{"id":176,"date":"2017-06-22T08:38:27","date_gmt":"2017-06-22T14:38:27","guid":{"rendered":"http:\/\/pcmdx.net\/blog\/?p=176"},"modified":"2017-06-22T08:38:27","modified_gmt":"2017-06-22T14:38:27","slug":"scam-e-mails-how-to-tell","status":"publish","type":"post","link":"http:\/\/pcmdx.net\/blog\/2017\/06\/22\/scam-e-mails-how-to-tell\/","title":{"rendered":"Scam E-Mails: How To Tell"},"content":{"rendered":"<p>&nbsp;<\/p>\n<p>Recently PCMDX received a call from a business who&#8217;s bank account had been compromised. \u00a0Someone, using legitimate information, was able to gain access to the account and make transfers from the account to another account, and also made wire transfers to a third party.<\/p>\n<p>The business had been told by the bank that their network had been hacked and that they should seek some help in securing their network, which is why they contacted PCMDX. \u00a0We focus providing network support for small businesses that have less than 15 computers, and one of our specialties is cybersecurity and compliance.<\/p>\n<p><a href=\"http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2017\/06\/hacker-2077138_640.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-178 alignleft\" src=\"http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2017\/06\/hacker-2077138_640-300x200.jpg\" alt=\"\" width=\"300\" height=\"200\" srcset=\"http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2017\/06\/hacker-2077138_640-300x200.jpg 300w, http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2017\/06\/hacker-2077138_640.jpg 640w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Although how the actors (the term used for the &#8220;bad guys&#8221; since they are &#8220;acting&#8221; as a legitimate party) were able to get the\u00a0necessary information is still under investigation, it&#8217;s likely that it was given to them by one of the company officers via e-mail.<\/p>\n<p>&nbsp;<\/p>\n<p>We recently received a scam e-mail and we&#8217;d like to share it with you so that you can learn how to determine if it&#8217;s a legitimate e-mail or not. \u00a0<strong>Please note: \u00a0If you&#8217;re not sure if the e-mail is legitimate, call the sender and ask them if they sent it, even if it passes all of the tests. \u00a0It&#8217;s better to be safe and verify authenticity than take a chance.<\/strong><\/p>\n<p>Here&#8217;s a screenshot of the e-mail we received, along with some notes (Click on the image for a full size view). \u00a0We blurred out information that is not relevant.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2017\/06\/fishing_e-mail.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-177 aligncenter\" src=\"http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2017\/06\/fishing_e-mail.jpg\" alt=\"\" width=\"734\" height=\"558\" srcset=\"http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2017\/06\/fishing_e-mail.jpg 1008w, http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2017\/06\/fishing_e-mail-300x228.jpg 300w, http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2017\/06\/fishing_e-mail-768x584.jpg 768w\" sizes=\"auto, (max-width: 734px) 100vw, 734px\" \/><\/a><\/p>\n<p>Let&#8217;s begin at the top. \u00a0The subject line <em>&#8220;Please Read! (Final Warning) | 06\/05\/2017&#8221;<\/em> sounds pretty threatening and will get your attention right away. \u00a0But it doesn&#8217;t indicate who it&#8217;s from or what it&#8217;s about.<\/p>\n<p>If you look at Blue Arrow 1, you&#8217;ll see that it&#8217;s from &#8220;ACME account team&#8221;, followed by the e-mail address of &#8220;admin@MAIL.HAMILTONTN.GOV&#8221;. \u00a0(We&#8217;re going to use ACME as the alias for the name of the company). \u00a0So here you have two major clues that this is a scam. \u00a0First, the words ACME account team. \u00a0Any legitimate company will list themselves as ACME Account Team, with all words capitalized. \u00a0This is a major clue that this e-mail did not originate in the US (most scam e-mails are from overseas, where grammar is poor).<\/p>\n<p>Our next clue is the e-mail address. \u00a0Although &#8220;admin&#8221; is legitimate, MAIL.HAMILTONTN.GOV is not. \u00a0That&#8217;s an e-mail server for the city of Hamilton, Tennessee. \u00a0It has a .gov domain ending, which can only be assigned to government entities, such as cities, counties, states and the federal government. \u00a0Why would ACME have this domain? \u00a0If it were a legitimate e-mail from ACME, it would end with something like ACME.<strong>com<\/strong> or ACME.<strong>net<\/strong>, not a .<strong>gov<\/strong> domain.<\/p>\n<p>The body of the e-mail is actually very good, at least when it comes to scam e-mails. \u00a0It&#8217;s convincing, it has information in it that the typical person would consider to be legitimate. \u00a0However, as we get to the bottom, some red flags appear.<\/p>\n<p>When you hover over a link (and the Blue Arrow 2 is pointing to two links, &#8220;Visit Help and Support&#8221; and &#8220;Login to My Account&#8221;), the bottom part of your browser, known as the status bar, will display the link that it&#8217;s pointing to, which we&#8217;re using the red arrow to point to. \u00a0In other words, when you click on the link, it&#8217;s taking you to the web site that is showing in the status bar.<\/p>\n<p>This particular link is pointing to <em>baltoo.com\/ACME\/index.php<\/em> . \u00a0 This should immediately sound an alarm with the person reading the e-mail. \u00a0The company that is sending this is ACME, but the domain it&#8217;s pointing to (the first part of the web address is always the domain) is <strong>baltoo.com<\/strong> . \u00a0Anything after the domain name is irrelevant, since that&#8217;s just the directory and folder inside the server it&#8217;s pointing to, and you can name that anything you want. \u00a0When you hover over the link, it should point to the company you&#8217;re trying to go to. \u00a0So it should read <em>acme.com\/Acme\/index.php<\/em>.<\/p>\n<p>Once you click on the link, one of two things will happen. \u00a0Either you will be shown a very convincing site that is asking for your user name and password, or you will end up on poisoned site that will infect your computer with malware, such as a virus, a Trojan, or <a href=\"http:\/\/pcmdx.net\/blog\/category\/computer-protection\/ransomware\/\" target=\"_blank\" rel=\"noopener\">ransomware<\/a>. \u00a0If it&#8217;s the former, you&#8217;ll enter the user name and password, and within minutes the actors will have gained access to your site (as they wanted to in this case), or perhaps gained information such as name, address, social security number, date of birth, etc. (under the guise of &#8220;verifying your identity&#8221;).<\/p>\n<p>Recent studies have shown that firewalls, anti-virus programs, and other security software and hardware, although still crucial in preventing attacks, need to be supplemented by <a href=\"http:\/\/www.post-gazette.com\/business\/tech-news\/2017\/05\/25\/phishing-scams-2017-ransomware-malware-wannacry-cybersecurity-pittsburgh\/stories\/201705260150\" target=\"_blank\" rel=\"noopener\">training of staff so they know what they should look for<\/a>. \u00a0(That page also has a quiz you can take to see how much you know about phishing attacks &#8211; we scored 10\/10. \u00a0How&#8217;s your score?).<\/p>\n<p>Our companion site, <a href=\"http:\/\/www.DontBecomeAnotherTarget.com\" target=\"_blank\" rel=\"noopener\">Don&#8217;t Become Another Target<\/a>\u00a0lists dozens of examples of how companies, some billion dollar plus companies, were compromised not by technology, but by social engineering. \u00a0In other words, a con job either via e-mail or via phone. \u00a0Adequate training would have prevented many of the attacks.<\/p>\n<p>If you&#8217;re a small business that doesn&#8217;t have an IT department, but would like IT level support, contact PCMDX today. \u00a0We&#8217;ll take care of your computer network and cybersecurity needs so you can take care of your business. \u00a0And don&#8217;t wait until you&#8217;ve been compromised. \u00a0The cleanup is much costlier than the prevention.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; Recently PCMDX received a call from a business who&#8217;s bank account had been compromised. \u00a0Someone, using legitimate information, was able to gain access to the account and make transfers from the account to another account, and also made wire transfers to a third party. The business had been told by the bank that their [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,15,7,21,33],"tags":[27,54,55,23,11,34],"class_list":["post-176","post","type-post","status-publish","format-standard","hentry","category-anti-virus","category-data-security","category-hack-prevention","category-pci-compliance","category-ransomware","tag-breach","tag-cybersecurity","tag-hacking","tag-pci-compliance","tag-phishing","tag-ransomeware"],"_links":{"self":[{"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/posts\/176","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/comments?post=176"}],"version-history":[{"count":1,"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/posts\/176\/revisions"}],"predecessor-version":[{"id":180,"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/posts\/176\/revisions\/180"}],"wp:attachment":[{"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/media?parent=176"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/categories?post=176"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/tags?post=176"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}