Wednesday 26 September 2007

Warning Notification

Here's a more realistic phishing email. This time the sender has taken the time to put a realistic PayPal logo and header banner across the top. The header even reminds you to stay protected online. All very reassuring, just a shame that they make a few basic mistakes that easily identify it as phishing:

1 - The To: field is not populated - they've BCc the list of recipients.
2 - The introduction is 'Dear paypal member' - PayPal always address by name.
3 - They threaten to suspend the account (I'm not aware of PayPal making this threat ever for not updating details...).
4 - They have said the information needs to be updated by 22 September, in an email sent on the 26 September.

All in all, not very convincing. Here's the content, minus the clever banner:



Dear paypal member,

It has come to our attention that your PayPal® account information needs to be updated as part of our continuing commitment to protect your account and to reduce the instance of fraud on our website. If you could please take 5-10 minutes out of your online experience and update your personal records you will not run into any future problems with the online service.

However, failure to update your records will result in account suspension. Please update your records before September 22, 2007.

Once you have updated your account records, your PayPal® account activity will not be interrupted and will continue as normal.

Click here to update your PayPal account information

Copyright © 1999-2007 PayPal. All rights reserved.
Information about FDIC pass-through insurance

No comments: