Recently, some cases of strange phone calls, apparently fraudulent, have been reported through social media, drawing the attention of the cybersecurity community.
According to testimonies, in these cases, unlike some popular phone scams, the perpetrators do not present themselves as bank employees or ask users for their card number and PIN; instead, they limit themselves to asking some seemingly meaningless questions (Are you Mr. NAME/SURNAME?, Are you a regular Internet user?, among others).
If these calls are part of a fraud, it seems the intention of the operators of this campaign is for target users to answer their questions with a simple 'yes', but why are the fraudsters interested in this?
Cybersecurity experts state that by doing this, threat actors are collecting biometric records directly related to some banks. An example of this is Russia, where banks can provide some services without customers having to visit branches in person.
Examples of biometric records
To access these remote services, bank customers must enable voice authentication, which requires users to repeat some phrases so the bank can store their biometric record, which will later be used to verify their identity.
Alexander Dvoryansky, a Russian cybersecurity expert, states: 'Hackers could access these biometric databases, extract them, and sell them on dark web forums; although in most cases it would not be possible to access a victim's account using only the word 'yes', hackers could access all of a user's voice recordings, which must contain keywords or the necessary phrases to compromise the bank account,' the expert says.
Andrey Golovin, from the Russian Department of Information Security, mentions: 'In addition to voice authentication, hackers would also require access to passwords or other biometric records (such as facial recognition) to access a bank account, so the complexity of the attack increases considerably.'
'Furthermore, each conversation with a bank employee will be different, and it would be really difficult for employees not to distinguish between a recorded audio sample and a real conversation,' the cybersecurity expert mentioned. Another point to highlight is that users of these remote banking services must previously provide their bank with a list of authorized payment cards, so a potential intruder could not make a transfer to any other card.
Specialists from the International Institute of Cyber Security (IICS) mention that one of the main protective measures against this potential fraud is to avoid answering phone calls from suspicious numbers, and if the user decides to take the call, not to say the word 'yes' during the call. Likewise, it is recommended that users who do not use voice authentication disable this service entirely.




