It started with a text message.
“Hi JJW, this is Marvin from ANZ. We need to speak to you about a banking matter. We will call you within a minute to discuss further. Do not reply.”
I didn’t even see the text. My phone vibrated with a call. But then somehow went to voicemail quite quickly. Huh. Another text pings through.
“ANZ has recently tried to contact you in regards to your card ending in ####. Please call us on +613 8654 XXXY. If overseas, search Australia Direct Reverse Charge for information on making calls from a landline.”
Weird.
I flip over to the voicemail thing, where my phone has helpfully made a transcription of the voice message.

“This is Ian at falcon. Please call us at 03 8654 XXXY. This is regarding a personal banking security matter. Thank you…”
Uh okay. This is super weird.
I had literally just used the card to buy ice cream and I was walking home — ice cream all through my beard — and I did not expect this. Super weird. I flipped over to my email.
Hmmm 🤔
Okay. This seems legit. But something doesn’t quite feel right.
When I got home (and washed the ice cream out of my beard), I fired up the ANZ app. There were no blocks on my card. Well that’s good. I opened up the in-app messaging service and navigated through the labyrinthine set of menus to try and find the right option. Eventually I found the right one and I sent off a message asking if they can confirm the call/email/text I just received.
While I’m sitting there waiting for the reply — which took +40 minutes — I Googled the number in the text, voicemail, and email: 03 8654 XXXY. No es bueno.
ANZ’s actual number is very similar — 03 9683 9999 — it’s close enough that if you’re just skimming, in a rush, worried you’re accounts are about to be drained you might just chalk it up to it being their special scam hotline number.

Sheeeeeesh.
I called the number on the ANZ website. The worst hold music I have ever heard jackhammered into my brain.
After 30 minutes someone on the in-app messaging service finally pings me back saying something to the effect of: we don’t call or email customers like this. It is a scam. Don’t click on any links, call the other number, or provide any personal information.
Fuckin’ hell.
I hang up on the absolutely dreadful hold music. Switch my mobile so caller ID is turned off and call the XXXY number:
JJW: “Hi, I just missed a call from this number”
Person: “Hi we’re from your bank, we’re calling about a security issue with your card. Can you please confirm your credit card number.”
JJW: “Hahahahahahahaah go fuck yourself, scammer.”
Person: [hangs up]
I’ve cancelled the card. No money was taken. I was lucky, this time. I almost fell for this phishing attempt. It looked legit.
But here’s the thing: I have recently been bingeing Darknet Diaries so I was primed to be suspicious. One of the points Jack Rhysider always brings up is you need to ‘trust, but verify’. By calling/messaging the actual bank, I verified this was a scam.
But the whole thing did get me spooked.
They had my phone number, my email, and the last 4 digits of my credit card. They also knew the card was with ANZ.
It looks like other people in Australia have been pwnd in this way too.
Given they a) had a lot of detail about me — the kind of details you have to provide with a purchase — but b) didn’t have my full credit card number, and c) it seems to be an ongoing issue, my bet is on someone clever cookie has wrangled access to a major retailer’s customer orders database, done an export, sold the raw info to a phishing operation in south east asia.
I haven’t seen any disclosures and have not received any emails from a retailer owning up to being compromised. Which leads me to think the hacker might still have access or said retailer hasn’t made a public statement, both of which are bad in their own way.
I would take a red hot guess at which retailer it was but I cannot substantiate it with proof, so I shan’t besmirch their name (mainly because I don’t want to be sued).

JJW’s top 7 online security spring/autumn cleaning tips to keep you safe
With everything online now you have to give all your details over to countless websites in order to get stuff done or buy anything. Unfortunately, not every website is trustworthy and even when they are trustworthy, every website is able to be compromised.
Luckily there are things you can do right now to minimise your likelihood of being scammed, phished, or losing control of your email, socials, accounts etc. There are lots of good reputable resources out there to help you figure this shit out, but what follows are my top 7 online security spring/autumn cleaning tips to keep you safe.
Password123
Make your passwords complex and long.
Use a password manager. It’s really simple. It means you only have to remember one password, and if you take the measures below, they are generally super secure.
Do not reuse passwords. Ever. For anything. Every single one should be unique.
Don’t share them. With anyone. Ever. No matter what.
Don’t write them in plain text and store them in a word doc.
Don’t write them on a sticky note and attach the sticky note to your monitor.
If you feel comfortable, create Passkeys for sites. Passkeys are a new way to secure your accounts and they are, if you keep the device the passkey is stored on safe, more secure than passwords. Here is a good explainer about them.
Turn on Multifactor Authentication
Turn it on. Right now. On any and all the accounts which allow it.
Multifactor Authentication (MFA) uses randomly generated codes only you have access to. These are generated in an app like Google Authenticator. Two Factor Authentication (2FA) — where you get an email or a text with a code — is good too.
With MFA it is significantly harder for malicious people to get into your accounts because they have to have another piece of information. Don’t ever share the codes with anyone.
Some sites — especially banks — offer a login/transaction notifications service. It will ping you if someone accesses your account or if they start sending money somewhere. Means you can get in touch with your bank fast (unless it’s ANZ and they take +40 mins to answer the goddamn phone).
Mask your emails
There are a few services which allow you to generate anonymous email addresses which forward to your main email. I’ve been using DuckDuckGo’s email protection. It gives you fun emails like party-plus-polo@duck.com.
This will get through to me. But the beauty is I haven’t given away my actual email address. You can make a new one for every single online thing you do which makes it harder for scammers to pivot from one account to another of yours if they somehow get your details and you can deactivate the address at any time.
The bonus with the DDG emails is it also strips out trackers, which means you get a tiny little sliver of privacy back.
Similarly, you can also use parcel lockers or package collect services which don’t rely on you handing over your home address, it also prevents parcel pirates!
Use a VPN
A virtual private network (VPN) hides where you’re accessing The Internet from. It’s another way of confusing wannabe scammers. It’s so easy to use one these days. Lots of options available. Sadly if it’s a free VPN, then they might be most probably are snooping on you/selling the traffic data somewhere, you are the product and all that. So if you can afford to pay for one, do it.
Trust, but verify
This is what saved my bacon. The phrase comes from an old Russian proverb “doveryay, no proveryay” and was popularised in the West by my hero Ronald Reagan.
Social Engineering — where people use psychological tricks to get you to tell them stuff or do things — like the answers to your ‘Secret Questions’ or install some malware — is frighteningly easy. It’s easy to clone an email template. It’s even stupidly simple to spoof a phone number.
As a general rule: don’t ever give out any information to anyone ever, especially if they’re putting a time pressure on you. No bank or other reputable institution will pressure you. Scammers use urgency to trick you. Go to the actual website of whatever service, look for the legit number, call it, make a coffee and a sandwich while you sing along to the absolutely atrocious hold music (once again: fuck you ANZ).
Clean up old accounts
If you’re an elder millennial like me, the chances are you have hundreds of orphaned accounts out there, all holding on to your data and waiting to be hacked. After the phishing attempt, I went through an almost 20-year-old email account and my password manager and painstakingly found more than 230 accounts or email lists I had signed up for at some point. One was a financial services app which had a significant amount of information about my spending habits between 2012 and 2015. Shit.
A couple of things you can do here:
- Delete all your info and close the account down.
- Some sites won’t allow you to do this yourself, so email them if there is no easy way.
- If you can’t shut it down, fuzz the information it has about you. Change your name, and other details. Update the account to a masked email. Make the password 40 characters long and then…
- Deactivate the masked email.
It’s not perfect, but the point is to remove as much information about you or at least make the info harder to tie back to you from sitting in random, maybe unsecure, places on The Internet.
The best defence is don’t sign up in the first place. Be careful about where you plug your info. Is the drop-shipped pair of shoes on a very dodgy looking site worth giving someone your full name, home address, mobile number, and credit card details? Probably not. (I may have done this very recently 😬)
Delete yourself
Europeans enjoy the protections of the General Data Protection Regulation (GDPR) which, in theory, means you should be able to delete/remove data collected about you. Us people in Australia, USA, New Zealand, and elsewhere are kind of at the whim of whatever your state/country’s legislation is, but nothing like the GDPR.
Why is this important?
lWell there are these companies called Data Brokers. Data Brokers are right up there with used car salesmen and real estate agents imho. They will be among the first up against the wall when the glorious JJW revolution happens. They’re insidious little shits who buy and sell data about people. You will probably never have interacted with one of these companies. But they know alllllllll about you and they don’t really have any ethics, morals, soul or qualms about selling your data off to anyone with the coin to pay for it.

I recently signed up to a service which uses the few mechanisms available here in Australia to delete shit from Data Brokers. One broker had pretty much all my details. I had never heard of them. Who knows how that info got to them or where it could or would end up. In the USA Data Brokers powers are starting to be curtailed and there are some rules here in Australia and NZ which should allow you to remove data. You should write to your local elected representative now and ask them to make these laws betterer.
This is also why email masking and VPNs are so important, they will not only make it harder for scammers to scam you but for these data brokers to track you.
Why take the time?
Say you’ve done none of the above things. The chances are you might coast through and never ever have any problems.
But, what if someone gets into one of your accounts and you’ve reused a password. They have your email address, whatever details are in that account like say your address, they have your password. The next thing they will try is other sites where you’re likely to have an account. So what was one account compromised is now three, five… more.
You might laugh, but one of the biggest hacks in history started because a person from Epic Games reused a password and an unbelievable number of other people did too, allowing the hackers to compromise more and more accounts. Wild.
Okay, so you’re locked out of a bunch of accounts. But your main email account — the one your bank account, your social accounts etc are linked to — is still safe, right? Well now the hacker is up in your shit, they can probably take a guess at your secret questions, or know enough about you to put together a nice social engineering opp to trick you into giving them more access. They get into your main email account because you didn’t have MFA turned on.
Now they have your email account they can reset the password on every single account.
You’re fucked.
For many people their entire digital identity relies on a single email account remaining secure. Someone captures your email and they instantly can go change the email account linked to your bank and drain your accounts. They can get into your utilities accounts and cancel your service, or run up huge bills. You’ve got a credit card saved to your Amazon account, and they max it out buying gift cards. There is money to be made here and it is easy work!
There are even more implications beyond the loss of money. There’s the loss of privacy too. If you get hacked or scammed even if you get your accounts back you don’t know what information they took or if they managed to plant malware on your device. They can see all the emails you’ve ever sent. All the messages to your significant other. Through your cloud storage they get all your photos, including the intimate ones.
It also has implications for your job. Imagine if you were working for a company and their Operational Security was compromised because you were being lax. Maybe the hacker is able to take more information from your organisation’s servers and dump it on the darknet. Maybe they put ransomware on all the company’s computers. Maybe you get fired or even sued. Maybe you can’t get a job in your field anymore.

And this all seems very conspiracy and pessimistic. But people are getting socially engineered and their accounts compromised every day. So far this year alone Australians have been scammed out of $186 million. To put that into context, $186mil is roughly enough money to buy every single person in Australia a medium sized jar of Vegemite. And that figure only accounts for the scams which are reported. People often feel ashamed or stupid they got conned, so this is most definitely a low ball.
Making sure you’re secure takes time. But it is worth it. Just to get rid of my nagging voice in the back of your head.
I’ve literally spent the last two weeks obsessing over this. Changing passwords. Masking emails. MFA’ing the shit out of every account. I’m finally at a point where I feel slightly more comfortable about tentatively being on The Internet. As I said, I’ve cleared out a bunch of my digital detritus and have tried to make it harder for scams to happen in the first place. I’ve also primed my brain to verify *everything *and not click on links unless I’m 100% confident it ain’t a phish.
A subtitle for the end
I hope Ian, Marvin, the lovely lady who sounded like she was taking my call from the street corner of a South Asian city, and the rest of the “ANZ Customer Protection Team” are living their best lives tricking people out of money.
Being scammed sucks. Losing the money is terrible. Losing your privacy and online identity is bloody hard. But the victims aren’t to blame. I’m not even sure the people doing the social engineering/hacker ops are to blame. They’re exploiting holes in the security of sites and companies, most of which could, if they wanted to, put systems and technologies in place to better prevent this stuff from happening. Maybe stop spending money on AI bullshittery and put it into security.

One good idea for how to better protect customers is to actually have call centre staff so they can pick up the phone to help customers. The scammers don’t make you wait, and I can easily imagine a world where I got sick of waiting for someone from ANZ’s generic number to pick up the phone and called the scam number.
Last year ANZ made more than $3.4 billion in operating profit (that’s 17 jars of Vegemite for every Australian). They can afford to hire more call centre staff. Just like they can develop better tools to identify and stop scams and to help customers who get scammed.
Governments should be better regulating data privacy rights too. Data brokers shouldn’t be a thing. You should be able to control what information companies store and you should expect it is stored as securely as possible. Legislation should compel them to do it and there should be massive fines or prison time for companies/organisations/people who don’t take security seriously.
But the best defence against all this is to be sceptical. Trust, but verify.
So good luck with your security spring clean 👋
I’ll be lurking around in my inbox waiting for your replies, providing advice, answering questions, and socially engineering you to hand over your passwords.
Look, I know I said I would be writing about AI democratising stuff in my next email. But then someone phished me, and you can see I have been busy. Stop judging me. Next one will be about AI and democracy. Promise.
In the meantime…
Stay safe, stay sane
<3
JJW