A call from someone claiming to be with Xfinity sounded too good to be true for one customer, Randy. He received an offer for a five-year guaranteed price of $20 a month on his Xfinity bill.
“We’d like to offer you a package. The package was a five-year guaranteed price of $20 a month,” said Randy.
The caller even offered to pay Randy’s current Xfinity bill to prove their good faith.
“To show you our good faith, go into your Xfinity app. We’re actually going to pay your last month’s bill, which was $50. I went into the app, they said, ‘Now watch, you’re going to see a credit come into your app for $50.’ Sure enough, it did,” said Randy.
However, the situation took a turn when the caller asked Randy to purchase a Target gift card.
“We’re partnering up with a Target, so you’re going to purchase a Target gift card,” said Randy.
That’s when Randy realized it was a scam. Cybersecurity expert Jordan Kelly agreed.
“In fact, when we see these bad actors potentially gaining access to accounts, they can begin to impersonate victims with really terrifying accuracy, and this takes things beyond the step of identity theft. This is really personal account takeover,” said Kelly.
Randy contacted Xfinity, who confirmed it was a scam but couldn’t explain how the scammers accessed his app. Kelly offered some insight.
“They’ve compromised passwords, whether they might even be sending text messages to your phone that you might click on, and it’s a great reminder of the fact that our online accounts are very much like our home, so we lock our front doors and we need to lock down our accounts,” said Kelly.
Randy’s skepticism paid off. Eight days later, the $50 payment was withdrawn from his account, leaving him unharmed financially.
“I lost no money. I actually was ahead 50 bucks for eight days,” said Randy.
In response, Xfinity promised to investigate. The number that called Randy is now disconnected.
To protect your accounts, experts recommend changing passwords regularly, using two-factor authentication, avoiding gift card purchases, not sharing personal information and never clicking on unknown links.