redelk

Moderator
Please... speak to the hand.
Posts: 3212
|
posted June 18, 2003 02:10 PM
Best Buy internet scam
Though they score points for it's convincing appearance, this e-mail is pure SCAM!
X-Originating-IP: [204.117.117.23]
From: "Mersey Belle"
To:
Subject: BestBuy Order #1095619. Fraud Alert.
Date: Wed, 18 Jun 2003 20:00:43 -0400 (EST)
Dear customer,
Recently we have received an order made by using your personal credit card information.
This order was made online at our official BestBuy website on 06/17/2003.
Our Fraud Department has some suspicions regarding this order and we need you to visit a special Fraud Department page at our web store where you can confirm or decline this transaction by providing us with the correct information.
This e-mail address has been taken from National Credit Bureau.
Click the link below to visit a special Fraud Department page to resolve the cause of the problem.
http://www.BestBuy.com/fraud_department.html
=====================================================================
ORDER# 1095619 - STATUS: SUSPENDED
ITEMS PURCHASED
=====================================================================
Item No: 73890
CDA-9815 In-Dash CD Player/Ai-Changer Controller
Price: $387.65 Qty: 2 Total: $775.3
----------------------------------------------------------------------------------------------------
The order listed above has not yet been processed.
The reason for the delay in processing your order is:
- UNVERIFIED SHIPPING ADDRESS
- Information provided:
Shipping
41 WINHAM ST
Staten Island, NY 10306
United States
phone# 206-337-9843
In our effort to deter fraudulent transactions, we need your help in providing us with the correct information. Your prompt response is needed to avoid any unauthorized charges to your credit card.
=====================================================================
Click the link below to visit a special Fraud Department page to resolve the cause of the problem.
http://www.BestBuy.com/fraud_department.html
When you click on the link, it takes you to a page that looks and acts like a Best Buy page. Click on the "tag" logo and it will take you to Best Buy's home page. Just like clicking on any of the other hyperlinks will take you to that appropriate page. The only problem is that the page your looking at is not addressed http://www.BestBuy.com/fraud_department.html, but is actually http://www.digitalgamma.com/fraud.html.
The first page looks innocent enough and asks for you name, address an so on. Then it asks for you to "confirm" or "decline" the order in question. What's kinda funny is that when you view the page's source code, the either link will take you to the same "next" page. Here's were the scam goes into full swing. It asks for your SSN, credit card number, mother's maiden name and the "signature" number on the back of the credit card. Things that make you go... Hmmmmmmmmmm.
I reported this e-mail to Best Buy, but I have not heard back from them. When I went to http://www.digitalgamma.com (dropping the fraud.html), I got a "Free Credit Report" website. What is interesting is that when I now try to open the any of the digitalgamma pages, all I get is a 404 page not found.
The actual e-mail came from an AOL e-mail account. Overall, I gottat give it props on being one of the most convincing credit card scams I have ever seen.
____________
There are only three sports: bullfighting, motor racing, and mountaineering; all the rest are merely games.
-Ernest Hemingway
|
harryzx-12

Needs a job
Posts: 3643
|
posted June 18, 2003 04:37 PM
I woulda sent them an email saying.... You need to visit my website.............. www.GoAndFuckYourself.com .........
____________
"Life should NOT be a journey to the grave with the intention of arriving safely in an attractive and well preserved body, but rather to skid in sideways- Body thoroughly used up, totally worn out...Screaming "WOO HOO, What a Ride !!!"
|
frEEk

Administrator
ummm... yeah
Posts: 9660
|
posted June 18, 2003 08:24 PM
dude, u got some kinda virus or bestbuy was hacked. there's no way a page on bestbuy.com would be redirecting to an outside scam page. but there is software (adware does this) that fucks with ur browser. sounds liek u maybe picked up the bug which triggered the email, and the took u to the wrong page. however, i'v search for such a scam/virus and cant find anything. all in all, a very weird thing indeed. be interesting to hear what best buy has to say about it. if u have antivirus software (mcaffee, norton), make sure its updated and do a full scan.
|
redelk

Moderator
Please... speak to the hand.
Posts: 3212
|
posted June 18, 2003 09:38 PM
Updated McAffee and latest version of AdAware. McAffee always active and run AdAware every week. Will run them both tomorrow and see what turns up.
One thing I did not mention was that after a while, if I tried to open the page, instead of 404 Page not found, I got a 403 Forbidden. Both the 404 and 403 pages belonged to a webpage hosting company called HYPERMART.
Now, all of it just plain... gone. Not a trace. No digitalgamma, no hypermart... nothing.
____________
There are only three sports: bullfighting, motor racing, and mountaineering; all the rest are merely games.
-Ernest Hemingway
|
your car is slow

Needs a job
Fuck Nitrous...Got Boost?
Posts: 4089
|
posted June 18, 2003 10:19 PM
You can make a link display as anything you want it to...and have it link anywhere you want it to...its simple html.
Thats why you can put
"Click here" and have it link anywhere you like....no reason "click here" cant read "http://www.bestbuy.com/whatever.html"
____________
Do not taunt happy fun ball!
|
frEEk

Administrator
ummm... yeah
Posts: 9660
|
posted June 19, 2003 01:40 AM
d'oh! it didnt dawn on me till u said it that the email could simply have been written in html, so then yes, they could do that. i guess i just assuemd it was text cause the copy pasted above looks text formatted. prolyl all part of the ruse!
i get nothing when going to digitalgamma.com also. the domain is registered by enom.com, which is a registrar tho, so they prolly registered it on a client's behalf. hmm.. get a different error now (site down/domain not found) than i did before (page cannot be displayed/404). maybe the scam was already busted?
|
slug

Pro
Out in search of my mind...
Posts: 1433
|
posted June 19, 2003 03:13 AM
or they got enough info to be rich and no longer needed/wanted the front....
|
redelk

Moderator
Please... speak to the hand.
Posts: 3212
|
posted June 19, 2003 01:26 PM
Got this from Best Buy today...
Thank you for contacting Best Buy about the e-mail you received . I'm Kevin with Customer Care.
We appreciate your concern about receiving the fraud e-mail.
As of Wednesday, June 18, Best Buy became aware of an unauthorized and deceptive e-mail to consumers nationwide titled "Fraud Alert" claiming to come from the BestBuy.com Fraud Department. This e-mail, which requests personal information (i.e. social security number and credit card information), is not from Best Buy. It was a spam e-mail sent out to many e-mail addresses that were obtained from another source. People who have never used or been in Best Buy have received the e-mail. We strongly recommend that you do not provided any information to the e-mail.
Best Buy is working with appropriate authorities to quickly contain and resolve the situation. If you think you have been affected by this fraudulent spam, please contact your bank or credit card company immediately. The privacy of personal consumer information is of the utmost importance to Best Buy.
Have you seen our "Click to Compare" feature? If you're having trouble deciding between products, this cool tool allows you to line them up side by side and see which one has the bells and whistles you're looking for. Just check the products you are interested and hit "Compare."
We look forward to your next visit to one of our stores or to www.BestBuy.com. Please do not hesitate to contact us with additional questions or concerns.
Best wishes from Best Buy,
Kevin and the Customer Care Team
____________
There are only three sports: bullfighting, motor racing, and mountaineering; all the rest are merely games.
-Ernest Hemingway
|
frEEk

Administrator
ummm... yeah
Posts: 9660
|
posted June 19, 2003 02:06 PM
man, how chintsy that they include a little ad of sorts (the click to compare thing) into an email like this.
|
kawachan
Pro
Posts: 1031
|
posted June 19, 2003 02:16 PM
It was on the radio news this morning too. But...... I'd already heard about it from here first. Isn't that scary?
____________
RED NINJAS RULE!!
|
|
|