The Art of Deception_ Controlling the Human Element of Security - Kevin D. Mitnick [12]
Grace’s new client was a lady who looked as if she had a pretty comfortable budget for clothes and jewelry. She walked into his office one day and took a seat in the leather chair, the only one that didn’t have papers piled on it. She settled her large Gucci handbag on his desk with the logo turned to face him and announced she was planning to tell her husband that she wanted a divorce, but admitted to “just a very little problem.”
It seemed her hubby was one step ahead. He had already pulled the cash out of their savings account and an even larger sum from their brokerage account. She wanted to know where their assets had been squirreled away, and her divorce lawyer wasn’t any help at all. Grace surmised the lawyer was one of those uptown, high-rise counselors who wouldn’t get his hands dirty on something messy like where-did-the-money-go.
Could Grace help?
He assured her it would be a breeze, quoted a fee, expenses billed at cost, and collected a check for the first payment.
Then he faced his problem. What do you do if you’ve never handled a piece of work like this before and don’t quite know how to go about tracking down a money trail? You move forward by baby steps. Here, according to our source, is Grace’s story.
I knew about CreditChex and how banks used the outfit—my ex-wife used to work at a bank. But I didn’t know the lingo and procedures, and trying to ask my ex- would be a waste of time.
Step one: Get the terminology straight and figure out how to make the request so it sounds like I know what I’m talking about. At the bank I called, the first young lady, Kim, was suspicious when I asked about how they identify themselves when they phone CreditChex. She hesitated; she didn’t know whether to tell me. Was I put off by that? Not a bit. In fact, the hesitation gave me an important clue, a sign that I had to supply a reason she’d find believable. When I worked the con on her about doing research for a book, it relieved her suspicions. You say you’re an author or a movie writer, and everybody opens up.
She had other knowledge that would have helped—things like what information CreditChex requires to identify the person you’re calling about, what information you can ask for, and the big one, what was Kim’s bank Merchant ID number. I was ready to ask those questions, but her hesitation sent up the red flag. She bought the book research story, but she already had a few niggling suspicions. If she’d been more willing right way, I would have asked her to reveal more details about their procedures.
You have to go on gut instinct, listen closely to what the mark is saying and how she’s saying it. This lady sounded smart enough for alarm bells to start going off if I asked too many unusual questions. And even though she didn’t know who I was or what number I was calling from, still in this business you never want anybody putting out the word to be on the lookout for someone calling to get information about the business. That’s because you don’t want to burn the source—you may want to call the same office back another time.
lingo
MARK The victim of a con.
BURN THE SOURCE An attacker is said to have burned the source when he allows a victim to recognize that an attack has taken place. Once the victim becomes aware and notifies other employees or management of the attempt, it becomes extremely difficult to exploit the same source in future attacks.
I’m always on the watch for little signs that give me a read on how cooperative a person is, on a scale that runs from “You sound like a nice person and I believe everything you’re saying” to “Call the cops, alert the National Guard, this guy’s up to no good.”
I read Kim as a little bit on edge, so I just called somebody at a different branch. On my second call with Chris, the survey trick played like a charm. The tactic here is to slip the important questions in among inconsequential ones that are used to create a sense of believability. Before I dropped the question