We’ve all seen phishing expeditions; however I have to admit that the following example has to be one of the cleverest I’ve seen so far, or a total fluke.

 

Traditionally you would expect a plea from a company explaining that your account or username has been compromised, and your urgent attention is required to correct the wrong. Good thing that the e-mail also has a link providing instant access to a swift password reset! As all of us are well aware, the link is bogus and redirects you to a Web site that captures your keystrokes.

 

So what’s different with this new example?

 

First off, it was not a request for urgent attention. Instead, the e-mail was just a notification of a purchase that involved a PayPal funds transfer. The mail outlined that I (the recipient) purchased a Dell computer that would be shipped to “Wayne E Bakewell” in “Brownsville, PA.” If this was incorrect, I could click a well placed Cancel Transaction link!. Since I knew better, this message just ended up in my trash.

 

Two hours later, another message followed. I receive an e-mail from eBay (not Dell) indicating that a purchase was made, and payment was due. The auction item matched the PayPal purchase message perfectly.

 

This is the first time I've had to go digging in my trash to find a PayPal spam message to confirm that the items were one and the same… Remarkably the two messages—that I bought a computer and it was going to Wayne!—were virtually identical. How odd, and synchronized.

 

As most of you read this, I’m sure you regard it as no different from the spam that clutters your inbox daily. But if you think about it from the perspective of a new user taught about the dangers of spam, I would think that this could be the tipping point between spam, and a real concern!  I dug the messages out of the trash because I wanted to see the similarities. The nefarious nature of spam mail such as this puts in perspective the lengths, and means some will go to, to swindle an account, and maybe an identity.

 

Some details to the spam:

Interestingly enough the Cancel Transaction and Respond Now buttons go to two unique IP addresses 202.93.112.29, 87.192.100.178 respectively. Of course both were dead by the time I got around to playing with this scam, but I did discover they were registered to an Indonesian and Irish ISP respectively.

 

Looking around on the net, it turns out that similar messages were proliferated during the February timeframe but purchasing Altec Lancing Speakers instead of a Dell computer. Based on the details, Wayne has been very busy!

 

So bottom line, if it looks too good or bad to be true just delete the message or pick up the phone and call if you are concerned about the validity of a message.

 

Oh a few other points of interest:

  1. The purchase order does not exist with Dell!
  2. And Wayne E Bakewell does exist and is the butt end of a bad joke.

 

Following are the spam messages, see for yourselves!

 

 

 

 

 

Dear member,

This email confirms that you have paid orders@dell.com $699.99 USD using PayPal.

This credit card transaction will appear on your bill as "PAYPAL *DELL INC".


Payment Details

 

Purchased From: Dell.Inc

 

Item #

Item Title

Quantity

Price

Subtotal

250016390196

New Dell 6400 e1505 Intel Core Duo 1.66GHz 1GB Laptop

1

$669.95 USD

$669.95 USD

 

Shipping & Handling via USPS First Class Mail to 154XX
(includes any seller handling fees)

$19.16 USD

Shipping Insurance (optional):

--

Sales Tax (6.000% inPA) :

$10.88 USD

Total:

$699.99 USD

 

Note: Thank you!

 


Shipping Information

Shipping Info:

Wayne E Bakewell
16 elm st
Brownsville, PA 15417
United States

Address Status:

:Confirmed

 



If you have questions about the shipping and tracking of your purchased item or service, please contact the seller orders@dell.com.


Do you confirm this transaction?

If this transaction was not made by you please immediately take the following steps:

  • Login to your account by clicking on the link below
  • Provide requested information to ensure you are the owner of the account
  • Find this transaction in HISTORY and click 'Cancel Transaction'

 

CANCEL TRANSACTION!


Thank you for using PayPal!
The PayPal Team

Please do not reply to this email. This mailbox is not monitored and you will not receive a response. For assistance, log in to your PayPal account and choose the Help link located in the top right corner of any PayPal page.

PayPal Email ID PP843

 

eBay sent this message on behalf of an eBay member via My Messages. Responses sent using email will not reach the eBay member.Use the Respond Now button below to respond to this message

 Question from Dell.Inc

About This Member

Dell.Inc ( 22 )

Positive Feedback:

100%

Member Since:

Apr-30-03

Location:

CA, United States

Registered On:

www.ebay.com


Hello,

 

Money was sent today to your paypal account.Please e-mail me as soon as possible because I want to know when I receive my package ASAP.


Thank you,
Dell.Inc

 

Respond to this question in My Messages.

   Respond

 

 

End date:

09-February-07 18:56:12 BST

 

 

 

Marketplace Safety Tip

Always remember to complete your transactions on eBay - it`s the safer way to trade.

Is this message an offer to buy your item directly through email without winning the item on eBay? If so, please help make the eBay marketplace safer by reporting it to us. These "outside of eBay" transactions may be unsafe and are against eBay policy. Learn more about trading safely.

Is this email inappropriate? Does it violate eBay policy? Help protect the community by reporting it.