Examples of Scams

CourseVector’s team of security experts receive scams and fake emails almost daily. We know it is becoming more difficult to tell the difference between scams, phishing and legitimate email requests. If you are in doubt about any email that you receive, forward it to support@coursevector.com and one of our technicians would be more than happy to provide you with comments and recommendations.

Examples of Scams, scams, phishing, phished, fake emails, fake email, Scam alert, Hacker attack, web security, phishing scam, Network security, Internet Security

Examples of Scams that we or our clients received . . .

Zelle and Money Transfer Scams

Zelle is a popular peer-to-peer money transfer service. But, scammers quickly took advantage of the ease with which to transfer funds and began scamming people out of large sums of money by posing as the transfer service.

Types of scams involving Zelle include:

Unsolicited emails or text messages asking you to confirm large sums of money being transferred. Your reply leads to a scammers follow-up phone call pretending to be a bank representative leading you through instructions on how to “reverse the transaction.” All the while, you’re just giving the scammer all of your financial information.

zelle scam example
Zelle scam example sent to one of our client.

An email message claiming your bank account has been compromised. Your response again leads to your giving scammers your financial information.

Scammers posing as other companies, like utility companies, threatening disconnection without an immediate transfer of funds.

To protect yourself, don’t respond to these types of unsolicited texts, emails, or phone calls. If you are concerned that these are real, go straight to the source – your financial institution via the phone number on your credit card, the bank’s website, or the utility company’s bill or website. Do not respond via the phone number given by the scammer or give any information over the phone when they’ve called you. It’s too easy for them to spoof a very real-looking phone number. Don’t let them pressure you into a false sense of urgency. Take a breath. Hang up the phone. Collect your thoughts. Then, follow up with the actual company with a clear head.

Don’t give out any codes! Your financial institutions have set up safety measures to protect you. Don’t give out two-factor authentication codes to anyone. Tech support on the part of the bank, utility company, and the like should not need such a code from you.

If you find that you’re a victim of fraud, it may be difficult to retrieve funds if you’ve voluntarily given money to a scammer. But, you should absolutely report it! Here is a list of FAQs from the Consumer Financial Protection Bureau regarding Electronic Financial Fraud: https://www.consumerfinance.gov/compliance/compliance-resources/deposit-accounts-resources/electronic-fund-transfers/electronic-fund-transfers-faqs/

If you are a victim of a P2P payment scam: File a complaint with the Federal Trade Commission or call 1-877-FTC-HELP (382-4357).

Storage Full Scams

In this email scam the cybercriminal will send you an email letting you know that your WordPress site storage is full. They are trying to trick you into clicking on the link they provide to try and infect your device. Here is the example:

Your coursevector.com is almost full

Dear support@coursevector.com,

15153 MB15206 MB
Current sizeMaximum size

You’re almost out of storage and may not receive new emails, You’ve used 99% of the 15 GB of coursevector.com Account storage.
Once you run out of space, you won’t be able to send or receive emails. To prevent any interruption in service,

Go here- https://Webclient.coursevector.com.com/settings/storage/  Click on storage and free up space.

Thanks,

Mail System Administrator

Please disregard this email if you have already taken action.

Geek Squad Scam

Here is another scam where the scammers are trying to get you to call them to get your personal information.

Digital Protection Plan alert 

This is the service alert to update you that your Geek Squad Total Protection pack will expire today and it  will be auto renewed today for next 3 years for 392.95 USD.

The charged amount will be auto deducted from your last saved payment method and  it will reflect in the acc. statement in 24 hours.

Plan summery is below :

Order id : GS-289279822 

Product : Geek Squad Total Protection Plan

Subscription validity : 3 Years

Total Payable Amount : 392.95 USD

Contact us on  +1 – (844) – (858)  –  (5523) if you have any questions regarding this service.

Windows Difender Scam

You read that right. This scam claims to be from Windows Difender (perhaps the long, lost cousin of the actual Windows Defender). Much like the McAfee scam mentioned here, the scammers want you to call them to give them your credit card information.

This email Confirms the Windows Difender,,  subscription:

We value your relationship with us and promise you to deliver best protection for your computer or laptop. Your renewal with your Technical Solution Team is successfully done ,,and amount of $279.99 will be deducted for your registered account details on file. You can enjoy the hassle free protection for the next 3 years….

The subscription period will automatically renew unless you turn it off on later than 24 hours before the end of the current period. To cancel auto-renewal or manage your subscription, click below and sign in..


How to cancel Windows Difender Subscription::

Haven’t placed this order?

We request you to contact our help desk as soon as possible to avoid the charge 

+ 916-888-9504

want to cancel ? Please contact to our support team +1 916-888-9504

Sincerely.
The Windows Support……

McAfee Payment Scam

We have received several email scams claiming to be from McAfee.

If you receive an email from someone claiming to be McAfee Security, it may be a scam. This email tried to get us to call a number, claiming that they were McAfee (and GeekSquad). If we didn’t respond within 24 hours, we were not allowed to dispute the “automatic” charge.

Thank You for your payment. Your account has been debited with $398.99 for the Auto Renewable plan of your McAfee family. The charges might reflect within a few moments to 24 hours. For any query or assistance please reach out to us @ +1 (903) 403-1710 / +1 (903) 403-1710.

Invoice Number # UDN254678Y

We are an associate of the Geek Squad.

With the email above, There is no charge. These scammers are hoping you’ll call them and give them your credit card information over the phone.

Here is a screenshot of the second email received days apart.

mcafee scam email

The second email had an attachment that would likely install malware onto the computer on which it was downloaded.

KuCoin Bitcoin Exchange Scam

There was no paypal purchase through our account for bitcoin on this date.

kucoin scam
Admin Relay E-mail Upgrade!

We received this email telling us that our “security info is no longer functional.” Again, we urge you to know your vendors. We host our own email, therefore we know this was a hoax. If you do receive an email like this, we recommend writing a new email to your email provider. Do not reply to this email or click the links.


email upgrade
“FedEx” Email Scam

This “FedEx” email was forwarded to us by a client. If you ever receive an email like this, call FedEx from a number on their website. Do not click any links, and certainly don’t download and unzip the attached file. Doing so will most certainly install malware onto your device.

Examples of Scams -
Hosting Renewal Scam

We cannot express enough how important it is to KNOW YOUR VENDORS! One of our hosting clients received a notice via USPS that they needed to renew their hosting with Sunshine Biz Services, Inc. We host this client’s site, not Sunshine Biz Services.

The wording states “We would like you to renew your web hosting with Sunshine Biz Services.” “Hosting your website with us will ensure your website remains active, that you retain exclusive rights to it on the Web, and now is the time to transfer your web hosting from your current provider to Sunshine Biz Services. Failure to renew your web hosting by the expiration date may result in website outages and a loss of your online identity making it difficult for your customers to reach you on the Web.”

Even thought it looks like a bill, look closely at the highlighted area that states “THIS IS A SOLICITATION”.

website hosting solicitation

Your Training Expires Soon

Scammers are spoofing a noted security awareness company. They send emails explaining that your security awareness training expires soon. Rather than linking to current training, the email links take users to a phishing website to steal their Microsoft Outlook or other credentials. KnowBe4, the spoofed company, posted about the scam on their blog. This scam “should serve as a reminder that no online company or brand is immune or impervious to being spoofed as part of a malicious email campaign. Online brands, sites, and services are all vulnerable to such attacks, and your users should be completely aware of this phenomenon.”

If you use KnowBe4 for security awareness training, do not click on email links. Rather, navigate to their website directly from their URL typed into a browser.

We found your parcel

Scammers have been sending emails and text messages claiming to have found a parcel from a month or more ago. The link in the message takes you to a site to steal money, your identity, or both.

If you are missing a package, please do not reply to or click on links within these messages. Instead, reach out to the seller or the service the seller used to ship the item. It is also important to remember that most of the big-name shippers (like UPS) do not require personal information to receive packages.

Windows Defender Updates

Windows users beware. Windows Defender does not require any paid update or renewals. If you see a message like the one below, it is a scam.

Thanks for Auto Renewal

This is your receipt – make sure to print or save a copy for your records.

Prerequisite:  You are receiving this notice because you enrolled in Windows Automaticrenewal service, and your subscription has been auto-renewed automatically. However,if you don’t want to proceed with the service and want a refund please contact our billinghelpline number [ 855- 700- 0591 ]  

Product ID:  US3456723

Product Name:  Defender Firewall

Auto Renewal Amount: $499.00 USD (for one year)   

TERMS & CONDITIONS: The payment is due. You are getting this notice because you registered with windows securities, and your subscripton has been Auto Renewed. However, if you don’t wish to proced with the service or want a refund of this amount, kindly contact our billing helpline number [855-700- 0591]              Microsoft Support – 1861 Belmont St, Paris, TX 75460 USA

“Secure DNS” Scam

This “Secure DNS scam was more believable than most. The email claimed to come from WordPress itself, and said that DNS security features would soon be added for our domain. DNSSEC for the server names that your hosting provider looks after for you certainly sounds like a good idea, and it isn’t something you should do on your own. When you click through, you are asked to enter your usual WordPress password. Don’t! The scammers are trying to gain access to your website. More information about this scam can be found on the Naked Security Website

Examples of Scams -

See the Naked Security article for more images related to this scam!

COVID-19 Phishing Scams

DocuSign Phishing Scam

Attackers are using the current COVID-19 worry to exploid unsuspecting victims. In this email, the scammer uses a very convincing Docusign facade, but the links in the document sends the user through a maze of links to a screen collecting the users DocuSign credentials and other sensitive information. More information about this scam can be found on the TechRepublic website.

Examples of Scams -
RoundCube Email Scam

Here is an example of an email phishing scam. RoundCube is the webmail software CourseVector uses for client emails. One of our clients received this email, but it’s not from RoundCube. Note that the “from” email address is a Japanese domain. (You can tell from the .jp extension.) Also if you roll over the link, it goes to a German domain. (Notice the .de extension.) There are also grammatical errors. Do not reply to the email. Do not click on the link. Permanently delete the email from you computer and the server. If you are still unsure if there is an email issue, please email support@coursevector.com instead. We’re happy to help.

Examples of Scams -
Email Gift Card Scam

DO NOT BUY GIFT CARDS FOR SOMEONE IN RESPONSE TO AN EMAIL REQUEST! Here is a recent example of an email one of our clients received requesting gift cards.

“Please I’d like to ask you for a favor, i need to get a gift card but I can’t do this now because I’m not feeling well. I’ve got the flu and I tried purchasing online but unfortunately no luck with that. Can you get it from any store around you? I’ll pay back as soon as I get better.”

A more in-depth explanation of this scam can be found in our Email Gift Card Scam article.

Email Add Recovery Number

Another dangerous scam warns users that if they do not add a recover phone number to their account all of their data will be deleted. Many companies use two-factor authentication as an added layer of security. Legitimate companies will not threaten you with data deletion, though.

If you do decide to click through to add an account recovery number from the bogus email, it will take you to a fake login screen. They will then collect your credentials for use at a later date.

Read more about this email scam and see images of the scam here.

Manage Your Undelivered Email Scam

This Outlook scam sends an email claiming that you must decide what to do with undelivered mail. The subject line might be something to the effect of: “Notifications | undelivered emails to your inbox” and pretends to be a list of email being held on the server for you. You must click through and decide what to do with each message in the list. But, when you click a message, you are taken to a bogus login screen. Your credentials are saved by the scammer to be used at a later date.

With this scam, the fake login screen is hosted on the scammer’s server. The URL is obviously not a Microsoft URL.

For more information, or to see examples of this type of email, click through to the Bleeping Computer article.

Email Hacked Scam

There has been a sharp increase in the number of “your email has been hacked” scams circulating lately. These emails are a scam. No one has control of your email or computer. Should you receive one of these, delete it. Do not reply. Do not pay.

Examples of Scams -
Domain Name Scams


Many domain name registrars send out notices, and bills, even though you do not have your domain name registered with them. Worse, they tend to charge more money, and, sometimes they can tie up your domain name to the point where you end up losing it or paying an extraordinary sum of money to get it back.

For most clients, your web site included a domain name and is included and paid for with your annual fee. If you get a domain name renewal notice or bill, please do not renew or pay without checking with contacting us. We will be happy to assist you in whatever way we can.

For the record, a domain name should only cost approximately $12. Normally, the companies that send out notices charge significantly more.

Following are examples of domain renewal notices that are not legitimate. We will be posting more as we can.

GoDaddy

Examples of Scams -

Notice that when you mouse-over the payment icon, the link does NOT go to GoDaddy, or even to PayPal.

Service Blue

Service Blue domain name scam

Web Domain Listings

Web Domain Listings domain name scam

Domain Listings

Domain Listings domain name scam

Domain Registry of America

Domain Registry of America domain name scam

No Company Identified

no company listed for this domain name scam
Email Sign Up Form

Scammers have started filling out request forms on legitimate websites with legitimate email addresses (yours). Because the website is legitimate and the email address is legitimate, these bogus requests are able to bypass spam filters.

If a confirmation email contains a link in the “from” field, it’s likely phishing. An example would be “Dear CourseVector [malicious link]”.

If you receive an email from a website that you did not sign up for – stay safe. Do NOT click on any links in the confirmation email. Instead, type in the website name yourself to verify its existence and then contact them and let them know that you didn’t fill out their form.

Amazon Email Scams

It is commonplace to see several emails in your inbox from Amazon. However, make sure that they are legitimate before clicking on them!

Examples of Scams -

Amazon explains that fraudulent emails often contain:

  • An order confirmation for an item you didn’t purchase or an attachment to an order confirmationNote: Go to Your Orders to see if there is an order that matches the details in the email. If it doesn’t match an order in Your Account, the message isn’t from Amazon.
  • Requests for your Amazon.com username and/or password, or other personal information
  • Requests to update payment informationNote: Go to Your Account and select Payment options. If you aren’t prompted to update your payment method on that screen, the message isn’t from Amazon.
  • Links to websites that look like Amazon.com, but aren’t Amazon
  • Attachments or prompts to install software on your computer
  • Typos or grammatical errors
  • Forged email addresses to make it look like the email is coming from Amazon.com

You can actually report spoofed Amazon phishing emails to Amazon

Job Interview Scam

One place people may not expect to be scammed is during a job interview. However, it happens! Prospective employers are not going to ask you to download anything special for the interview process. If you are asked to download something during a job interview, don’t – especially if you are using a government or employer computer for the interview!

Interview Scam

Receiving Files in a Word Document
Examples of Scams -

As if it’s not difficult enough to tell the difference between a legitimate email and a phishing email, cyber criminals will often steal logos from real companies to make their scams look real. How do you keep yourself safe? Companies like Norton and TripAdvisor won’t send you videos or files via a Word Document. Most companies want you on their site or sent standard alert boxes. These types of message will not be sent in a Word Document. If you receive one, delete it immediately.

Examples of Scams -

More information

Team of IT Service Providers

One of our staff recently received an email similar to this. Notice that the grammar is pretty bad and the name of the company is too generic to be legitimate:

All staffs;

We are migrating all personnel email accounts to Staff Outlook 2018 desktop e-mail and as such, all active staff members must check and log in for the upgrade and migration to take effect now. This is done to improve security and efficiency due to recent spam received.

Please all staff 
CLICK HERE  <link removed> Switch to Outlook Webmail 2018 for staff

Regards,
Team of IT Service Providers,
Outlook Services for Staff and Internet Services
Copyright 2018

Email From Someone Familiar
Examples of Scams -

Sometimes an email comes from someone familiar with an attachment. That doesn’t always mean it is safe. If you are ever concerned with a link from a familiar email address, you can do either or both of the following:

  1. Open it in a sandbox to make sure it does not contain a payload.  If you are not able to do this, ask IT for help.
  2. Follow up with the sending firm (which WAS legit in this case) rather than clicking on anything in the Email.
Enabling Macros
Examples of Scams -

Enabling macros through an application such as Microsoft Word can spread a virus. When you enable something like macros, it allows for the language of the application (in this case Microsoft Word) to reach out to the internet and install a virus. Keep these things in mind the next time you are prompted to enable macros on Microsoft Word or any application for that matter.

WordPress Database Upgrade Needed
Examples of Scams -

Emails are being circulated telling customers that their WordPress installations need to be upgraded. As with many scam emails, there are many grammatical errors. The “Click here” box takes the user to a phishing page, asking for WordPress credentials.

Examples of Scams -
Website Suspension Alert
Examples of Scams -


We received this email from “cPanel” stating that our website was going to be shut down. Now, we know that our website is not going to be shut down because we host and control it. But, should you ever receive a message like this, here are some things to watch out for.

Examples of Scams -
cPanel site deletion message

If we host your website, website suspension emails are going to come from CourseVector, not cPanel. But, if you see this and feel panicked, here are some things to look at. They make it seen pretty official with real screenshots of cPanel. However, this is not a screenshot of YOUR cPanel account! If you look closely, it’s a dummy account. Additionally the links are fishy. They do not go to a CourseVector website, which they should since we are the host. When in doubt, contact your website host before clicking on anything!

PayPal Account Access Suspended

One of our team members received this email, stating that he needed to provide all of his account details on their secure server. There are several ways to tell that this is a scam. The grammar and punctuation are horrible. Additionally, the “secure link” does not go to a PayPal website. But, if you’re in doubt, “To protect yourself, always log in to your PayPal account to confirm the information you received in an email. You can find all your transactions in your Activity page. For any cases such as buyer complaints or limitations, you can find them in the Resolution Center.” (PayPal)

Examples of Scams -

Search

Sign Up for Our Newsletter

Thank you for your interest in our newsletter! Fill in the form below to receive periodic updates on internet and website security, free cybersecurity posters, WordPress news, and more!

"*" indicates required fields

Name*

Your privacy is important to us. We do not share your information with anyone. You can opt out of our newsletter at any time.

Stay up to date with technology, scams, WordPress, and more. Follow CourseVector on Facebook today!