Attacks on IVR systems and call centers of bank are interesting and funny, but sometimes they are not so effective. Usually hacker should know some user's information for authorization. So, hacker can gain access to private information and money (sometimes) of one known person, but what he can do, if he want to attack thousands users? Luckily (or no) many people share their information in the Internet.In this talk I will show, how and where attacker can gather information, which can be used for attack on IVR systems. At the final I will show practical case from one private bank.