# Social engineering: the one buying with details the victim handed over and the customer travelling leave the same trace

Someone who got the number, the CVC and even the code over the phone, and a customer buying from another country, leave the same trace: a card with every detail correct used from an unknown device. What actually separates them, and how the attack mutates once you block it.

2026-08-16 · https://frauddi.com/en/blog/ingenieria-social/

---

## How it attacks

There is nothing to guess here. The customer handed the details over.

A call from the bank that was not the bank. A message about a parcel held at customs. A page that looks exactly like the usual one. The customer types the number, the expiry date and the CVC, and when the code lands on their phone they read it out loud, because someone on the other end is calmly explaining that the code is there to protect their account.

From that moment the caller holds what you hold: full name, card, email, phone. And they have the code whenever they want it, because they call again.

So they take their time. Purchases during office hours, amounts in the range that customer normally spends, spread across several days. Every purchase clears verification because every detail is right. No retries, no declines, no burst.

The one thing they did not get is the customer's phone and the connection that customer always buys from.


## Who looks like it and is honest

And this is where it gets hard.

The one who is travelling. They connect to the hotel network and buy at odd hours: tomorrow's tour, dinner, the ride to the airport. Their card shows up in a city it had never shown up in.

The one with a brand new phone. They switched handsets over the weekend. They reinstalled the app, logged back in and kept buying the usual things from a device your system is seeing for the first time.

The family sharing a card. Mum buys from hers, dad from his, the kid from the household tablet. One card, three devices, and none of the three tells you when it is someone else's turn.

All three produce what the rule is looking for: a card with every detail correct, used from a device or a place it had never been used from.

And blocking the traveller hurts twice as much, because they are far from home and just lost the way to pay for anything.


## What actually separates them

- What happened on the account in the days before. The traveller did not change their email or their phone number before leaving. When someone got the details over a call, there is often a contact change shortly before the first purchase, so the alerts stop reaching the owner.

- What the usual device is doing. On a trip and in a family the known phone keeps showing up in between, one day and the next. When the known one goes quiet and the new one buys alone, two explanations are left: the customer changed phones, or somebody else got in.

- What the money buys. The one who changed handsets keeps buying the same things at the same merchants. A trip is shaped like a trip: hotel, food, transport, and it ends when the customer comes home. Someone else's details buy whatever resells fast.

- Where the goods land. The traveller ships home. The family ships home. A shipping address used for the first time on the same day as a device used for the first time is two new things at once.

- What happens when you ask for confirmation. The traveller answers, annoyed, and finishes the purchase. And here is the uncomfortable part: whoever got the details over the phone can also bring the code, because they call the customer again and ask for it.

None of these signals is enough on its own. A customer who switched phones the same day they left on holiday lights up almost all of them.


## How it mutates once you detect it

Every block teaches them which part of the impersonation shows from outside.

- You block the purchase coming from another country. They make their connection appear in the customer's city. The purchase lands at the usual hour and from the usual place.

- You block the unknown device. They stop buying themselves. They call the customer again and walk them through it step by step so the purchase comes from the household phone.

- You ask for the code sent by text. They ask for it on the same call. They tell the customer the code is there to cancel the charge that just went through, and the customer reads it out.

- You block the new shipping address. They buy what needs no address: top-ups, balance, gift cards, services that activate on the spot.

- You cap the amount. They buy under the cap, several times, on different days, and reach the same total.

At the end of that ladder sits a purchase made from the customer's own phone, at their usual hour, from their usual city, with their own code. And something still does not fit: that customer had never bought this, nor this often, nor in this hurry.

Every step forces a longer conversation with the victim and a story that has to hold up for longer. And the longer the call runs, the more people hang up.


## Closing

The work is in letting the one on holiday keep buying and stopping the one buying with their details from another device, when both purchases arrive on screen with everything correct. That depends on whether you can look at that customer's whole history, or only at the purchase that just came in.


### So how do you solve it?

Tuning this by hand takes days, and every day costs chargebacks and good sales. That is what we are solving at Frauddi. We will show you on your own data.

Next: the patient one, the attacker holding back on purpose so as not to draw attention, and the regular customer who buys a little every month (6 of 9).

Written by Elio Rincón, founder of Frauddi. He writes about AI, security and fraud at e1i0.com.
