Thank you for calling tech support, this is Marvin Dcosta how may I assist you today?
Okay I will surely go ahead and help you with this issue, but before we proceed ahead please help me with your first name, your last name and your zip code so that I can raise a ticket about your concern.
Thank you for sharing the information. May I put you on hold so that I can raise a ticket about your concern?
Thank you
Please grab a piece of paper and a pen so that you can write down my information and the ticket number that I have raised about your concern. Please let me know once you are ready to write.
Please write down my name first its MARVIN DCOSTA, please write down my employee id number.
Please write down the ticket number that I have raised about your concern. Now I want you to write down the callback number, incase if the line gets disconnected and if I am unable to connect with you please make sure you callback on this number and ask for my name to avoid going through the entire procedure again. Okay?
Now I have raised a ticket about your concern. But before we proceed ahead please help me with your apple id, it’s the email id that you have registered with apple so that I can have a complete check in my system
Thank you for sharing the information. Please may I put you on a hold for a couple of minutes so that I can have a complete check? Thank you
Okay now before we proceed ahead please tell me how many devices are connected with your apple id as per your knowledge.
The reason I asked you this question was because as I am checking into my system I can see that there are around 10 devices connected with your apple id from 4 different locations and they are customers state. texas china and Russia. So does any of your family member or your friends or relatives use your apple id to connect their devices?
Cus- no
Have you been recently visiting these places and used your apple id to connect any apple device?
Have you connected your device to any public wifi may be in past 48-72 hrs or in past one week?
Have you shared your home wifi network password with anyone in past 48-72 hours?
The reason I am asking you these questions is because as I am checking into my system I can see that there is a breach in your network and several attempts of hacking have taken place in past 48 hours. You need not worry about this we will surely help you with this issue and see that its resolved.
But first we need to have a security check so that we can confirm whether your device is secured or the hackers have established their connection with your device and network. Okay?
So please put me on a speaker phone and come back to your home screen
First security check
Settings - General – about – certificate trust settings – trust asset version
Okay please tell me whether trust asset version is opening up or you see some numbers?
Please can you read out the numbers to me?
Cus – 1003
Oh my god !!!
The number 1003 means that there are around 10 devices connected with your apple id from 4 different locations.
I am sorry to say but These hackers have established their connection with your network and device. But you don’t have to worry about it we will surely disconnect all these hackers from your device and network.
Now as you are aware that your device and network are hacked , what we need to do is connect your device with the apple secured server.
It’s a temporary security provided to you by apple so that only you can have an access to your device till the time you are connected with it and we can run a complete scan on your device to check what all damage has been done ? what all data has to be erased from their system and what exactly is required to be done to disconnect all these hackers from your device.
Now in order to connect your device with the secured server you will have to download an apple certified application with the help of which we will connect your device with the secured server, so do you know how to download an application from app store?
After access
Okay now you are successfully connected to the secured server.
Let me inform the security team to run a complete scan on your device, meanwhile we can run few more security checks on your device.
Now I want you to come back on your home screen.
Lets have few more security checks till the time scan is completed on your device.
I want you to open settings again and click on
2nd security check
Settings – privacy and security – analytics & improvements – analytics data
Okay now the analytics data folder is supposed to be empty is it empty or you see some entries there?
Cus – whole bunch of entries
All these entries are done by the hackers to steal information from your device.
I want you to click any one of the entries and please tell me do you see a computerized coded language?
Cus – yes
Okay you need not worry we will surely see to it that these hackers are disconnected from your device,
Now lets have the last security check I want you to come back on the main page of settings and click on passwords
3rd security check
Settings – passwords – security recommendations
Now do you see detect compromised passwords? Its it enabled or disabled?
Cus – its enabled
Its enabled because when someone is stealing information from your phone it automatically gets enabled and shows you the application under high priority recommendation so do you see any applications under high
priority recommendations.
Cus – yes
These hackers have gained an access to all these application.
Okay now I need to ask you a few questions preferably answer them in a yes or no.
Do you do online shopping on this device?
Do you pay bills online?
Do you check emails on this device?
Do you visit social media sites like Facebook or Instagram on this device?
Do you do online banking on this device?
Do you watch YouTube or Netflix etc. on this device?
Thank you for sharing the information. Now I have got an update from the security team that the scan on your device is complete and I can see the final report which even you should know.
In all there are 5 activities in the FINAL REPORT
CLAMPI VIRUS DETECTED
CHILD PORNOGRAPHY UPLOADED ON WWW.PORNHUB.COM
BANK LOGIN ID AND PASSWORD DETECTED
DEBIT CARDS AND CREDIT CARDS USED ON CRYPTO. COM
PURCHASES MADE ON CRYPTO.COM USING DEBIT CARDS AND CREDIT CARDS WITH STARTING DIGITS 5… 3….6…4
PHONE LINES ARE HACKED NETWORK IS HACKED.
EXPLAIN THE FINAL REPORT
Now do you know what clampy virus is?
Cus – no
Not an issue I will explain it to you,
Clampy virus is an advanced hacking tool used by the hackers to attack your network and devices connected to that network gain access of your network and the devices connected with it and steal all personal and financial information from those devices. In simple words clampy virus is a man hiding in your system stealing all your personal and financial information. Okay
The 2nd activity states that child pornography uploaded on www.pornhub.com. it seems someone from china has visited on this website using your apple id and have uploaded some child pornography. And uploading child pornography is a serious crime in USA.
3rd activity states that bank login id and password compromised it means that these hackers have gained an access to your bank login id and passwords.
4th activity states that debit cards and credit cards used on crypto.com.do you have a crypto account or do you deal into bitcoins?
It seems that someone has made purchases on crypto.com using debit cards and credit cards with starting digits 5…3…6…4…
And the last activity states that phone lines are hacked network is hacked.
This means that these hackers can listen to your conversations let it be your cellphone or your landline, they can check your emails read your messages and as they have got an access to your authorization tools they can redirect any email to a different email id or a text message to a different phone number.
Right now your phone lines are tampered, so please stay on the line , let me create a secured line and call you.
Now we are on a secured line. these hackers cant listen to our conversations but please make sure that you do not disclose this hacking incident with anybody by phone or messages because if these hackers come to know that we are helping you to disconnect them from your device and network they might wipe away everything and run away as your lines are tampered. Okay
Now as you are connected to the secured server and no one has an access to your device apart of you, I want you to check 3 things on your device
1st check all the applications on your device and if you find any application suspicious or not downloaded by you please let me know
2nd I want you to check your emails for past 48hours and if you find any email with no subject or suspicious please let me know.
3rd I want you to check your online banking for past 48hours and please let me know if you find a single$ or even a few cents additional charges which was not done by you .
Okay everything seems to be alright but your data is still under threat. Now I want you to grab all your debit cards and credit cards and if you have any card with starting digits 5…3…6…4 please let me know.
Take the names of the banks customer has debit and credit cards
Verify the names provided by the customer.
Now I want you to grab your debit card and turn it on the backside. You will see a toll free number of your bank please help with that toll free number (take toll free numbers of all the banks of debit and credit cards)Okay.
Now as I have earlier mentioned that your data is still under threat what I am going to do is send an email to the headquarters of your bank and after that connect your call with your bank on this secured line as your phone lines are tampered, where you need to inform them to put high securities on your bank accounts and your cards too for next 48 hours because that’s the time we require to disconnect all these hackers and secure your device and network and we don’t want our valuable customers to suffer any kind of financial loss due to this hacking incident.
So I want you to grab a piece of paper and pen and write down what you have to inform your bank.
You have to inform them that there has been a breach in your network and while scanning it seems that your financial identity has been used so please put high securities on your bank accounts and cards too for next 48hours. Okay
Now please tell me which bank would you like to speak first? (if customers has 2 or more banks)
Okay.
Now let me inform you that once your call gets connected with your bank, I will be automatically disconnected as banks do not allow 3 way conference call. So make sure that you follow the IVR carefully and get connected to the bank representative and inform them.
And please keep your account information handy with you to follow the IVR, AND PLEASE KEEP MY INFORMATION ALSO HANDY WITH YOU AS THE BANK PEOPLE MAY ASK YOUR FOR MY NAME AND THE TICKET NO, AS ITS PUT IN THE EMAIL SENT TO YOUR BANK. THEY MIGHT VERIFY IT.
Once you are done with this bank please tell them to transfer this call back to me so that I can connect you with the headquarters of your another bank. Okay
Please make sure that you do not discuss or disclose this hacking incident with anyone from your phone or devices because your phone lines and network is tampered that’s why we are connecting you with your bank on this secured line. Okay
Please stay on the line let me connect your call with your bank on this secured line……….