Hello to everyone.
a few days ago a good amount of money was stolen from my bank account (I have home banking,but not for much longer).
I am still trying to think about how this could have happened,by reasoning about the traces left by the thief. What I know is that :
a) at the same moment that I've logged into my bank account,I've got an email message,telling me that someone with an "Iphone 14 Pro Max" has been able to login. But I read this email later,when I logged out,because when I was inside , my attention was focused... to the money spent.
b) the messages that I've got to my email address say that he has been able to enter using the Android App installed on my phone /that I never use/,because after having logged in using the double factor authentication,I use my FreeBSD system to surf to the bank home page using Firefox
c) looking the timing the thief has gained access to my bank account simultaneously with me (a man on the middle attack ?)
d) I've got some sms telling me that he also tried to activate the Android app of the bank to my phone and to his phone,requesting the code,but since it has been sent to my phone he didn't know it and he failed (this makes me think that my phone is not compromised)
My question is how he has been able to bypass the double factor authentication ? How has he been able to know the user id,the pin code and to validate his connection through my phone ? It seems to be complicated,but probably it seems to be like this because I don't fully understand the method used. Probably for him it has been easy. It becomes easy to do something that you know and that you did several times already,not ?
Take also in consideration that I had already requested to change my credit card codes twice recently.
Please be free to express your thoughts.
a few days ago a good amount of money was stolen from my bank account (I have home banking,but not for much longer).
I am still trying to think about how this could have happened,by reasoning about the traces left by the thief. What I know is that :
a) at the same moment that I've logged into my bank account,I've got an email message,telling me that someone with an "Iphone 14 Pro Max" has been able to login. But I read this email later,when I logged out,because when I was inside , my attention was focused... to the money spent.
b) the messages that I've got to my email address say that he has been able to enter using the Android App installed on my phone /that I never use/,because after having logged in using the double factor authentication,I use my FreeBSD system to surf to the bank home page using Firefox
c) looking the timing the thief has gained access to my bank account simultaneously with me (a man on the middle attack ?)
d) I've got some sms telling me that he also tried to activate the Android app of the bank to my phone and to his phone,requesting the code,but since it has been sent to my phone he didn't know it and he failed (this makes me think that my phone is not compromised)
My question is how he has been able to bypass the double factor authentication ? How has he been able to know the user id,the pin code and to validate his connection through my phone ? It seems to be complicated,but probably it seems to be like this because I don't fully understand the method used. Probably for him it has been easy. It becomes easy to do something that you know and that you did several times already,not ?
Take also in consideration that I had already requested to change my credit card codes twice recently.
Please be free to express your thoughts.