Shop Online? Watch out for Fake Email Order Scam
A new report suggests that hackers are using fake email orders with malicious links to fool victims into installing malware onto their machines. Security experts are therefore warning all Internet shoppers to take extra care when opening their emails this holiday season.
According to Brian Krebs, a former Washington Post writer who covers cyber crime, the problem is becoming more and more prevalent. "If you receive an email this holiday season asking you to 'confirm' an online e-commerce order or package shipment, please resist the urge to click the included link or attachment," Krebs notes on his blog. "Malware purveyors and spammers are blasting these missives by the millions each day in a bid to trick people into giving up control over their computers and identities." (Source: krebsonsecurity.com)
Asprox Spam Botnet Harvests Personal Information
Security experts at Malcovery, a firm that monitors email-based malware threats, say that many hackers are currently using this tactic to spread the Asprox spam botnet. Once a system is infected, personal information is harvested from the victim's PC (including passwords, and possibly credit card data); the PC then becomes part of the spamming botnet to propagate itself onto other machines.
Malcovery says people should look out for subject lines that read the following: "Acknowledgment of Order," "Order Confirmation," "Order Status," "Thank you for buying from [insert merchant name here]", and a "Thank you for your order."
Scammers Getting Better at Designing Fake Emails
The tactic is essentially 'phishing,' or the use of legitimate-looking emails designed to convince victims to click on malicious links. Craig Young, a security researcher at Tripwire, says past phishing campaigns were easy to spot because the scams looked so incredibly fake and often contained obvious spelling errors. But that's changing, Young insists.
"Scammers have become incredibly good at making fraudulent emails look legitimate to the untrained eye," Young said. "Attackers will commonly flood the web with spam mail claiming you have a package waiting to be picked up, an order awaiting confirmation, and a plethora of other emails designed to get users to click links." (Source: pcworld.com)
Busy People Easy Targets during Holiday Season
The holiday shopping season is particularly lucrative for phishing scammers who know that people are expecting lots of emails confirming their purchases through online retailers, such as Amazon. That makes it far easier to trick people into clicking on a fishy email link. Ken Westin, who also works in security at Tripwire, says hackers "are able to take advantage of people's impulsive nature more easily during this time of year."
What's Your Opinion?
Have you ever been affected by a holiday season phishing scam, or a courier email scam purporting to have tracking ID on a package shipment? Do you use any particular strategy for spotting and filtering out spam emails? Do you agree that phishing scams are getting harder to recognize?
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.
Comments
Fake E-Mail scam
Yes, scammers are getting better at looking like the real thing, but they still make mistakes. Read everything VERY carefully; you will probably find misspellings and wording that isn't quite right. Also, if you haven't ordered from ABC company, don't open the bloody e-mail!!! I have received several e-mails from "Fed-EX". Funny thing is, I hadn't ordered anything, and no family member was sending me anything. Those went immediately to the real Fed-Ex abuse email.