First off I should explain what phishing is. Phishing is basically the act of tricking a victim into divulging information. It involves the receiving of an email message with a link to a website where the victim would enter personal information. In this particular scam, you get an email from "Personal Banking: personalbanking@wellsfargo.com" stating that there may have been some unauthorized access to your account and that you should click the link and enter your account and verify some information. When you click the link you are taken to a site which looks identical to the Wells Fargo site.
If you look at the HTML code of the site, you'll notice that they are almost identical. One thing about this scam which was somewhat surprising is that the message made it past my G-mail spam filter. This is slightly different to scams I have seen before in that they don't ask you to reply to this email with your account number like most others, and they don't ask for passwords or anything like that. They simply request that you log in, as you normally do, which would not raise the eyebrow of normal users. On a closer inspection of the site you will notice that the forms submit the data entered (user name and password) to some foreign script and not to Well Fargo. Most probably, the scammer is having all the usernames and passwords emailed to him. After submission of your information the site responds that your password is incorrect. Here an unsuspecting victim would assume that this was because of the supposed unauthorized access mentioned in the email.
If you try to submit information a few more times, it takes you to another Wells Fargo look-alike page called "Online Banking Verification". Here they ask for SSN number, your ATM card number, the expiration date, the pin number and the CVV2# (4 digit verification). With the ATM information the scammer could max out your debit card. With all the rest of the information he has gathered it would not be at all difficult to call up Wells Fargo and basically take over your account. He could change billing addresses, get checks for you account, and simply wipe it out.
How to spot scams like this
Scams like these are usually easy to spot, but this one in particular was a bit tricky, however there are some basic methods you can use to spot these types of scams.
First of all, check the link. Although it looks like the link is going to Wells Fargo's website, if you let the mouse hover over the link for a while and look in the status bar, you will get the real address of the link. In this case the scammer used just an IP address of his domain or machine. This, however, can be overridden on the internet (if the scammer changes the status bar) and sometimes even in your email, depending on what your security settings are.
Check the address bar. In this case, the address bar reported that the website was also from the scammer's IP address. Simply put, it did not say www.wellsfargo.com. Very seldom would a scammer be able to fake this. They may, however, employ other tricks like buying a domain name with a slight spelling difference that the user might not notice or by simply loading the link in a new window and hiding the address bar altogether.
Lastly, the only full proof method to avoid becoming a victim to a scam like this is to simply call in and verify the information over the phone. Please note; do not use a phone number in the email if one is given. Open up your phone book and locate the number for your firm and ask them about it.
Just remember, if it looks funny and feels funny, it's probably a scam. Do not ever reply to such email messages for personal information as sensitive as account information and SSN.
Below is a copy of the email message for your review and amusement. The link is active, however DO NOT ENTER ANY PERSONAL INFORMATION INTO THESE FORMS. THIS IS NOT WELLSFARO'S SITE.
Kevin. A. Lloyd.
From: Personal Banking < personalbanking@wellsfargo.com >
To: me@me.com
Date: Jun 2, 2005 2:22 PM
Subject: Security Notice #291240 Wells Fargo Internet Banking account
Update Necesary!
Dear Member,
We recently reviewed your account, and suspect that your Wells Fargo Internet Banking account may have been accessed by an unauthorized third party. Protecting the security of your acount and of the Wells Fargo network is our primary concern. Therefore, as a preventative measure, we have temporarily limited access to sensitive account features. To restore your account access, please take the following steps to ensure that your account has not been compromised:
1. Login to your Wells Fargo Internet Banking account. In case you are not enrolled for Internet Banking, you will have to use your Social Security Number as both your Personal ID and Password and fill in all the required information, including your name and account number. 2. Review your recent account history for any unauthorized withdrawls or deposits, and check your account profile to make sure not changes have been made. If any unauthorized activity has taken p! la ce on your account, report this to Wells Fargo staff immediately.
To get started, please click on the link below:
https://online.wellsfargo.com/signon?LOB=CONS
We apologize for any inconvenience this may cause, and appreciate your assistance in helping us maintain the integrity of the entire Wells Fargo system. Thank you for your prompt attention to this matter.
Sincerly,
The Wells Fargo Team
Kevin A. Lloyd:
Just launched a website, http://www.DeleteMySpam.com/, dedicated to helping to eliminate the spam crisis.
![]() |
|
![]() |
|
![]() |
|
![]() |
NETWORK SECURITIES: IMPORTANCE OF SECURITIESComputers and securities must form a... Read More
Chris Simpson, head of Scotland Yard's computer crime unit was... Read More
You are at your computer, checking out software on EBay.... Read More
The Loss Prevention Manager should be receptive to the needs... Read More
Electronic Fraud and Identity Theft Human beings are pretty... Read More
Well, this is an article I never thought I would... Read More
So called phishers try to catch the information about the... Read More
Having a good Spyware eliminator on your computer is vital... Read More
On December 8, 2004 Webroot, an award winning anti-spyware solution... Read More
The internet is undoubtedly a fantastic resource for families and... Read More
As the number of people using the Internet as an... Read More
The first thing people think about when defending their computers... Read More
Blaster, Welchia, Sobig, W32, Backdoor, Trojan, Melissa, Klez, Worm, Loveletter,... Read More
IPv6, IntroductionThe high rate at wich the internet continualy evolves... Read More
We all get the odd virus now and then, but... Read More
Spyware is software that runs on a personal computer without... Read More
We all know that it's dangerous to use the same... Read More
When it comes to a secure website and passwords it... Read More
Spyware and adware are becoming major problems for online surfers... Read More
The most frustrating part of having Spyware on your computer... Read More
Every day millions of people go online to find information,... Read More
Monday morning, 6am; the electric rooster is telling you it's... Read More
There are ways to insure security though. You can get... Read More
I Challenge You To Crack The Code ------------------------------------- I had... Read More
Identity theft ? also known as ID theft, identity fraud... Read More
Some months ago, before there was much publicity regarding phishing... Read More
You can detect spyware online using free spyware cleaners and... Read More
A couple of days ago, I was searching for a... Read More
1)Spyware is on your system. Like it or not, statistically... Read More
These six ways to prevent identity theft offer you valuable... Read More
Spyware is software or hardware installed on a computer without... Read More
Let us take the example of scrambling an egg. First,... Read More
Before you enter your name, address or any other data... Read More
It has been said that with the wealth of information,... Read More
Spyware symptoms happen when your computer gets bogged down with... Read More
If you are wondering how to fight spyware for safe... Read More
WHAT IS HACKING?Hacking, sometimes known as "computer crime" has only... Read More
Ok, you've got a computer, and you get online. You... Read More
If you know what is the 'Fishing' then it's very... Read More
They're out there. Individuals trying to make a quick buck... Read More
Glieder (Win32.Glieder.AK), Fantibag (Win32.Fantibag.A) and Mitglieder (Win32.Mitglieder.CT) are not names... Read More
At this point, if you've got the whole "turning the... Read More
So called phishers try to catch the information about the... Read More
Yes, I'm wearing my encryption hat again. Why you may... Read More
Paypal is a great site and is used by many... Read More
Have been an Internet user for more than 9 years,... Read More
Have you ever got an email asking you to confirm... Read More
A week or so ago, I received an inquiry from... Read More
If you run any type of Internet business, Adware and... Read More
Many of us have run into an annoying and time-consuming... Read More
Long gone are the days that we could feel secure... Read More
Working from home has its advantages, including no commute, a... Read More
There is no doubt that "how-to articles" have become a... Read More
Spyware protection software is the easiest way of removing spyware... Read More
Phishing in its "classic" variant is relatively well-known. Actually, 43.4... Read More
First I would like to stress I am condoning the... Read More
Internet is the ocean of knowledge. In this ocean you... Read More
Fishing on the Internet has come a long way. However,... Read More
When the Internet first came about, it was realized it... Read More
If you are a parent, you have probably wondered at... Read More
Shopping for horse gifts or other gift items on the... Read More
Viruses, Bugs, Worms, Dataminers, Spybots, and Trojan horses. The Internet... Read More
From: "Paypal Security" Subject: New Security Requirements Date: Tue, 26... Read More
The Internet offers a global marketplace for consumers and businesses.... Read More
It's late. You've been scouring the web for that perfect... Read More
Phishing is the act of some individual sending an email... Read More
Internet Security |