thoughts on changing technologies

you heard it here second

Archive for the 'spear phishing' Category

Spanish Prisoners and other Scams

Posted by bmackay on 25th November 2008

1216-1.jpgWhile some TRU staff have fallen victim to targeted spear-phishing incidents here,  I am hopeful that everyone is aware of the Spanish Prisoner confidence trick or the modern variant, the 419 Nigerian Money Transfer Scam.  You know the drill: you receive an spam email with copious spelling mistakes informing you how a deposed rich person has picked you and needs your help (the Mark) to move money out of a country  in return for a ridiculously large sum of money as your “payment.”

The scammer’s goal is to appeal to that universal human frailty: greed.  Of course the Mark doesn’t get any actual money while the scammers siphon off the Mark’s life savings to fund an ever growing list of fabrications including local bribes and other red tape that stands in the way of the Mark hitting the jackpot.

Terrifying stuff and Canadians fall victim to this every year.

But revenge on scammers is a dish that is just as tasty served cold. An absolutely fascinating, frightening and highly entertaining look at the world of  419 Scammers can be found at 419eater.com as our hero (the scam-baiter) takes on the scammers at their own game. A delicious sample of the 419 eater work relates to getting the scammers to hand copy an entire Harry Potter book. But wise advice from another blogger – “don’t try this at home.”

Picture is from the movie “The Spanish Prisoner” , one of my faves.

Posted in spam, spear phishing | No Comments »

Spear Phishing at TRU

Posted by bmackay on 29th September 2008

TRU Spear Phishing PosterOver the weekend, many TRU users received an email request that asked for their ID and password. The email was from “webmaster@tru.ca” so it looked legitimate but the actual “reply-to” message went elsewhere. While we were able to notify everyone that this was a targeted spear phishing attack on our institution, it may have fooled some people.

Just to be clear, IT Services would never ask for your user name and password in an email.

To learn more about spear-phishing to protect yourself, your identity and TRU, play the Carnegie-Melon’s Anti-Phishing Phil game.  ITSecurity.com created a nice list to check if a message is real or spam. Finally, be sure to check out the our IT Security site for more information on how to protect TRU and yourself online.

Posted in spear phishing | No Comments »