fraud of any sort is never a walk in the park. Even for experienced folks, it's not easy.
The game isn't what it used to be. But we still gotta appreciate the fact that we still get to eat good amidst it all.
Theres no 100% guaranteed solution, scroll up theres some valuable information on thus threadAny solution to otp? It’s still needed