PermaLink What price identity?
The Beeb carries a report entitled "UK identities sold for £80 online".

Internet fraudsters sell complete financial identities for just £80, according to an online safety group.

The details packaged and sold online include names, addresses, passport numbers and confidential financial data such as credit card numbers.

With six out of 10 people now managing finances online, experts say the public needs to do more to prevent e-crime.

So, how are these Internet fraudsters obtaining complete financial identities in order to offer them for sale?

A spam trapped by an anti-phishing rule a short while ago demonstrates just one of many possible avenues.

Dear Real Name,

PayPal Resolution Center: Your account is limited.

Why is my account access limited?

As part of our security measures, we regularly screen activity in the PayPal system. During a recent screening, we noticed an issue regarding your account:

Our system detected unusual number of invalid logging attempts [1] on you account from these Blacklist [2] ip address.

(Your case ID for this reason is PP-xxxxxxx.)

How can I restore my account access?

For your protection, we have limited access to your account until additional security measures can be completed. We apologize for any inconvenience this may cause. In order to assist us with this security measure, we ask that you send us a photocopy or scan of one document from each of the three categories listed below and return them via email to [redacted@email.address] :
  • A clear copy of your Passport, Photographic Drivers Licence or I.D. Card (both sides).

  • A clear copy of both sides of the credit/debit card on your paypal profile.

  • A clear copy of a recent bank statement or utility bill on which your name and address are clearly visible - less than 3 months old.
Completing all of the checklist items will automatically restore your account access [3]

Thank you for using PayPal! [4]
The PayPal an eBay Company [5]

-------------------------------------

Please do not reply to this email. This mailbox is not monitored and you will not receive a response [6]. For assistance, log in to your PayPal account and click the Help link located in the top right corner of any PayPal page.

PayPal Email ID PP-xxxxxxx.

This is clearly bogus, although intriguingly the miscreant here does already know his mark's real name and does not address him simply as Dear Valued Customer or Dear email address.


  1. Invalid logging attempts? Somebody tried to cut down the wrong tree?
  2. Does the sender mean blacklisted? In any case, he fails to list any IP addresses, blacklisted or otherwise.
  3. Completing all of the checklist items may have altogether different consequences.
  4. That word of thanks clearly requires the emphasis implied by the exclamation mark, but why only one?
  5. The PayPal?
  6. The email address which sent the email is of course not the one to which the mark is directed to forward his scanned documents. It is a real PayPal address which may be why replies are undesirable, at least from the phisherman's point of view.



Category: Spam miscellany
Technorati:

Comments :
None yet...
Unable to post a comment? Please read this for a possible explanation...
Add Manual Trackback
Please enter the details of the trackback post. Your trackback will not appear on the site until it has been verified. This won't be immediate, as trackbacks are validated on a scheduled basis. Be patient.











Search
Hot Categories
Monthly Archive
Links
Contact Me
Subscribe
Subscribe to articlesArticles

Subscribe to commentsComments

Visitor Locations
Hosted by