this post was submitted on 12 Oct 2023
801 points (98.5% liked)

Lemmy.World Announcements

30479 readers
3 users here now

This Community is intended for posts about the Lemmy.world server by the admins.

Follow us for server news 🐘

Outages πŸ”₯

https://status.lemmy.world/

For support with issues at Lemmy.world, go to the Lemmy.world Support community.

Support e-mail

Any support requests are best sent to info@lemmy.world e-mail.

Report contact

Donations πŸ’—

If you would like to make a donation to support the cost of running this platform, please do so at the following donation URLs.

If you can, please use / switch to Ko-Fi, it has the lowest fees for us

Ko-Fi (Donate)

Bunq (Donate)

Open Collective backers and sponsors

Patreon

Join the team

founded 2 years ago
MODERATORS
801
Phishing Mails (lemmy.world)
submitted 2 years ago* (last edited 2 years ago) by lwadmin@lemmy.world to c/lemmyworld@lemmy.world
 

This will be a quick post. We have received a phishing mail to our info@lemmy.world mail address telling that they are "lemmy.world Security Team", telling that they will "disconnect" your account from our instance. This is ofc, not us. Do not fall for it! The attached image is how the mail looks like.

~Lemmy World Team.

top 50 comments
sorted by: hot top controversial new old
[–] NOT_RICK@lemmy.world 97 points 2 years ago (4 children)

Hello, it is I, John Security. Please respond to this message with your name and SSN or the FBI will arrest you for unpaid back taxes. Also, do you have any iTunes or Google play gift cards laying around?

[–] jordanlund@lemmy.world 36 points 2 years ago (1 children)

Don't forget! Lemmy automatically detects and blocks sensitive information so it's totally safe to enter your SSN:

###-##-####

See! It works!

[–] NOT_RICK@lemmy.world 29 points 2 years ago (2 children)
load more comments (1 replies)
[–] trustnoone@lemmy.sdf.org 8 points 2 years ago

Mr McAfee noooo.

[–] Emerald@lemmy.world 7 points 2 years ago

Arnold Michael Scott 419-06-1111

I have $5000 in iTunes and $6,000,000 in Google play gift cards, why do you ask?

load more comments (1 replies)
[–] TheGoldenGod@lemmy.world 82 points 2 years ago (1 children)

Jesus. Phishing emails like this have become so commonplace I actually miss the old Viagra spam emails in l33tspeak.

[–] SpaceNoodle@lemmy.world 34 points 2 years ago (1 children)

My spam folder is still chock full of those.

[–] BeanEater@lemmy.world 16 points 2 years ago (2 children)

When’s the last time you checked your spam folder, 2003? I legitimately haven’t seen the 1337sp34k spam in 20 years. Lately it’s been Africans leaving me money at the embassy that I have to go pick up

[–] echodot@feddit.uk 15 points 2 years ago

For some reason I seem to be getting a lot of spam emails in French. And all of the links are pretending to be French Canadian postal service websites.

I don't know why because I'm neither French nor Canadian. Nor have I ever been to Canada.

load more comments (1 replies)
[–] Annoyed_Crabby@monyet.cc 66 points 2 years ago (2 children)

How do you guys know it's not you guys?

Joke aside, i wonder why they wanna phish for user account in lemmy? Unlike the exploit like a few months ago that specifically target admin, this one seems like it target anyone, it so random.

[–] ChaoticNeutralCzech@feddit.de 25 points 2 years ago (1 children)

To exploit password reuse.

load more comments (1 replies)
[–] echodot@feddit.uk 15 points 2 years ago

Awesome because of the way it's written it's practically guaranteed that admins will know it's a scam.

[–] dependencyInjection@sh.itjust.works 58 points 2 years ago (3 children)

Isn’t it a waste of time trying these scams on lemmy.

I could be wrong here but I would argue the vast majority of users are somewhat tech proficient since it’s not reached mass adoption and the user base is well, just us nerds?

[–] Bitrot@lemmy.sdf.org 53 points 2 years ago (2 children)

Tech folks still fall for phishing. It takes a momentary lapse, failure to caffeinate, it happens.

Lemmy is currently full of newly registered domains with weird suffixes, the kind that traditionally have been a phishing indicator. Lemmy.world is going to be harder to phish than some of the other ones where you have to read closely.

[–] dependencyInjection@sh.itjust.works 13 points 2 years ago (1 children)

I guess hubris can be a factor too.

[–] sudo@lemmy.today 8 points 2 years ago

I'm not "ignoring your emails" and "never responding", I'm just security conscious

load more comments (1 replies)
[–] SgtAStrawberry@lemmy.world 30 points 2 years ago (3 children)

Well one of the best scam hunters on YouTube lost his account to a scam. So not really a waste of time, trying Lemmy.

[–] RubberElectrons@lemmy.world 9 points 2 years ago (3 children)

That sounds so crazy, who was it? What happened?

[–] Xel@mujico.org 6 points 2 years ago (1 children)

I was curious too so I googled it:

Scam baiter Jim Browning bamboozled by scammers into deleting his own YouTube channel

https://www.bitdefender.com/blog/hotforsecurity/scam-baiter-jim-browning-bamboozled-by-scammers-into-deleting-his-own-youtube-channel/

From what I read, some scammer tricked him by impersonating YouTube Support and telling him he would lose all his adsense revenue, which prompted Browning to fall for it.

load more comments (1 replies)
load more comments (2 replies)
load more comments (1 replies)
[–] affiliate@lemmy.world 14 points 2 years ago (1 children)

i click every link that shows up in my email, keeps life interesting

[–] shotgun_crab@lemmy.world 8 points 2 years ago (1 children)
load more comments (1 replies)
[–] FlyingSquid@lemmy.world 46 points 2 years ago (2 children)

I got an almost believable phishing text yesterday from a 'collection agency' that wanted me to download a PDF and go to their website. It looked very official and I'm having some debt issues, but it didn't tell me who it was representing or what I owed or anything like that, so I could tell it was phishing. But a less-savvy person could have totally been fooled by it because it looked very real.

[–] henfredemars@infosec.pub 21 points 2 years ago

I got a spam message that was surprisingly well written until I realized wait a minute, if this is true, why do you need me to tell you who I am?

[–] SnipingNinja@slrpnk.net 16 points 2 years ago

It's especially bad if you are half asleep and panic click on something, especially with session hijacking

[–] Clbull@lemmy.world 37 points 2 years ago (11 children)

Why would they target Lemmy users?

Your typical Lemming (for lack of a better term) is not technologically inept and would generally not fall for a phishing scam. They'd earn a lot more money from targeting Redditors.

[–] Dax87@forum.stellarcastle.net 32 points 2 years ago

software devs and other highly technical IT roles fail phishing tests at my company

[–] callyral@pawb.social 8 points 2 years ago (1 children)

Your typical Lemming (for lack of a better term)

idk i like "lemming"

load more comments (1 replies)
[–] Honytawk@lemmy.zip 7 points 2 years ago

Probably overreach of an automated system

load more comments (7 replies)
[–] affiliate@lemmy.world 35 points 2 years ago

how do you know it’s not from the secret second mod team?

[–] zepheriths@lemmy.world 33 points 2 years ago (1 children)

That's absolutely hilarious. It's like people don't know how Lemmy works

[–] DudeDudenson 13 points 2 years ago

That's exactly how run of the mill phishing scams work. They prey on the people stupid or senile enough to not see anything wrong with this email and avoid wasting time on the people that easily spot the scam

[–] ShitOnABrick@lemmy.world 26 points 2 years ago (1 children)
[–] quinten@lemmy.world 12 points 2 years ago
[–] obinice@lemmy.world 19 points 2 years ago (1 children)

Why are these sorts of things always written by somebody who can clearly barely speak English?

[–] Koen967@feddit.nl 16 points 2 years ago (1 children)

What is unclear? All you have to do is resolve the Lemmy world app on Android and install the errors on your iPhone mail.

[–] echodot@feddit.uk 9 points 2 years ago

Yeah I'm not actually quite sure I understand what the issue they are pretending is.

[–] cole@lemdro.id 17 points 2 years ago (2 children)

I've gotten an email like this before for lemdro.id. I think it's a generic phishing email since the community links look like email addresses (and actually often are)

load more comments (2 replies)
[–] CrayonRosary@lemmy.world 13 points 2 years ago (1 children)

Such good English, too. How could you not trust that?

[–] Papanca@lemmy.world 12 points 2 years ago (1 children)

At least, it doesn't say 'kindly'

load more comments (1 replies)
[–] MicrowaveOvens@lemmy.world 11 points 2 years ago (2 children)

Hey, quick question. I'm assuming these emails are automated, so how do they know your account's email? Is this part of a leak or are they sending email via "send notification to email" option in lemmy?

load more comments (2 replies)
[–] nodimetotie@lemmy.world 9 points 2 years ago

I wonder what they thought of when they wrote "Security Team." I just think of security guards.

[–] aeharding@lemmy.world 7 points 2 years ago

Thanks for the heads up!

load more comments
view more: next β€Ί