Tuesday, June 7, 2011

Western Union Phishing Scam - The Fake Attention Important Message Email.



Share

Western Union customers should watch their inbox for a phishing scam campaign targeting them. The email appears to come from "westernunion@emails.westernunion.co.uk" and is bearing the subject line "Attention - Important Message". The body of the email urges the intended victims to "Log in to their Western Union account" by stating the company has locked their account due to suspected "third party access". If the intended victim falls for the bait and click the link provided in the email, they are transferred to a fake Western Union UK Account log in web page at "209.50.103.186.nw.nuvox.net/default.html". The fake website has been marked as a web forgery already, but I would suspect their are other website associated with this scam campaign. Note: In my opinion this is a well put together phishing email and site. Quite a few people may actually fall for it.

There are several issue with the email however: 
  1. Where the email appears to originate from.
  2. The use of the generic "Dear Western Union Member" instead of actually addressing the customer by name.
  3. The Fact that Western Union will never contact a customer by email to urge them to log into their account.

Example Of The Email - Click to Enlarge

The FAKE Western Union Uk Website - Click to Enlarge
 

The REAL Western Union UK Log in Site - Click to Enlarge

If you find this type of email in your inbox don't not follow the links provided in it. Instead forward the message to spoof@westernunion.com then mark the message as spam and delete it. Remember, never follow the links in emails that urge you to log into your online accounts and before you log into any of your accounts always be sure to verify the sites web address is the correct one by looking in your web browsers address bar..


Sunday, June 5, 2011

The Online Service Message Email Is A Google Account Phishing Scam.



Share

GMail users should watch their inbox for a Google Account phishing scam campaign targeting them. The email appears to come from "info.service@google-account.com" and is bearing the subject line "Online Service Message". The body of the email urges the intended victims to "Verify Their Account" by stating Google is preforming some type of routine maintenance. If the intended victim falls for the bait and click the link provided in the email, they are transferred to a fake Google Account log in web page at "phpquick.com/google.updates/info.login.htm".

There are several issue with the email such as: 
  1. Where the email appears to originate from.
  2. The use of the generic "Dear Gmail User" instead of actually addressing the user by name.
  3. Grammar and misspellings, plus the use of "Pls" instead of "Please".
  4. The Fact that Google will never contact a user by email to have them verify their account.

Example Of The Email - Click to Enlarge

Example Of The Phishing Website - Click to Enlarge
If you find this type of email in your GMail inbox don't not follow the links provided in it. Instead forward the message to abuse@google.com then mark the message as spam and delete it. Remember, never follow the links in emails that urge you to log into your online accounts and before you log into any of your accounts always be sure to verify the sites web address is the correct one by looking in your web browsers address bar..

Additional Google Resources

Messages asking for personal information
http://mail.google.com/support/bin/answer.py?hl=en&answer=8253&hl=en

Email Authentication
http://mail.google.com/support/bin/answer.py?hl=en&answer=180707

Messages asking for personal information (phishing)
http://mail.google.com/support/bin/answer.py?hl=en&answer=184963