Scheme uses E-Mail and Blogs to Encourage Recipients to Register Software with BBB
Following is a copy of an actual e-mail associated with this phishing scheme:
---------- Original Message ----------------------------------
From: "Better Business Bureaus Account Service"
Date: Wed, 22 Oct 2008 21:04:22 +0000
Attention Better Business Bureaus Consumers!
We've enhanced web surfing process with new security measures to keep your online data and personal information safer.
All registered and new BBB consumers must register new software and update contact information until October 24, 2008.
Please read the following information carefully:
Register your BBB company certificate here>>>Link
As always, we appreciate your business. And thank you for working with us.
Sincerely, Sherry Hopper.
2008 Council of Better Business Bureaus
BBB has determined that there are a number of addresses and subject lines being used in to perpetrate the e-mail element of the attack. Following is a representative sample of actual address and subject lines used in this attack.
· Address: “
· Subject Line: Council of Better Business Bureaus - We restrict access to nonpublic personal information about you
· Address: "Better Business Bureaus Update" provisor633@bbb.org
· Subject Line: Better Business Bureaus, Attention: Protecting your personal information
· Address:
· Subject Line: Better Business Bureaus, Attention: Shred unwanted documents that contain personal information.
The phishing scheme is also appearing on multiple blog sites. Following is a representative example of the type message BBB research and investigation has discovered on a number of blog sites.
“We've enhanced web surfing process with new security measures to keep your online data and personal information safer.
All registered and new BBB consumers must register new software and update contact information until October 24, 2008.”
Please read the following information carefully>>>Link
BBB is advising consumers and businesses to take the following precautions and actions to steer clear of this phishing attack and to protect their computer systems and networks.
- Anyone receiving an e-mail similar to those described should not open the message, not click on any links, or respond to the message – the message is not from any entity affiliated with BBB. Opening or viewing a preview of the e-mail, or clicking on the link within the e-mail, could enable a discreet download of a virus or spyware.
- Report receipt of any such messages. BBB is working with the U.S. Secret Service's Electronic Crimes Task Force (ECTF) to address phishing issues using the BBB name. BBB has established an e-mail address - phishing@council.bbb.org – people can use to forward the message to, thereby reporting the incident to BBB and the ECTF.
- The public can view updates and the latest information on the phishing attack on the BBB Web site at the Security and Alerts Web page at http://www.bbb.org/securityalerts.
No comments:
Post a Comment