I haven’t seen this scam yet on AH, but it is the popular one going around and I was hit up with It only a couple days ago trying to sell a set of Skis on FB.
Facts you all must understand. Every person reading this has had their credentials harvested(hacked) from some place at sometime. That Chevy forum you visited once? The registration for your kid’s school calendar? So your common username and password, or your email address and password for some site is On the darkweb and can be purchased with 10,000 other usernames and passwords for about a penny.
Now here is how your world gets turned upside down:
1.) You used that username and password on another site that does matter, like your bank, or your mobile provider, or some other financial site you care deeply about. Problem is, any high security site also requires you to use multi factor authentication too. So you have to put in a one-time PIN that comes to your phone.
2.) The scammer trying to buy your whatever or sell you a whatever says this: “You seem legit, but there are so many scams out there these days I need to verify your identity. I’m going to send you a code and you need to read it back to me“.
3.) That code is the PIN code for a one-time authentication at a site that matters: Airline, Bank, Cell, Travel, etc. If you give them that code, coupled with the already compromised username and password that happened to match another website that was hacked, they’ve got you. They can clean you out for your entire net worth and you are 100% finanancially liable. You didn’t protect your password, and you didn’t protect your PIN. The law says you deserve to lose everything and you’ll have no recourse.