Spotting a Phishing Scam

April 14, 2009
Written by Cathy

2802180448_3c98618a1a Spam and scams are on the rise again.  With the downturn in the economy, predators are looking for opportunity in others’ misfortune.  The best defense is vigilance and knowledge.  Do you know how to protect yourself from a phishing scam?  If so, it never hurts to review the rules.

  1. Be skeptical.  When receiving an email claiming to be from a financial source, immediately assume it could be a scam.  This puts you on alert to notice something unusual.
  2. Use a tool to filter your emails.  Since I have my email filtered through Google, it cuts spam and phishing scams from my inbox dramatically.  However, you should never rely on Google or another tool entirely.
  3. Create an email address for your financial institutions.  Use it only with your financial institutions.  Free email addresses are easy to get.  Don’t use it anywhere else.  The fewer places where your address is used, your risk of being exposed to a scammer is diminished.  (Rule #1 still applies.)  If you get an email claiming to be from a bank on your personal or work address, you immediately know it’s a phishing scam.  Forward it to a phishing report address right away, like spoof@ebay.com or spoof@paypal.com.
  4. Notice punctuation and grammar.  Legit emails will not make obvious errors.
  5. Check the sender of the email.  Why would eBay send an email through an address like secure-ebay.com?  Why wouldn’t they send it through ebay.com?
  6. Hover your mouse over all email links.  If you’re in an web client, the linked address will appear in a tooltip.  If you’re in a mail client, the linked address will usually be in the lower frame of your program window.  The linked address should match the text in the email.
  7. Even if the From address appears to match, it could be a fake.  With domain spoofing, you can fake a different address.  Open the original source headers.  How to do this varies depending on the email client you use, but generally it is under a View->Headers menu.  Several lines of information will appear – don’t worry about all of them.  What you are looking for is whether the return path matches the domain you expect.  If you see the from address as admin@ebay.com and the return path as scammy@aol.com, you have a spoofed address. Note even if this matches, it still may not be authentic.  This just tips you off to the more obvious attempts.
  8. Do not click links that claim your account has been closed, or you need to verify information.  Call your bank.  Check your account balance through the phone.  If you can still access your account info through the phone, your account is not closed.  Talk to a customer service representative if you want to be sure.
  9. If in doubt, send the email to the phishing report address for your institution.  For eBay, forward it to spoof@ebay.com.  They will respond back and let you know if it is authentic.

    I received an email once from PayPal asking me to verify a new security measure.  There were no links in the email directing me to PayPal, and no spoofed addresses.  It looked 100% legitimate.  There was nothing that tipped off warning bells.  However, I was not 100% sure.  Before I logged into PayPal, I forwarded it to spoof@paypal.com.  They responded back a couple hours later and verified it was from them.

  10. Phishing happens through telephone too.  If someone calls you claiming to be your bank and starts asking you personal information, tell them you’re in the middle of something and you’ll call them back.  Ask for their employee number, department and extension.  If they refuse to give it to you, hang up.  Beware – they may try to bully and scare you by saying if you hang up, they’ll cancel your account.  Ask yourself why a legitimate phone call to verify your information wouldn’t let you call them back at a more convenient time?  If it’s legit, why would you want to do business with them if they threaten you?

    If they give you one, call the number listed on the back of your card or the website.  Do not call back the number on your caller id!  Ask the operator to connect you with the employee number you received.

Stay on alert, and be informed.  Protect your information.

How do you score on the Consumer Reports Phishing Test?

Update: Phishing scams are also hitting Facebook. Always remember to check the links!  Beware of Fake Facebook

  • Share/Bookmark


30 Responses to “Spotting a Phishing Scam”

  1. Hi all great information here and good thread. May I ask how did you think of these ideas ?

  2. Thanks for this post, it is great :)

  3. Hi – It’s good to find such interesting writing on the Internet as I have been able to discover here. I agree with much of what is written here and I’ll be returning to this site again. Thanks again for posting such great reading material!!

  4. Thankyou, this is really helpful information, cheers.

  5. Your post is very good, most of the time when I visit blogs they are complete crap and the articles are written purely for search engine traffic. But in your case this is very good, straightforward and simple. If you want to make some money with your blog definitely check out the mini site formula!

  6. Hi, maybe i’m being a off topic here, but I was browsing your site and it looks stimulating. I’m making a blog and trying to make it look clean, but everytime I touch it I mess something up. Did you design the blog yourself? Could someone with little experience do it, and add updates without messing it up? Anyways, good information on here, very informative.

  7. Hi Bro, I’m from germany and really like your blog. This post was great btw ;-) Ok but I have a question: Next month I will be in your country because of my job (car-trader) and I’m looking for sites like http://dimida.de (a big german classified ad for every stuff) to sell my cars and other stuff local. Do you know some sites like this? I know there is ebay but I need more sites, to have more chances in your country! Thank you and best regards :) (in three days I will look for an answer in your blog)

  8. Easily, the article is really the sweetest on this valuable topic. I agree with your conclusions and will eagerly look forward to your next updates. Just saying thanks will not just be sufficient, for the phenomenal clarity in your writing. I will at once grab your rss feed to stay privy of any updates. Fabulous work and much success in your business efforts!

  9. Someone I work with visits your blog regularly and recommended it to me to read as well. The writing style is excellent and the content is relevant. Thanks for the insight you provide the readers!

  10. I enjoy coming back daily to see your thoughts. I have your page bookmarked on my daily read list!

  11. My own circumstances could require a shake up and the knowledge you’ve listed in this article should really aid.

  12. How did I think of these things? I’m very familiar and comfortable with technology, and I stay informed on latest trends. Phishing scams are predatory bait in nature. They are not targeted directly at you. They are bait cast and wait for a bite. So you have to recognize the bait.

    I’m really glad everyone is finding this useful! I’m thrilled if it’s helped!

  13. Kord Scheibel: Autotrader.com is probably the most popular site for selling cars in the US.

  14. Just the information that we was trying to find. Should probably shake up our funds soon.

  15. I really like what you posted right here nevertheless it may be somewhat enhanced, but you have undoubtedly fit in some top notch effort and I hope you maintain it up. Your website is surely inspiring. Thank you!

  16. Hello. I like your weblog. Was wondering if you wanted to make some money from it? I recently signed up to a program that pays out 1 dollars every time one of my visitors do a quick quiz to get access to premium content. Check out my website for more info. Think it is good for this website. Kindest Regards

  17. Would it be possible to get permission to use some of your posts on forums with a link?

  18. What spam filter are you using? I’m having a lot of trouble keeping spam off of my BlogEngine blogs..its driving me crazy!

  19. Even though I do think the article is on the right track there are two points i tend not to believe.

  20. This is certainly a superb bit of information, I currently have conducted quite a chunk of browsing your material of late and consequently i have to state it is undoubtedly awesome to find some different not to mention factual reading instead of all of the duplicated junk which is published all around the net. I hope there is going to be a lot to come and i definitely will be certainly sure to visit back shortly and bring in your rss feed

  21. be certain to use salami instead of ham to give it that even texture

  22. Are you selling advertising space on your blog? If not, do you think you will anytime in the near future?

  23. Hello, I recently came across your blog and have been reading along. I thought I would leave my first comment. I don’t know what to say except that I have enjoyed reading. Nice blog. I will keep visiting your site often.That is some inspirational stuff. Never knew that opinions could be this varied. Thanks for all the enthusiasm to offer such helpful information here.

  24. Took me time to read all the comments, but I really enjoyed the article. It proved to be Very helpful to me and I am sure to all the commenters here! It’s always nice when you can not only be informed, but also entertained!

  25. Are you selling advertising space on your blog? If not, do you think you will anytime in the near future? Regards, Benassi Warner,

  26. Very useful informations about these subject. I have found them with googling and you seems number one of these subjects ! . . .

  27. Nice information, many thanks to the author. It is incomprehensible to me now, but in general, the usefulness and significance is overwhelming. Thanks again and good luck!

  28. Hello,I love reading through your blog, I wanted to leave a little comment to support you and wish you a good continuation. Wishing you the best of luck for all your blogging efforts.

  29. Hey – great blog, just looking around some blogs, seems a really nice platform you are using. I’m currently using Wordpress for a few of my blogs but looking to change one of them over to a platform similar to yours as a trial run. Anything in particular you would recommend about it?

  30. Thanks for taking the time to chat about  this, I feel  fervently  about this and I benefit from learning about this subject.  Please, as you gain information, please add to  this blog with more information.  I have found it really useful.

Leave a Reply

You must be logged in to post a comment.