Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools
Author
Thread Post New Thread    Reply
Registered
 
Shaun @ Tru6's Avatar
 
Join Date: Dec 2001
Location: Cambridge, MA
Posts: 44,703
Interesting scam

Bought something on eBay and paid via paypal.

Confirmed through both sites purchase and payment went through. and got email confirmations as well.

Got this email very soon after purchase. I have not clicked on anything for fear it will do something, who knows what.

I'm guessing the Return to Merchant button will ask me to enter user and password giving them access to my paypal account.

But it knew I bought this thing on eBay.


__________________
Tru6 Restoration & Design
Old 02-28-2020, 03:22 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #1 (permalink)
AutoBahned
 
RWebb's Avatar
 
Join Date: Jul 2007
Location: Greater Metropolitan Nimrod, Orygun
Posts: 55,993
Garage
Hmmm....

have you run a virus scan recently?
Old 02-28-2020, 03:26 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #2 (permalink)
Registered
 
Shaun @ Tru6's Avatar
 
Join Date: Dec 2001
Location: Cambridge, MA
Posts: 44,703
I have but I think I need to again. Have Avast on my Mac.
__________________
Tru6 Restoration & Design
Old 02-28-2020, 03:27 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #3 (permalink)
Brew Master
 
cabmandone's Avatar
 
Join Date: Jul 2013
Location: Delphos OH
Posts: 32,270
Garage
Wanna talk interesting scam? A friend sold a machine to a person in NY. He sends his wire instructions to the buyer. The buyer receives another email appearing to be from my friend with new wire instructions. Buyer sends money to new wire instructions without calling my friend to confirm. Buyer is now out money. How did they know about the wire instructions my friend sent?
__________________
Nick
Old 02-28-2020, 03:37 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #4 (permalink)
Brew Master
 
cabmandone's Avatar
 
Join Date: Jul 2013
Location: Delphos OH
Posts: 32,270
Garage
FWIW Shaun, I don't think you have a virus on your system. I could be wrong but I don't think it's on your system.
__________________
Nick
Old 02-28-2020, 03:38 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #5 (permalink)
Back in the saddle again
 
masraum's Avatar
 
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 56,625
I'm just thinking outloud here.

I think what you think (phishing scam) is right on. They wouldn't send you an email if they had their hooks in deep. They are trying to get the good info.

So, assuming the payment amount and any other specific details of the email are accurate, I'd assume that they have either 1) seen some of the details of the sale, maybe from the merchant's side or paypal (less likely to me) or 2) they have seen your email with confirmation (which I also think is less likely unless they have your email account user/pass info.

My guess is that they've got a small hook in at the vendor end that allows them to see superficial info about sales.
__________________
Steve
'08 Boxster RS60 Spyder #0099/1960
- never named a car before, but this is Charlotte.
'88 targa SOLD 2004 - gone but not forgotten
Old 02-28-2020, 03:39 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #6 (permalink)
 
Back in the saddle again
 
masraum's Avatar
 
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 56,625
Quote:
Originally Posted by cabmando View Post
Wanna talk interesting scam? A friend sold a machine to a person in NY. He sends his wire instructions to the buyer. The buyer receives another email appearing to be from my friend with new wire instructions. Buyer sends money to new wire instructions without calling my friend to confirm. Buyer is now out money. How did they know about the wire instructions my friend sent?
One of the 2 end points is compromised.
__________________
Steve
'08 Boxster RS60 Spyder #0099/1960
- never named a car before, but this is Charlotte.
'88 targa SOLD 2004 - gone but not forgotten
Old 02-28-2020, 03:42 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #7 (permalink)
Back in the saddle again
 
masraum's Avatar
 
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 56,625
Quote:
Originally Posted by cabmando View Post
FWIW Shaun, I don't think you have a virus on your system. I could be wrong but I don't think it's on your system.
I agree
__________________
Steve
'08 Boxster RS60 Spyder #0099/1960
- never named a car before, but this is Charlotte.
'88 targa SOLD 2004 - gone but not forgotten
Old 02-28-2020, 03:42 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #8 (permalink)
Brew Master
 
cabmandone's Avatar
 
Join Date: Jul 2013
Location: Delphos OH
Posts: 32,270
Garage
Quote:
Originally Posted by masraum View Post
One of the 2 end points is compromised.
I know he had his IT person do all sorts of work to make sure it wasn't on his end but the buyer lost the money. I heard today that the lady on Shark Tank had something similar happen. After my friend told me what happened I started calling buyers to let them know they'd only get one set of wire instructions and to call me to confirm prior to sending.
__________________
Nick
Old 02-28-2020, 03:44 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #9 (permalink)
AutoBahned
 
RWebb's Avatar
 
Join Date: Jul 2007
Location: Greater Metropolitan Nimrod, Orygun
Posts: 55,993
Garage
Quote:
Originally Posted by Shaun @ Tru6 View Post
I have but I think I need to again. Have Avast on my Mac.
an Apple Tech (the level 2 type, not the guys at Starbucks) told me that they use MalwareBytes - it's free (has a pay for more option)

so I got that on both macs that connect to the internet
Old 02-28-2020, 03:49 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #10 (permalink)
AutoBahned
 
RWebb's Avatar
 
Join Date: Jul 2007
Location: Greater Metropolitan Nimrod, Orygun
Posts: 55,993
Garage
Quote:
Originally Posted by masraum View Post
I'm just thinking outloud here.

I think what you think (phishing scam) is right on. They wouldn't send you an email if they had their hooks in deep. They are trying to get the good info.

So, assuming the payment amount and any other specific details of the email are accurate, I'd assume that they have either 1) seen some of the details of the sale, maybe from the merchant's side or paypal (less likely to me) or 2) they have seen your email with confirmation (which I also think is less likely unless they have your email account user/pass info.

My guess is that they've got a small hook in at the vendor end that allows them to see superficial info about sales.
the vendor end seems most likely but a scan on his unit is the easiest thing to do

How would he address this to the vendor? If he sends an Email it can be seen...
Old 02-28-2020, 03:51 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #11 (permalink)
Registered
 
Join Date: Nov 2016
Location: Indiana
Posts: 4,580
Garage
Seems like they come up with a new scam every week. They keep coming with the old scams too. I got a email today about my multi million dollar inheiritance from someone I never heard of.
__________________
Keep talking, Im gonna put you in the trunk.
Old 02-28-2020, 03:52 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #12 (permalink)
 
Brew Master
 
cabmandone's Avatar
 
Join Date: Jul 2013
Location: Delphos OH
Posts: 32,270
Garage
Quote:
Originally Posted by RWebb View Post
an Apple Tech (the level 2 type, not the guys at Starbucks) told me that they use MalwareBytes - it's free (has a pay for more option)

so I got that on both macs that connect to the internet
I detected things with Kaspersky that Malwarebites never picked up.
__________________
Nick
Old 02-28-2020, 03:53 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #13 (permalink)
Brew Master
 
cabmandone's Avatar
 
Join Date: Jul 2013
Location: Delphos OH
Posts: 32,270
Garage
Quote:
Originally Posted by RWebb View Post
the vendor end seems most likely but a scan on his unit is the easiest thing to do

How would he address this to the vendor? If he sends an Email it can be seen...
Hey Shaun! You have to scan his unit!
__________________
Nick
Old 02-28-2020, 03:54 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #14 (permalink)
Back in the saddle again
 
masraum's Avatar
 
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 56,625
Quote:
Originally Posted by cabmando View Post
I know he had his IT person do all sorts of work to make sure it wasn't on his end but the buyer lost the money. I heard today that the lady on Shark Tank had something similar happen. After my friend told me what happened I started calling buyers to let them know they'd only get one set of wire instructions and to call me to confirm prior to sending.
I did a search for "second wire transfer instructions scam" (without the quotes) and the first 3 articles that I looked at said that this is common and means that one of the parties probably has compromised email from phishing.

To me it makes the most sense that the person that received the email with the instructions has a compromised account and when the crook saw that email come in, they then sent another very similar email really quickly with the new data. Of course, it could be the email account at the other end too. Either end would work. What would be smartest would be to have the business end hacked, but if you've got enough consumer ends hacked and just monitor them for certain keywords...
__________________
Steve
'08 Boxster RS60 Spyder #0099/1960
- never named a car before, but this is Charlotte.
'88 targa SOLD 2004 - gone but not forgotten
Old 02-28-2020, 03:59 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #15 (permalink)
MRM MRM is offline
Registered
 
Join Date: Aug 2000
Location: Palm Beach, Florida, USA
Posts: 7,713
Quote:
Originally Posted by cabmando View Post
Wanna talk interesting scam? A friend sold a machine to a person in NY. He sends his wire instructions to the buyer. The buyer receives another email appearing to be from my friend with new wire instructions. Buyer sends money to new wire instructions without calling my friend to confirm. Buyer is now out money. How did they know about the wire instructions my friend sent?
I don't fully understand the details, but this scam is well known in financial and legal circles. Our professional liability carrier has advised all lawyers to not send any payment information by email at all and to only operate by fax (faxes are too low tech for the contents to get compromised) and to follow up with an in-person or phone confirmation.

There is a way for scammers to get access to your Outlook account and plant a program there. Outlook is less secure than the rest of your system and a scan won't reveal anything because virus scans only look at the operating system. I don't recall how it is that they attach the program to your email. Anyway, the program allows them to see and send emails as though they were on your computer. The scammers target people who are likely to exchange money - finance and legal professionals, real estate agents, title companies, etc. When they see a transaction they swoop in and tell the buyer to send the money somewhere else and it looks like the message is from the seller.

Over Christmas I changed my Amazon account to deliver some packages to my mother in law's house because she was there to receive them and the packages would have sat on my door step for a while. Within an hour I received an email from "Amazon" saying I needed to log back in to confirm my change in shipping location and to use the conveniently provided link.
__________________
MRM 1994 Carrera
Old 02-28-2020, 04:00 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #16 (permalink)
Driver, not Mechanic
 
Join Date: May 2013
Location: SF Bay Area
Posts: 3,019
Quote:
Originally Posted by cabmando View Post
Wanna talk interesting scam? A friend sold a machine to a person in NY. He sends his wire instructions to the buyer. The buyer receives another email appearing to be from my friend with new wire instructions. Buyer sends money to new wire instructions without calling my friend to confirm. Buyer is now out money. How did they know about the wire instructions my friend sent?
Reminds me of wire fraud where the victims were local residents here - $780K. I don't know whose system compromised, the buyers' or the lender's... I think they were able to recover the money but not sure if the scammers were caught.
Old 02-28-2020, 04:01 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #17 (permalink)
Back in the saddle again
 
masraum's Avatar
 
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 56,625
Quote:
Originally Posted by RWebb View Post
the vendor end seems most likely but a scan on his unit is the easiest thing to do

How would he address this to the vendor? If he sends an Email it can be seen...
Yes, the vendor end is the most intelligent/lucrative, but if the crook has gotten the user and password for either end or for enough consumer ends, then it's like panning for gold. you go through a lot of silt, but you've only got to find a nugget every once in a while. And if you've got software setup to download emails and scan for keywords...
__________________
Steve
'08 Boxster RS60 Spyder #0099/1960
- never named a car before, but this is Charlotte.
'88 targa SOLD 2004 - gone but not forgotten
Old 02-28-2020, 04:02 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #18 (permalink)
AutoBahned
 
RWebb's Avatar
 
Join Date: Jul 2007
Location: Greater Metropolitan Nimrod, Orygun
Posts: 55,993
Garage
Does "your Outlook account" mean Outlook on the web? or Outlook running as a program on your computer?
Old 02-28-2020, 04:06 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #19 (permalink)
Information Overloader
 
Join Date: Mar 2003
Location: NW Lower Michigan
Posts: 29,666
"Over Christmas I changed my Amazon account to deliver some packages to my mother in law's house because she was there to receive them and the packages would have sat on my door step for a while. Within an hour I received an email from "Amazon" saying I needed to log back in to confirm my change in shipping location and to use the conveniently provided link."

That is sneeeeeky.

Old 02-28-2020, 04:08 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #20 (permalink)
Reply


 


All times are GMT -8. The time now is 08:30 PM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.