Blog

The phone call my mother made

Fromenance exists because of one email, one copycat page, and one phone number. The founder's account of the scam that took thousands of dollars from his mother, and why communication provenance is the answer he could not find that day.

George Rios5 min read

I started Fromenance because of a phone call my mother made two months ago. Everything the product does, and the reason we call the category communication provenance, comes back to the minutes she spent on that call, so I want to tell the story plainly before I say anything about software.

The email

It arrived on an ordinary day in July and looked like every other message her bank had ever sent her. Same logo. Same colors. A line saying there had been suspicious activity on her account and that she needed to secure it right away. A link. She is careful, and she did what careful people are told to do: she did not reply to the email and she did not type her password into it. She clicked the link to see what was going on.

The link took her to a page that looked like the bank. Not close to the bank. Like the bank. It repeated the warning, and it did the thing that made all the difference. It gave her a phone number to call.

The call

She called it. A calm, professional voice answered with the bank's name, thanked her for calling so quickly, and walked her through "securing" the account. The person on the line had been expecting her, because they had written the email, built the page, and put their own number on it. Over the next few minutes they asked for the things a bank might plausibly ask for, and she gave them, because she believed she was talking to the people whose job it was to protect her.

Here is the part that still gets me. The email said her account had been hacked. It had not been. It was being hacked, right then, while she was on the phone with the people doing it. The urgency was not a warning about a crime. It was the crime. By the time she hung up, feeling relieved, thousands of dollars were gone.

What she did right, and why it did not matter

I have gone over it many times, and I keep landing in the same place. She did not fall for anything stupid. She got a message that looked legitimate, she was skeptical enough to want to speak to a person, and she called the number she was given. Every step was reasonable. The problem was that at no point did she have a way to ask the only question that mattered, and get a real answer: did my bank actually send this?

The bank had DMARC. The email did not come from the bank's domain, so DMARC had nothing to say about it. Her mail provider's filter had let it through, because it looked like a thousand real ones. The copycat site was taken down eventually, which helped the next person and did nothing for her. Every control in the chain was doing its job. None of them could tell her, in the moment she needed it, whether the message in front of her was real.

And the honest answer is that the bank could not have told her either, even if she had found the real number and reached a real agent. The agent would have looked at the same email she was looking at and guessed.

The question nobody could answer

That is the gap I could not stop thinking about. The one party that knows for certain whether a message is real is the institution that did or did not send it. Banks send millions of messages and keep no record that a customer can check against. So the customer is left to judge appearance, and appearance is exactly what the attacker controls.

Fromenance is my answer to that afternoon. An institution registers every communication as it goes out, with a short code inside it. When a customer wonders, they forward the message to an address on the bank's own domain, or type the code on the bank's own page, and within seconds they get one of three fixed answers: it matches a communication we registered, no registered communication matches, or we did not send this. No score, no "probably", and no words that overpromise. The reply is written so that it never claims more than the record supports.

If my mother had been able to forward that email to her bank and get "no registered communication matches" back in a few seconds, she would not have called the number. I am fairly sure of that, because the reason she called was that she wanted someone to confirm what was going on. She was looking for exactly this, and it did not exist.

The other half

There is a second thing in that story that I did not appreciate until later. The email, the copycat page, and the phone number were a complete phishing kit, delivered straight to a real customer of the targeted bank. If she had forwarded it to the bank, the bank's fraud team would have had the lure, the domain, and the number within seconds, while the campaign was still running. Instead it went into a spam folder, and the number kept ringing for whoever called next.

So Fromenance does that too. Every message that fails verification goes to the tenant's fraud team with the domains and phone numbers already pulled out. Customers who are worried enough to ask become the fastest source of intelligence the bank has, and the number my mother called could have been blocked before the next person dialed it.

Why I am telling you this

I am not sharing this to make anyone feel sorry for her. She is fine, she is sharper about this than most people I know now, and she gave me permission to write it. I started building Fromenance within days of that call, and it has been the whole of my working life for the two months since. I am sharing it because when I talk to security teams about impersonation, the conversation tends to stay abstract: takedown rates, DMARC coverage, classifier accuracy. Those numbers are real and they matter. But the customer on the phone, being told her account is hacked by the people hacking it, is what the numbers are for.

Fromenance is a communication provenance platform, and it was built so that the next person in her position can ask one question and get a straight answer before they pick up the phone. If you run fraud or security at an institution and this story sounds familiar, I would like to hear yours.

foundercommunication provenancevishing

Start with one stream and a 60 to 90 day pilot.

Pick your fraud alerts or your transaction alerts, the messages your customers already squint at. At the end you get a written report: how many people asked, what they were told, which campaigns turned up, and what your existing feeds missed.