<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.3.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>PC-Armor Computer Security News Blog &#187; Phishing Scams</title>
	<link>http://www.pc-armor.com/blog</link>
	<description>Computer Security News for Everyday Computer Users</description>
	<pubDate>Sun, 22 Jun 2008 06:21:41 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.2</generator>
	<language>en</language>
			<item>
		<title>Nigerian Scam</title>
		<link>http://www.pc-armor.com/blog/?p=117</link>
		<comments>http://www.pc-armor.com/blog/?p=117#comments</comments>
		<pubDate>Sun, 28 Oct 2007 20:38:43 +0000</pubDate>
		<dc:creator>blog</dc:creator>
		
		<category><![CDATA[E-Mail Scams]]></category>

		<category><![CDATA[Identity Theft]]></category>

		<category><![CDATA[Information]]></category>

		<category><![CDATA[Internet Fraud]]></category>

		<category><![CDATA[Phishing Scams]]></category>

		<guid isPermaLink="false">http://www.pc-armor.com/blog/?p=117</guid>
		<description><![CDATA[Greetings,
While checking the Email for &#8220;info@pc-armor.com&#8221; today, I came across what appears to be a Nigerian Scam.  Before I show you the body of the Email, I would like to quote a warning by the FTC that is posted on their website at:
http://www.ftc.gov/bcp/conline/pubs/alerts/nigeralrt.shtm
 &#8220;If you&#8217;re tempted to respond to an offer, the FTC suggests you stop [...]]]></description>
			<content:encoded><![CDATA[<p>Greetings,</p>
<p>While checking the Email for &#8220;<strong>info@pc-armor.com</strong>&#8221; today, I came across what appears to be a <strong>Nigerian Scam</strong>.  Before I show you the body of the Email, I would like to quote a warning by the FTC that is posted on their website at:</p>
<p><strong><a href="http://www.ftc.gov/bcp/conline/pubs/alerts/nigeralrt.shtm" title="FTC Definition of Nigerian Scam" target="_blank">http://www.ftc.gov/bcp/conline/pubs/alerts/nigeralrt.shtm</a></strong></p>
<blockquote><p> &#8220;If you&#8217;re tempted to respond to an offer, the FTC suggests you stop and ask yourself two important questions: <em><strong>Why would a perfect stranger pick you — also a perfect stranger — to share a fortune with</strong></em>, and <strong><em>why would you share your personal or business information, including your bank account numbers or your company letterhead, with someone you don&#8217;t know?</em></strong> And the U.S. Department of State cautions against traveling to the destination mentioned in the letters. According to State Department reports, people who have responded to these &#8220;advance-fee&#8221; solicitations have been beaten, subjected to threats and extortion, and in some cases, murdered.</p>
<p>If you receive an offer via email from someone claiming to need your help getting money out of Nigeria — or any other country, for that matter — forward it to the FTC at <a href="mailto:spam@uce.gov">spam@uce.gov</a>.</p>
<p>If you have lost money to one of these schemes, call your local Secret Service field office. Local field offices are listed in the Blue Pages of your telephone directory.&#8221;</p></blockquote>
<p>Or course, the FTC site has more information about such scams, but I wanted you to see the important questions to ask yourself and what to do if you receive anything like the following example, which would be to forward the entire email to &#8220;<strong>spam@uce.gov</strong>&#8221; and then delete the message.  Now, let&#8217;s see what the body of one of these emails might look like&#8230;</p>
<blockquote><p>Dear friend,</p>
<p>I know this will come to you as a surprise because you dont know me. I am <em>(named removed for your protection)</em> I work in the Citibank International Plc as the Head Of the Packaging and Courrier service Dept. During the air-lift of some Royal Luggages to Middle east, I decided to include additional Luggages Containing $15M(Fiftheen Million US Dollars)Only for my own Benefit though it was Labelled Security &#8220;Equipment&#8221; for security reasons.</p>
<p>I am Obliged to contact you to assist me in getting this luggage cleared and delivered to you from the agent as I have agreed on the Following terms.<br />
1) Relevant Documents to claim this luggage will be procured in your name to enable the agent clear and deliver it to your mailing address.<br />
2) That you will be entitled to a share of 30% of the total Money.<br />
3) That 10% of the total money will be set aside for any expenses.<br />
4) That 60% of the money will be for me.</p>
<p>If this business Transaction/Terms is ok by you, do Furnish me with your full names,Mailing Address,Your Personal Telephone/Fax Numbers for Communication and Onward Transfer to the agent in Middle East. You can reach me at my private email address: <em>(Email address removed for your protection)</em></p>
<p>Note that this Business Transaction is 100% risk free as all relevant documents to back up the claim of the luggage will be provide for you hence we advice you to keep the entire transaction close to yourself until you must have received the luggage,for security reasons.Other modalities will be discussed as soon as you get back to me. Use this code when replying: <em>(Secret Code Removed for your protection)</em>/CitiBank.</p>
<p>Yours Faithfully,<br />
<em>(named removed for your protection)</em><br />
Courier Dept(Citibank Plc).<br />
+<em>(Probably a Fraudulent Telephone Number, Removed for your protection)</em></p></blockquote>
<p>Not only does the Email ask for personal information, it has numerous spelling and grammatical errors; which are dead giveaways to fraudulent scams!  It is important to understand that <strong>NO LEGITIMATE BUSINESS WILL EVER ASK YOU TO DIVULGE ANY OF YOUR PERSONAL INFORMATION IN AN UNSOLICITED MANNER</strong>, and that includes Email, Regular Mail, by Telephone, or in person.  As long as you can remember that very simple concept, you will avoid becoming a victim of such scams, because you didn&#8217;t take the bait!  The best thing you can do if you ever receive scams such as this, would be to forward the entire email to &#8220;<strong>spam@uce.gov</strong>&#8220;, as well as <strong>the investigative department</strong> of the company the email is imitating.</p>
<p>Common Sense will go a long way in protecting your financial security and personal identity.</p>
<p>PC-Armor.com</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pc-armor.com/blog/?feed=rss2&amp;p=117</wfw:commentRss>
		</item>
		<item>
		<title>Amazon Phishing Scam</title>
		<link>http://www.pc-armor.com/blog/?p=98</link>
		<comments>http://www.pc-armor.com/blog/?p=98#comments</comments>
		<pubDate>Thu, 07 Jun 2007 18:51:51 +0000</pubDate>
		<dc:creator>blog</dc:creator>
		
		<category><![CDATA[Identity Theft]]></category>

		<category><![CDATA[Phishing Scams]]></category>

		<guid isPermaLink="false">http://www.pc-armor.com/blog/?p=98</guid>
		<description><![CDATA[Here is a new phishing scam…this time, the attackers are fraudulently scamming “Amazon.com”.  For your reference, you will find a copy of the e-mail with footnotes and references at the bottom of the sample.

From: Amazon.com Security- Center.
Sent: Tuesday, May 29, 2007 9:33 AM
Subject: &#8220;Amazon.com&#8221;: Possibile[1] Account Theft !
Dear Customer,
-Due to recent account takeovers and [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal">Here is a new phishing scam…this time, the attackers are fraudulently scamming “<strong>Amazon.com</strong>”.<span>  </span>For your reference, you will find a copy of the e-mail with footnotes and references at the bottom of the sample.</p>
<blockquote>
<p class="MsoNormal"><em>From: <st1:place w:st="on"><st1:placename w:st="on">Amazon.com</st1:placename> <st1:placename w:st="on">Security-</st1:placename> <st1:placetype w:st="on">Center</st1:placetype></st1:place>.<o:p></o:p></em></p>
<p class="MsoNormal"><em>Sent: Tuesday, May 29, 2007 9:33 AM<o:p></o:p></em></p>
<p class="MsoNormal"><em>Subject: &#8220;Amazon.com&#8221;: <strong>Possibile</strong><a href="#_ftn1" title="_ftnref1" name="_ftnref1"><span class="MsoFootnoteReference"><span><!--[if !supportFootnotes]--><span class="MsoFootnoteReference"><strong><span style="font-size: 12pt; font-family: 'Times New Roman'">[1]</span></strong></span><!--[endif]--></span></span></a> Account Theft !<o:p></o:p></em></p>
<p class="MsoNormal"><em>Dear Customer,<o:p></o:p></em></p>
<p class="MsoNormal"><em>-Due to recent account takeovers and unauthorized listings, Amazon.com <o:p></o:p>is requesting a new account verification procedure. From time to time, <o:p></o:p>randomly selected accounts (seller and/or buyer)are placed under an <o:p></o:p>advanced updating process based on merchant accounts/bank <strong>relationsand</strong><a href="#_ftn2" title="_ftnref2" name="_ftnref2"><span class="MsoFootnoteReference"><span><!--[if !supportFootnotes]--><span class="MsoFootnoteReference"><strong><span style="font-size: 12pt; font-family: 'Times New Roman'">[2]</span></strong></span><!--[endif]--></span></span></a> <o:p></o:p>on-file credit cards. Amazon.com may also request in an email message <o:p></o:p>scanned/faxed copies of one or more photo ID&#8217;s. Your account <o:p></o:p>confirmation may go wrong if your credit card/bank account has expired, <o:p></o:p>or if you have changed/replaced your credit card without letting us know <o:p></o:p>about the change.<o:p></o:p></em></p>
<p class="MsoNormal"><em>-Your account is not suspended, but if in 36 hours after you receive <o:p></o:p>this message your account is not confirmed we reserve the right to <o:p></o:p>terminate your Amazon subscription.<o:p></o:p></em></p>
<p class="MsoNormal"><em>-If you received this notice and you are not an authorized Amazon <o:p></o:p>account holder, please be aware that it is in violation of Amazon policy <o:p></o:p></em></p>
<p class="MsoNormal"><em>to represent oneself as an Amazon user. Such action may also be in <o:p></o:p>violation of local, national, and/or international law.<o:p></o:p></em></p>
<p class="MsoNormal"><em>To confirm your identity with us please click <strong><span style="color: blue">here</span></strong><a href="#_ftn3" title="_ftnref3" name="_ftnref3"><span class="MsoFootnoteReference"><span><!--[if !supportFootnotes]--><span class="MsoFootnoteReference"><strong><span style="font-size: 12pt; font-family: 'Times New Roman'">[3]</span></strong></span><!--[endif]--></span></span></a><o:p></o:p></em></p>
<p class="MsoNormal"><em>-We apologize in advance for any inconvenience this may cause you and we<o:p></o:p> would like to thank you for your cooperation as we review this matter.<o:p></o:p></em></p>
<p class="MsoNormal"><em>Respectfully,<o:p></o:p></em></p>
<p class="MsoNormal"><em>Amazon.com, Inc.<o:p></o:p></em></p>
<p class="MsoNormal"><em>Copyright 2007 Amazon.com, Inc. All rights reserved.<o:p></o:p></em></p>
<p class="MsoNormal"><em>Amazon sent this e-mail to you because your Notification Preferences <o:p></o:p></em></p>
<p class="MsoNormal"><em>indicate that you want to receive information about Special Events &amp; <o:p></o:p></em></p>
<p class="MsoNormal"><em>Promotions.<a href="#_ftn1" title="_ftnref1" name="_ftnref1"><span class="MsoFootnoteReference"><span><!--[if !supportFootnotes]--><span class="MsoFootnoteReference"><strong><span style="font-size: 12pt; font-family: 'Times New Roman'">[4]</span></strong></span><!--[endif]--></span></span></a>Amazon will request personal data (password, credit card/bank <o:p></o:p></em></p>
<p class="MsoNormal"><em>numbers) only on our home site, <strong>wich</strong><a href="#_ftn2" title="_ftnref2" name="_ftnref2"><span class="MsoFootnoteReference"><span><!--[if !supportFootnotes]--><span class="MsoFootnoteReference"><strong><span style="font-size: 12pt; font-family: 'Times New Roman'">[5]</span></strong></span><!--[endif]--></span></span></a> is securely <strong>incrypted</strong><a href="#_ftn3" title="_ftnref3" name="_ftnref3"><span class="MsoFootnoteReference"><span><!--[if !supportFootnotes]--><span class="MsoFootnoteReference"><strong><span style="font-size: 12pt; font-family: 'Times New Roman'">[6]</span></strong></span><!--[endif]--></span></span></a> with SLL.<o:p></o:p></em></p>
</blockquote>
<p><!--[if !supportFootnotes]--></p>
<p class="MsoNormal">Now that you have seen a sample of the phishing scam, here is a break down of red flags within the e-mail:</p>
<hr align="left" size="1" width="33%" />  <!--[endif]--></p>
<p class="MsoFootnoteText"><a href="#_ftnref1" title="_ftn1" name="_ftn1"><span class="MsoFootnoteReference"><span><!--[if !supportFootnotes]--><span class="MsoFootnoteReference"><span style="font-size: 10pt; font-family: 'Times New Roman'">[1]</span></span><!--[endif]--></span></span></a> Spelling Error: Should be “<strong>Possible</strong>”</p>
<p class="MsoFootnoteText"><a href="#_ftnref2" title="_ftn2" name="_ftn2"><span class="MsoFootnoteReference"><span><!--[if !supportFootnotes]--><span class="MsoFootnoteReference"><span style="font-size: 10pt; font-family: 'Times New Roman'">[2]</span></span><!--[endif]--></span></span></a> Grammatical Errors: There is no space between “<strong>relations</strong>” &amp; “<strong>and</strong>”</p>
<p class="MsoFootnoteText"><a href="#_ftnref3" title="_ftn3" name="_ftn3"><span class="MsoFootnoteReference"><span><!--[if !supportFootnotes]--><span class="MsoFootnoteReference"><span style="font-size: 10pt; font-family: 'Times New Roman'">[3]</span></span><!--[endif]--></span></span></a> If someone clicks this link, it will not take them to “Amazon.com”; instead, it will take them to <strong>http://www.amazon.com.somewhere.com/security.html</strong>.”   <span> </span><span>  </span><u>I substituted “<strong>somewhere</strong>” for the actual address for your protection.</u><span>   As you can see, the link points to &#8220;<strong>somewhere.com</strong>&#8220;, instead of &#8220;<strong>Amazon.com</strong>&#8220;.   A common ploy is to trick the user into thinking the link is legitimate by inserting the scammed domain name <em>(www.amazon.com)</em> ahead of the actual domain name <em>(somewhere.com)</em>. </span></p>
<p class="MsoFootnoteText"><a href="#_ftnref4" title="_ftn4" name="_ftn4"><span class="MsoFootnoteReference"><span><!--[if !supportFootnotes]--><span class="MsoFootnoteReference"><span style="font-size: 10pt; font-family: 'Times New Roman'">[4]</span></span><!--[endif]--></span></span></a> There is no space after the period; technically, there should be two spaces after each period.</p>
<p class="MsoFootnoteText"><a href="#_ftnref5" title="_ftn5" name="_ftn5"><span class="MsoFootnoteReference"><span><!--[if !supportFootnotes]--><span class="MsoFootnoteReference"><span style="font-size: 10pt; font-family: 'Times New Roman'">[5]</span></span><!--[endif]--></span></span></a> Spelling Errors: Should be “<strong>which</strong>”</p>
<p class="MsoFootnoteText"><a href="#_ftnref6" title="_ftn6" name="_ftn6"><span class="MsoFootnoteReference"><span><!--[if !supportFootnotes]--><span class="MsoFootnoteReference"><span style="font-size: 10pt; font-family: 'Times New Roman'">[6]</span></span><!--[endif]--></span></span></a> Spelling error:<span>  </span>Should be “<strong>encrypted</strong>”</p>
<p class="MsoNormal">Finally, <strong>Amazon.com</strong> explicitly states on their website that, “<strong><em>Amazon will never ask for…requests to verify or confirm your account information</em></strong>”.<span>  </span>You will find this policy at:</p>
<p class="MsoNormal"><a href="http://www.amazon.com/gp/help/customer/display.html?nodeId=15835501" title="Identifying Phishing or Spoofed E-mails" target="_blank">http://www.amazon.com/gp/help/customer/display.html?nodeId=15835501</a></p>
<p class="MsoNormal">Whenever you receive any e-mail asking you to verify your account information from anyone, investigate the policy of the business that “apparently” sent the request.<span>  </span>As with Amazon, most legitimate companies will have similar policies.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pc-armor.com/blog/?feed=rss2&amp;p=98</wfw:commentRss>
		</item>
		<item>
		<title>Call Forwarding Phishing Attack</title>
		<link>http://www.pc-armor.com/blog/?p=94</link>
		<comments>http://www.pc-armor.com/blog/?p=94#comments</comments>
		<pubDate>Tue, 22 May 2007 00:52:59 +0000</pubDate>
		<dc:creator>blog</dc:creator>
		
		<category><![CDATA[Phishing Scams]]></category>

		<guid isPermaLink="false">http://www.pc-armor.com/blog/?p=94</guid>
		<description><![CDATA[Last month, Don Jackson wrote an article that appeared on the SecureWorks “Threat Analyses” web page outlining a new type of Phishing attack utilizing a call forwarding scheme.   The victims are warned that if they do not update their bank account information using the steps outlined in the e-mail, their accounts will be [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal">Last month, <strong>Don Jackson</strong> wrote an article that appeared on the <strong>SecureWorks</strong> “Threat Analyses” web page outlining a new type of Phishing attack utilizing a <strong>call forwarding scheme</strong>.   The victims are warned that if they do not update their bank account information using the steps outlined in the e-mail, their accounts will be suspended.</p>
<p class="MsoNormal">As Mr. Jackson explains, victims receive an e-mail with instructions to dial *72 and then a “secure” number they state is the victim’s bank telephone number.   After completing these tasks, the victim will supposedly receive a confirmation call within an hour and then the victim will be able to complete the process, which involves updating their personal information using an online form.   Once the victim has completed the steps, the scammers are then able to use their personal information fraudulently, knowing that if the victim’s bank calls the victim&#8217;s telephone number on file to verify charges on their account(s), the calls will be forwarded to the scammer’s telephone number…who will in turn tell the bank the charges are authorized.   This is a clever tactic and you need to be aware of it to avoid a nightmare of consequences.</p>
<p class="MsoNormal">As always, computer users should never fall for any scheme, intimidation attempt, or any form of solicitation in the form of an e-mail.  You can read about this new scam at:</p>
<p class="MsoNormal"><a title="Call Forwarding article on SecureWorks.com" href="http://www.secureworks.com/research/threats/callforward/?threat=callforward">http://www.secureworks.com/research/threats/callforward/?threat=callforward</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pc-armor.com/blog/?feed=rss2&amp;p=94</wfw:commentRss>
		</item>
		<item>
		<title>Social Networks are an Effective Tool for Scammers</title>
		<link>http://www.pc-armor.com/blog/?p=93</link>
		<comments>http://www.pc-armor.com/blog/?p=93#comments</comments>
		<pubDate>Sun, 20 May 2007 03:14:02 +0000</pubDate>
		<dc:creator>blog</dc:creator>
		
		<category><![CDATA[Information]]></category>

		<category><![CDATA[Phishing Scams]]></category>

		<guid isPermaLink="false">http://www.pc-armor.com/blog/?p=93</guid>
		<description><![CDATA[Lenny Zeltser wrote an eye-opening article for the SANS Internet Storm Center Wednesday, May 16, explaining why scammers are attracted to Social Networks and how such networks can result in huge returns for them.
If you or anyone you know uses MySpace, Facebook, or similar social networks, this is an article worth reading.  A phisher was [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal"><span lang="EN">Lenny Zeltser wrote an eye-opening article for the <strong>SANS Internet Storm Center</strong> Wednesday, May 16, explaining why scammers are attracted to Social Networks and how such networks can result in huge returns for them.</span></p>
<p class="MsoNormal"><span lang="EN">If you or anyone you know uses <strong>MySpace</strong>, <strong>Facebook</strong>, or similar social networks, this is an article worth reading.  A phisher was interviewed for the article and explains how [they] use social networks for [their] malicious deeds and why social networks yield such high returns compared to other sources.</span></p>
<p class="MsoNormal"><span lang="EN">The article ends with suggestions to limit your risk of exposing sensitive information to phishers and their scams.</span></p>
<p class="MsoNormal"><span lang="EN">You can read the article at: <a href="http://isc.sans.org/diary.html?storyid=2808">http://isc.sans.org/diary.html?storyid=2808</a></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pc-armor.com/blog/?feed=rss2&amp;p=93</wfw:commentRss>
		</item>
		<item>
		<title>419 Death Threat Scam</title>
		<link>http://www.pc-armor.com/blog/?p=91</link>
		<comments>http://www.pc-armor.com/blog/?p=91#comments</comments>
		<pubDate>Tue, 15 May 2007 01:29:02 +0000</pubDate>
		<dc:creator>blog</dc:creator>
		
		<category><![CDATA[On the Radar]]></category>

		<category><![CDATA[Phishing Scams]]></category>

		<guid isPermaLink="false">http://www.pc-armor.com/blog/?p=91</guid>
		<description><![CDATA[On Tuesday, May 8, 2007, the SANS Internet Storm Center reported on a new e-mail scam with a new twist&#8230;a death threat against your life!
In looking at the example of such e-mails, the grammar is consistent with e-mails originating from overseas addresses, or the spammers are just plain illiterate.  At any rate, this is [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal">On Tuesday, May 8, 2007, the <strong>SANS Internet Storm Center</strong> reported on a new e-mail scam with a new twist&#8230;a death threat against your life!</p>
<p class="MsoNormal">In looking at the example of such e-mails, the grammar is consistent with e-mails originating from overseas addresses, or the spammers are just plain illiterate.  At any rate, this is a story worth reading and offers suggestions if you receive this type of e-mail, including where to report the threat(s).</p>
<p class="MsoNormal">You will find the story at:</p>
<p class="MsoNormal"><a title="SANS ISC 419 Death Threat Article" target="_blank" href="http://isc.incidents.org/diary.html?storyid=2771">http://isc.incidents.org/diary.html?storyid=2771</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pc-armor.com/blog/?feed=rss2&amp;p=91</wfw:commentRss>
		</item>
		<item>
		<title>Virginia Tech Phishing Scams</title>
		<link>http://www.pc-armor.com/blog/?p=80</link>
		<comments>http://www.pc-armor.com/blog/?p=80#comments</comments>
		<pubDate>Tue, 17 Apr 2007 23:29:53 +0000</pubDate>
		<dc:creator>blog</dc:creator>
		
		<category><![CDATA[Phishing Scams]]></category>

		<guid isPermaLink="false">http://www.pc-armor.com/blog/?p=80</guid>
		<description><![CDATA[The SANS Internet Storm Center reported that there are a large number of new domains being registered today in connection with the Virginia Tech massacre yesterday.  If you think back to Hurricane Catrina, there were numerous scams that came out of the wood work hoping to take advantage of caring and giving individuals who donated [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>SANS Internet Storm Center</strong> reported that there are a large number of new domains being registered today in connection with the Virginia Tech massacre yesterday.  If you think back to Hurricane Catrina, there were numerous scams that came out of the wood work hoping to take advantage of caring and giving individuals who donated money with the intent of providing assistance to the unfortunate victims.</p>
<p>If you are looking to donate to the victims of the Virginia Tech tragedy, do some research before freely giving out your personal information and donations over the Internet.  You can read the story at:</p>
<p><a target="_blank" title="ISC - 04/17/2007" href="http://isc.sans.org/diary.html">http://isc.sans.org/diary.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pc-armor.com/blog/?feed=rss2&amp;p=80</wfw:commentRss>
		</item>
		<item>
		<title>Beware of IRS Tax Phishing Scams</title>
		<link>http://www.pc-armor.com/blog/?p=79</link>
		<comments>http://www.pc-armor.com/blog/?p=79#comments</comments>
		<pubDate>Mon, 16 Apr 2007 23:26:48 +0000</pubDate>
		<dc:creator>blog</dc:creator>
		
		<category><![CDATA[Phishing Scams]]></category>

		<guid isPermaLink="false">http://www.pc-armor.com/blog/?p=79</guid>
		<description><![CDATA[Warnings have been issued over the past couple of months regarding IRS Tax Phishing Scams and now that the tax deadline is almost here, there may be one last wave of attacks.
There are reports of Web sites claiming to be legitimate places where tax payers can file their returns electronically for free…but for the informed [...]]]></description>
			<content:encoded><![CDATA[<p>Warnings have been issued over the past couple of months regarding <strong>IRS Tax Phishing Scams</strong> and now that the tax deadline is almost here, there may be one last wave of attacks.</p>
<p>There are reports of Web sites claiming to be legitimate places where tax payers can file their returns electronically for free…but for the informed and Internet savvy, we all know that this is simply not true.</p>
<p>Do not become another victim and if you wish to file for free, the IRS does have a “Free File Program” located on the <strong>IRS.gov</strong> site.  You would be well-advised to type the address <strong>IRS.gov</strong> in to your browser, rather than trusting a link.  You can read more on this story at:</p>
<p><a target="_blank" title="PC World IRS Tax Phishing Scam" href="http://www.pcworld.com/printable/article/id,130789/printable.html">http://www.pcworld.com/printable/article/id,130789/printable.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pc-armor.com/blog/?feed=rss2&amp;p=79</wfw:commentRss>
		</item>
		<item>
		<title>Beware of US Bank Phishing e-mail(s)</title>
		<link>http://www.pc-armor.com/blog/?p=71</link>
		<comments>http://www.pc-armor.com/blog/?p=71#comments</comments>
		<pubDate>Thu, 05 Apr 2007 00:28:13 +0000</pubDate>
		<dc:creator>blog</dc:creator>
		
		<category><![CDATA[Phishing Scams]]></category>

		<guid isPermaLink="false">http://www.pc-armor.com/blog/?p=71</guid>
		<description><![CDATA[Today, I received an e-mail with the subject of “U.S. Bancorp Commercial and Business : Important Security Mail For All Customerss”.  There are a number of things wrong here…
- I am not a US Bank customer;
- “Customers” is spelled with an extra “s” (misspellings are common in fraudulent emails);
- The US Bank website specifically states, [...]]]></description>
			<content:encoded><![CDATA[<p>Today, I received an e-mail with the subject of “<em>U.S. Bancorp Commercial and Business : Important Security Mail For All Customerss</em>”.  There are a number of things wrong here…</p>
<p>- I am not a <strong>US Bank</strong> customer;</p>
<p>- “Customers” is spelled with an extra “s” <em>(misspellings are common in fraudulent emails)</em>;</p>
<p>- The US Bank website specifically states, “<strong>U.S. Bank Security Commitment</strong><br />
At <strong>U.S. Bank</strong>, we&#8217;re committed to protecting your privacy and security. We will never initiate a request for sensitive information from you via email (ie., Social Security Number, Personal ID, Password, PIN or account number). We strongly suggest that you do not share your Personal ID, Password, PIN or account number with anyone, ever.”</p>
<p>- The originating IP address of this email was a “<strong>Comcast.net</strong>” address; which obviously is not “<strong>USBank.com</strong>”</p>
<p>The body of this particular email reads:</p>
<p><em>Dear U.S. Bank Connections Web and bus.E Ebanking Services client!</p>
<p>Our Technical Subdivision is carrying out a scheduled<br />
ibanking-services update.</p>
<p>By following the link below please start the procedure of the client details update:</em></p>
<p><u><strong> Link removed for your protection</strong></u></p>
<p><em>These directives are to be sent and followed by all Connections Web and bus.E Internet Banking members of the U.S. Bancorp.</p>
<p>U.S. Bank does apologize for any problems caused, and is very thankful for your collaboration.</p>
<p>If you are not client of the US Bank Connections Web and bus.E please ignore this letter!</p>
<p>Copyright © 2007 US Bank Commercial and Business Internet Banking All Rights Reserved.</em></p>
<p>Your best decision would be to <u><strong>NOT OPEN</strong></u> the email and quickly <u><strong>delete the message</strong></u>.  This e-mail contains an image file, which could have harmful code hidden within it.  You would be particularly vulnerable to harmful code if you read your e-mail in HTML instead of text.</p>
<p>As always, legitimate businesses will usually never initiate a request for sensitive information; therefore, you would be advised to delete any e-mail requesting any type of information.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pc-armor.com/blog/?feed=rss2&amp;p=71</wfw:commentRss>
		</item>
		<item>
		<title>Phishing scam targets Dell customers</title>
		<link>http://www.pc-armor.com/blog/?p=64</link>
		<comments>http://www.pc-armor.com/blog/?p=64#comments</comments>
		<pubDate>Mon, 26 Mar 2007 23:04:25 +0000</pubDate>
		<dc:creator>blog</dc:creator>
		
		<category><![CDATA[Phishing Scams]]></category>

		<guid isPermaLink="false">http://www.pc-armor.com/blog/?p=64</guid>
		<description><![CDATA[There are reports of new spoofed e-mails being distributed to Dell customers with the intent of obtaining financial gain at the expense of the victim(s).
At least one such e-mail appears as an order confirmation from Dell, complete with an order number, Dell customer number, and an order amount.
The e-mail(s) may contain a virus or have [...]]]></description>
			<content:encoded><![CDATA[<p>There are reports of new spoofed e-mails being distributed to <strong>Dell customers</strong> with the intent of obtaining financial gain at the expense of the victim(s).</p>
<p>At least one such e-mail appears as an order confirmation from Dell, complete with an order number, Dell customer number, and an order amount.</p>
<p>The e-mail(s) <u><strong>may contain a virus</strong></u> or have a virus attached to the links contained within the e-mail; therefore, you are advised to delete the e-mail.  You should not open, forward, or respond to the e-mail; nor should you click any of the links within the e-mail.</p>
<p>According to the <strong>Direct2Dell Blog</strong>, it looks similar to Dell order confirmation e-mails; however, the fake e-mail does not contain &#8220;Bill to&#8221; or &#8220;Ship To&#8221; information.  Legitimate order confirmation e-mails from Dell contain this information.  You can read more about this new phishing scam at:</p>
<p><a href="http://direct2dell.com/one2one/archive/2007/03/23/9351.aspx">http://direct2dell.com/one2one/archive/2007/03/23/9351.aspx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pc-armor.com/blog/?feed=rss2&amp;p=64</wfw:commentRss>
		</item>
		<item>
		<title>Unsure about clicking on that link?</title>
		<link>http://www.pc-armor.com/blog/?p=60</link>
		<comments>http://www.pc-armor.com/blog/?p=60#comments</comments>
		<pubDate>Wed, 21 Mar 2007 02:10:50 +0000</pubDate>
		<dc:creator>blog</dc:creator>
		
		<category><![CDATA[Phishing Scams]]></category>

		<guid isPermaLink="false">http://www.pc-armor.com/blog/?p=60</guid>
		<description><![CDATA[I received another e-mail with the following subject and body today:
Subject: Confirmation link
Thank you for your loan request, which we received yesterday, your refinance application has been accepted.  Good Credit or Not, We are ready to give you a $315,000 loan, after further review, our lenders have established the lowest monthly payments.
Approval process will take [...]]]></description>
			<content:encoded><![CDATA[<p>I received another e-mail with the following subject and body today:</p>
<p><em>Subject: Confirmation link</em></p>
<p><em>Thank you for your loan request, which we received yesterday, your refinance application has been accepted.  Good Credit or Not, We are ready to give you a $315,000 loan, after further review, our lenders have established the lowest monthly payments.</em></p>
<p><em>Approval process will take only 1 minute.  Please visit the confirmation link below and fill-out our short 30 second Secure Web-Form. </em></p>
<p>Obviously this is another scam, but to reinforce my suspicions, I searched for the location of the originating IP address, which came from Skopje, Macedonia.  Next, I searched for information on the domain the link was pointing to <em>(if I would have been foolish enough to click it)</em>, and it just happens the domain was created yesterday, on 03-19-2007. </p>
<p>First off, I never applied for any loans over the Internet.  But more importantly, when a domain is registered 1 day before the spam made it into my Inbox, odds are quite high it is a phishing scam!</p>
<p>If you have doubts about the validity of any link, you can research them at <a href="http://www.dnsstuff.com/">http://www.dnsstuff.com/</a>.  You will be able to find out to whom the domain is registered, when it was created, when it expires, the country or origin, and other important information.</p>
<p>Be smart and do your homework BEFORE you make a big mistake!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pc-armor.com/blog/?feed=rss2&amp;p=60</wfw:commentRss>
		</item>
	</channel>
</rss>
