Most of us have received emails like the one below at one time or another:
PayPal
Report
Invoice no: 5JAE 60E0 URXR VR7G
Dear Customer,
Thank you for using PayPal.
Your account has been charged with $481.88 USD and will be going to deduct from your account within 24 hours. If you did not recognize this transaction or want to cancel this charge.
Please contact Toll Free Customer Support Number: +1(801)-882-2752
Invoice No : 876-42154522
Order No : CL7-4512212-54451
Invoice Amount : $481.88 USD
Invoice Date : 30 November,2022
Date : 01 December,2022
Payment Method : PayPal.
Or like this:
Rеdіlеѵеrу rеquеst.
Yоur pаrсеl hаs аrrіѵеd аt оur lосаl pоst-оffісе
Wе аrе mіssіng іnfоrmаtіоns іn оrdеr tо соmplеtе уоur dеlіѵеrу
Рlеаsе сlісk thе lіnk bеlоw tо соrrесt уоur аdrеss аnd pау thе fееs оf (3 USD) fоr thе nеw dеlіѵеrу аttеmpt іt wіll аrrіѵе іn nеxt 2 dауs.
You know you haven’t purchased anything and you don’t think you have any packages due but you have that urge to check messages like these out.
Don’t.
Both are scams and if you examine the messages closely you can spot the giveaways. In both, there are errors in grammar. In the first, “…and will be going to decuct from your account…” is fractured English and would never be sent out by a reputable company like PayPal. It was obviously composed by someone in a place well out of the reach of law enforcement authorities in this country.
The second one, you will notice, says, “Your parcel has arrived at our local post-office…” Notice that the message does not describe which post office – just “our local post-office.” Whose local? Where is that “local post-office”? Also, “post office” should not be hyphonated, a glaring error that points to an overseas hacker who is not quite as familiar with our language as he should be. Plus, he was a bit careless in misspelling “Redelivery.”
So, what’s the purpose of these scams? After all, the latter message only says that I owe $3 to get the mysterious package (that I never ordered) delivered “in next 2 days” (again, notice the incorrect grammar). I mean, what’s three bucks? No one scams for three bucks, right? Wrong
You are either supposed to call the number in the first message or click on a link provided (but not included here) in the second message. In either case, you will doubtless be asked to provide personal information, such as your PayPal account number, credit care information, or banking account information. You may even be asked to provide social security numbers (to ensure proper identification, of course) as well as other personal information.
If you do that, they gotcha and you will see your bank account eddy away like the last water down a bathtub drain. Or you may see the balance on your credit card balance explode like you just signed on one of those hidden Donald Trump contribution online solicitations.
Which brings up a third scam that was just attempted on yours truly but for the quick action of some alert employee of Hancock-Whitney Bank who thwarted the scammer’s efforts.
I received a phone call from a Hancock employee who informed me that an effort had been made to transfer funds from my LouisianaVoice checking account into a Huntington Bank account.
First of all, I have never and will never authorize any electronic payment from that account. I’m old school: I write the old paper checks for all transactions from that account as well as our personal checking account.
Second, and this theory was supported by the Hancock representative as well: there most probably is no such animal as a Huntington Bank; it’s quite likely some untracable sham paper conduit through which money is skimmed from countless accounts like mine worldwide. Had it not been for that quick-acting Hancock risk management employee, $1,000 would have floated away, most likely to some overseas recipient.
As it was, the attempt was intercepted and my bank account frozen so that nothing can be deposited or withdrawn – not even by me. Now, I have to go in to the bank, close out that account and set up a brand-new account. But, it’s a minor inconvenience in order to keep from finding my account balance reduced by a thousand bucks.
The thing that most surprised me, however, was the amount they attempted to grab. Normally, these hackers go for smaller amounts in the hopes that (a) it won’t attract the bank’s attention (as it did in this case) and (b) the account holder won’t miss an insignificant amount like say, $50 or $75 or even $100 which, repeated in tens of thousands of other accounts across the map, can produce a substantial windfall for cyber thieves. In my case, they got greedy and their efforts failed.
Obviously, I’m certainly grateful to the folks at Hancock.
At the same time, I feel it’s important to use thie near-miss of a lesson to offer words of warning to those who have worked hard their entire lives to accumulate a few dollars to be ever-vigilant for unscrupulous hackers who want to sit at a computer and rob you of your life’s savings.
The elderly are especially vulnerable targets of these crooks, so it’s critical that when messages like the two at the beginning of this post pop up in your email, DO NOT OPEN them. Instead, just DELETE! You have absolutely nothing to gain and everything to lose by opening the messages and especially by responding to them. (I don’t like typing in all caps because it’s the email equivalent to shouting, but this is important so I’ll repeat: BE CAREFUL!)
So many unsuspecting locals have their personal data leaked on the dark web, it is frightening. Several large companies in the Baton Rouge area have been breached and provide little in the way of detail as to the exact amount of data stolen. Two examples are Baton Rouge General (6/22) and Lake Charles Medical Center (11/22). Each was targeted and breached by the Hive Ransomware Group with gigabytes and in some cases terabytes of data leaked. Another leak in the last year was Spine Diagnostic Center in Baton Rouge. That leak contained copies of driver’s licenses, credit cards, medications, and insurance information. Larger breaches can have several million identities leaked at once. If you haven’t checked the website, haveibeenpwned.com, you should. Search by your email address or name to get a list of publicized and confirmed breaches. Real dark web or deep web leaks take a bit more skill to locate and can be risky if you aren’t using Tor and obfuscating your location. Reach out to someone in IT and preferably in IT Security to have them look on ransomware leak sites for your data. Never, ever, reuse a password on multiple sites and always protect your accounts with multifactor authentication.
I often get examples of the first one from “someone at Amazon”. I also receive quite a few of your second example. One day my wife received one from the Amazon hacker. She calls and the next thing I hear is she giving up her social security number and other important information. I told her to hang up, it’s a scam.
I have been hacked twice (I think) and both times I got my money back after a few days. I had built up a little in $credits or points. I now continue my retirement goal of spending every penny I can get my hands on. I double dare any hacker to attempt to get in my wife’s separate property account. She still uses paper and like her mother, she found an error of $15.00 back in the 70’s. Thanks and great article. ron thompson
I have gotten the usual scam emails & calls but this one is new and quite scary! I have a call blocker gadget for my landline, never answer any call that doesn’t leave a message that is legit, (my answering machine is on always), and never answer my cell unless I know who it is. Same for bogus texts. I pray my credit union has a good identity theft/security team. I feel confident they do. Thanks for this info and everyone stay safe and constantly check your stuff!
Excellent article and so true!! I worry for those who fall prey to these scammers who are at the very bottom of the cesspool as a human. There are a few great scambaiters out there that do good work and the FBI also has a unit, we just do not have enough to protect everyone.
Keep up the articles of this type, one of your best!