Mess with a Scammer!


Yesterday I received the following email from a person whom I know, but not well (I am hiding the identity out of courtesy). I was immediately suspicious, and after contacting the real owner of the email address, I decided to have a little fun and document the shenanigans for my readers enjoyment.

THE INITIAL EMAIL

In our current, connected, environment there are countless ways for you to be digitally swindled. One of the easies and most popular methods is social engineering. Social engineering is the art of preying upon human psychology, instead of technical expertise, to gain access to protected resources. In layman’s terms a hacker preys on the person rather than the technology to gain access.

Perhaps the most famous example of social engineering was the Trojan Horse. The Greeks were able to circumvent the massive defensive measures of the city of Troy, and enter the city, without firing a single arrow. Rather than fight through an army, beat down walls, and suffer thousands of casualties doing so… the Greeks preyed on the Trojans psychology. They gave them a gift and counted on their pride, greed, and curiosity to essentially invite them into the city!

There are many types of social engineering ranging from elaborate to extremely simple. The example I will be sharing today is one of the more simple, yet despicable, methods that hackers will use. In this scenario, there are two potential victims. The first victim is the person who’s being impersonated. I am not certain how this occurred, their email account could have been hacked, or the hacker could simply be trying to impersonate them. Regardless, the hacker is aware that I know the victim and is going to manipulate that relationship to make me the second victim.

MY RESPONSE

At this point I am suspicious but not certain that this is a phishing attempt…

HACKERS RESPONSE

Now I know this is a phishing attempt and I decided to have a little fun!

MY RESPONSE

I offer some CatchMark gift cards and also offer to deliver them.

HACKERS RESPONSE

Of course this isn’t what they are looking for, they are probably contacting me from another continent and have no use for CatchMark gift cards. I received the below response!

NEXT COUPLE RESPONSES

Now it is getting fun. I begin playing dumb… no worries, those are not real EBAY cards just a picture I pulled from the internet.

THE HACKER IS GETTING IMPATIENT

While I am searching online for more fake eBay card images I apparently take a little too long…

I GIVE HIM A LITTLE HOPE

I send a fake card but “accidentally” leave out the last 3 numbers!

THEN I MESS WITH HIM A LITTLE MORE

The hacker lets me know that he needs the whole number so I sent him the below…

I GET AN EXAMPLE

The hacker sends me an example of what he needs to see to which I reply…

HE REASSURES ME THAT IT WAS JUST AN EXAMPLE

I LET HIM KNOW HOW RELIEVED I AM

I tell him that I spent a lot of money and didn’t want it to go to waste and provide the pot of gold, albeit fake, so he can toil away at trying to cash them in…

LAST CORRESPONDANCE

In his last correspondence he lets me know that there was a problem with cashing in the cards and he was struggling to get them to function…

TO WHICH I RESPOND…

A COMMON EVENT

I would like to say that the above exchange is rare, or that nobody falls victim to this type of attack but that is simply not the case. Unfortunately, millions of dollars are swindled from innocent victims each year in this manner.

PROTECT YOURSELF

Many are probably asking, “How do we protect ourselves?” There are a few simple steps you can take:

  1. Be suspicious of unsolicited contacted from individuals seeking internal organizational data or personal information.
  2. Do not provide personal information or passwords over email or on the phone.
  3. Do not provide information about your organization.
  4. Pay attention to website URLs that use a variation in spelling or a different domain (e.g., .com vs. .net).
  5. Verify a request’s authenticity by contacting the company directly.
  6. Install and maintain anti-virus software, firewalls, and email filters.
  7. Use complex passwords and change them often… or use two factor authentication.

If you think you are a victim of a social engineering attack:

  • Report the incident immediately.
  • Contact your financial institution and monitor your account activity.
  • Immediately change all of your passwords.
  • Report the attack to the police, and file a report with the Federal Trade Commission (http://ftc.gov) and US-CERT (https://www.us-cert.gov).
  • Call and expert like CatchMark Technologies (www.catchmarkit.com)

Summary

Cyber crime can and will happen to everyone. Be active in protecting yourself and if you need help call an expert.

,

Leave a Reply

Discover more from

Subscribe now to keep reading and get access to the full archive.

Continue reading