How I avoided being scammed, and you can too!
I was working from home when I got a call on my mobile, which is not uncommon as I get alot of random calls (given I run JasonIT and my mobile is all over the place!) – so I answered it and was met with a rather urgent gentlemen on the other line. He claimed he was from Amazon Security, and had put a hold on my account as a hacker was trying to buy a new Apple iPhone on my account (Oh how nice of him to stop the hacker!)
You will very, very rarely get a call from a company proactively protecting you – It’s hard enough to get onto support when you DO have a problem, let alone them calling you, so that’s red flag! Especially if there is a sense of urgency. The only situation where this might be real is your bank, in which case you should hang up and call them back on their customer support line.
What is the Amazon OTP Scam?
The scam involves them going to Amazon and requesting a password reset using your mobile number. This generates a OTP (Which is a One-Time-Password) coming from Amazon to your mobile – This code is 100% real. The scammers tell you to NOT give them this number (Which is very considerate of them, considering the OTP text message tells you not to give it out)
For those interested to see where the scammers start, you can visit the link below (it just takes you to the Amazon reset password page, completely safe)
Reset Your Password – Amazon Customer Service
This is where the scam gets clever! They then tell you to hop onto the App store (for Apple) or Play Store (For Google/Android) and ask you to download a remote software app. It my case they tried both Zoho Helpdesk and AnyDesk Remote desktop. Now both of these remote tools ARE 100% legit, but the scammers will ask you to download them in order to provide you support.
Some IT companies will use remote software (I have used it with my clients) however large companies will rarely initiate the use of remote desktop tools (Amazon, Microsoft, ATO etc will not use remote desktop tools like this) This is a red flag. If you do not know the person/company you are talking to, do NOT install anything they give you!
For my clients reading this.. you can totally trust me and install the remote software I send you…. Okay moving on.
Once you download this remote software tool, they will then ask you to provide the IT support code which they will then use to connect to your mobile phone directly. Once they have access, they look at the OTP in your text messages! (How clever. You see, you didn’t tell them the confidential code, they just looked over your digital shoulder and stole it)
They then simply use the code on their end to change your password, where they will then log in and purchase lots of gift cards – redeeming them almost instantly and leaving you out of pocket
The scammers then disconnect the call, and you’ve been scammed before you know it!
So how was I targeted?
I have had my mobile number for a very long time, and it’s been online for almost as long, so it’s well and truly out there in the wild, in scammers spreadsheets, as being an active number. My mobile gets sold and passed around from our scammer to the next as being an ‘active’ mobile. Yours is probably on the list next to mine as well. There isn’t really anything you can do to remove it besides changing your mobile number, which is why its so important to remain vigilant
Be skeptical of unsolicited contact. Unexpected emails, messages or calls, especially if they claim to be urgent or ‘too good to be true’ are usually the first signs to raise caution.
These days you can targeted via Email, SMS, Calls, and soon in the future I wouldn’t be surprised if they elect to Facetime / Video call you with realistic fake AI. The tools change, but the routine and tactics are the same and can be applied to the same tricks used 300 years ago, and will probably remain relevant for another 300 years in the future. Be skeptical, be protective, and trust your gut.
What to Do If You’ve Been Targeted
If you have been the victim of a scam, it can be completely overwhelming; but keep calm and follow the steps
1. Call your bank and inform them straight away.
2. Reset your Password as soon as possible (Do this from a device NOT targeted by the scam, just incase they have still have access.
3. Remove and Uninstall any new software the scammers may have installed.
4. Call an IT professional if required, to give you the clean bill of health.
Conclusion
In today’s digital age, it’s crucial to stay vigilant and informed to protect yourself from online scams. Remember to be skeptical of unsolicited contacts, especially those with unexpected messages or from unknown senders. Look out for red flags like poor grammar, unusual requests, or a sense of urgency, as these are common tactics used by scammers. Always verify the authenticity of communications by checking email addresses and URLs, and never click on suspicious links or download attachments from unknown sources.
Educate yourself and your loved ones about common scams and share your experiences to help others avoid falling victim. When it comes to payments, be cautious of requests for gift cards or wire transfers.



