Last night I got a call from a credit card fraudster /scammer (as it turned out). You know the thing, someone calls, saying there's an emergency, there are unusual charges on your card, blah blah. You're supposed to call the bank back, and not give them any information. So I said I'd do that, and he said, yes please, please call us back right away, it's an emergency. I called the HSBC number on the back of the card (08475 404 404) and I got routed back to him via some guy who said he was HSBC customer service! The call didn't reach HSBC, whom I later called on my mobile, realised that their genuine system is automated at first (so it was clear that I hadn't reached it earlier), and they confirmed that this guy was asking for things they do not ask for, and appearing to follow policies they don't have.
My question is: how did they diddle the phones? Has anyone else heard of this (I googled, didn't come up)? if this is well-known obviously IABU but I thought the key thing to avoid these types of phishing is to call the bank back. They have gotten around this (though it became clear that they only had a limited window of opportunity for re-routing the call, because he kept calling me back and didn't want me to call him back after that first time). Scary!