Security Information

Wells Fargo Report Phishing Scam


First off I should explain what phishing is. Phishing is basically the act of tricking a victim into divulging information. It involves the receiving of an email message with a link to a website where the victim would enter personal information. In this particular scam, you get an email from "Personal Banking: personalbanking@wellsfargo.com" stating that there may have been some unauthorized access to your account and that you should click the link and enter your account and verify some information. When you click the link you are taken to a site which looks identical to the Wells Fargo site.

If you look at the HTML code of the site, you'll notice that they are almost identical. One thing about this scam which was somewhat surprising is that the message made it past my G-mail spam filter. This is slightly different to scams I have seen before in that they don't ask you to reply to this email with your account number like most others, and they don't ask for passwords or anything like that. They simply request that you log in, as you normally do, which would not raise the eyebrow of normal users. On a closer inspection of the site you will notice that the forms submit the data entered (user name and password) to some foreign script and not to Well Fargo. Most probably, the scammer is having all the usernames and passwords emailed to him. After submission of your information the site responds that your password is incorrect. Here an unsuspecting victim would assume that this was because of the supposed unauthorized access mentioned in the email.

If you try to submit information a few more times, it takes you to another Wells Fargo look-alike page called "Online Banking Verification". Here they ask for SSN number, your ATM card number, the expiration date, the pin number and the CVV2# (4 digit verification). With the ATM information the scammer could max out your debit card. With all the rest of the information he has gathered it would not be at all difficult to call up Wells Fargo and basically take over your account. He could change billing addresses, get checks for you account, and simply wipe it out.

How to spot scams like this

Scams like these are usually easy to spot, but this one in particular was a bit tricky, however there are some basic methods you can use to spot these types of scams.

First of all, check the link. Although it looks like the link is going to Wells Fargo's website, if you let the mouse hover over the link for a while and look in the status bar, you will get the real address of the link. In this case the scammer used just an IP address of his domain or machine. This, however, can be overridden on the internet (if the scammer changes the status bar) and sometimes even in your email, depending on what your security settings are.

Check the address bar. In this case, the address bar reported that the website was also from the scammer's IP address. Simply put, it did not say www.wellsfargo.com. Very seldom would a scammer be able to fake this. They may, however, employ other tricks like buying a domain name with a slight spelling difference that the user might not notice or by simply loading the link in a new window and hiding the address bar altogether.

Lastly, the only full proof method to avoid becoming a victim to a scam like this is to simply call in and verify the information over the phone. Please note; do not use a phone number in the email if one is given. Open up your phone book and locate the number for your firm and ask them about it.

Just remember, if it looks funny and feels funny, it's probably a scam. Do not ever reply to such email messages for personal information as sensitive as account information and SSN.

Below is a copy of the email message for your review and amusement. The link is active, however DO NOT ENTER ANY PERSONAL INFORMATION INTO THESE FORMS. THIS IS NOT WELLSFARO'S SITE.

Kevin. A. Lloyd.

From: Personal Banking < personalbanking@wellsfargo.com >
To: me@me.com
Date: Jun 2, 2005 2:22 PM
Subject: Security Notice #291240 Wells Fargo Internet Banking account
Update Necesary!

Dear Member,
We recently reviewed your account, and suspect that your Wells Fargo Internet Banking account may have been accessed by an unauthorized third party. Protecting the security of your acount and of the Wells Fargo network is our primary concern. Therefore, as a preventative measure, we have temporarily limited access to sensitive account features. To restore your account access, please take the following steps to ensure that your account has not been compromised:

1. Login to your Wells Fargo Internet Banking account. In case you are not enrolled for Internet Banking, you will have to use your Social Security Number as both your Personal ID and Password and fill in all the required information, including your name and account number. 2. Review your recent account history for any unauthorized withdrawls or deposits, and check your account profile to make sure not changes have been made. If any unauthorized activity has taken p! la ce on your account, report this to Wells Fargo staff immediately.

To get started, please click on the link below:

https://online.wellsfargo.com/signon?LOB=CONS

We apologize for any inconvenience this may cause, and appreciate your assistance in helping us maintain the integrity of the entire Wells Fargo system. Thank you for your prompt attention to this matter.

Sincerly,
The Wells Fargo Team

Kevin A. Lloyd:

Just launched a website, http://www.DeleteMySpam.com/, dedicated to helping to eliminate the spam crisis.


MORE RESOURCES:

Tri State Defender

Brenner: Social Security off limits to most creditors
Newsday, NY - 4 hours ago
If I elect to start to receive my Social Security benefit, will I get the check, or will the Internal Revenue Service take it to pay down my debt? ...
For Your Benefit Still time to file for economic stimulus check Honolulu Star-Bulletin
About 1100 in Bay County haven't filed for federal stimulus checks The Bay City Times - MLive.com
Thousands may lose out on stimulus checks Salt Lake Tribune
Concord Monitor - Ventura County Star
all 211 news articles


Think Progress

Time works against candidates on Social Security, Medicare fixes
The Miami Herald, FL - 6 hours ago
By DAVID LIGHTMAN AND KEVIN G. HALL WASHINGTON -- Social Security and Medicare long have been considered the nation's fiscal time bombs, and the ticking is ...
Obama offers the better plan on Social Security Pueblo Chieftain
Elders' self-interest is to vote for Obama Newsday
Miller: Questions on retirement for the debate Daily News Tribune
Vineland Daily Journal - DesMoinesRegister.com
all 36 news articles


ABC News

Are 401(k)s Still Viable
Washington Post, United States - 11 hours ago
Until three decades ago, Social Security and pensions, formally known as defined-benefit plans, were the main sources of retirement income. ...
House Democrats contemplate abolishing 401(k) tax breaks InvestmentNews
Americans Look to Next Administration for Help in Achieving a ... MarketWatch
401(k) fallout Reforms are needed to ensure retirement security Sarasota Herald-Tribune
Wall Street Journal - Online Athens
all 631 news articles


Booming global demand for security products prompts Global Sources ...
MarketWatch - 9 hours ago
Security Products Pavilion at China Sourcing Fair: Electronics & Components to expand into new show at AsiaWorld-Expo Oct. 12-15, ...


Boston Globe

Taleban killed in Afghan battles
BBC News, UK - 6 hours ago
Dozens of Taleban militants have been killed by security forces in fighting in southern Afghanistan, according to Afghan and British officials. ...
NATO Air Strikes Kill 64 Militants in Southern Afghanistan Bloomberg
At least 60 militants killed in Afghan strikes Radio Australia
Afghan battles kill more than 100 CNN International
Javno.hr - PRESS TV
all 406 news articles


Backlog jam grows for Social Security
Minneapolis Star Tribune, MN - 12 hours ago
He waited about two years for his Social Security disability benefit claim to be resolved. His wife, Linda, returned to work full time to see them through. ...


Canada.com

Security tight in riot-torn Acre
BBC News, UK - 3 hours ago
Overnight Jewish and Arab demonstrators threw stones at each other, before being dispersed by the security forces. On Sunday the normally busy Old City was ...
Israel Beef Up Security After Clashes In Acre AHN
Israel increases security after clashes CCTV
Arab-Jewish clashes prompt high security SABC News
Israel News Agency - Ynetnews
all 913 news articles


Wired News

US Security Agency operators eavesdrop on Americans abroad
Press Trust of India, India - Oct 9, 2008
New York, Oct 10 (PTI) The US' National Security Agency's (NSA) intercept operators spent their time eavesdropping on saucy conversations between Americans ...
As feared, government has listened in on Americans The Wichita Eagle
No harm, no law broken? Augusta Chronicle
NSA SPIED ON RED CROSS AND INNOCENT AMERICANS American Chronicle
Wired News - CNET News
all 146 news articles


Boston Globe

New voters boxed out already
Denver Post, CO - 7 hours ago
Would-be voters who used their Social Security numbers as identification, yet didn't check a box stating that they don't have a Colorado drivers license or ...
Voter registration deadline nears Statesman Journal
Forum: This year's soccer moms Traverse City Record Eagle
BRIAN DICKERSON Do allegations of massive voter purge hold water? Detroit Free Press
The Associated Press - New York Times
all 691 news articles


The Associated Press

Envoy: US-Iraq Security Pact Pertains to Iraqis
Fars News Agency, Iran - 23 hours ago
Speaking in an interview by the Los Angeles Times, he noted the security pact is one-sided and emphasized the US should respect Iraq's internal affairs. ...
Iran opposes US-Iraq security deal The Associated Press
Wars without end Cobar Age
US-Iraq security pact a "pure Iraqi issue": Iran's Ambassador Payvand
Tehran Times - International Herald Tribune
all 317 news articles

Security - Google News

home | site map
© 2006