top of page

Oh, Brother: Part One

3 days ago
10 min read

I mentioned the other day that I was dealing with a numbing computer issue. I'm finally at enough distance to write about it -- needed for decompressing, since it was so galling. On many levels. Much of which was my utter, gut-wrenching stupidity. And much for the scam. And much for the length of time dealing with it all. Just know upfront that the end result isn't "terrible" -- especially considering what it could have been. But it's the totality of it, on all ends, that's so teeth-grinding.


Know, too, that I'm not going to get into all the details. Some because I have a limit on how much of my own stupidity I want to dive into (not that a lot of the stupidity wasn't done for understandable reasons, but it takes much too long to explain those reasons each time), and some because the tale would be much, much too long. Even "in brief," each part is long.


And also because the main reason for writing this is to let others know what to avoid. As a result, most of the minutiae of details are secondary.


I should also mention that what makes my stupidity all the more infuriating is that all along the way I thought something was wrong and even asked about it several times. But because of those "understandable reasons," I accepted things as they were, despite my wariness.


On that Thursday afternoon, I had a problem with my Brother printer. It was printing but I couldn't get the scanning feature to work. Eventually I did a search for the issue I was encountering, saw a Brother Support page result, and clicked on it. First Rule of Stupidity: Don't click on links to big companies without double and triple checking, and probably even then. To be 100% safe, type the address you want in. Links can be spoofed or have slight changes in the spelling that if you're not vigilant, you miss. Most people know this. I know this. I clicked on the link which took me to the Brother Support page. I've been there often and know what it looks like.


So do the scammers. As I was searching the page, a chatbot opened, and after a few questions, asked if I'd like to talk to a human technician. That's odd, I thought, usually I have to ask - but said sure. A few minutes later, the Brother tech rep called. Although, as we all here now know, he wasn't a Brother tech rep at all. But I had no reason to doubt it, I was on the Brother Support website.


This is a part I'll trim, because I spent two hours with the guy and his more advanced tech supervisor. And that made it another reason it was all understandable -- scammers don't spend two hours dealing with a tech issue. It's "take the money and run". As fast as possible.


Early in the process, "Nick" emailed me one of those common software apps for tech support that let them gain access to your computer so they can find the problems and resolve them. I deal with these apps all the time. Yet here, I was wary and even asked how I knew he was from Brother. And his answer was "understandable" -- he came to me through Brother's site. So, I gave my authorization, and he logged in. Second Rule of Stupidity: Never allow someone to take over your computer unless you're 100% certain (100%) that you know who they are -- like who you personally know or that you made the phone call to the company on what you know is the corporate line. He tried several things to get my scanner to work and -- like me -- couldn't. File updates were not installing. So, he did a search to see if anything was blocking this, and for the next hour or so, I saw on my monitor my file system fly by being checked, as I've seen it checked before. It was all very legitimate -- except that it probably wasn't. And we discussed at length things about computer maintenance, which I knew was valid.


Eventually, he and his more experienced tech expert -- who called me back -- said they found the 'asprox botnet" installed on my system, a very dangerous trojan. It showed 107 devices were connected to me. Except they probably weren't. Third Rule of Stupidity: "You have a trojan" is the default claim of scammers. Trojans are real, but just saying you have one doesn't make them real on your system. You can do a scan yourself with anti-virus software -- including some good, free ones online. But "Nick" and the guy said they'd get rid of it, so that was good to know. First, though, he said I had to do several things with my backup computers to help on my end.


And yes, I was actually wary. But I "knew" not only did he come from Brother's support site, but they'd been on the phone with me at this point for almost 90 minutes. And the discussion about computers was pretty accurate. And they hadn't brought up money at all, even after saying they'd gotten rid of the trojan. So, it seemed like all a part of Brother service, since my printer is fairly new and still under warranty. And...and this is the absolutely weirdest part of the story -- they seemed to have fixed the problem with my printer's scanner!! They did a test, and it worked!


So, all that's why I mean that, for as gallingly stupid as I was -- and I'm leaving out many stupid things -- I had very understandable reasons to believe this was real (despite my continually wariness), including that...they seemed to have fixed the problem!


Keep in mind, this was not a case of them calling me that I had a problem. I had a problem. That's why I went looking online for solutions when I couldn't resolve it. Long before I tried to contact Brother. And the scanner problem actually appears fixed. And confirming this, later in the evening I had to scan something -- on my own, the phone calls had long-since ended -- and the scanner now worked! So...what kind of weird scammers are they?? And they were scammers. More on that in a bit.


Eventually after a couple hours, they did bring up money. But it wasn't much, for two hours work, $295. Some new printers are a lot less, mine was more. (Also, as my tech whiz friend Ed Bott later said -- he comes into the tale later at length -- these guys were probably from Pakistan or India, or such, and $295 to them was more like $2,000.) They did also try to upsell me a Brother/Cisco software firewall for security, but when I said I wanted to think about that, he didn't put any pressure on and asked if he could call back on Saturday. Sure.


So, he sent an invoice, and I -- warily -- gave them my credit card information. (Hey, they were from Brother's support and spent two hours with me and seem to have actually fixed my printer, so I'm going to say now that I'm not going to pay??) When "Nick" finished filling in the forms, he listed a different phone number from the one my phone showed he called on -- which I caught and asked him about. "Oh, they changed my number yesterday, and I forgot." Okay, he's from Brother. And I also noticed that on his email address to contact him, he seemed to have mistakenly added an "s", since it said "Brothers." I asked him about that, too. I was good about asking questions that didn't seem quite right. And unfortunately, I was also good about accepting the answers ("Yes, that's how our email address is spelled") because, though weird, he came from Brother's website, spent two hours, and apparently fixed my computer. And the call ended. I was glad my scanner was working, but still had nagging thoughts. There were too many things offbeat. (I've left out several.) So, I began to search online. His company "Gatex Solution" (remember that name, should you ever come across it) didn't seem to exist. Neither did his direct phone number or the company phone number. And when I asked Search if their email address was real, the answer came back -- no.


Jumping ahead in the tale, when I got a voice mail from "Nick" on his promised Saturday follow-up call (which I didn't answer, but blocked the number after the call was completed), the transcribed message showed that he referred to being from "Brothers." And that's when I realized all his verbal mentions weren't of "Brother's," but rather "Brothers" without the apostrophe. And so, I had heard them without the "apostrophe-s", because they blended into all the real mentions of "Brother." So, I felt mortified, utterly idiotic and angry. I'm so diligent about such things. And I even asked questions. And then...this. But -- they did seem to have fixed the scan feature. (And as I said, I also used the scanner later that night, which I wasn't able to before.) But I also put an immediate lock on my credit card and soon after called the card company and cancelled the card. This is the next weird thing about them as scammers. In that intervening hour, there was only that one $295 charge. They didn't instantly start making purchases. And they clearly hadn't immediately sold the card number to others who'd normally quickly make numerous charges. Just that one $295. A charge by guys who seem to have fixed the scanner on my printer. (I keep saying "seem" because I can't swear how it got fixed. But...it absolutely appears that they did fix it, rather than just get lucky. Because it was the fixing it that kept me going ahead. In fact, when you're feeling this foolish and pummeled, all that makes one question if it actually qualified as a "real" scam since what they said is they'd fix the scanner, apparently fixed it, and charged a high but acceptable price for the work and no more. But, of course, they also created a fake website, which is the definition of a fraudulent act,, said they were from "Brother's" which is a fake name, had a company that didn't seem to exist and phone numbers that weren't real. So, yeah, they also checked all the "scam" boxes. Even if they seemingly fixed the printer..


Still, though, I was sickened. Not only for what I just said about my stupidity -- but because I had turned on my two backup laptops and mobile phone, like they said was necessary. And I had this horrible feeling that my main computer, two backups and phone had all been corrupted.


It was late in the evening by the time I got around to writing my tech whiz guru Ed Bott. And that meant it was three hours later for him, so I knew he wouldn't be answering until morning. That's another long part of the tale, which I knew wasn't over yet until we dealt with those other issues. So, I'll hold that continuation for later. This has gone on long enough. I'll just note this one thing --


Everyone should have an Ed Bott in their life. You've heard the expression about someone highly knowledgeable about a subject, "Hey, he wrote the book on..." the topic. Well...Ed really did literally write the book on how to use Windows. He's been hired by Microsoft Press to write their official books on each version of Windows since Windows XP. In fact, he currently is proofing the galleys for the new, major update coming to Windows 11. So, believe me, everyone should have an Ed Bott in their life. I'm just thrilled that I do.



I'll get more into more about Ed in Part Two, since he plays the significant role. But for now, suffice it to say that the next morning, when I couldn't sleep any more after about 4-1/2 hours of rest and went to my computer at 5:55 AM, there was an email from Ed.


"I have a busy morning and not a lot of time to deal with this, sorry. But here's my quick take." And he gave a low-key, honest assessment and then, after a couple of follow-up email exchanges (despite him saying he didn't have much time), he wrote the most comforting thing I could read, especially coming from someone at the level of Ed Bott, responding to my greatest concerns --

 

"Your other computers are not affected. They can't install software on your phone. Do not worry about your phone.  Your files in the cloud are unaffected.

 

"This is a very low-level operation. These are not sophisticated criminals."


It's hard to describe the depth of relief washing over me when reading that. And then re-reading it, to reinforce the words.


But that's Part Two of the story, with the starting point being to remember Ed Bott saying, "I have a busy morning and not a lot of time to deal with this, sorry.." Because over the next three days, Ed sent me probably over 100 emails! Because he wanted to resolve issues with my computer. (Issues, to be clear, not related to viruses, but to "start fresh on that computer," which ran into a ton of hurdles. And more computer hell.)


So, this story isn't over yet. All we have right now is the moral of Part One and reason for writing this:


Even if you are vigilant, be even more vigilant. Even if you know what you're doing, don't take that for granted and look only for the worst, while overlooking the basics. If you have yellow caution lights when dealing with others or with websites, follow up on that caution. And know that when you click on a link for a company in the Search results, websites can be spoofed, so type the URL address in manually.


As it happens, only 10 days after all this began, the Washington Post did a terrific article about a new kind of scam that's similar to what I went through. It's not the same, but overlaps in many ways -- and gives great advice. I highly recommend it here. I got incredibly lucky. It's been a mess, but it could have been a meltdown disaster. I could have lost a great-many thousands of dollars and (as I thought at the time) had all my systems and my phone corrupted. But I spent $295, had to clean my system just to be safe...and apparently got my printer problem fixed. But there is much more to the tale, however. And that'll be upcoming soon in Part Two.




Comments


bottom of page