<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Email FAIL Blog &#187; phishing</title>
	<atom:link href="http://www.emailfail.com/tag/phishing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.emailfail.com</link>
	<description>Stories of Email Overload, Email Hell, and Email FAIL in Action</description>
	<lastBuildDate>Wed, 31 Mar 2010 16:44:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Real Phishing Attack, or PayPal Auto Response?</title>
		<link>http://www.emailfail.com/real-phishing-attack-or-paypal-auto-response/</link>
		<comments>http://www.emailfail.com/real-phishing-attack-or-paypal-auto-response/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 16:21:17 +0000</pubDate>
		<dc:creator>Jay</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[PayPal]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.emailfail.com/?p=1512</guid>
		<description><![CDATA[Can PayPal tell the difference between emails it sends out and phishing emails from scammers trying to trick users into providing sensitive information? Looks like the answer is no. Blogger Randy Abrams works for an online security company. His ESET Threat Blog is filled with information about how to avoid hacking, malware, and other such [...]]]></description>
			<content:encoded><![CDATA[<p></p><p style="text-align: left;">Can PayPal tell the difference between emails it sends out and phishing emails from scammers trying to trick users into providing sensitive information?</p>
<p style="text-align: left;">Looks like the answer is no.</p>
<p style="text-align: left;">
<div class="wp-caption aligncenter" style="width: 332px">
	<a href="http://www.flickr.com/photos/hitchster/3627047656"><img src="http://farm4.static.flickr.com/3306/3627047656_39c44c36bf.jpg" alt="http://www.flickr.com/photos/hitchster/ / CC BY 2.0" width="332" height="500" /></a>
	<p class="wp-caption-text">http://www.flickr.com/photos/hitchster/ / CC BY 2.0</p>
</div>
<p>Blogger Randy Abrams works for an online security company. His <a href="http://www.eset.com/threat-center/blog/" target="_blank">ESET Threat Blog</a> is filled with information about how to avoid hacking, malware, and other such computer security threats. It&#8217;s obviously a subject he knows a lot about.</p>
<p style="text-align: left;">So when he received a legitimate email from PayPal that contained a link to the PayPal login page, he wrote to them. His point was that people in his industry have been warning email users to be wary of emails containing links to banks and other financial institution&#8217;s home pages. The landing pages are often spoofed to look like the real site, and when users log in, the scammers have their personal information. So he wanted PayPal to know that it was a bad idea to include the link in their email, because it could be confusing an already confused population.</p>
<p style="text-align: left;">PayPal wrote back, in part:</p>
<blockquote style="text-align: left;"><p>Hello Randy Abrams,</p>
<p>Thanks for forwarding that suspicious-looking email. You&#8217;re right – it was a phishing attempt, and we&#8217;re working on stopping the fraud. By reporting the problem, you&#8217;ve made a difference!</p></blockquote>
<p style="text-align: left;">There are only a few explanations for how PayPal decided its own email was phishing.</p>
<ol style="text-align: left;">
<li>It was an automated response, and Randy could have emailed anything to the address he used and gotten the same response.</li>
<li>A harried employee sent the wrong email template.</li>
<li>PayPal staff can&#8217;t tell their own emails from scams.</li>
</ol>
<p style="text-align: left;">I&#8217;m betting on #1.</p>
<p style="text-align: left;">But #3 would be funnier.</p>



Share and Enjoy:


	<a rel="nofollow"  href="http://www.printfriendly.com/print?url=http%3A%2F%2Fwww.emailfail.com%2Freal-phishing-attack-or-paypal-auto-response%2F&amp;partner=sociable" title="Print"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print" alt="Print" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.emailfail.com%2Freal-phishing-attack-or-paypal-auto-response%2F&amp;title=Real%20Phishing%20Attack%2C%20or%20PayPal%20Auto%20Response%3F%20&amp;bodytext=Can%20PayPal%20tell%20the%20difference%20between%20emails%20it%20sends%20out%20and%20phishing%20emails%20from%20scammers%20trying%20to%20trick%20users%20into%20providing%20sensitive%20information%3F%0D%0ALooks%20like%20the%20answer%20is%20no.%0D%0A%0D%0A%0D%0A%0D%0A%0D%0A%0D%0ABlogger%20Randy%20Abrams%20works%20for%20an%20online%20security%20compan" title="Digg"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.emailfail.com%2Freal-phishing-attack-or-paypal-auto-response%2F&amp;title=Real%20Phishing%20Attack%2C%20or%20PayPal%20Auto%20Response%3F%20&amp;notes=Can%20PayPal%20tell%20the%20difference%20between%20emails%20it%20sends%20out%20and%20phishing%20emails%20from%20scammers%20trying%20to%20trick%20users%20into%20providing%20sensitive%20information%3F%0D%0ALooks%20like%20the%20answer%20is%20no.%0D%0A%0D%0A%0D%0A%0D%0A%0D%0A%0D%0ABlogger%20Randy%20Abrams%20works%20for%20an%20online%20security%20compan" title="del.icio.us"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.emailfail.com%2Freal-phishing-attack-or-paypal-auto-response%2F&amp;t=Real%20Phishing%20Attack%2C%20or%20PayPal%20Auto%20Response%3F%20" title="Facebook"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=Real%20Phishing%20Attack%2C%20or%20PayPal%20Auto%20Response%3F%20&amp;body=http%3A%2F%2Fwww.emailfail.com%2Freal-phishing-attack-or-paypal-auto-response%2F" title="email"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.friendfeed.com/share?title=Real%20Phishing%20Attack%2C%20or%20PayPal%20Auto%20Response%3F%20&amp;link=http%3A%2F%2Fwww.emailfail.com%2Freal-phishing-attack-or-paypal-auto-response%2F" title="FriendFeed"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.emailfail.com%2Freal-phishing-attack-or-paypal-auto-response%2F&amp;title=Real%20Phishing%20Attack%2C%20or%20PayPal%20Auto%20Response%3F%20" title="StumbleUpon"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Real%20Phishing%20Attack%2C%20or%20PayPal%20Auto%20Response%3F%20%20-%20http%3A%2F%2Fwww.emailfail.com%2Freal-phishing-attack-or-paypal-auto-response%2F" title="Twitter"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.emailfail.com/real-phishing-attack-or-paypal-auto-response/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing for Everything They Can Get</title>
		<link>http://www.emailfail.com/phishing-for-everything-they-can-get/</link>
		<comments>http://www.emailfail.com/phishing-for-everything-they-can-get/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 19:14:50 +0000</pubDate>
		<dc:creator>Jay</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://www.emailfail.com/?p=1487</guid>
		<description><![CDATA[I have an email address that I never use. It&#8217;s on a few Web pages, but I&#8217;ve never used it to create any accounts or as a contact address for anything at any time. In fact, I pretty much only check it these days to see what entertaining spam might appear. This arrived in my [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>I have an email address that I never use. It&#8217;s on a few Web pages, but I&#8217;ve never used it to create any accounts or as a contact address for anything at any time. In fact, I pretty much only check it these days to see what entertaining spam might appear.</p>
<p>This arrived in my inbox yesterday:</p>
<blockquote><p><tt>Below is the result of your feedback form.  It was submitted by<br />
(Account.Update.@msnn.com) on Wednesday, December 9, 2009 at 09:59:45<br />
-----------------------------------------------------------------------<br />
: We Here at MSN, are sorry to inform you that we are having problem's<br />
with the billing information on your account.(XBOX Live, MSN Hotmail, Verizon,)<br />
We would appreciate it if you would go to our website and fill out the<br />
proper information that we  need to keep you as an<br />
MSN  member.</tt></p>
<p><tt>Please Update your account information by visiting our updates web site<br />
below.<br />
</tt></p>
<p><tt>&lt;a href="</tt><tt>http://members.lycos.co.uk/verizoncellphone/msnlive</tt><tt>"&gt; verizon updates&lt;/a&gt;<br />
</tt></p>
<p><tt>Steve.<br />
Updates Center<br />
Account Team.<br />
.550268889550268889</tt></p></blockquote>
<p>Seemed like a run of the mill phishing  email, complete with weird punctuation,  random use of uppercase letters, and a  &#8216;close but no cigar&#8217; From address  &#8212; Account.Update@msnn.com. Anyone with a half a clue would see that extra N and know it was fake, right?</p>
<p>The failed attempt to embed the link in the body of the email is pretty funny too &#8212; I mean, even if somebody didn&#8217;t catch on that this was bogus before they saw that, they&#8217;d know that Verizon would not use a lycos.co.uk domain, right? Right?</p>
<p>Of course, I went to the site. Here&#8217;s what it looks like. Note the misspellings, and the sheer gall of these people to ask for <em><strong>two</strong></em> credit card numbers, a state ID (driver&#8217;s license?) number, social security number, mother&#8217;s maiden name, bank account numbers, email address and password&#8230;</p>
<p>It saddens me that somebody somewhere has probably lost a lot of money because of this.</p>
<p><em><strong>Update: I reported this site to Lycos Tripod yesterday, and when I checked it today they had already taken it down.</strong></em></p>
<p><img class="aligncenter size-full wp-image-1495" title="Bogusbilling" src="http://www.emailfail.com/wp-content/uploads/2009/12/Bogusbilling1.png" alt="Bogusbilling" width="1235" height="1728" /></p>



Share and Enjoy:


	<a rel="nofollow"  href="http://www.printfriendly.com/print?url=http%3A%2F%2Fwww.emailfail.com%2Fphishing-for-everything-they-can-get%2F&amp;partner=sociable" title="Print"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print" alt="Print" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.emailfail.com%2Fphishing-for-everything-they-can-get%2F&amp;title=Phishing%20for%20Everything%20They%20Can%20Get&amp;bodytext=I%20have%20an%20email%20address%20that%20I%20never%20use.%20It%27s%20on%20a%20few%20Web%20pages%2C%20but%20I%27ve%20never%20used%20it%20to%20create%20any%20accounts%20or%20as%20a%20contact%20address%20for%20anything%20at%20any%20time.%20In%20fact%2C%20I%20pretty%20much%20only%20check%20it%20these%20days%20to%20see%20what%20entertaining%20spam%20might%20app" title="Digg"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.emailfail.com%2Fphishing-for-everything-they-can-get%2F&amp;title=Phishing%20for%20Everything%20They%20Can%20Get&amp;notes=I%20have%20an%20email%20address%20that%20I%20never%20use.%20It%27s%20on%20a%20few%20Web%20pages%2C%20but%20I%27ve%20never%20used%20it%20to%20create%20any%20accounts%20or%20as%20a%20contact%20address%20for%20anything%20at%20any%20time.%20In%20fact%2C%20I%20pretty%20much%20only%20check%20it%20these%20days%20to%20see%20what%20entertaining%20spam%20might%20app" title="del.icio.us"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.emailfail.com%2Fphishing-for-everything-they-can-get%2F&amp;t=Phishing%20for%20Everything%20They%20Can%20Get" title="Facebook"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=Phishing%20for%20Everything%20They%20Can%20Get&amp;body=http%3A%2F%2Fwww.emailfail.com%2Fphishing-for-everything-they-can-get%2F" title="email"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.friendfeed.com/share?title=Phishing%20for%20Everything%20They%20Can%20Get&amp;link=http%3A%2F%2Fwww.emailfail.com%2Fphishing-for-everything-they-can-get%2F" title="FriendFeed"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.emailfail.com%2Fphishing-for-everything-they-can-get%2F&amp;title=Phishing%20for%20Everything%20They%20Can%20Get" title="StumbleUpon"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Phishing%20for%20Everything%20They%20Can%20Get%20-%20http%3A%2F%2Fwww.emailfail.com%2Fphishing-for-everything-they-can-get%2F" title="Twitter"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.emailfail.com/phishing-for-everything-they-can-get/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
