Another Phishing Scam – You may be targeted

It has just been brought to my attention that there is a phishing scam going on where people who have websites at 20i.com (I have your a reseller account here) are being sent phishing emails. It works like this:

The hacker has done some research based on name servers and then identified the websites that are hosted at a data centre. They then visit the website and scrape an email from it. They then take a screen shot of a legitimate page from the parent hosting company and attach that into the body of a an email.  

Fortunately none of you receive any emails from 20i.com directly, so hopefully your suspicions will be raised immediately. However it would be possible for me to automate the accounting side of my reseller package and you would receive emails like this. I have just never bothered to set it up. 

In the image below I shown the email which someone had kindly detected and flagged to me. I recognised it immediately as a 20i message. You would never receive one of these unless you had your own account with them. 

I have also placed my cursor over the image so you can see where the link goes to. You can see immediately it does not go to 20i.com, it goes to a server in Spain. 

This is a classic Phishing Scam. What they are after is maybe payment, or a username and password to log into the system. Either way it is a criminal act. 

Ways to detect these types of scams

When you look at the image above, it does look genuine on first glancing at it and not looking closely. It is actually based on a real message that they send out, but I am the only one that might get one, not you. 

There is a glaring error on the first line where they have adapted the message. “…. will expire within the next days.”  The actual number of days is missing. That is so they can create a reusable block of text for anyone. There are also special characters embedded in it which do not display correctly and if you look at the punctuation it is incorrectly spaced as well. 

Bottom line

If you receive a message and it does not look right, it probably is not right. The general give away is not much context and a link, or a lot of credible context, but the link is through an image. You can always find where a link goes to in most mail programs by placing your cursor on top of the link but not clicking.  In this case you would be passing information to a hacked server at http://……clinicapodologiabarcelona.es  (I suspect a foot clinic in Barcelona). 

Invoices relating to your services

You will only ever receive a message directly from me, it will not contain any links for you to login somewhere else. You would never receive a message from the hosting provider I use directly unless you had an account with them. 

Please remain vigilant, and drop me a line if you are unsure about anything, I would rather spend time replying than see anyone caught out, there is a lot of this going on right now. 

 

Wingrove-Services
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

You can adjust all of your cookie settings by navigating the tabs on the left hand side.

My privacy policy can be located here: Wingrove Media Privacy Policy (opens in a new window)

My Cookies Policy can be found here: Wingrove Media Cookies Policy (opens in a new window)