<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet type="text/xsl" href="atom.xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <id>https://secure-techie.com/blog/</id>
    <title>Secure Techie</title>
    <updated>2025-09-11T11:10:00.000Z</updated>
    <generator>https://github.com/jpmonette/feed</generator>
    <link rel="alternate" href="https://secure-techie.com/blog/"/>
    <subtitle>Stay informed about the latest scams, phishing attempts, and fraud — learn how to protect yourself online.</subtitle>
    <icon>https://secure-techie.com/img/favicon.svg</icon>
    <rights>Copyright © 2026 Dewiride Technologies Private Limited.</rights>
    <entry>
        <title type="html"><![CDATA[Fraud: LOAN / INVESTMENT OFFER ( from US$ 10 Million to US$ 10 Billion for your project)]]></title>
        <id>https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/</id>
        <link href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/"/>
        <updated>2025-09-11T11:10:00.000Z</updated>
        <summary type="html"><![CDATA[LOAN / INVESTMENT OFFER ( from US$ 10 Million to US$ 10 Billion for your project) | Leonard Bernstein Global Investment Scam]]></summary>
        <content type="html"><![CDATA[<p>LOAN / INVESTMENT OFFER ( from US$ 10 Million to US$ 10 Billion for your project) | Leonard Bernstein Global Investment Scam</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p><strong>From</strong>: Leonard Bernstein <code>&amp;lt;info@investmentbank.com&amp;gt;</code><br>
<strong>Subject</strong>: LOAN / INVESTMENT OFFER ( from US$ 10 Million to US$ 10 Billion for your project)</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-body">Email Body<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#email-body" class="hash-link" aria-label="Direct link to Email Body" title="Direct link to Email Body" translate="no">​</a></h3>
<p>Attn: Sir/Madam,</p>
<p>I am contacting you with a keen interest to consider a possible collaboration through investments in viable projects in your country. By way of introduction, I'm a financial consultant based in the United States.</p>
<p>I am solely responsible for investing a client's funds through a diversified investment strategy, targeting positive capital returns through a global expansive portfolio.</p>
<p>Although, my client's initial interest was to invest in the United Arab Emirates and Qatar economy, as he is originally from that region, specifically from the Saudi Arabia, but because of his embattled political background in his home country of Saudi Arabia, he decided to export his investment outside The Gulf Cooperation Council (GCC) region, hence his interest to seek possible collaboration with a capable private individual or firm globally.</p>
<p>His plan is to focus more on U.S. and Canadian markets as well as emerging markets in Europe, Brazil, Mexico, China, Japan, Bahamas, and Indonesia (etc).</p>
<p>He intends to invest in areas of agriculture, mining, manufacturing, construction, Real estates, trading etc. He is ready to invest in project developments and business ventures that can generate at least 3% Annual Return on Investment (ROI).</p>
<p>He will be willing to go on an Investment/Loan Funding Program with you in any viable project initiative within your scope of funding. If interested please write to me directly for possible business collaboration and further details.</p>
<p>I am looking forward to hearing from you</p>
<p>Yours Sincerely,<br>
<!-- -->Mr. Leonard Bernstein</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<p>This message is a textbook example of a large-capital advance-fee / investment facilitation scam. It mixes wealth-flight narrative, generic institution branding, unrealistic capital access, and a deliberately low sophistication threshold (only 3% ROI) to lure targets into prolonged engagement that leads to staged fee extraction or money laundering risk.</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="1-generic--unverifiable-sender-identity">1. Generic &amp; Unverifiable Sender Identity<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#1-generic--unverifiable-sender-identity" class="hash-link" aria-label="Direct link to 1. Generic &amp; Unverifiable Sender Identity" title="Direct link to 1. Generic &amp; Unverifiable Sender Identity" translate="no">​</a></h3>
<ul>
<li class=""><strong>Email Address</strong>: <code>info@investmentbank.com</code> uses a highly generic domain. Reputable global investment banks use distinctive, trademarked domains; a plain descriptive domain is suspicious (often parked or newly registered).</li>
<li class=""><strong>No Regulatory Disclosures</strong>: Missing SEC / FINRA / FCA style disclaimers, CRD numbers, IARD references, Form ADV, or jurisdictional licensing statements that are standard in legitimate outbound institutional communication.</li>
<li class=""><strong>No Physical Coordinates</strong>: No office address, phone, encrypted channel, or professional signature block.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="2-unrealistic-funding-range">2. Unrealistic Funding Range<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#2-unrealistic-funding-range" class="hash-link" aria-label="Direct link to 2. Unrealistic Funding Range" title="Direct link to 2. Unrealistic Funding Range" translate="no">​</a></h3>
<ul>
<li class="">Claims access to <strong>US$10 Million to US$10 Billion</strong> — a span (x1000) that no genuine mandate letter would present without segmentation, fund vehicle type, governance constraints, or deployment schedule.</li>
<li class="">Large institutional capital allocators require KYC/AML, project due diligence, risk modeling, and staged tranches—not blind introductions via cold email.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="3-vague-role--authority">3. Vague Role &amp; Authority<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#3-vague-role--authority" class="hash-link" aria-label="Direct link to 3. Vague Role &amp; Authority" title="Direct link to 3. Vague Role &amp; Authority" translate="no">​</a></h3>
<ul>
<li class="">States: <em>“I am solely responsible for investing a client's funds”</em> — in institutional practice, discretionary authority is governed by mandates, investment committees, custodians, and compliance controls.</li>
<li class="">No mention of fund type (family office, private equity, sovereign wealth, structured credit, mezzanine, infrastructure fund, etc.).</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="4-geopolitical-narrative-manipulation">4. Geopolitical Narrative Manipulation<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#4-geopolitical-narrative-manipulation" class="hash-link" aria-label="Direct link to 4. Geopolitical Narrative Manipulation" title="Direct link to 4. Geopolitical Narrative Manipulation" translate="no">​</a></h3>
<ul>
<li class="">A <strong>politically exposed person (PEP)</strong> angle (“embattled political background”) is used to justify capital relocation—classic laundering / sanctions-evasion pretext.</li>
<li class="">Reference to GCC exit and multi-region diversification is broad, non-technical, and plausibly deniable.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="5-scattergun-target-market-list">5. Scattergun Target Market List<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#5-scattergun-target-market-list" class="hash-link" aria-label="Direct link to 5. Scattergun Target Market List" title="Direct link to 5. Scattergun Target Market List" translate="no">​</a></h3>
<ul>
<li class="">Listing many jurisdictions (US, Canada, Europe, Brazil, Mexico, China, Japan, Bahamas, Indonesia) signals copy‑paste template — real allocators narrow focus by sector, geography, risk class, currency, and regulatory regime.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="6-overly-broad-sector-coverage">6. Overly Broad Sector Coverage<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#6-overly-broad-sector-coverage" class="hash-link" aria-label="Direct link to 6. Overly Broad Sector Coverage" title="Direct link to 6. Overly Broad Sector Coverage" translate="no">​</a></h3>
<ul>
<li class="">Agriculture, mining, manufacturing, construction, real estate, trading, etc. — impossible for a single discretionary portfolio without internal specialization. Aimed at making any recipient think they “fit.”</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="7-implausible-roi-threshold">7. Implausible ROI Threshold<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#7-implausible-roi-threshold" class="hash-link" aria-label="Direct link to 7. Implausible ROI Threshold" title="Direct link to 7. Implausible ROI Threshold" translate="no">​</a></h3>
<ul>
<li class=""><strong>“At least 3% Annual ROI”</strong> is absurdly low for private direct project finance and contradicts the claimed sophistication of a multi-billion mandate. This attempts to appear conservative to reduce skepticism.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="8-absence-of-standard-deal-artifacts">8. Absence of Standard Deal Artifacts<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#8-absence-of-standard-deal-artifacts" class="hash-link" aria-label="Direct link to 8. Absence of Standard Deal Artifacts" title="Direct link to 8. Absence of Standard Deal Artifacts" translate="no">​</a></h3>
<ul>
<li class="">No NDA reference, no teaser deck, no mandate letter, no RFP, no fund structure (LP/GP), no escrow instructions, no custodian name, no compliance contact.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="9-psychological-engineering">9. Psychological Engineering<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#9-psychological-engineering" class="hash-link" aria-label="Direct link to 9. Psychological Engineering" title="Direct link to 9. Psychological Engineering" translate="no">​</a></h3>
<ul>
<li class=""><strong>Authority Illusion</strong>: Claims control over massive funds.</li>
<li class=""><strong>Inclusivity Hook</strong>: “Capable private individual or firm globally” — extremely unscreened.</li>
<li class=""><strong>Urgency by Ambiguity</strong>: Avoids timelines so prospect imagines scarcity/competition.</li>
<li class=""><strong>Greed &amp; Low Barrier</strong>: “Any viable project” + low ROI make engagement feel easy.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="10-likely-next-steps-if-you-respond">10. Likely Next Steps if You Respond<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#10-likely-next-steps-if-you-respond" class="hash-link" aria-label="Direct link to 10. Likely Next Steps if You Respond" title="Direct link to 10. Likely Next Steps if You Respond" translate="no">​</a></h3>
<p>Scammers typically escalate with:</p>
<ol>
<li class="">Fake proof of funds (screenshots, banking letters, forged SWIFT docs)</li>
<li class="">Request for project executive summary to harvest intel</li>
<li class="">Introduction of intermediary “attorney / compliance officer”</li>
<li class="">Demand for upfront fees: due diligence, retainer, “tax clearance”, anti-corruption certification, unlocking escrow, insurance bond, notarization</li>
<li class="">Push for sensitive KYC docs (passport, corporate registrations) — identity theft risk</li>
<li class="">Pressure to open a new “correspondent” or “escrow” account under their guidance</li>
</ol>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="11-potential-money-laundering-risk">11. Potential Money Laundering Risk<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#11-potential-money-laundering-risk" class="hash-link" aria-label="Direct link to 11. Potential Money Laundering Risk" title="Direct link to 11. Potential Money Laundering Risk" translate="no">​</a></h3>
<ul>
<li class="">You may be groomed as an unwitting <strong>money mule / layering facilitator</strong> if you agree to “temporarily receive and forward” funds.</li>
<li class="">Accepting unexplained inbound international transfers can trigger AML reporting obligations, account freezes, or legal exposure.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="12-linguistic--structural-indicators">12. Linguistic &amp; Structural Indicators<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#12-linguistic--structural-indicators" class="hash-link" aria-label="Direct link to 12. Linguistic &amp; Structural Indicators" title="Direct link to 12. Linguistic &amp; Structural Indicators" translate="no">​</a></h3>
<ul>
<li class="">Mixed capitalization (“Real estates”), awkward redundancy, and generic corporate phrasing without technical financial lexicon (no IRR, hurdle rate, risk banding, liquidity horizon, governance framework).</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="how-this-scam-typically-progresses">How This Scam Typically Progresses<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#how-this-scam-typically-progresses" class="hash-link" aria-label="Direct link to How This Scam Typically Progresses" title="Direct link to How This Scam Typically Progresses" translate="no">​</a></h2>
<table><thead><tr><th>Phase</th><th>Tactic</th><th>Objective</th></tr></thead><tbody><tr><td>1. Hook</td><td>Flattering unsolicited mandate</td><td>Elicit reply / validate active inbox</td></tr><tr><td>2. Credential Theater</td><td>Fake fund sheets, POF, LOI</td><td>Build perceived legitimacy</td></tr><tr><td>3. Administrative Gate</td><td>“Compliance / clearance” forms</td><td>Justify fee request</td></tr><tr><td>4. Fee Extraction</td><td>Due diligence / insurance / tax</td><td>Monetize victim repeatedly</td></tr><tr><td>5. Escalation</td><td>Bigger tranches, urgency</td><td>Deepen sunk-cost commitment</td></tr><tr><td>6. Termination</td><td>Silence or new alias</td><td>Exit after max extraction</td></tr></tbody></table>
<p>If you resist fee payment, they may pivot to: money laundering proposal, crypto wallet “liquidity bridging,” or sale of fake SBLC / BG instruments.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="recommended-actions">Recommended Actions<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#recommended-actions" class="hash-link" aria-label="Direct link to Recommended Actions" title="Direct link to Recommended Actions" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="immediate">Immediate<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#immediate" class="hash-link" aria-label="Direct link to Immediate" title="Direct link to Immediate" translate="no">​</a></h3>
<ul>
<li class="">Do <strong>not</strong> respond.</li>
<li class="">Mark as phishing / spam in your mail client (improves future filtering).</li>
<li class="">Do <strong>not</strong> forward internally without a security warning context.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="verification-if-curious--perform-passively-only">Verification (If Curious — Perform Passively Only)<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#verification-if-curious--perform-passively-only" class="hash-link" aria-label="Direct link to Verification (If Curious — Perform Passively Only)" title="Direct link to Verification (If Curious — Perform Passively Only)" translate="no">​</a></h3>
<ul>
<li class="">Passive WHOIS lookup of the domain <code>investmentbank.com</code> (age, registrant, hosting). Newly registered or privacy-shielded = higher risk.</li>
<li class="">Search the exact subject line — often appears in scam reporting forums.</li>
<li class="">Check if parts of the text appear online (string search) to confirm template reuse.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="do-not-provide">Do NOT Provide<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#do-not-provide" class="hash-link" aria-label="Direct link to Do NOT Provide" title="Direct link to Do NOT Provide" translate="no">​</a></h3>
<ul>
<li class="">Passports, PAN, corporate certificates, bank comfort letters, solvency declarations.</li>
<li class="">Upfront “retainer,” “escrow activation,” or “anti-terror compliance” payments.</li>
<li class="">Consent to open joint accounts or crypto wallets under remote instruction.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="if-you-already-replied">If You Already Replied<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#if-you-already-replied" class="hash-link" aria-label="Direct link to If You Already Replied" title="Direct link to If You Already Replied" translate="no">​</a></h3>
<ul>
<li class="">Cease further communication.</li>
<li class="">Monitor for follow-up social engineering attempts (LinkedIn, WhatsApp, Telegram).</li>
<li class="">Flag any unusual inbound transfer attempts to your bank’s fraud team.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="reporting-optional">Reporting (Optional)<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#reporting-optional" class="hash-link" aria-label="Direct link to Reporting (Optional)" title="Direct link to Reporting (Optional)" translate="no">​</a></h3>
<ul>
<li class="">National cybercrime portal / CERT in your jurisdiction.</li>
<li class="">Anti-fraud intelligence communities / ISACs if corporate environment.</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="educational-notes">Educational Notes<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#educational-notes" class="hash-link" aria-label="Direct link to Educational Notes" title="Direct link to Educational Notes" translate="no">​</a></h2>
<table><thead><tr><th>Legitimate Investment Outreach</th><th>This Scam</th></tr></thead><tbody><tr><td>Specific sector thesis</td><td>"Any viable project"</td></tr><tr><td>Regulated entity disclosure</td><td>None</td></tr><tr><td>Defined ticket size &amp; tranche</td><td>US$10M–US$10B span</td></tr><tr><td>Professional signature &amp; contacts</td><td>Generic name only</td></tr><tr><td>NDA / mandate before details</td><td>Immediate open solicitation</td></tr><tr><td>Clear ROI framework / risk band</td><td>Arbitrary 3% floor</td></tr></tbody></table>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="defensive-checklist-quick-scan">Defensive Checklist (Quick Scan)<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#defensive-checklist-quick-scan" class="hash-link" aria-label="Direct link to Defensive Checklist (Quick Scan)" title="Direct link to Defensive Checklist (Quick Scan)" translate="no">​</a></h2>
<table><thead><tr><th>Indicator</th><th>Present</th></tr></thead><tbody><tr><td>Generic salutation (Sir/Madam)</td><td>Yes</td></tr><tr><td>Massive capital claim</td><td>Yes</td></tr><tr><td>Politically exposed backstory</td><td>Yes</td></tr><tr><td>Vague sectors / geographies</td><td>Yes</td></tr><tr><td>Minimal ROI ask</td><td>Yes</td></tr><tr><td>No compliance identifiers</td><td>Yes</td></tr><tr><td>Seeks “collaboration” pre-due diligence</td><td>Yes</td></tr></tbody></table>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion">Conclusion<a href="https://secure-techie.com/blog/fraud-loan-investment-offer-from-usd-10-million-to-usd-10-billion-for-your-project/#conclusion" class="hash-link" aria-label="Direct link to Conclusion" title="Direct link to Conclusion" translate="no">​</a></h2>
<p>This email is a high-level <em>advance-fee / investment mandate</em> scam framework engineered to capture ambitious entrepreneurs, SMEs, or intermediaries seeking large capital injections. Its persuasive levers: oversized capital capacity, extremely low performance threshold, geopolitical displacement story, and artificially simplified onboarding. Every structural element substitutes <em>verifiability</em> with <em>narrative volume</em>. Treat it as malicious social engineering and do not engage.</p>
<p><strong>Principle</strong>: Legitimate large-capital introductions arrive through verifiable networks (licensed advisors, investment banks, fund managers) — not cold generic emails with inflated mandate ranges.</p>
<p>Stay vigilant; archive for training / awareness if useful.</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Fraud" term="Fraud"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Fraud: Pharmaceutical Supply Partnership | Maj. Austin Lake American Army Ukraine]]></title>
        <id>https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/</id>
        <link href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/"/>
        <updated>2025-09-09T10:30:00.000Z</updated>
        <summary type="html"><![CDATA[My name is Maj. Austin Lake, an American Army, currently in Ukrain for peacekeeping duty. I wish to introduce to you a business of supplying Pharmaceutical active ingredients from India to an American company.]]></summary>
        <content type="html"><![CDATA[<p>My name is Maj. Austin Lake, an American Army, currently in Ukrain for peacekeeping duty. I wish to introduce to you a business of supplying Pharmaceutical active ingredients from India to an American company.</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p>from: Maj. Austin Lake <code>&amp;lt;motilalpritam22@whirlpool.com&amp;gt;</code><br>
<!-- -->reply-to: "Maj. Austin Lake" <code>&amp;lt;austinlake6611@gmail.com&amp;gt;</code><br>
<!-- -->date: Sep 6, 2025, 12:16 AM<br>
<!-- -->subject: Awaiting your response<br>
<!-- -->mailed-by: <code>whirlpool.com</code></p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-body">Email Body<a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#email-body" class="hash-link" aria-label="Direct link to Email Body" title="Direct link to Email Body" translate="no">​</a></h3>
<p>Hello</p>
<p>My name is Maj. Austin Lake, an American Army, currently in Ukrain for peacekeeping duty. I wish to introduce to you a business of supplying Pharmaceutical active ingredients from India to an American company, I have done this business with an Indian partner until I lost him.</p>
<p>There is an active pharma ingredient oil, which I have supplied to the American company from India through an Indian partner. Right now I am in Ukrain for a peacekeeping mission, so I cannot execute the business by myself hence I'm seeking your partnership, the Director of the American company has asked me for the contact of the India dealer of the Pharma oil to enable them to contact them for the supply.</p>
<p>But, I do not wish to give the American company management, the contact of the Indian dealer of the pharma oil, because of the profit we made in the business last time. We made good profit and it was too encouraging to give away, I intended to present you as the Indian Dealer of the Pharma oil to the American company (That means that you will stand as a middle person between the American company and original Indian Dealer) so that the American company will not know the source and real cost of the oil.</p>
<p>The Original Indian dealer is selling the oil at the cost of 4,370USD Per Liter, while the American company bought the oil at the cost of 13,980USD Per Liter. The American Company bought 1500 Liters then. We will get the oil from the original Indian dealer and supply it to the American company and make our profit.</p>
<p>We will get the oil from the Original dealer and supply it to the American Company then we (you and I) will share the profit made on the basis of 60% for you and 40% for me.</p>
<p>Your role must be played perfectly and the least I will expect from you is betrayal. Again, I don’t want the American company to know the real cost or source of the oil, likewise I don't want the Indian dealer to have the contact of the American company.</p>
<p>Kindly get back to me if you are capable of handling the business with me.</p>
<p>Awaiting your response<br>
<!-- -->Maj. Austin Lake</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<p>This email exhibits numerous characteristics of an advanced advance-fee fraud (419 scam) that combines military impersonation with business opportunity deception. Below is a detailed analysis of the suspicious elements:</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="1-email-authentication-and-domain-inconsistencies"><strong>1. Email Authentication and Domain Inconsistencies</strong><a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#1-email-authentication-and-domain-inconsistencies" class="hash-link" aria-label="Direct link to 1-email-authentication-and-domain-inconsistencies" title="Direct link to 1-email-authentication-and-domain-inconsistencies" translate="no">​</a></h3>
<ul>
<li class=""><strong>Corporate Email vs. Military Identity</strong>: The sender claims to be a U.S. Army Major but uses a Whirlpool Corporation email address (<code>motilalpritam22@whirlpool.com</code>). This is completely inappropriate - military personnel use <code>.mil</code> domains for official communications, not corporate domains.</li>
<li class=""><strong>Indian Name in Corporate Email</strong>: The email username "motilalpritam22" appears to be an Indian name, which contradicts the claimed American military identity.</li>
<li class=""><strong>Mismatched Reply-To Address</strong>: The reply-to address uses Gmail (<code>austinlake6611@gmail.com</code>), indicating the scammer wants responses to go to a different, unverified account.</li>
<li class=""><strong>Domain Spoofing</strong>: Using a legitimate company's domain (whirlpool.com) to send fraudulent emails suggests email spoofing or compromised accounts.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="2-military-impersonation-red-flags"><strong>2. Military Impersonation Red Flags</strong><a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#2-military-impersonation-red-flags" class="hash-link" aria-label="Direct link to 2-military-impersonation-red-flags" title="Direct link to 2-military-impersonation-red-flags" translate="no">​</a></h3>
<ul>
<li class=""><strong>Incorrect Military Terminology</strong>: Real U.S. Army personnel would write "U.S. Army" not "American Army." The phrasing sounds foreign and unprofessional.</li>
<li class=""><strong>Geographic Inconsistencies</strong>: Writing "Ukrain" instead of "Ukraine" shows poor attention to detail uncommon in military communications.</li>
<li class=""><strong>Inappropriate Business Activities</strong>: Active military personnel are subject to strict regulations regarding private business activities, especially international pharmaceutical trade.</li>
<li class=""><strong>No Military Email Domain</strong>: Legitimate military communications use <code>.mil</code> domains with proper rank and unit identifications.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="3-business-proposal-inconsistencies"><strong>3. Business Proposal Inconsistencies</strong><a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#3-business-proposal-inconsistencies" class="hash-link" aria-label="Direct link to 3-business-proposal-inconsistencies" title="Direct link to 3-business-proposal-inconsistencies" translate="no">​</a></h3>
<ul>
<li class=""><strong>Unrealistic Profit Margins</strong>: The claimed price difference (4,370 USD to 13,980 USD per liter) represents over 200% markup, which is unrealistic in legitimate pharmaceutical supply chains.</li>
<li class=""><strong>Vague Product Description</strong>: "Active pharma ingredient oil" is deliberately vague - legitimate pharmaceutical ingredients have specific names, classifications, and regulatory requirements.</li>
<li class=""><strong>Unethical Business Model</strong>: The proposal explicitly involves deception ("I don't want the American company to know the real cost or source"), which legitimate businesses would never propose.</li>
<li class=""><strong>No Company Details</strong>: No specific names of the supposed American company or Indian dealer are provided, making verification impossible.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="4-psychological-manipulation-tactics"><strong>4. Psychological Manipulation Tactics</strong><a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#4-psychological-manipulation-tactics" class="hash-link" aria-label="Direct link to 4-psychological-manipulation-tactics" title="Direct link to 4-psychological-manipulation-tactics" translate="no">​</a></h3>
<ul>
<li class=""><strong>Emotional Appeal</strong>: Claims about losing a previous Indian partner are designed to evoke sympathy and create urgency.</li>
<li class=""><strong>Greed Exploitation</strong>: The promise of substantial profits (60% share) targets the recipient's desire for easy money.</li>
<li class=""><strong>Trust Building</strong>: Offering the larger share (60%) to the victim is a common tactic to appear generous and trustworthy.</li>
<li class=""><strong>Exclusivity</strong>: Emphasizing secrecy and the need to keep information from other parties creates a false sense of being chosen for a special opportunity.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="5-language-and-communication-issues"><strong>5. Language and Communication Issues</strong><a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#5-language-and-communication-issues" class="hash-link" aria-label="Direct link to 5-language-and-communication-issues" title="Direct link to 5-language-and-communication-issues" translate="no">​</a></h3>
<ul>
<li class=""><strong>Poor Grammar</strong>: Multiple errors including "an American Army," "Ukrain," and awkward phrasing throughout.</li>
<li class=""><strong>Inconsistent Tone</strong>: The communication style doesn't match professional military or business correspondence standards.</li>
<li class=""><strong>Repetitive Content</strong>: The email repeats the same concepts multiple times, indicating copy-paste from template scam emails.</li>
<li class=""><strong>Unprofessional Closing</strong>: Real military personnel would include proper rank, unit, and contact information in their signatures.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="6-legal-and-regulatory-violations"><strong>6. Legal and Regulatory Violations</strong><a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#6-legal-and-regulatory-violations" class="hash-link" aria-label="Direct link to 6-legal-and-regulatory-violations" title="Direct link to 6-legal-and-regulatory-violations" translate="no">​</a></h3>
<ul>
<li class=""><strong>Military Ethics Violations</strong>: The proposed activities would violate numerous military codes of conduct and conflict of interest regulations.</li>
<li class=""><strong>Pharmaceutical Regulations</strong>: International pharmaceutical trade requires extensive licensing, documentation, and regulatory compliance not mentioned in the proposal.</li>
<li class=""><strong>Deceptive Practices</strong>: The business model explicitly involves deception, which violates international trade laws and business ethics.</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="how-this-scam-typically-progresses"><strong>How This Scam Typically Progresses</strong><a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#how-this-scam-typically-progresses" class="hash-link" aria-label="Direct link to how-this-scam-typically-progresses" title="Direct link to how-this-scam-typically-progresses" translate="no">​</a></h2>
<p>If victims respond positively to this email, scammers typically follow this pattern:</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="phase-1-trust-building"><strong>Phase 1: Trust Building</strong><a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#phase-1-trust-building" class="hash-link" aria-label="Direct link to phase-1-trust-building" title="Direct link to phase-1-trust-building" translate="no">​</a></h3>
<ul>
<li class="">Provide fake military documentation or identification</li>
<li class="">Share fabricated business contracts or purchase orders</li>
<li class="">Create false urgency about military deployment schedules</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="phase-2-initial-commitment"><strong>Phase 2: Initial Commitment</strong><a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#phase-2-initial-commitment" class="hash-link" aria-label="Direct link to phase-2-initial-commitment" title="Direct link to phase-2-initial-commitment" translate="no">​</a></h3>
<ul>
<li class="">Request detailed business information and capabilities</li>
<li class="">Ask for company registration documents or licenses</li>
<li class="">Gradually increase the sense of mutual trust and partnership</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="phase-3-financial-extraction"><strong>Phase 3: Financial Extraction</strong><a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#phase-3-financial-extraction" class="hash-link" aria-label="Direct link to phase-3-financial-extraction" title="Direct link to phase-3-financial-extraction" translate="no">​</a></h3>
<ul>
<li class="">Request upfront payments for "sample procurement"</li>
<li class="">Demand fees for "export licenses" or "regulatory approvals"</li>
<li class="">Ask for "security deposits" to demonstrate commitment</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="phase-4-escalation"><strong>Phase 4: Escalation</strong><a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#phase-4-escalation" class="hash-link" aria-label="Direct link to phase-4-escalation" title="Direct link to phase-4-escalation" translate="no">​</a></h3>
<ul>
<li class="">Create fake emergencies requiring additional payments</li>
<li class="">Use sunk cost fallacy to extract more money</li>
<li class="">Eventually disappear once maximum extraction is achieved</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion-and-recommendations"><strong>Conclusion and Recommendations</strong><a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#conclusion-and-recommendations" class="hash-link" aria-label="Direct link to conclusion-and-recommendations" title="Direct link to conclusion-and-recommendations" translate="no">​</a></h2>
<p>This email represents a sophisticated military impersonation fraud combined with a fake business opportunity scam. The numerous inconsistencies and red flags make it clear this is not from any legitimate U.S. military personnel.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="immediate-actions"><strong>Immediate Actions:</strong><a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#immediate-actions" class="hash-link" aria-label="Direct link to immediate-actions" title="Direct link to immediate-actions" translate="no">​</a></h3>
<ul>
<li class=""><strong>Do Not Respond</strong>: Never reply to this email or provide any information</li>
<li class=""><strong>Report Military Impersonation</strong>: Forward to the FBI's Internet Crime Complaint Center (IC3) as military impersonation is a federal crime</li>
<li class=""><strong>Mark as Phishing</strong>: Use your email provider's reporting mechanisms</li>
<li class=""><strong>Delete Permanently</strong>: Remove the email to prevent accidental future interaction</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="verification-steps"><strong>Verification Steps:</strong><a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#verification-steps" class="hash-link" aria-label="Direct link to verification-steps" title="Direct link to verification-steps" translate="no">​</a></h3>
<ul>
<li class=""><strong>Military Verification</strong>: Real U.S. military personnel can be verified through official Department of Defense channels</li>
<li class=""><strong>Business Legitimacy</strong>: Legitimate pharmaceutical businesses are registered with appropriate regulatory bodies</li>
<li class=""><strong>Domain Verification</strong>: Check if whirlpool.com has been compromised by contacting them directly through official channels</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="educational-measures"><strong>Educational Measures:</strong><a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#educational-measures" class="hash-link" aria-label="Direct link to educational-measures" title="Direct link to educational-measures" translate="no">​</a></h3>
<ul>
<li class=""><strong>Share Awareness</strong>: Inform business contacts about military impersonation scams</li>
<li class=""><strong>Report to Authorities</strong>: File reports with local cybercrime units and international fraud reporting systems</li>
<li class=""><strong>Stay Informed</strong>: Learn about advance-fee fraud tactics and military impersonation schemes</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-protection-tips"><strong>Additional Protection Tips</strong><a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#additional-protection-tips" class="hash-link" aria-label="Direct link to additional-protection-tips" title="Direct link to additional-protection-tips" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="military-communication-verification"><strong>Military Communication Verification:</strong><a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#military-communication-verification" class="hash-link" aria-label="Direct link to military-communication-verification" title="Direct link to military-communication-verification" translate="no">​</a></h3>
<ul>
<li class="">Authentic military emails use <code>.mil</code> domains exclusively</li>
<li class="">Military personnel include proper rank, unit, and contact information</li>
<li class="">Official military business follows established protocols and channels</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="business-opportunity-verification"><strong>Business Opportunity Verification:</strong><a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#business-opportunity-verification" class="hash-link" aria-label="Direct link to business-opportunity-verification" title="Direct link to business-opportunity-verification" translate="no">​</a></h3>
<ul>
<li class="">Legitimate international pharmaceutical trade requires extensive documentation</li>
<li class="">Real business partnerships involve verifiable companies and references</li>
<li class="">Ethical businesses never propose deceptive practices</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="general-fraud-protection"><strong>General Fraud Protection:</strong><a href="https://secure-techie.com/blog/fraud-pharmaceutical-supply-maj-austin-lake-american-army-ukraine/#general-fraud-protection" class="hash-link" aria-label="Direct link to general-fraud-protection" title="Direct link to general-fraud-protection" translate="no">​</a></h3>
<ul>
<li class="">Be skeptical of unsolicited high-profit opportunities</li>
<li class="">Verify all claims through independent, official sources</li>
<li class="">Never send money or personal information based on email requests alone</li>
</ul>
<p><strong>Remember</strong>: This scam combines multiple deception layers (military authority, business opportunity, pharmaceutical trade) to appear legitimate. The sophisticated approach makes it particularly dangerous, but the numerous inconsistencies reveal its fraudulent nature. Always verify military and business claims through official channels before engaging in any communication or business activities.</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Fraud" term="Fraud"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Scam: Payment Notification — United Nations Compensation (Lance Gooden)]]></title>
        <id>https://secure-techie.com/blog/scam-payment-notification-united-nations-compensation-lance-gooden/</id>
        <link href="https://secure-techie.com/blog/scam-payment-notification-united-nations-compensation-lance-gooden/"/>
        <updated>2025-08-10T12:00:00.000Z</updated>
        <summary type="html"><![CDATA[Advance‑fee scam impersonating the United Nations Payment Reconciliation Office promising a $5,000,000 compensation and urging a reply.]]></summary>
        <content type="html"><![CDATA[<p>Advance‑fee scam impersonating the United Nations Payment Reconciliation Office promising a $5,000,000 compensation and urging a reply.</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/scam-payment-notification-united-nations-compensation-lance-gooden/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p>From: Lance Gooden <code>&amp;lt;lance.gooden0920366@hotmail.com&amp;gt;</code><br>
<!-- -->Subject: Payment Notification</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-body">Email Body<a href="https://secure-techie.com/blog/scam-payment-notification-united-nations-compensation-lance-gooden/#email-body" class="hash-link" aria-label="Direct link to Email Body" title="Direct link to Email Body" translate="no">​</a></h3>
<p>UNITED NATIONS PAYMENT RECONCILIATION OFFICE<br>
<!-- -->AMERICAN QUARTERS, TEXAS USA</p>
<p>Payment Notification</p>
<p>Attention: Beneficiary</p>
<p>This is to bring to your notice that the United Nations Secretary General Antynio Guterres has deliberated with the World Bank Group President Ajay Banga for a compensation payment of Five Million US Dollars (US$5,000,000.00) to scammed victims from Asia, America, Africa and Europe.</p>
<p>Meanwhile, your name and email address has emerged as one of the lucky beneficiaries. To enable us start processing your payment, you are hereby advised to get back to us as quickly as you receive this email for quick release of your $5,000,000.00 to you through our paying bank.</p>
<p>Yours faithfully,</p>
<p>Lance Gooden<br>
<!-- -->Representative Coordinator | <code>lance.gooden@un-payment.com</code><br>
<!-- -->Texas Office, USA</p>
<p>NOTE: If you receive this message in your SPAM/JUNK folder, that is because of the restrictions implemented by your Internet Service Provider, we urge you to treat it genuinely.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/scam-payment-notification-united-nations-compensation-lance-gooden/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<p>This message is a classic advance‑fee/419 scam. Key indicators:</p>
<ol>
<li class=""><strong>Unverifiable sender</strong>: The email is sent from a free Hotmail address (<code>lance.gooden0920366@hotmail.com</code>) and not an official UN domain like <code>@un.org</code>. The signature references <code>un-payment.com</code>, which is unrelated to the UN and is an attempt to appear legitimate.</li>
<li class=""><strong>Impersonation of high‑profile officials</strong>: Mentions the UN Secretary‑General and the World Bank President to gain trust. Legitimate communications from such bodies do not arrive unsolicited and never come from free email accounts.</li>
<li class=""><strong>Too‑good‑to‑be‑true payout</strong>: Promises a massive "compensation" of US$5,000,000. Scammers often dangle large sums to lure victims into paying “processing” or “release” fees later.</li>
<li class=""><strong>Generic greeting and lack of specifics</strong>: No personal details, case ID, or verification steps—just “Attention: Beneficiary.”</li>
<li class=""><strong>Urgent call to reply</strong>: Pushes you to "get back to us as quickly as you receive this email"—a pressure tactic to bypass rational checks.</li>
<li class=""><strong>Inconsistent and dubious details</strong>: A non‑existent "United Nations Payment Reconciliation Office" and a vague address ("American Quarters, Texas"). The language contains grammatical issues and misspellings (e.g., "Antynio").</li>
<li class=""><strong>Security banner warning</strong>: Your email client explicitly says it couldn’t verify the sender—another strong indicator of fraud.</li>
</ol>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-you-should-do">What You Should Do<a href="https://secure-techie.com/blog/scam-payment-notification-united-nations-compensation-lance-gooden/#what-you-should-do" class="hash-link" aria-label="Direct link to What You Should Do" title="Direct link to What You Should Do" translate="no">​</a></h3>
<ol>
<li class=""><strong>Do not reply or click anything</strong> in the message. Do not provide personal info, IDs, bank details, or pay any “fees.”</li>
<li class=""><strong>Report as phishing/spam</strong> in your email client to help block future attempts.</li>
<li class=""><strong>Block the sender</strong> and delete the email. If you engaged already, stop contact immediately and monitor accounts for unusual activity.</li>
<li class=""><strong>Verify independently</strong>: Real UN/World Bank communications use official channels and domains (e.g., <code>un.org</code>, <code>worldbank.org</code>) and do not offer unsolicited compensation.</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion">Conclusion<a href="https://secure-techie.com/blog/scam-payment-notification-united-nations-compensation-lance-gooden/#conclusion" class="hash-link" aria-label="Direct link to Conclusion" title="Direct link to Conclusion" translate="no">​</a></h2>
<p>This “Payment Notification” is a fraudulent advance‑fee scheme that impersonates the United Nations. The free email address, unrealistic payout, urgency, and unverifiable details make it clearly malicious. Ignore, report, and delete the email.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="contribution">Contribution<a href="https://secure-techie.com/blog/scam-payment-notification-united-nations-compensation-lance-gooden/#contribution" class="hash-link" aria-label="Direct link to Contribution" title="Direct link to Contribution" translate="no">​</a></h2>
<p>This scam email was shared with us by one of our readers. Special thanks to <strong>KV Reddy</strong> for helping raise awareness and protect our community from online fraud. If you have a suspicious email or scam to report, feel free to contribute and help others stay safe!</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Scam" term="Scam"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Scam: न्यायालय आदेश चेतावनी⚖️ | Ritambra Prakash ACP Cyber Crime Coordination Centre]]></title>
        <id>https://secure-techie.com/blog/scam-court-order-warning-ritambra-prakash-acp-cyber-crime-coordination-centre/</id>
        <link href="https://secure-techie.com/blog/scam-court-order-warning-ritambra-prakash-acp-cyber-crime-coordination-centre/"/>
        <updated>2025-07-25T16:00:00.000Z</updated>
        <summary type="html"><![CDATA[There is an alleged court order against your Internet IP traffic by the Central Bureau of Investigation, Department of Research and Analysis Wing.]]></summary>
        <content type="html"><![CDATA[<p>There is an alleged court order against your Internet IP traffic by the Central Bureau of Investigation, Department of Research and Analysis Wing.</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/scam-court-order-warning-ritambra-prakash-acp-cyber-crime-coordination-centre/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p>from: Cyber Crime Coordination Centre <code>&amp;lt;intellgencbureu@gmail.com&amp;gt;</code><br>
<!-- -->reply-to: <code>intellgencbureu@gmail.com</code><br>
<!-- -->to:<br>
<!-- -->bcc: <code>&amp;lt;My Email&amp;gt;</code><br>
<!-- -->date: Jul 23, 2025, 3:55 AM<br>
<!-- -->subject: न्यायालय आदेश चेतावनी⚖️<br>
<!-- -->mailed-by: gmail.com<br>
<!-- -->signed-by: gmail.com</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-body">Email Body<a href="https://secure-techie.com/blog/scam-court-order-warning-ritambra-prakash-acp-cyber-crime-coordination-centre/#email-body" class="hash-link" aria-label="Direct link to Email Body" title="Direct link to Email Body" translate="no">​</a></h3>
<p>OFFICIAL COURT ORDER</p>
<p>There is an alleged court order against your Internet IP traffic by the Central Bureau of Investigation, Department of Research and Analysis Wing.</p>
<p>It is quite unfortunate that you're using your Internet to watch a juvenile pornographic movie.</p>
<p>The Central Bureau of Investigation works in partnership with the Police Cybercrime Special Units in handling all complex And sensitive cases of cybercrime,</p>
<p>Kindly get back to this message immediately Be assured that legal action will be taken against you if you fail to respond to this notice within 48 hours of receipt.</p>
<p>Sincerely,<br>
<!-- -->Ritambra Prakash ACP and CB<br>
<!-- -->For Deputy Commissioner Of Police<br>
<!-- -->Cyber Crime Cell and Computer Centre<br>
<!-- -->Police Headquarters,</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/scam-court-order-warning-ritambra-prakash-acp-cyber-crime-coordination-centre/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<p>This email is a classic intimidation scam designed to frighten recipients into responding through fear of legal consequences. Below is a detailed analysis of the numerous suspicious elements:</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="1-fraudulent-email-address-and-authentication"><strong>1. Fraudulent Email Address and Authentication</strong><a href="https://secure-techie.com/blog/scam-court-order-warning-ritambra-prakash-acp-cyber-crime-coordination-centre/#1-fraudulent-email-address-and-authentication" class="hash-link" aria-label="Direct link to 1-fraudulent-email-address-and-authentication" title="Direct link to 1-fraudulent-email-address-and-authentication" translate="no">​</a></h3>
<ul>
<li class=""><strong>Gmail Domain for Government Agency</strong>: The email claims to be from "Cyber Crime Coordination Centre" but uses a Gmail address (<code>intellgencbureu@gmail.com</code>), which is completely inappropriate for official government communications. Legitimate Indian government agencies use verified domains ending with <code>.gov.in</code> or <code>.nic.in</code>.</li>
<li class=""><strong>Misspelled Email Address</strong>: The email address contains "intellgencbureu" which is a misspelling of "Intelligence Bureau," indicating this is not from any official source.</li>
<li class=""><strong>Unprofessional Email Authentication</strong>: Government emails are typically sent through secure, verified government mail servers, not through Gmail's infrastructure.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="2-poor-language-and-formatting"><strong>2. Poor Language and Formatting</strong><a href="https://secure-techie.com/blog/scam-court-order-warning-ritambra-prakash-acp-cyber-crime-coordination-centre/#2-poor-language-and-formatting" class="hash-link" aria-label="Direct link to 2-poor-language-and-formatting" title="Direct link to 2-poor-language-and-formatting" translate="no">​</a></h3>
<ul>
<li class=""><strong>Grammatical Errors</strong>: Multiple errors throughout, including "It is quite unfortunate that you're using your Internet" and incomplete sentences like "The Central Bureau of Investigation works in partnership with the Police Cybercrime Special Units in handling all complex And sensitive cases of cybercrime," (note the incomplete ending).</li>
<li class=""><strong>Inconsistent Capitalization</strong>: Random capitalization of words like "And" in the middle of sentences shows unprofessional composition.</li>
<li class=""><strong>Hindi Subject with English Body</strong>: The use of Hindi in the subject line (न्यायालय आदेश चेतावनी) mixed with English content is inconsistent with official government communication standards.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="3-illegitimate-legal-claims"><strong>3. Illegitimate Legal Claims</strong><a href="https://secure-techie.com/blog/scam-court-order-warning-ritambra-prakash-acp-cyber-crime-coordination-centre/#3-illegitimate-legal-claims" class="hash-link" aria-label="Direct link to 3-illegitimate-legal-claims" title="Direct link to 3-illegitimate-legal-claims" translate="no">​</a></h3>
<ul>
<li class=""><strong>Vague Accusations</strong>: The email makes serious allegations about "juvenile pornographic movie" without providing any specific evidence, case numbers, IP addresses, dates, or other details that would be present in legitimate legal notices.</li>
<li class=""><strong>No Official Case Reference</strong>: Real legal proceedings always include specific case numbers, court names, dates, and detailed documentation. This email provides none of these essentials.</li>
<li class=""><strong>Improper Legal Language</strong>: The phrase "alleged court order against your Internet IP traffic" is not proper legal terminology and makes no legal sense.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="4-intimidation-tactics"><strong>4. Intimidation Tactics</strong><a href="https://secure-techie.com/blog/scam-court-order-warning-ritambra-prakash-acp-cyber-crime-coordination-centre/#4-intimidation-tactics" class="hash-link" aria-label="Direct link to 4-intimidation-tactics" title="Direct link to 4-intimidation-tactics" translate="no">​</a></h3>
<ul>
<li class=""><strong>False Urgency</strong>: The 48-hour deadline is designed to pressure recipients into responding quickly without thinking rationally or seeking advice.</li>
<li class=""><strong>Emotional Manipulation</strong>: The serious nature of the false accusations is intended to cause panic and immediate compliance.</li>
<li class=""><strong>Threatening Tone</strong>: The email uses intimidating language to coerce a response rather than following proper legal notification procedures.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="5-organizational-inconsistencies"><strong>5. Organizational Inconsistencies</strong><a href="https://secure-techie.com/blog/scam-court-order-warning-ritambra-prakash-acp-cyber-crime-coordination-centre/#5-organizational-inconsistencies" class="hash-link" aria-label="Direct link to 5-organizational-inconsistencies" title="Direct link to 5-organizational-inconsistencies" translate="no">​</a></h3>
<ul>
<li class=""><strong>Mixed Agency References</strong>: The email confusingly references multiple organizations (Central Bureau of Investigation, Research and Analysis Wing, Police Cybercrime Units) in ways that don't reflect actual government structure.</li>
<li class=""><strong>Incorrect Official Titles</strong>: "Ritambra Prakash ACP and CB" uses abbreviated titles that don't follow standard Indian police designation formats.</li>
<li class=""><strong>No Verifiable Contact Information</strong>: No official phone numbers, addresses, or reference numbers that could be independently verified.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="6-technical-and-procedural-violations"><strong>6. Technical and Procedural Violations</strong><a href="https://secure-techie.com/blog/scam-court-order-warning-ritambra-prakash-acp-cyber-crime-coordination-centre/#6-technical-and-procedural-violations" class="hash-link" aria-label="Direct link to 6-technical-and-procedural-violations" title="Direct link to 6-technical-and-procedural-violations" translate="no">​</a></h3>
<ul>
<li class=""><strong>BCC Usage</strong>: Legitimate government communications are not sent via BCC to multiple recipients simultaneously.</li>
<li class=""><strong>Lack of Digital Signature</strong>: Official government emails typically include proper digital signatures and security certificates.</li>
<li class=""><strong>No Official Letterhead</strong>: Genuine court orders and legal notices include official letterheads, seals, and proper formatting.</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="how-this-scam-typically-works"><strong>How This Scam Typically Works</strong><a href="https://secure-techie.com/blog/scam-court-order-warning-ritambra-prakash-acp-cyber-crime-coordination-centre/#how-this-scam-typically-works" class="hash-link" aria-label="Direct link to how-this-scam-typically-works" title="Direct link to how-this-scam-typically-works" translate="no">​</a></h2>
<p>If victims respond to this email, scammers typically:</p>
<ol>
<li class=""><strong>Escalate Fear</strong>: Provide fake "evidence" or documentation to increase panic</li>
<li class=""><strong>Demand Personal Information</strong>: Request ID documents, bank details, or personal information under the guise of "verification"</li>
<li class=""><strong>Request Payments</strong>: Ask for "fine payments," "processing fees," or "bail money" to "resolve" the fake case</li>
<li class=""><strong>Create False Legitimacy</strong>: Use fake government websites, documents, or phone numbers to appear official</li>
<li class=""><strong>Maintain Pressure</strong>: Continue threatening immediate arrest or legal action to prevent rational thinking</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion-and-recommendations"><strong>Conclusion and Recommendations</strong><a href="https://secure-techie.com/blog/scam-court-order-warning-ritambra-prakash-acp-cyber-crime-coordination-centre/#conclusion-and-recommendations" class="hash-link" aria-label="Direct link to conclusion-and-recommendations" title="Direct link to conclusion-and-recommendations" translate="no">​</a></h2>
<p>This email is a fraudulent intimidation scam impersonating Indian law enforcement agencies. It is crucial to:</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="immediate-actions"><strong>Immediate Actions:</strong><a href="https://secure-techie.com/blog/scam-court-order-warning-ritambra-prakash-acp-cyber-crime-coordination-centre/#immediate-actions" class="hash-link" aria-label="Direct link to immediate-actions" title="Direct link to immediate-actions" translate="no">​</a></h3>
<ul>
<li class=""><strong>Do Not Respond</strong>: Never reply to this email or provide any information</li>
<li class=""><strong>Do Not Panic</strong>: Remember that legitimate legal notices follow proper legal procedures and channels</li>
<li class=""><strong>Report as Spam</strong>: Mark the email as phishing/spam in your email client</li>
<li class=""><strong>Delete Immediately</strong>: Remove the email to prevent accidental interaction</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="verification-steps"><strong>Verification Steps:</strong><a href="https://secure-techie.com/blog/scam-court-order-warning-ritambra-prakash-acp-cyber-crime-coordination-centre/#verification-steps" class="hash-link" aria-label="Direct link to verification-steps" title="Direct link to verification-steps" translate="no">​</a></h3>
<ul>
<li class=""><strong>Contact Authorities Directly</strong>: If concerned about any legal matters, contact local police through official numbers listed on government websites</li>
<li class=""><strong>Check Official Channels</strong>: Legitimate legal notices are served through proper legal channels, not email</li>
<li class=""><strong>Verify Through Gov.in Websites</strong>: All authentic Indian government communications come from verified <code>.gov.in</code> domains</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="educational-measures"><strong>Educational Measures:</strong><a href="https://secure-techie.com/blog/scam-court-order-warning-ritambra-prakash-acp-cyber-crime-coordination-centre/#educational-measures" class="hash-link" aria-label="Direct link to educational-measures" title="Direct link to educational-measures" translate="no">​</a></h3>
<ul>
<li class=""><strong>Share Awareness</strong>: Inform family and friends about such scams to protect them</li>
<li class=""><strong>Report to Cybercrime</strong>: Report the scam to India's National Cyber Crime Reporting Portal (cybercrime.gov.in)</li>
<li class=""><strong>Stay Informed</strong>: Keep updated about common scam tactics targeting Indian citizens</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-protection-tips"><strong>Additional Protection Tips</strong><a href="https://secure-techie.com/blog/scam-court-order-warning-ritambra-prakash-acp-cyber-crime-coordination-centre/#additional-protection-tips" class="hash-link" aria-label="Direct link to additional-protection-tips" title="Direct link to additional-protection-tips" translate="no">​</a></h2>
<ul>
<li class=""><strong>Government Email Verification</strong>: Always verify government emails through official <code>.gov.in</code> domains</li>
<li class=""><strong>Legal Notice Procedures</strong>: Understand that real legal notices are served through registered post or in-person delivery</li>
<li class=""><strong>Cybercrime Awareness</strong>: Remember that legitimate law enforcement agencies never demand immediate email responses for serious criminal allegations</li>
<li class=""><strong>Trust Official Channels</strong>: When in doubt, contact authorities through verified phone numbers from official government websites</li>
</ul>
<p><strong>Remember</strong>: Real legal proceedings follow established procedures and never depend on email responses within arbitrary deadlines. This email is designed purely to create fear and extract money or personal information from victims.</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Scam" term="Scam"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Fraud: Business Supply Partnership | Clara Davidson from United Kingdom]]></title>
        <id>https://secure-techie.com/blog/fraud-business-supply-partnership-clara-davidson-united-kingdom/</id>
        <link href="https://secure-techie.com/blog/fraud-business-supply-partnership-clara-davidson-united-kingdom/"/>
        <updated>2025-07-25T15:30:00.000Z</updated>
        <summary type="html"><![CDATA[I am Ms,Clara Davidson. From United Kingdom, currently in search of a Business Supply partner in India; Kindly indicate your interest for more details.]]></summary>
        <content type="html"><![CDATA[<p>I am Ms,Clara Davidson. From United Kingdom, currently in search of a Business Supply partner in India; Kindly indicate your interest for more details.</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/fraud-business-supply-partnership-clara-davidson-united-kingdom/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p>from: Business Supply <code>&amp;lt;undepartments6@gmail.com&amp;gt;</code><br>
<!-- -->to:<br>
<!-- -->date: Jul 23, 2025, 12:55 PM<br>
<!-- -->subject: Supply<br>
<!-- -->mailed-by: gmail.com<br>
<!-- -->signed-by: gmail.com</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-body">Email Body<a href="https://secure-techie.com/blog/fraud-business-supply-partnership-clara-davidson-united-kingdom/#email-body" class="hash-link" aria-label="Direct link to Email Body" title="Direct link to Email Body" translate="no">​</a></h3>
<p>Greetings!</p>
<p>I am Ms,Clara Davidson. From United Kingdom, currently in search of a Business Supply partner in India; Kindly indicate your interest for more details, Email: <code>claradavidson30@gmail.com</code></p>
<p>Await your prompt reply.</p>
<p>Ms. Clara Davidson.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/fraud-business-supply-partnership-clara-davidson-united-kingdom/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<p>This email exhibits multiple characteristics typical of business email compromise (BEC) and advance-fee fraud scams. Below is a detailed analysis of the suspicious elements:</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="1-suspicious-email-address-and-authentication"><strong>1. Suspicious Email Address and Authentication</strong><a href="https://secure-techie.com/blog/fraud-business-supply-partnership-clara-davidson-united-kingdom/#1-suspicious-email-address-and-authentication" class="hash-link" aria-label="Direct link to 1-suspicious-email-address-and-authentication" title="Direct link to 1-suspicious-email-address-and-authentication" translate="no">​</a></h3>
<ul>
<li class=""><strong>Sender Display Name vs. Email</strong>: The email claims to be from "Business Supply" but uses a generic Gmail address (<code>undepartments6@gmail.com</code>), which is unprofessional and not associated with any legitimate business entity.</li>
<li class=""><strong>Generic Gmail Account</strong>: Legitimate international businesses, especially those seeking partnerships, typically use professional email domains reflecting their company name, not free email services like Gmail.</li>
<li class=""><strong>Mismatched Contact Information</strong>: The email provides a different Gmail address for replies (<code>claradavidson30@gmail.com</code>), which is another red flag indicating potential deception.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="2-vague-and-unprofessional-content"><strong>2. Vague and Unprofessional Content</strong><a href="https://secure-techie.com/blog/fraud-business-supply-partnership-clara-davidson-united-kingdom/#2-vague-and-unprofessional-content" class="hash-link" aria-label="Direct link to 2-vague-and-unprofessional-content" title="Direct link to 2-vague-and-unprofessional-content" translate="no">​</a></h3>
<ul>
<li class=""><strong>Lack of Specificity</strong>: The email mentions being in search of a "Business Supply partner" without specifying what type of supplies, products, or services are needed. Legitimate business inquiries are typically detailed and specific.</li>
<li class=""><strong>No Company Information</strong>: No company name, registration details, official address, phone number, or website is provided. Professional business communications always include comprehensive contact information.</li>
<li class=""><strong>Generic Greeting</strong>: The email uses a simple "Greetings!" without addressing the recipient by name, suggesting it's part of a mass mailing campaign.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="3-unusual-communication-pattern"><strong>3. Unusual Communication Pattern</strong><a href="https://secure-techie.com/blog/fraud-business-supply-partnership-clara-davidson-united-kingdom/#3-unusual-communication-pattern" class="hash-link" aria-label="Direct link to 3-unusual-communication-pattern" title="Direct link to 3-unusual-communication-pattern" translate="no">​</a></h3>
<ul>
<li class=""><strong>Minimal Content</strong>: The extremely brief message lacks the detail expected in professional business correspondence, particularly for international partnerships.</li>
<li class=""><strong>Poor Grammar and Punctuation</strong>: Notice the incorrect comma usage in "I am Ms,Clara Davidson" and the awkward phrasing throughout the email.</li>
<li class=""><strong>Urgency Without Context</strong>: The phrase "Await your prompt reply" creates artificial urgency without providing sufficient information to warrant such urgency.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="4-geographical-red-flags"><strong>4. Geographical Red Flags</strong><a href="https://secure-techie.com/blog/fraud-business-supply-partnership-clara-davidson-united-kingdom/#4-geographical-red-flags" class="hash-link" aria-label="Direct link to 4-geographical-red-flags" title="Direct link to 4-geographical-red-flags" translate="no">​</a></h3>
<ul>
<li class=""><strong>UK-India Partnership Claim</strong>: While legitimate UK-India business partnerships exist, the lack of specific details about the nature of the business or supplies needed is suspicious.</li>
<li class=""><strong>No Physical Address</strong>: No UK address, company registration number, or other verifiable business credentials are provided.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="5-common-fraud-indicators"><strong>5. Common Fraud Indicators</strong><a href="https://secure-techie.com/blog/fraud-business-supply-partnership-clara-davidson-united-kingdom/#5-common-fraud-indicators" class="hash-link" aria-label="Direct link to 5-common-fraud-indicators" title="Direct link to 5-common-fraud-indicators" translate="no">​</a></h3>
<ul>
<li class=""><strong>Advance-Fee Fraud Setup</strong>: This type of initial contact is commonly used to establish trust before requesting upfront payments for "registration fees," "samples," or "documentation."</li>
<li class=""><strong>Information Harvesting</strong>: The email may be designed to collect business information that could be used for future fraud attempts or identity theft.</li>
<li class=""><strong>Mass Distribution</strong>: The generic nature suggests this email was likely sent to many potential victims simultaneously.</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="how-this-scam-typically-progresses"><strong>How This Scam Typically Progresses</strong><a href="https://secure-techie.com/blog/fraud-business-supply-partnership-clara-davidson-united-kingdom/#how-this-scam-typically-progresses" class="hash-link" aria-label="Direct link to how-this-scam-typically-progresses" title="Direct link to how-this-scam-typically-progresses" translate="no">​</a></h2>
<p>If you were to respond to this email, the scammer would likely:</p>
<ol>
<li class=""><strong>Establish Trust</strong>: Provide fake company credentials and documentation</li>
<li class=""><strong>Create Urgency</strong>: Claim time-sensitive opportunities or limited availability</li>
<li class=""><strong>Request Information</strong>: Ask for detailed company information, bank details, or personal identification</li>
<li class=""><strong>Demand Upfront Payments</strong>: Request fees for "registration," "samples," "shipping," or "documentation"</li>
<li class=""><strong>Disappear</strong>: Once payment is received, the scammer becomes unreachable</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion-and-recommendations"><strong>Conclusion and Recommendations</strong><a href="https://secure-techie.com/blog/fraud-business-supply-partnership-clara-davidson-united-kingdom/#conclusion-and-recommendations" class="hash-link" aria-label="Direct link to conclusion-and-recommendations" title="Direct link to conclusion-and-recommendations" translate="no">​</a></h2>
<p>This email is a classic example of a business supply scam designed to target Indian businesses seeking international partnerships. It is advisable to:</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="immediate-actions"><strong>Immediate Actions:</strong><a href="https://secure-techie.com/blog/fraud-business-supply-partnership-clara-davidson-united-kingdom/#immediate-actions" class="hash-link" aria-label="Direct link to immediate-actions" title="Direct link to immediate-actions" translate="no">​</a></h3>
<ul>
<li class=""><strong>Do Not Respond</strong>: Avoid replying or providing any business or personal information</li>
<li class=""><strong>Mark as Spam</strong>: Use your email client's spam/phishing reporting features</li>
<li class=""><strong>Delete the Email</strong>: Remove it to prevent accidental future interaction</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="protective-measures"><strong>Protective Measures:</strong><a href="https://secure-techie.com/blog/fraud-business-supply-partnership-clara-davidson-united-kingdom/#protective-measures" class="hash-link" aria-label="Direct link to protective-measures" title="Direct link to protective-measures" translate="no">​</a></h3>
<ul>
<li class=""><strong>Verify Independently</strong>: Always verify international business inquiries through official channels, company websites, and trade directories</li>
<li class=""><strong>Be Skeptical of Unsolicited Offers</strong>: Legitimate business partnerships rarely begin with unsolicited emails</li>
<li class=""><strong>Use Professional Networks</strong>: Utilize established business networks, trade associations, and verified platforms for international partnerships</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="education-and-awareness"><strong>Education and Awareness:</strong><a href="https://secure-techie.com/blog/fraud-business-supply-partnership-clara-davidson-united-kingdom/#education-and-awareness" class="hash-link" aria-label="Direct link to education-and-awareness" title="Direct link to education-and-awareness" translate="no">​</a></h3>
<ul>
<li class=""><strong>Train Your Team</strong>: Ensure employees can recognize similar scam attempts</li>
<li class=""><strong>Stay Informed</strong>: Keep updated on current fraud tactics targeting businesses</li>
<li class=""><strong>Report Suspicious Activity</strong>: Report such emails to cybercrime authorities to help protect others</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-tips"><strong>Additional Tips</strong><a href="https://secure-techie.com/blog/fraud-business-supply-partnership-clara-davidson-united-kingdom/#additional-tips" class="hash-link" aria-label="Direct link to additional-tips" title="Direct link to additional-tips" translate="no">​</a></h2>
<ul>
<li class=""><strong>Verify Company Registration</strong>: Legitimate UK companies can be verified through Companies House</li>
<li class=""><strong>Check Professional Networks</strong>: Real business contacts can usually be found on LinkedIn or other professional platforms</li>
<li class=""><strong>Trust Your Instincts</strong>: If something feels too good to be true or seems unprofessional, it probably is</li>
</ul>
<p>Always exercise extreme caution with unsolicited business proposals, especially those involving international partnerships, and verify all claims through official channels before engaging in any business discussions.</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Fraud" term="Fraud"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Fraud: Ghana Gold Mining Equipment Supply Contract - Chief Account Officer Kwesi]]></title>
        <id>https://secure-techie.com/blog/fraud-ghana-gold-mining-equipment-supply-contract-kwesi/</id>
        <link href="https://secure-techie.com/blog/fraud-ghana-gold-mining-equipment-supply-contract-kwesi/"/>
        <updated>2025-07-21T12:00:00.000Z</updated>
        <summary type="html"><![CDATA[I am the Chief Account Officer of Ghana Gold. I have a deal here in my office, and I need a foreign partner to execute it with my colleague and me. We over-invoiced a contract payment valued at US$100 million.]]></summary>
        <content type="html"><![CDATA[<p>I am the Chief Account Officer of Ghana Gold. I have a deal here in my office, and I need a foreign partner to execute it with my colleague and me. We over-invoiced a contract payment valued at US$100 million.</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/fraud-ghana-gold-mining-equipment-supply-contract-kwesi/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p><strong>From</strong>: <code>k1122@gmail.com</code><br>
<strong>Subject</strong>: Business</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-body">Email Body<a href="https://secure-techie.com/blog/fraud-ghana-gold-mining-equipment-supply-contract-kwesi/#email-body" class="hash-link" aria-label="Direct link to Email Body" title="Direct link to Email Body" translate="no">​</a></h3>
<p>To Future Partner,</p>
<p>Good day, I know this email will come as a surprise, but I need to contact you due to the urgency and confidentiality of this business transaction. I am the Chief Account Officer of Ghana Gold. I have a deal here in my office, and I need a foreign partner to execute it with my colleague and me. We over-invoiced a contract payment valued at US$100 million. We awarded contracts for the supply and maintenance of all the Gold field and mining equipment for the national gold mines to some foreign contractors valued at US$5 billion, which we over-invoiced by US$100 million in addition to the total contract sum.<br>
<!-- -->Most contractors have been paid, and the remaining contractors’ payments are currently being processed for payment. With that, my colleague and I have decided to include you among these remaining contractors to process the sum of US$100 million in your company or in your name to claim it for our mutual benefit. I am now contacting you to present you as the subcontractor who has been awarded the contract for the supply of heavy mining equipment used in the recent overhauling of the refineries and mining sites, with a value of US$100 million.<br>
<!-- -->I will advise you to furnish me with your personal information, including your cell phone number and the name of your company with address, to enable me to register it with our corporate affairs commission in charge of allied and companies registration as an indigenous company.<br>
<!-- -->Any foreign company must be registered in this country. Also, with your acceptance to execute this business with me, I need to be sure of your confidentiality regarding the conclusion of this deal. you will be given 30% of the total amount, while my colleague and I will take 70% once the money gets into your company account in your country. Also, with my position here, I can officially arrange with you to be lifting 140 or 200 Kilograms of gold per month by getting a one-year or two-year Gold allocation contract in your name and company name, whether you are here or not. With this, we can make more money from the Gold lifting here in Ghana. I will detail more on this once I get your response.<br>
<!-- -->Thank you, and hope to hear from you as soon as possible. Send me your cell phone number or Email to call you for more details.</p>
<p>Best Regards</p>
<p>Kwesi</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/fraud-ghana-gold-mining-equipment-supply-contract-kwesi/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags-identified-in-the-email"><strong>Red Flags Identified in the Email:</strong><a href="https://secure-techie.com/blog/fraud-ghana-gold-mining-equipment-supply-contract-kwesi/#red-flags-identified-in-the-email" class="hash-link" aria-label="Direct link to red-flags-identified-in-the-email" title="Direct link to red-flags-identified-in-the-email" translate="no">​</a></h3>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="1-classic-advance-fee-fraud-419-scam"><strong>1. Classic Advance Fee Fraud (419 Scam)</strong><a href="https://secure-techie.com/blog/fraud-ghana-gold-mining-equipment-supply-contract-kwesi/#1-classic-advance-fee-fraud-419-scam" class="hash-link" aria-label="Direct link to 1-classic-advance-fee-fraud-419-scam" title="Direct link to 1-classic-advance-fee-fraud-419-scam" translate="no">​</a></h3>
<ul>
<li class=""><strong>Over-Invoicing Scheme</strong>: The email describes a fraudulent over-invoicing scheme involving US$100 million, which is a common premise used in advance fee fraud scams. The sender claims to be offering you a share of stolen money, which is both illegal and fictitious.</li>
<li class=""><strong>Unsolicited Partnership</strong>: You are being offered a large sum of money (30% of $100 million = $30 million) from a complete stranger without any prior business relationship or legitimate reason.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="2-suspicious-sender-information"><strong>2. Suspicious Sender Information</strong><a href="https://secure-techie.com/blog/fraud-ghana-gold-mining-equipment-supply-contract-kwesi/#2-suspicious-sender-information" class="hash-link" aria-label="Direct link to 2-suspicious-sender-information" title="Direct link to 2-suspicious-sender-information" translate="no">​</a></h3>
<ul>
<li class=""><strong>Generic Email Address</strong>: The sender uses <code>k1122@gmail.com</code>, which is a generic Gmail address with no connection to any official government or corporate entity in Ghana.</li>
<li class=""><strong>Vague Identity</strong>: The sender only provides the first name "Kwesi" and claims to be a "Chief Account Officer of Ghana Gold" without providing any verifiable credentials, official contact information, or company details.</li>
<li class=""><strong>No Official Letterhead</strong>: Legitimate government or corporate communications would include official letterhead, contact information, and proper identification.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="3-unrealistic-financial-claims"><strong>3. Unrealistic Financial Claims</strong><a href="https://secure-techie.com/blog/fraud-ghana-gold-mining-equipment-supply-contract-kwesi/#3-unrealistic-financial-claims" class="hash-link" aria-label="Direct link to 3-unrealistic-financial-claims" title="Direct link to 3-unrealistic-financial-claims" translate="no">​</a></h3>
<ul>
<li class=""><strong>Massive Contract Value</strong>: The claim of a US$5 billion contract for mining equipment with a US$100 million over-invoice is unrealistic and designed to seem impressive to potential victims.</li>
<li class=""><strong>Gold Lifting Offer</strong>: The additional offer to arrange "140 or 200 Kilograms of gold per month" is completely fabricated and designed to make the scam seem more attractive.</li>
<li class=""><strong>Percentage Split</strong>: The specific percentage split (30% to you, 70% to them) is a common tactic in 419 scams to make the offer seem "reasonable" and pre-negotiated.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="4-requests-for-personal-information"><strong>4. Requests for Personal Information</strong><a href="https://secure-techie.com/blog/fraud-ghana-gold-mining-equipment-supply-contract-kwesi/#4-requests-for-personal-information" class="hash-link" aria-label="Direct link to 4-requests-for-personal-information" title="Direct link to 4-requests-for-personal-information" translate="no">​</a></h3>
<ul>
<li class=""><strong>Personal Details Required</strong>: The scammer requests your personal information, cell phone number, company name, and address, which would be used for identity theft or to make the scam more convincing in future communications.</li>
<li class=""><strong>Company Registration Scam</strong>: The mention of registering your company with their "corporate affairs commission" is a setup for future requests for registration fees or other payments.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="5-emphasis-on-confidentiality-and-urgency"><strong>5. Emphasis on Confidentiality and Urgency</strong><a href="https://secure-techie.com/blog/fraud-ghana-gold-mining-equipment-supply-contract-kwesi/#5-emphasis-on-confidentiality-and-urgency" class="hash-link" aria-label="Direct link to 5-emphasis-on-confidentiality-and-urgency" title="Direct link to 5-emphasis-on-confidentiality-and-urgency" translate="no">​</a></h3>
<ul>
<li class=""><strong>Confidentiality Requirements</strong>: The emphasis on confidentiality is designed to prevent victims from consulting with others who might recognize the scam.</li>
<li class=""><strong>Urgency Tactic</strong>: The email mentions "urgency" to pressure you into responding quickly without proper consideration.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="6-poor-language-and-grammar"><strong>6. Poor Language and Grammar</strong><a href="https://secure-techie.com/blog/fraud-ghana-gold-mining-equipment-supply-contract-kwesi/#6-poor-language-and-grammar" class="hash-link" aria-label="Direct link to 6-poor-language-and-grammar" title="Direct link to 6-poor-language-and-grammar" translate="no">​</a></h3>
<ul>
<li class=""><strong>Grammatical Errors</strong>: The email contains numerous grammatical errors and awkward phrasing, such as "due to the urgency and confidentiality of this business transaction" and inconsistent capitalization.</li>
<li class=""><strong>Unprofessional Tone</strong>: The informal greeting "Good day" and overall casual tone are inappropriate for a legitimate high-value business transaction.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="7-illegal-activity-admission"><strong>7. Illegal Activity Admission</strong><a href="https://secure-techie.com/blog/fraud-ghana-gold-mining-equipment-supply-contract-kwesi/#7-illegal-activity-admission" class="hash-link" aria-label="Direct link to 7-illegal-activity-admission" title="Direct link to 7-illegal-activity-admission" translate="no">​</a></h3>
<ul>
<li class=""><strong>Admitted Fraud</strong>: The sender openly admits to over-invoicing contracts and engaging in fraudulent activities, which no legitimate business person would do in writing.</li>
<li class=""><strong>Money Laundering Scheme</strong>: The entire premise involves laundering money through your account, which would make you complicit in criminal activity.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="8-no-verification-possible"><strong>8. No Verification Possible</strong><a href="https://secure-techie.com/blog/fraud-ghana-gold-mining-equipment-supply-contract-kwesi/#8-no-verification-possible" class="hash-link" aria-label="Direct link to 8-no-verification-possible" title="Direct link to 8-no-verification-possible" translate="no">​</a></h3>
<ul>
<li class=""><strong>Unverifiable Claims</strong>: There is no way to verify the existence of "Ghana Gold" as described, or the sender's position within such an organization.</li>
<li class=""><strong>No Official Channels</strong>: Legitimate government contracts would go through official procurement channels, not unsolicited emails to random recipients.</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="how-this-scam-typically-progresses"><strong>How This Scam Typically Progresses:</strong><a href="https://secure-techie.com/blog/fraud-ghana-gold-mining-equipment-supply-contract-kwesi/#how-this-scam-typically-progresses" class="hash-link" aria-label="Direct link to how-this-scam-typically-progresses" title="Direct link to how-this-scam-typically-progresses" translate="no">​</a></h2>
<ol>
<li class=""><strong>Initial Contact</strong>: You receive this email claiming a lucrative opportunity</li>
<li class=""><strong>Personal Information Harvest</strong>: If you respond, they collect your personal and company details</li>
<li class=""><strong>Documentation Phase</strong>: They send fake contracts and official-looking documents</li>
<li class=""><strong>Fee Requests</strong>: Eventually, they request payments for:<!-- -->
<ul>
<li class="">Registration fees</li>
<li class="">Legal documentation</li>
<li class="">Government permits</li>
<li class="">Banking charges</li>
<li class="">Customs clearance</li>
<li class="">Tax payments</li>
</ul>
</li>
<li class=""><strong>Escalation</strong>: Fees continue to increase with new "unexpected" complications</li>
<li class=""><strong>Disappearance</strong>: After extracting money, the scammers disappear completely</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="recommendations"><strong>Recommendations</strong>:<a href="https://secure-techie.com/blog/fraud-ghana-gold-mining-equipment-supply-contract-kwesi/#recommendations" class="hash-link" aria-label="Direct link to recommendations" title="Direct link to recommendations" translate="no">​</a></h2>
<ol>
<li class=""><strong>Do Not Respond</strong>: Never reply to this email or provide any personal information</li>
<li class=""><strong>Delete Immediately</strong>: Delete the email and mark it as spam/phishing</li>
<li class=""><strong>Report the Scam</strong>: Report to:<!-- -->
<ul>
<li class="">Your local authorities</li>
<li class="">The FBI's IC3 (Internet Crime Complaint Center) if in the US</li>
<li class="">Anti-fraud agencies in your country</li>
</ul>
</li>
<li class=""><strong>Warn Others</strong>: Share information about this scam type with friends and colleagues</li>
<li class=""><strong>Verify Independently</strong>: If you ever receive legitimate-seeming business offers, always verify through official channels</li>
<li class=""><strong>Never Send Money</strong>: Never send money, fees, or provide banking details in response to unsolicited emails</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion"><strong>Conclusion</strong>:<a href="https://secure-techie.com/blog/fraud-ghana-gold-mining-equipment-supply-contract-kwesi/#conclusion" class="hash-link" aria-label="Direct link to conclusion" title="Direct link to conclusion" translate="no">​</a></h2>
<p>This email is a classic example of an advance fee fraud (419 scam) specifically targeting individuals with promises of large sums of money from fictitious gold mining contracts in Ghana. The sender is attempting to steal your personal information and will eventually request advance payments for various fake fees. This is a well-known scam pattern that has defrauded thousands of people worldwide. Always be extremely suspicious of unsolicited emails offering large sums of money, especially those involving foreign business deals, over-invoiced contracts, or any scheme requiring advance payments or personal information.</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Fraud" term="Fraud"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Phishing: Còpia de: Exclusive $3,000 balance https://t.me/s/attention616011#2503]]></title>
        <id>https://secure-techie.com/blog/phishing-copia-de-exclusive-3000-balance-tme-s-attention616011-2503/</id>
        <link href="https://secure-techie.com/blog/phishing-copia-de-exclusive-3000-balance-tme-s-attention616011-2503/"/>
        <updated>2025-06-23T15:03:00.000Z</updated>
        <summary type="html"><![CDATA[Això és una còpia del missatge que vas enviar a EcoSostenibleWine 2019 via EcoSostenibleWine.]]></summary>
        <content type="html"><![CDATA[<p>Això és una còpia del missatge que vas enviar a EcoSostenibleWine 2019 via EcoSostenibleWine.</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/phishing-copia-de-exclusive-3000-balance-tme-s-attention616011-2503/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p>from: ECOSOSTENIBLEWINE <code>&amp;lt;inscripciones@ecososteniblewine.com&amp;gt;</code><br>
<!-- -->reply-to: "Win a $3,000 reward from us <code>https://t.me/s/attention466411#9296</code> Inquiry №8311008" <code>&amp;lt;\{myEmail\}@gmail.com&amp;gt;</code><br>
<!-- -->date: Jun 23, 2025, 3:03 PM<br>
<!-- -->subject: Còpia de: Exclusive $3,000 balance <code>https://t.me/s/attention616011#2503</code><br>
<!-- -->mailed-by: <code>ecososteniblewine.com</code></p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-body">Email Body<a href="https://secure-techie.com/blog/phishing-copia-de-exclusive-3000-balance-tme-s-attention616011-2503/#email-body" class="hash-link" aria-label="Direct link to Email Body" title="Direct link to Email Body" translate="no">​</a></h2>
<p>Això és una còpia del missatge que vas enviar a EcoSostenibleWine 2019 via EcoSostenibleWine</p>
<p>Aquest és un correu-e de requeriment via <code>http://www.ecososteniblewine.com/</code> des de:
Win a $3,000 reward from us
<code>https://t.me/s/attention466411#9296</code>
Inquiry №8311008 &lt;{myEmail}@gmail.com&gt;</p>
<p>Reap a $3,000 cash bonus
<code>https://t.me/s/attention602234#751</code></p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/phishing-copia-de-exclusive-3000-balance-tme-s-attention616011-2503/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags-identified-in-the-email"><strong>Red Flags Identified in the Email:</strong><a href="https://secure-techie.com/blog/phishing-copia-de-exclusive-3000-balance-tme-s-attention616011-2503/#red-flags-identified-in-the-email" class="hash-link" aria-label="Direct link to red-flags-identified-in-the-email" title="Direct link to red-flags-identified-in-the-email" translate="no">​</a></h3>
<ol>
<li class="">
<p><strong>Suspicious Links and Promises:</strong></p>
<ul>
<li class="">The email contains multiple Telegram links promising a $3,000 reward, which is a common phishing tactic.</li>
<li class="">Unsolicited offers of large sums of money are typical of scams.</li>
</ul>
</li>
<li class="">
<p><strong>Impersonation of a Legitimate Organization:</strong></p>
<ul>
<li class="">The sender uses the name and domain of EcoSostenibleWine, but the content is unrelated to wine or their business.</li>
</ul>
</li>
<li class="">
<p><strong>Reply-to Address Manipulation:</strong></p>
<ul>
<li class="">The reply-to address is crafted to look like a reward offer and includes the recipient's email, which is suspicious.</li>
</ul>
</li>
<li class="">
<p><strong>Unusual Language and Formatting:</strong></p>
<ul>
<li class="">The email mixes English and Catalan, and the subject and body contain odd phrasing and formatting.</li>
</ul>
</li>
<li class="">
<p><strong>Use of Public Messaging Platforms:</strong></p>
<ul>
<li class="">The email encourages recipients to visit Telegram channels, which are often used in phishing and crypto scams.</li>
</ul>
</li>
<li class="">
<p><strong>No Personalization or Official Branding:</strong></p>
<ul>
<li class="">The message lacks any personal greeting, official branding, or legitimate contact information.</li>
</ul>
</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion-and-recommendations"><strong>Conclusion and Recommendations:</strong><a href="https://secure-techie.com/blog/phishing-copia-de-exclusive-3000-balance-tme-s-attention616011-2503/#conclusion-and-recommendations" class="hash-link" aria-label="Direct link to conclusion-and-recommendations" title="Direct link to conclusion-and-recommendations" translate="no">​</a></h2>
<p>This email is a phishing attempt designed to lure recipients into visiting suspicious Telegram channels and potentially steal personal information or money. It is advisable to:</p>
<ul>
<li class=""><strong>Do Not Respond:</strong> Avoid replying or engaging with the sender.</li>
<li class=""><strong>Do Not Click on Links:</strong> The Telegram links may lead to scams or malware.</li>
<li class=""><strong>Report the Email:</strong> Mark as spam/phishing and report to your email provider or IT/security team.</li>
<li class=""><strong>Delete the Email:</strong> Remove it to prevent accidental interaction.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-tips"><strong>Additional Tips:</strong><a href="https://secure-techie.com/blog/phishing-copia-de-exclusive-3000-balance-tme-s-attention616011-2503/#additional-tips" class="hash-link" aria-label="Direct link to additional-tips" title="Direct link to additional-tips" translate="no">​</a></h2>
<ul>
<li class=""><strong>Be Skeptical of Unsolicited Rewards:</strong> Legitimate organizations do not give away large sums of money via email.</li>
<li class=""><strong>Verify Sender Information:</strong> Always check the sender's address and the legitimacy of the offer.</li>
<li class=""><strong>Stay Informed:</strong> Learn about common phishing tactics and educate others.</li>
</ul>
<p>Always exercise caution with emails promising rewards or asking you to visit unfamiliar links or channels.</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Phishing" term="Phishing"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Fraud: Supply Prospect | Josephine Braimah of Transpacific Biochem Logistics Manager]]></title>
        <id>https://secure-techie.com/blog/fraud-supply-prospect-josephine-braimah-transpacific-biochem-logistics-manager/</id>
        <link href="https://secure-techie.com/blog/fraud-supply-prospect-josephine-braimah-transpacific-biochem-logistics-manager/"/>
        <updated>2025-06-17T21:57:00.000Z</updated>
        <summary type="html"><![CDATA[I am Josephine Braimah of Transpacific Biochem Logistics Manager, under Ghana Health Ministry; I hope to explore a huge supply prospect with you involving our company.]]></summary>
        <content type="html"><![CDATA[<p>I am Josephine Braimah of Transpacific Biochem Logistics Manager, under Ghana Health Ministry; I hope to explore a huge supply prospect with you involving our company.</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/fraud-supply-prospect-josephine-braimah-transpacific-biochem-logistics-manager/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p>from: J. Braimah <code>&amp;lt;direzione.sportiva@sslazio.it&amp;gt;</code><br>
<!-- -->reply-to: <code>transpacificlaboratoryghana@gmail.com</code><br>
<!-- -->to: "J. Braimah" <code>&amp;lt;marco.caruso@arnascivico.it&amp;gt;</code><br>
<!-- -->subject: Supply Prospect<br>
<!-- -->mailed-by: <code>sslazio.it</code></p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-body">Email Body<a href="https://secure-techie.com/blog/fraud-supply-prospect-josephine-braimah-transpacific-biochem-logistics-manager/#email-body" class="hash-link" aria-label="Direct link to Email Body" title="Direct link to Email Body" translate="no">​</a></h2>
<p>Very Good morning and happy new week to you Sir<br>
<!-- -->Grateful to reach you here and now.</p>
<p>I am Josephine Braimah of Transpacific Biochem Logistics Manager, under Ghana Health Ministry; I hope to explore a huge supply prospect with you involving our company operations director as he plans to visit India soonest to find a reliable firm to undertake and reactivate Our 2-Year renewable Indian Raw-material Supply contract with Our Health Ministry here in Ghana; But if I can confide the details with you, we can explore it for much greater good.</p>
<p>I hope to find a reliable business front in India, with whom to secure this huge prospective contract and keep it wrapped up and also long-term between us. Let me know if we can work this out together in confidential trust, then send me your Contact Number in your email reply; so we can proceed in good faith.</p>
<p>Dr Josephine Braimah (Madam)<br>
<!-- -->Materials logistics Manager @Transpacific BioChem-Gh<br>
<!-- -->Thema Industrial Village, AgroBio- Allied Zone Box-7447, Gt 566 TA 00 Tema, Ghana</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/fraud-supply-prospect-josephine-braimah-transpacific-biochem-logistics-manager/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags-identified-in-the-email"><strong>Red Flags Identified in the Email:</strong><a href="https://secure-techie.com/blog/fraud-supply-prospect-josephine-braimah-transpacific-biochem-logistics-manager/#red-flags-identified-in-the-email" class="hash-link" aria-label="Direct link to red-flags-identified-in-the-email" title="Direct link to red-flags-identified-in-the-email" translate="no">​</a></h3>
<ol>
<li class="">
<p><strong>Suspicious Email Addresses:</strong></p>
<ul>
<li class=""><strong>Sender's Email:</strong> <code>direzione.sportiva@sslazio.it</code> (an Italian football club domain, unrelated to Ghana Health Ministry)</li>
<li class=""><strong>Reply-to Email:</strong> <code>transpacificlaboratoryghana@gmail.com</code> (generic Gmail address, not an official government or business domain)</li>
</ul>
</li>
<li class="">
<p><strong>Unsolicited Business Proposal:</strong></p>
<ul>
<li class="">The email proposes a large business deal out of the blue, which is a common tactic in scam emails.</li>
</ul>
</li>
<li class="">
<p><strong>Request for Confidentiality and Personal Information:</strong></p>
<ul>
<li class="">The sender asks for your contact number and emphasizes confidentiality, which is typical in advance-fee frauds.</li>
</ul>
</li>
<li class="">
<p><strong>Inconsistent and Unverifiable Details:</strong></p>
<ul>
<li class="">The sender claims to represent a Ghanaian government entity but uses unrelated or unverifiable contact information.</li>
<li class="">The use of multiple unrelated email addresses is suspicious.</li>
</ul>
</li>
<li class="">
<p><strong>Emotional Manipulation and Urgency:</strong></p>
<ul>
<li class="">The email appeals to trust and confidentiality to pressure the recipient into responding quickly.</li>
</ul>
</li>
<li class="">
<p><strong>Grammatical Errors and Unprofessional Language:</strong></p>
<ul>
<li class="">The message contains awkward phrasing and grammatical mistakes, which are common in scam emails.</li>
</ul>
</li>
<li class="">
<p><strong>Lack of Professionalism:</strong></p>
<ul>
<li class="">No official documentation, letterhead, or verifiable credentials are provided.</li>
</ul>
</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion-and-recommendations"><strong>Conclusion and Recommendations:</strong><a href="https://secure-techie.com/blog/fraud-supply-prospect-josephine-braimah-transpacific-biochem-logistics-manager/#conclusion-and-recommendations" class="hash-link" aria-label="Direct link to conclusion-and-recommendations" title="Direct link to conclusion-and-recommendations" translate="no">​</a></h2>
<p>This email exhibits multiple red flags typical of business email compromise (BEC) or advance-fee fraud scams. It is advisable to:</p>
<ul>
<li class=""><strong>Do Not Respond:</strong> Avoid replying or providing any personal or business information.</li>
<li class=""><strong>Do Not Click on Links or Download Attachments:</strong> There may be malicious content.</li>
<li class=""><strong>Report the Email:</strong> Mark as spam/phishing and report to your organization's IT/security team.</li>
<li class=""><strong>Delete the Email:</strong> Remove it to prevent accidental interaction.</li>
<li class=""><strong>Educate Your Team:</strong> Make others aware of such scams to prevent future incidents.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-tips"><strong>Additional Tips:</strong><a href="https://secure-techie.com/blog/fraud-supply-prospect-josephine-braimah-transpacific-biochem-logistics-manager/#additional-tips" class="hash-link" aria-label="Direct link to additional-tips" title="Direct link to additional-tips" translate="no">​</a></h2>
<ul>
<li class=""><strong>Verify Unsolicited Proposals:</strong> Always verify the sender and their claims through official channels.</li>
<li class=""><strong>Be Skeptical of Confidentiality Requests:</strong> Scammers often use secrecy to avoid scrutiny.</li>
<li class=""><strong>Stay Informed:</strong> Keep up to date with common scam tactics and educate your team.</li>
</ul>
<p>Always exercise caution with unsolicited business proposals, especially those involving confidential information or large sums of money.</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Fraud" term="Fraud"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Fake: TCS is Hiring, Submit your CV, Your Application has been shortlisted]]></title>
        <id>https://secure-techie.com/blog/fake-tcs-is-hiring-submit-your-cv-your-application-has-been-shortlisted/</id>
        <link href="https://secure-techie.com/blog/fake-tcs-is-hiring-submit-your-cv-your-application-has-been-shortlisted/"/>
        <updated>2025-01-17T12:00:00.000Z</updated>
        <summary type="html"><![CDATA[TCS is Hiring, Submit your CV, Your Application has been shortlisted. You are Selected for TCS Interview, Submit your CV Click Here.]]></summary>
        <content type="html"><![CDATA[<p>TCS is Hiring, Submit your CV, Your Application has been shortlisted. You are Selected for TCS Interview, Submit your CV Click Here.</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/fake-tcs-is-hiring-submit-your-cv-your-application-has-been-shortlisted/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p>from: Interview Call <code>&amp;lt;info@skill.getujobs.com&amp;gt;</code><br>
<!-- -->reply-to: <code>info@skill.getujobs.com</code><br>
<!-- -->subject: TCS is Hiring, Submit your CV, Your Application has been shortlisted<br>
<!-- -->mailed-by: <code>skill.getujobs.com</code></p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-body">Email Body<a href="https://secure-techie.com/blog/fake-tcs-is-hiring-submit-your-cv-your-application-has-been-shortlisted/#email-body" class="hash-link" aria-label="Direct link to Email Body" title="Direct link to Email Body" translate="no">​</a></h3>
<p>Hi Jagdish</p>
<p>You are Selected for TCS Interview, Submit your CV Click Here</p>
<p>Dont miss to register</p>
<p>If you wish to opt out of all type of emails, click Unsubscribe.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/fake-tcs-is-hiring-submit-your-cv-your-application-has-been-shortlisted/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="judgment-this-email-is-a-phishingscam-attempt"><strong>Judgment: This Email is a Phishing/Scam Attempt</strong><a href="https://secure-techie.com/blog/fake-tcs-is-hiring-submit-your-cv-your-application-has-been-shortlisted/#judgment-this-email-is-a-phishingscam-attempt" class="hash-link" aria-label="Direct link to judgment-this-email-is-a-phishingscam-attempt" title="Direct link to judgment-this-email-is-a-phishingscam-attempt" translate="no">​</a></h3>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="reasons-for-identifying-as-phishingscam"><strong>Reasons for Identifying as Phishing/Scam</strong>:<a href="https://secure-techie.com/blog/fake-tcs-is-hiring-submit-your-cv-your-application-has-been-shortlisted/#reasons-for-identifying-as-phishingscam" class="hash-link" aria-label="Direct link to reasons-for-identifying-as-phishingscam" title="Direct link to reasons-for-identifying-as-phishingscam" translate="no">​</a></h3>
<ol>
<li class="">
<p><strong>Generic Sender Domain</strong>:</p>
<ul>
<li class="">The email is from <code>info@skill.getujobs.com</code>, which does not belong to TCS (Tata Consultancy Services). Legitimate communications from TCS would come from an official "@tcs.com" domain.</li>
</ul>
</li>
<li class="">
<p><strong>Unprofessional Email Content</strong>:</p>
<ul>
<li class="">The email lacks proper formatting, capitalization (e.g., "Dont miss to register"), and professionalism expected from a reputed organization like TCS.</li>
</ul>
</li>
<li class="">
<p><strong>No Personalized Details</strong>:</p>
<ul>
<li class="">The email uses "Hi Jagdish" without including a last name or specific details, which is characteristic of mass phishing attempts.</li>
</ul>
</li>
<li class="">
<p><strong>Suspicious Call-to-Action</strong>:</p>
<ul>
<li class="">The phrase "Submit your CV Click Here" is vague and redirects to an unknown link, likely intended to steal personal information or infect your device.</li>
</ul>
</li>
<li class="">
<p><strong>Unverified Unsubscribe Option</strong>:</p>
<ul>
<li class="">The unsubscribe link is likely another attempt to gather personal data or confirm the email as active.</li>
</ul>
</li>
<li class="">
<p><strong>No Detailed Job Information</strong>:</p>
<ul>
<li class="">Legitimate job offers from TCS or any professional company include detailed job descriptions, interview schedules, and proper contact information.</li>
</ul>
</li>
</ol>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="recommended-actions"><strong>Recommended Actions</strong>:<a href="https://secure-techie.com/blog/fake-tcs-is-hiring-submit-your-cv-your-application-has-been-shortlisted/#recommended-actions" class="hash-link" aria-label="Direct link to recommended-actions" title="Direct link to recommended-actions" translate="no">​</a></h3>
<ol>
<li class=""><strong>Do Not Click</strong> any links in the email or provide personal information.</li>
<li class=""><strong>Report the Email</strong> as phishing or spam in your email client.</li>
<li class=""><strong>Verify with TCS</strong>:<!-- -->
<ul>
<li class="">If you believe the email could be genuine, contact TCS through their official website or verified contact numbers to confirm.</li>
</ul>
</li>
<li class=""><strong>Delete the Email</strong> immediately after reporting.</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion"><strong>Conclusion</strong>:<a href="https://secure-techie.com/blog/fake-tcs-is-hiring-submit-your-cv-your-application-has-been-shortlisted/#conclusion" class="hash-link" aria-label="Direct link to conclusion" title="Direct link to conclusion" translate="no">​</a></h2>
<p>This email contains multiple signs of phishing or scam behavior. It is not a legitimate communication from TCS.</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Fake" term="Fake"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Phishing: Re: Priority Notice - Review Doc_Xerox File Shared to Dewiride:MDT _Ref.59b43df15d05ddab0f8bc1bd9cc74524]]></title>
        <id>https://secure-techie.com/blog/phishing-re-priority-notice-review-doc-xerox-file-shared-dewiride-mdt-ref-59b43df15d05ddab0f8bc1bd9cc74524/</id>
        <link href="https://secure-techie.com/blog/phishing-re-priority-notice-review-doc-xerox-file-shared-dewiride-mdt-ref-59b43df15d05ddab0f8bc1bd9cc74524/"/>
        <updated>2025-01-16T12:00:00.000Z</updated>
        <summary type="html"><![CDATA[Dear Support. You have a fax document from Xerox Scanner. Pages: 2 Full scanned PDF/HTML File. Remote ID: 34455191. Priority Notice - Review Doc_Xerox File Shared]]></summary>
        <content type="html"><![CDATA[<p>Dear Support. You have a fax document from Xerox Scanner. Pages: 2 Full scanned PDF/HTML File. Remote ID: 34455191. Priority Notice - Review Doc_Xerox File Shared</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/phishing-re-priority-notice-review-doc-xerox-file-shared-dewiride-mdt-ref-59b43df15d05ddab0f8bc1bd9cc74524/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p>From: <code>sammy@vataxattorney.com</code> <code>&amp;lt;sammy@vataxattorney.com&amp;gt;</code><br>
<!-- -->Subject: Re: Priority Notice - Review Doc_Xerox File Shared to Dewiride<!-- -->:MDT<!-- --> _Ref.59b43df15d05ddab0f8bc1bd9cc74524<br>
<!-- -->Attachments: IMPORTANT_DOCUMENT_Dewiride.htm</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-body">Email Body<a href="https://secure-techie.com/blog/phishing-re-priority-notice-review-doc-xerox-file-shared-dewiride-mdt-ref-59b43df15d05ddab0f8bc1bd9cc74524/#email-body" class="hash-link" aria-label="Direct link to Email Body" title="Direct link to Email Body" translate="no">​</a></h3>
<p>This sender has been verified from safe senders list.</p>
<p>New Fax Received For<br>
<code>support@dewiride.com</code></p>
<p>Dear Support. You have a fax document from Xerox Scanner.<br>
<!-- -->Pages: 2 Full scanned PDF/HTML File.</p>
<p>Received: 05:27:30 AM</p>
<p>Date: 1/15/2025</p>
<p>Remote ID: 34455191</p>
<p>For more information on Xerox products and solutions please visit: <code>https://www.xerox.com</code>
Workplace and Digital Pricing Solutions | Xerox</p>
<p>Workplace solutions, document management and digital printing techcologies to help organizations communicate, connect and work.</p>
<p><code>www.xerox.com</code></p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/phishing-re-priority-notice-review-doc-xerox-file-shared-dewiride-mdt-ref-59b43df15d05ddab0f8bc1bd9cc74524/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="judgment-this-email-is-a-phishingscam-attempt"><strong>Judgment: This Email is a Phishing/Scam Attempt</strong><a href="https://secure-techie.com/blog/phishing-re-priority-notice-review-doc-xerox-file-shared-dewiride-mdt-ref-59b43df15d05ddab0f8bc1bd9cc74524/#judgment-this-email-is-a-phishingscam-attempt" class="hash-link" aria-label="Direct link to judgment-this-email-is-a-phishingscam-attempt" title="Direct link to judgment-this-email-is-a-phishingscam-attempt" translate="no">​</a></h3>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="reasons-for-identifying-as-phishingscam"><strong>Reasons for Identifying as Phishing/Scam</strong>:<a href="https://secure-techie.com/blog/phishing-re-priority-notice-review-doc-xerox-file-shared-dewiride-mdt-ref-59b43df15d05ddab0f8bc1bd9cc74524/#reasons-for-identifying-as-phishingscam" class="hash-link" aria-label="Direct link to reasons-for-identifying-as-phishingscam" title="Direct link to reasons-for-identifying-as-phishingscam" translate="no">​</a></h3>
<ol>
<li class="">
<p><strong>Suspicious Sender Email</strong>:</p>
<ul>
<li class="">The sender's email, <code>sammy@vataxattorney.com</code>, does not match the claimed purpose or source related to Xerox or fax services.</li>
</ul>
</li>
<li class="">
<p><strong>Malicious Attachment</strong>:</p>
<ul>
<li class="">The attachment, "IMPORTANT_DOCUMENT_Dewiride.htm," is potentially harmful. Files with the <code>.htm</code> extension are often used to redirect recipients to fraudulent websites or execute malicious scripts.</li>
</ul>
</li>
<li class="">
<p><strong>Impersonal Greeting</strong>:</p>
<ul>
<li class="">The use of "Dear Support" instead of a specific name is a common tactic used in phishing emails to target a broad audience.</li>
</ul>
</li>
<li class="">
<p><strong>Fake Verification Claim</strong>:</p>
<ul>
<li class="">The line "This sender has been verified from safe senders list" is an attempt to create a false sense of trust and authenticity.</li>
</ul>
</li>
<li class="">
<p><strong>Poor Grammar and Spelling</strong>:</p>
<ul>
<li class="">Errors such as "techcologies" instead of "technologies" and awkward sentence structures reduce credibility and indicate a lack of professionalism.</li>
</ul>
</li>
<li class="">
<p><strong>Irrelevant Links</strong>:</p>
<ul>
<li class="">The email includes references to Xerox’s official website, which is irrelevant and seems to be added to give the email a false appearance of legitimacy.</li>
</ul>
</li>
</ol>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="recommended-actions"><strong>Recommended Actions</strong>:<a href="https://secure-techie.com/blog/phishing-re-priority-notice-review-doc-xerox-file-shared-dewiride-mdt-ref-59b43df15d05ddab0f8bc1bd9cc74524/#recommended-actions" class="hash-link" aria-label="Direct link to recommended-actions" title="Direct link to recommended-actions" translate="no">​</a></h3>
<ol>
<li class=""><strong>Do Not Open</strong> the attachment, as it may compromise your system or data.</li>
<li class=""><strong>Avoid Clicking</strong> any links within the email.</li>
<li class=""><strong>Report the Email</strong> as phishing or spam through your email platform.</li>
<li class=""><strong>Verify Communications</strong> with Xerox or other parties directly through official and verified contact methods.</li>
<li class=""><strong>Delete the Email</strong> immediately after taking the necessary precautions.</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion"><strong>Conclusion</strong>:<a href="https://secure-techie.com/blog/phishing-re-priority-notice-review-doc-xerox-file-shared-dewiride-mdt-ref-59b43df15d05ddab0f8bc1bd9cc74524/#conclusion" class="hash-link" aria-label="Direct link to conclusion" title="Direct link to conclusion" translate="no">​</a></h2>
<p>This email contains multiple indicators of phishing or scam activity and should not be trusted.</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Phishing" term="Phishing"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Phishing: Re: Advice - Remittance 86,000 Process for Dewiride:MDT _Ref.c0670a134f064f87e93021f312960a6d]]></title>
        <id>https://secure-techie.com/blog/phishing-re-advice-remittance-86000-process-dewiride-mdt-ref-c0670a134f064f87e93021f312960a6d/</id>
        <link href="https://secure-techie.com/blog/phishing-re-advice-remittance-86000-process-dewiride-mdt-ref-c0670a134f064f87e93021f312960a6d/"/>
        <updated>2025-01-15T12:00:00.000Z</updated>
        <summary type="html"><![CDATA[Dear Support. You have a fax document from Xerox Scanner. Pages: 2 Full scanned PDF/HTML File. Remote ID: 34455191. Advice - Remittance 86,000 Process.]]></summary>
        <content type="html"><![CDATA[<p>Dear Support. You have a fax document from Xerox Scanner. Pages: 2 Full scanned PDF/HTML File. Remote ID: 34455191. Advice - Remittance 86,000 Process.</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/phishing-re-advice-remittance-86000-process-dewiride-mdt-ref-c0670a134f064f87e93021f312960a6d/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p>From: <code>mg@sulmed.com.br</code> <code>&amp;lt;mg@sulmed.com.br&amp;gt;</code><br>
<!-- -->Subject: Re: Advice - Remittance 86,000 Process for Dewiride<!-- -->:MDT<!-- --> _Ref.c0670a134f064f87e93021f312960a6d<br>
<!-- -->Attachments: ELECTRONIC RECEIPT_Dewiride.htm</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-body">Email Body<a href="https://secure-techie.com/blog/phishing-re-advice-remittance-86000-process-dewiride-mdt-ref-c0670a134f064f87e93021f312960a6d/#email-body" class="hash-link" aria-label="Direct link to Email Body" title="Direct link to Email Body" translate="no">​</a></h3>
<p>This sender has been verified from safe senders list.</p>
<p>New Fax Received For<br>
<code>support@dewiride.com</code></p>
<p>Dear Support. You have a fax document from Xerox Scanner.<br>
<!-- -->Pages: 2 Full scanned PDF/HTML File.</p>
<p>Received: 12:49:21 PM</p>
<p>Date: 1/14/2025</p>
<p>Remote ID: 34455191</p>
<p>For more information on Xerox products and solutions please visit: <code>https://www.xerox.com</code>
Workplace and Digital Pricing Solutions | Xerox</p>
<p>Workplace solutions, document management and digital printing techcologies to help organizations communicate, connect and work.</p>
<p><code>www.xerox.com</code></p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/phishing-re-advice-remittance-86000-process-dewiride-mdt-ref-c0670a134f064f87e93021f312960a6d/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="analysis-of-the-email-a-phishing-or-malware-attempt"><strong>Analysis of the Email: A Phishing or Malware Attempt</strong><a href="https://secure-techie.com/blog/phishing-re-advice-remittance-86000-process-dewiride-mdt-ref-c0670a134f064f87e93021f312960a6d/#analysis-of-the-email-a-phishing-or-malware-attempt" class="hash-link" aria-label="Direct link to analysis-of-the-email-a-phishing-or-malware-attempt" title="Direct link to analysis-of-the-email-a-phishing-or-malware-attempt" translate="no">​</a></h3>
<hr>
<ol>
<li class="">
<p><strong>Suspicious Sender Address</strong>:</p>
<ul>
<li class="">The email is sent from "<code>mg@sulmed.com.br</code>," which does not seem connected to Xerox or Dewiride. The sender’s domain does not align with the content or purpose of the email.</li>
</ul>
</li>
<li class="">
<p><strong>Attachments</strong>:</p>
<ul>
<li class="">The attachment name, "ELECTRONIC RECEIPT_Dewiride.htm," is concerning. <code>.htm</code> files can contain malicious scripts that execute when opened, potentially compromising your device.</li>
</ul>
</li>
<li class="">
<p><strong>Generic Greeting</strong>:</p>
<ul>
<li class="">The salutation "Dear Support" is impersonal and a common tactic used in phishing emails to target organizations without addressing specific individuals.</li>
</ul>
</li>
<li class="">
<p><strong>Urgency and Lack of Specificity</strong>:</p>
<ul>
<li class="">The email attempts to create a sense of urgency by referencing a "fax document" and "new fax received." However, it lacks details about the content of the document.</li>
</ul>
</li>
<li class="">
<p><strong>Links to External Sites</strong>:</p>
<ul>
<li class="">The link to the Xerox website could be legitimate but is irrelevant in this context. Scammers often include real links to mask malicious intent.</li>
</ul>
</li>
<li class="">
<p><strong>Technical Errors</strong>:</p>
<ul>
<li class="">Grammar issues and awkward phrasing like "Full scanned PDF/HTML File" and "techcologies" detract from the email's credibility.</li>
</ul>
</li>
</ol>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-you-should-do"><strong>What You Should Do</strong><a href="https://secure-techie.com/blog/phishing-re-advice-remittance-86000-process-dewiride-mdt-ref-c0670a134f064f87e93021f312960a6d/#what-you-should-do" class="hash-link" aria-label="Direct link to what-you-should-do" title="Direct link to what-you-should-do" translate="no">​</a></h3>
<ol>
<li class="">
<p><strong>Do Not Open the Attachment</strong>:</p>
<ul>
<li class="">Avoid downloading or opening the <code>.htm</code> attachment, as it could contain malicious scripts or phishing attempts.</li>
</ul>
</li>
<li class="">
<p><strong>Do Not Click Any Links</strong>:</p>
<ul>
<li class="">Refrain from clicking the Xerox link in the email. Even legitimate-looking links can redirect to malicious websites.</li>
</ul>
</li>
<li class="">
<p><strong>Verify Independently</strong>:</p>
<ul>
<li class="">If you receive emails about sensitive matters like remittance or faxes, verify directly with the supposed sender using trusted contact details.</li>
</ul>
</li>
<li class="">
<p><strong>Mark as Spam/Phishing</strong>:</p>
<ul>
<li class="">Report the email as phishing in your email client to prevent further messages from this sender.</li>
</ul>
</li>
<li class="">
<p><strong>Check Your System</strong>:</p>
<ul>
<li class="">If you've already opened the attachment, run a full malware scan using reputable antivirus software.</li>
</ul>
</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion"><strong>Conclusion</strong><a href="https://secure-techie.com/blog/phishing-re-advice-remittance-86000-process-dewiride-mdt-ref-c0670a134f064f87e93021f312960a6d/#conclusion" class="hash-link" aria-label="Direct link to conclusion" title="Direct link to conclusion" translate="no">​</a></h2>
<p>This email is highly a <strong>phishing or malware scam</strong>. Do not interact with the attachment or links. Always confirm the authenticity of such emails with the purported sender or through secure, verified channels.</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Phishing" term="Phishing"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Phishing: Pending lncoming Tuesday, January 7, 2025:6:03:03 PM - Message ID:XVMQN3LPSBW5SEJ05IHC5IE3OU28D22UZ6XE]]></title>
        <id>https://secure-techie.com/blog/phishing-pending-incoming-tuesday-january-7-2025-message-id-xvmqn3lpsbw5sej05ihc5ie3ou28d22uz6xe/</id>
        <link href="https://secure-techie.com/blog/phishing-pending-incoming-tuesday-january-7-2025-message-id-xvmqn3lpsbw5sej05ihc5ie3ou28d22uz6xe/"/>
        <updated>2025-01-14T12:00:00.000Z</updated>
        <summary type="html"><![CDATA[We've restricted 7 incoming Inbox messages to info@dewiride.com due to server error.   We apologize for delay, check and retrieve them by clicking below link.]]></summary>
        <content type="html"><![CDATA[<p>We've restricted 7 incoming Inbox messages to <a href="mailto:info@dewiride.com" target="_blank" rel="noopener noreferrer" class="">info@dewiride.com</a> due to server error. We apologize for delay, check and retrieve them by clicking below link.</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/phishing-pending-incoming-tuesday-january-7-2025-message-id-xvmqn3lpsbw5sej05ihc5ie3ou28d22uz6xe/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p>From: lT | Messge Sender <code>&amp;lt;mkhan@lyonslaw.com.au&amp;gt;</code>
Subject: Pending lncoming Tuesday, January 7, 2025:6:03:03 PM - Message ID<!-- -->:XVMQN3LPSBW5SEJ05IHC5IE3OU28D22UZ6XE</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-body">Email Body<a href="https://secure-techie.com/blog/phishing-pending-incoming-tuesday-january-7-2025-message-id-xvmqn3lpsbw5sej05ihc5ie3ou28d22uz6xe/#email-body" class="hash-link" aria-label="Direct link to Email Body" title="Direct link to Email Body" translate="no">​</a></h3>
<p>Hello <a href="mailto:info@dewiride.com" target="_blank" rel="noopener noreferrer" class="">info@dewiride.com</a>,<br>
<!-- -->We've restricted 7 incoming Inbox messages to <a href="mailto:info@dewiride.com" target="_blank" rel="noopener noreferrer" class="">info@dewiride.com</a> due to server error. We apologize for delay, check and retrieve them by clicking below link to confirm and Retrieve your messages.<br>
<!-- -->Review Messages.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/phishing-pending-incoming-tuesday-january-7-2025-message-id-xvmqn3lpsbw5sej05ihc5ie3ou28d22uz6xe/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<p>This email is a phishing attempt aimed at obtaining sensitive information or exploiting the recipient.</p>
<ol>
<li class="">
<p><strong>Suspicious Sender Address</strong>:</p>
<ul>
<li class="">The email is sent from a domain (<code>lyonslaw.com.au</code>) that does not correspond to an email service provider or IT department. This mismatch raises suspicion.</li>
</ul>
</li>
<li class="">
<p><strong>Generic and Vague Content</strong>:</p>
<ul>
<li class="">The email refers to "7 incoming Inbox messages" without any specific details, such as sender information or subjects of the emails.</li>
</ul>
</li>
<li class="">
<p><strong>Call to Action with a Link</strong>:</p>
<ul>
<li class="">"Clicking below link" is a common phishing tactic to lure recipients into entering credentials or downloading malware. Legitimate organizations would rarely ask users to retrieve emails this way.</li>
</ul>
</li>
<li class="">
<p><strong>Unprofessional Formatting and Language</strong>:</p>
<ul>
<li class="">Errors such as "lT | Messge Sender" and "check and retrieve them by clicking below link" indicate poor grammar and spelling, which is uncommon in official communication.</li>
</ul>
</li>
<li class="">
<p><strong>Urgency Without Explanation</strong>:</p>
<ul>
<li class="">The message creates a false sense of urgency ("We've restricted 7 incoming Inbox messages") without providing a legitimate reason.</li>
</ul>
</li>
</ol>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-you-should-do"><strong>What You Should Do</strong><a href="https://secure-techie.com/blog/phishing-pending-incoming-tuesday-january-7-2025-message-id-xvmqn3lpsbw5sej05ihc5ie3ou28d22uz6xe/#what-you-should-do" class="hash-link" aria-label="Direct link to what-you-should-do" title="Direct link to what-you-should-do" translate="no">​</a></h3>
<ol>
<li class="">
<p><strong>Do Not Click the Link</strong>:</p>
<ul>
<li class="">Avoid clicking on any links in the email. These often lead to malicious websites designed to steal login credentials or distribute malware.</li>
</ul>
</li>
<li class="">
<p><strong>Mark as Spam/Phishing</strong>:</p>
<ul>
<li class="">Report the email as phishing in your email client to block further messages from this sender.</li>
</ul>
</li>
<li class="">
<p><strong>Verify Directly</strong>:</p>
<ul>
<li class="">If you're concerned about missing emails, log into your email account directly via its official website or application, not through the provided link.</li>
</ul>
</li>
<li class="">
<p><strong>Check Email Settings</strong>:</p>
<ul>
<li class="">Review your email account's security settings to ensure no unauthorized changes have been made.</li>
</ul>
</li>
<li class="">
<p><strong>Educate Yourself and Others</strong>:</p>
<ul>
<li class="">Learn to identify phishing emails and share this knowledge with colleagues or team members.</li>
</ul>
</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion"><strong>Conclusion</strong><a href="https://secure-techie.com/blog/phishing-pending-incoming-tuesday-january-7-2025-message-id-xvmqn3lpsbw5sej05ihc5ie3ou28d22uz6xe/#conclusion" class="hash-link" aria-label="Direct link to conclusion" title="Direct link to conclusion" translate="no">​</a></h2>
<p>This email is highly a <strong>phishing scam</strong>. Do not interact with it in any way. Always access your email account through official channels and verify any claims independently.</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Phishing" term="Phishing"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Scam: Attend To FILE No. 2910-110/CPM-5/2025]]></title>
        <id>https://secure-techie.com/blog/scam-attend-to-file-no-2910-110-cpm-5-2025/</id>
        <link href="https://secure-techie.com/blog/scam-attend-to-file-no-2910-110-cpm-5-2025/"/>
        <updated>2025-01-06T12:00:00.000Z</updated>
        <summary type="html"><![CDATA[This is to inform you of the alleged court order against your Internet IP traffic by the Central Bureau of Investigation, Department of Research and Anal]]></summary>
        <content type="html"><![CDATA[<p>This is to inform you of the alleged court order against your Internet IP traffic by the Central Bureau of Investigation, Department of Research and Anal</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/scam-attend-to-file-no-2910-110-cpm-5-2025/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p>from: Vivek Phansalkar CP <code>&amp;lt;cybercrime.police.gove.in-24@simmobilies.com&amp;gt;</code><br>
<!-- -->reply-to: <code>cp.vivek.mumbaipol@gmail.com</code><br>
<!-- -->subject: Attend To FILE No. 2910-110/CPM-5/2025<br>
<!-- -->mailed-by: <code>simmobilies.com</code></p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-body">Email Body<a href="https://secure-techie.com/blog/scam-attend-to-file-no-2910-110-cpm-5-2025/#email-body" class="hash-link" aria-label="Direct link to Email Body" title="Direct link to Email Body" translate="no">​</a></h3>
<p>Attend To FILE No. 2910-110/CPM-5/2025</p>
<p>Office Of The Commissioner Of Police</p>
<p>Cyber Crime Cell / Computer Centre</p>
<p>Mumbai</p>
<p>Police Investigation</p>
<p>This is to inform you of the alleged court order against your Internet IP traffic by the Central Bureau of Investigation, Department of Research and Anal</p>
<p>It is quite unfortunate to turn your official or private Internet into a juvenile pornographic movie cyber.</p>
<p>The Central Bureau of Investigation works in partnership with the Police Cybercrime Special Units in handling all complex and sensitive cases of cybercrime, especially when the victims are women and minor children.</p>
<p>Our laboratories are equipped with state of the art spider/crawling digital software and equipment, having forensic capabilities such as extraction of deleted data from hard drives and mobile phones, imaging and hash value calculation, forensic servers, and portable forensic tools for on-site examination, facility to extract data from latest Android or IOS as well as Chinese phones.</p>
<p>Based on the above, it is extremely difficult for any victim to consciously or unconsciously visit juvenile pornographic sites without being digitally captured.</p>
<p>More information or clarification on the court order will be made available to you upon receipt of your response within 24 hours; our office operates 24 hours / 7 days.</p>
<p>Be assured that serious legal action will be taken against you if you fail to respond to this notice within 24 hours of receipt.</p>
<p>Sincerely,</p>
<p>Vivek Phansalkar(CP)</p>
<p>Commissioner Of Police</p>
<p>Cybercrime Cell / Computer Centre</p>
<p>Mumbai</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/scam-attend-to-file-no-2910-110-cpm-5-2025/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<p>This email contains multiple indications that it is fraudulent. It appears to be a scare tactic designed to manipulate the recipient into responding, potentially leading to extortion or data theft.</p>
<hr>
<ol>
<li class="">
<p><strong>Unprofessional Sender Address</strong>:</p>
<ul>
<li class="">The sender's email domain (<code>simmobilies.com</code>) is unrelated to any official Indian government or police organization. Legitimate government emails use verified domains like <code>@nic.in</code> or <code>@gov.in</code>.</li>
</ul>
</li>
<li class="">
<p><strong>Poor Grammar and Formatting</strong>:</p>
<ul>
<li class="">The email contains awkward phrasing, grammatical errors, and incomplete sentences, such as "Department of Research and Anal."</li>
</ul>
</li>
<li class="">
<p><strong>Unrealistic Accusations</strong>:</p>
<ul>
<li class="">The vague allegation about accessing juvenile pornographic content is a common scare tactic used in phishing scams.</li>
<li class="">No official entity would accuse someone of such a crime via email.</li>
</ul>
</li>
<li class="">
<p><strong>Generic Content</strong>:</p>
<ul>
<li class="">The email lacks specific details, such as the recipient’s name, IP address, or dates related to the alleged activity. Official legal communications always include precise information.</li>
</ul>
</li>
<li class="">
<p><strong>Reply-To Address</strong>:</p>
<ul>
<li class="">The reply-to address (<code>cp.vivek.mumbaipol@gmail.com</code>) is a free Gmail account, not an official government email.</li>
</ul>
</li>
<li class="">
<p><strong>Threatening Tone</strong>:</p>
<ul>
<li class="">Scammers often use urgency and threats ("serious legal action will be taken against you if you fail to respond") to intimidate recipients into acting without thinking.</li>
</ul>
</li>
</ol>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-you-should-do"><strong>What You Should Do</strong><a href="https://secure-techie.com/blog/scam-attend-to-file-no-2910-110-cpm-5-2025/#what-you-should-do" class="hash-link" aria-label="Direct link to what-you-should-do" title="Direct link to what-you-should-do" translate="no">​</a></h3>
<ol>
<li class="">
<p><strong>Do Not Respond</strong>:</p>
<ul>
<li class="">Avoid engaging with the sender or replying to the email.</li>
</ul>
</li>
<li class="">
<p><strong>Verify with Authorities</strong>:</p>
<ul>
<li class="">If you're concerned, contact the Mumbai Police or Central Bureau of Investigation directly using their official contact information available on government websites.</li>
</ul>
</li>
<li class="">
<p><strong>Mark as Spam/Phishing</strong>:</p>
<ul>
<li class="">Report the email as phishing in your email client to block further communication from the sender.</li>
</ul>
</li>
<li class="">
<p><strong>Avoid Clicking Links or Downloading Attachments</strong>:</p>
<ul>
<li class="">The email does not contain visible links or attachments, but if it did, refrain from interacting with them.</li>
</ul>
</li>
<li class="">
<p><strong>Educate Yourself</strong>:</p>
<ul>
<li class="">Familiarize yourself with common scam tactics to avoid falling victim to such schemes in the future.</li>
</ul>
</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion"><strong>Conclusion</strong><a href="https://secure-techie.com/blog/scam-attend-to-file-no-2910-110-cpm-5-2025/#conclusion" class="hash-link" aria-label="Direct link to conclusion" title="Direct link to conclusion" translate="no">​</a></h2>
<p>This email is a <strong>scam</strong> attempting to manipulate you through fear. Official government entities do not communicate allegations of criminal activity in this manner. Ignore and report the email, and if in doubt, confirm directly with relevant authorities through official channels.</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Scam" term="Scam"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Fraud: WOODSIDE ENERGY COMPANY AUSTRALIA FOR SERIOUS CANDIDATES]]></title>
        <id>https://secure-techie.com/blog/fraud-woodside-energy-company-australia-for-serious-candidates/</id>
        <link href="https://secure-techie.com/blog/fraud-woodside-energy-company-australia-for-serious-candidates/"/>
        <updated>2024-12-19T12:00:00.000Z</updated>
        <summary type="html"><![CDATA[WOODSIDE ENERGY COMPANY AUSTRALIA FOR SERIOUS CANDIDATES LOOKING FOR JOB IN  WOODSIDE ENERGY COMPANY AUSTRALIA KINDLY SEND YOUR CV TO THE EMAIL.]]></summary>
        <content type="html"><![CDATA[<p>WOODSIDE ENERGY COMPANY AUSTRALIA FOR SERIOUS CANDIDATES LOOKING FOR JOB IN WOODSIDE ENERGY COMPANY AUSTRALIA KINDLY SEND YOUR CV TO THE EMAIL.</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/fraud-woodside-energy-company-australia-for-serious-candidates/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p>from: <code>fs923a@op.pl</code><br>
<!-- -->to: <code>australia@careers-woodside.com</code><br>
<!-- -->subject: Application<br>
<!-- -->mailed-by: <code>op.pl</code></p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-body">Email Body<a href="https://secure-techie.com/blog/fraud-woodside-energy-company-australia-for-serious-candidates/#email-body" class="hash-link" aria-label="Direct link to Email Body" title="Direct link to Email Body" translate="no">​</a></h2>
<p>DEAR CANDIDATE,</p>
<p>WOODSIDE ENERGY COMPANY AUSTRALIA FOR SERIOUS CANDIDATES LOOKING FOR JOB IN WOODSIDE ENERGY COMPANY AUSTRALIA KINDLY SEND YOUR CV TO THE EMAIL(<code>australia@careers-woodside.com</code></p>
<p>Thank you for your time. We look forward to receiving your application.</p>
<p>Job Positions</p>
<p>• Electrical Technician Engineer • Process Engineering Assistant • Store Keeper •</p>
<p>• Accounting • Civil Engineering, • Mechanical Engineering • Site Engineering • Electrical</p>
<p>Engineering • Medical Doctor or Nurse • Project Manager • Site manager • Store Manager.</p>
<p>• Civil Site Engineering • Computer operator • Accountant • Marketing • Information Technology.</p>
<p>• Supervision • Site Supervision • Quality Control • Quality Engineering • Maintenance Engineering.</p>
<p>KINDLY SEND YOUR CV TO THE EMAIL(<code>australia@careers-woodside.com</code><br>
<!-- -->WORKING HOUR = 8 HOURS<br>
<!-- -->VISA TYPE: 3 YEARS WORKING PERMIT<br>
<!-- -->CONTRACT: 3 YEARS DEPENDS ON EMPLOYEE</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/fraud-woodside-energy-company-australia-for-serious-candidates/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<p>This email exhibits multiple signs of a <strong>job scam</strong> attempting to prey on individuals seeking employment. Below is a detailed breakdown of its red flags and suggested actions.</p>
<hr>
<ol>
<li class="">
<p><strong>Unprofessional Email Address</strong>:</p>
<ul>
<li class="">The sender's email (<code>fs923a@op.pl</code>) is unrelated to Woodside Energy, a legitimate Australian energy company. Companies use official domains for recruitment, such as <code>@woodside.com</code> or <code>@woodside.com.au</code>.</li>
</ul>
</li>
<li class="">
<p><strong>Generic Content</strong>:</p>
<ul>
<li class="">The email does not address the recipient personally or provide specific details about the job application process.</li>
<li class="">It lists a broad range of job roles without relevance to the energy industry, making it suspicious.</li>
</ul>
</li>
<li class="">
<p><strong>Caps Lock and Poor Formatting</strong>:</p>
<ul>
<li class="">Excessive use of capital letters and poor grammar are hallmarks of scam emails.</li>
<li class="">Professional communication from a reputable company would maintain proper language and tone.</li>
</ul>
</li>
<li class="">
<p><strong>Unverified Contact Email</strong>:</p>
<ul>
<li class="">The recruitment email provided (<code>australia@careers-woodside.com</code>) is not associated with Woodside Energy. Scammers often use lookalike emails to deceive victims.</li>
</ul>
</li>
<li class="">
<p><strong>Suspicious Details</strong>:</p>
<ul>
<li class="">Mention of visa sponsorship, 3-year contracts, and broad job categories without specifics indicate an unrealistic offer.</li>
</ul>
</li>
<li class="">
<p><strong>No Official Process or Application Portal</strong>:</p>
<ul>
<li class="">Reputable companies have structured hiring processes and official application portals. This email bypasses those processes entirely.</li>
</ul>
</li>
</ol>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-this-likely-means"><strong>What This Likely Means</strong><a href="https://secure-techie.com/blog/fraud-woodside-energy-company-australia-for-serious-candidates/#what-this-likely-means" class="hash-link" aria-label="Direct link to what-this-likely-means" title="Direct link to what-this-likely-means" translate="no">​</a></h3>
<ul>
<li class=""><strong>Scam Purpose</strong>:<!-- -->
<ul>
<li class="">The sender may aim to collect personal information (e.g., CV, contact details).</li>
<li class="">They might later demand money for processing fees, visas, or other fabricated expenses.</li>
<li class="">Alternatively, this could be a phishing attempt to gain access to sensitive data.</li>
</ul>
</li>
</ul>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-you-should-do"><strong>What You Should Do</strong><a href="https://secure-techie.com/blog/fraud-woodside-energy-company-australia-for-serious-candidates/#what-you-should-do" class="hash-link" aria-label="Direct link to what-you-should-do" title="Direct link to what-you-should-do" translate="no">​</a></h3>
<ol>
<li class="">
<p><strong>Do Not Respond</strong>:</p>
<ul>
<li class="">Avoid replying to the email or sending your CV or personal details.</li>
</ul>
</li>
<li class="">
<p><strong>Verify the Legitimacy</strong>:</p>
<ul>
<li class="">Visit the official <strong>Woodside Energy</strong> website (<code>https://www.woodside.com/</code>) and check their careers section for genuine job postings.</li>
<li class="">Contact Woodside Energy directly to confirm the authenticity of the recruitment effort.</li>
</ul>
</li>
<li class="">
<p><strong>Mark as Spam or Phishing</strong>:</p>
<ul>
<li class="">Report the email as spam or phishing in your email client to prevent further contact.</li>
</ul>
</li>
<li class="">
<p><strong>Protect Your Information</strong>:</p>
<ul>
<li class="">If you've already shared your CV or details, monitor your accounts for suspicious activity. Consider using identity theft protection services.</li>
</ul>
</li>
<li class="">
<p><strong>Educate Yourself and Others</strong>:</p>
<ul>
<li class="">Share this incident with friends and family to help them recognize similar scams.</li>
</ul>
</li>
</ol>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion"><strong>Conclusion</strong><a href="https://secure-techie.com/blog/fraud-woodside-energy-company-australia-for-serious-candidates/#conclusion" class="hash-link" aria-label="Direct link to conclusion" title="Direct link to conclusion" translate="no">​</a></h3>
<p>This email is almost certainly a <strong>job scam</strong>. Reputable companies like Woodside Energy do not use unprofessional email addresses or vague, mass-distributed emails for recruitment. Ignore it, verify opportunities through official channels, and report the sender.</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Fraud" term="Fraud"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Scam: Network Service Company which is the domain name registration center in China]]></title>
        <id>https://secure-techie.com/blog/scam-network-service-company-domain-name-registration-center-in-china/</id>
        <link href="https://secure-techie.com/blog/scam-network-service-company-domain-name-registration-center-in-china/"/>
        <updated>2024-12-04T12:00:00.000Z</updated>
        <summary type="html"><![CDATA[Network Service Company which is the domain name registration center in China., we received an application from Huadai Holdings Ltd requested.]]></summary>
        <content type="html"><![CDATA[<p>Network Service Company which is the domain name registration center in China., we received an application from Huadai Holdings Ltd requested.</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/scam-network-service-company-domain-name-registration-center-in-china/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p>From: <code>elaine.weng@mgcai.cn</code><br>
<!-- -->Subject: <code>Domain Name</code></p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-body">Email Body<a href="https://secure-techie.com/blog/scam-network-service-company-domain-name-registration-center-in-china/#email-body" class="hash-link" aria-label="Direct link to Email Body" title="Direct link to Email Body" translate="no">​</a></h3>
<p>Dear CEO,</p>
<p>(If you are not the person who is in charge of this, please forward this to your CEO, because this is urgent. Thanks!)</p>
<p>We are a Network Service Company which is the domain name registration center in China., we received an application from Huadai Holdings Ltd requested” <code>Domain Name</code> ”as their internet keyword and China (CN) domain names. But after checking it, we find this name conflict with your company name or trademark. In order to deal with this matter better, it’s necessary to send email to you and confirm whether this company is associated with your company or not?</p>
<p>Best Regards,</p>
<p>Elaine Weng</p>
<p>Tel:Tel:+86.559 51454830</p>
<p>Fax:Tel:+86.559 51454830</p>
<p>Address<!-- -->:No<!-- -->.1385 Xiyou Rd,High-tech industry, Hefei, China</p>
<p><code>www.mgcai.org.cn</code></p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/scam-network-service-company-domain-name-registration-center-in-china/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="analysis-of-the-email-likely-a-domain-name-scam"><strong>Analysis of the Email: Likely a Domain Name Scam</strong><a href="https://secure-techie.com/blog/scam-network-service-company-domain-name-registration-center-in-china/#analysis-of-the-email-likely-a-domain-name-scam" class="hash-link" aria-label="Direct link to analysis-of-the-email-likely-a-domain-name-scam" title="Direct link to analysis-of-the-email-likely-a-domain-name-scam" translate="no">​</a></h3>
<p>This email fits the pattern of a <strong>domain name scam</strong> where a sender claims that a third party is attempting to register a domain name similar to your company's name or trademark. Here’s a breakdown of the red flags and suggested actions.</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags-in-the-email"><strong>Red Flags in the Email</strong><a href="https://secure-techie.com/blog/scam-network-service-company-domain-name-registration-center-in-china/#red-flags-in-the-email" class="hash-link" aria-label="Direct link to red-flags-in-the-email" title="Direct link to red-flags-in-the-email" translate="no">​</a></h3>
<ol>
<li class="">
<p><strong>Urgent Tone and Escalation</strong>:</p>
<ul>
<li class="">The email insists that the recipient take immediate action by contacting the sender. This urgency is a common tactic in scams.</li>
</ul>
</li>
<li class="">
<p><strong>No Specific Details</strong>:</p>
<ul>
<li class="">The email does not provide specific details about the domain name in question. It only vaguely mentions "Domain Name" and does not identify your company by name.</li>
</ul>
</li>
<li class="">
<p><strong>Unverified Entity</strong>:</p>
<ul>
<li class="">The sender claims to be from a domain registration service but does not belong to a known or credible organization. The provided URL and contact information lack legitimacy.</li>
</ul>
</li>
<li class="">
<p><strong>Push to Engage</strong>:</p>
<ul>
<li class="">The sender pressures the recipient to reply and confirm whether the alleged third-party applicant is associated with their company. This is often a precursor to offering overpriced domain registration services.</li>
</ul>
</li>
<li class="">
<p><strong>Generic Address</strong>:</p>
<ul>
<li class="">The physical address and contact details appear generic and unverifiable.</li>
</ul>
</li>
<li class="">
<p><strong>Suspicious Domain Name</strong>:</p>
<ul>
<li class="">The sender's email domain (<code>mgcai.cn</code>) and website (<code>www.mgcai.org.cn</code>) do not match reputable domain registration services.</li>
</ul>
</li>
</ol>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-this-likely-means"><strong>What This Likely Means</strong><a href="https://secure-techie.com/blog/scam-network-service-company-domain-name-registration-center-in-china/#what-this-likely-means" class="hash-link" aria-label="Direct link to what-this-likely-means" title="Direct link to what-this-likely-means" translate="no">​</a></h3>
<ul>
<li class="">This is likely a <strong>phishing attempt or scam</strong> designed to:<!-- -->
<ul>
<li class="">Trick you into registering unnecessary domain names at inflated prices.</li>
<li class="">Extract personal or company information.</li>
<li class="">Scam your company into paying for fake services.</li>
</ul>
</li>
</ul>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-you-should-do"><strong>What You Should Do</strong><a href="https://secure-techie.com/blog/scam-network-service-company-domain-name-registration-center-in-china/#what-you-should-do" class="hash-link" aria-label="Direct link to what-you-should-do" title="Direct link to what-you-should-do" translate="no">​</a></h3>
<ol>
<li class="">
<p><strong>Do Not Reply</strong>:</p>
<ul>
<li class="">Avoid engaging with the sender. Replying confirms that your email address is active and may lead to further harassment.</li>
</ul>
</li>
<li class="">
<p><strong>Verify Domain Status Independently</strong>:</p>
<ul>
<li class="">If you are concerned about the domain name, verify its availability by visiting a legitimate domain registrar (e.g., GoDaddy, Namecheap) or contacting a trusted provider.</li>
</ul>
</li>
<li class="">
<p><strong>Report the Email</strong>:</p>
<ul>
<li class="">Mark the email as spam/phishing in your inbox.</li>
<li class="">Report the sender to your email service provider.</li>
</ul>
</li>
<li class="">
<p><strong>Ignore Pressure to Act Quickly</strong>:</p>
<ul>
<li class="">Scammers rely on creating urgency. Take your time to evaluate the situation with trusted sources.</li>
</ul>
</li>
<li class="">
<p><strong>Secure Your Brand's Domains</strong>:</p>
<ul>
<li class="">If protecting your brand's name is a concern, consider registering common variations of your company's name through a legitimate registrar.</li>
</ul>
</li>
<li class="">
<p><strong>Consult Legal Counsel or IT Experts</strong>:</p>
<ul>
<li class="">If you're unsure about the legitimacy of this email, seek professional advice before taking action.</li>
</ul>
</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion"><strong>Conclusion</strong><a href="https://secure-techie.com/blog/scam-network-service-company-domain-name-registration-center-in-china/#conclusion" class="hash-link" aria-label="Direct link to conclusion" title="Direct link to conclusion" translate="no">​</a></h2>
<p>This email is highly likely a <strong>scam</strong>. It uses fear and urgency to pressure you into unnecessary actions. Ignore it, verify your domain concerns independently, and strengthen your domain protection strategy with trusted services.</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Scam" term="Scam"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Sextortion Scam: Intrusion Alert - Transfer $1300 USD to my BTC crypto wallet]]></title>
        <id>https://secure-techie.com/blog/sextortion-scam-intrusion-alert-transfer-1300-usd-to-my-btc-crypto-wallet/</id>
        <link href="https://secure-techie.com/blog/sextortion-scam-intrusion-alert-transfer-1300-usd-to-my-btc-crypto-wallet/"/>
        <updated>2024-11-18T12:00:00.000Z</updated>
        <summary type="html"><![CDATA[I want to apprise you about a very dreadful condition for you. However, you can gain from it, if you will react intelligently. Have you learned about Pegasus?]]></summary>
        <content type="html"><![CDATA[<p>I want to apprise you about a very dreadful condition for you. However, you can gain from it, if you will react intelligently. Have you learned about Pegasus?</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/sextortion-scam-intrusion-alert-transfer-1300-usd-to-my-btc-crypto-wallet/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p>From: Jamal Bryant <code>&amp;lt;greenpeace@jomablue.com&amp;gt;</code><br>
<!-- -->Subject: Intrusion Alert</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-body">Email Body<a href="https://secure-techie.com/blog/sextortion-scam-intrusion-alert-transfer-1300-usd-to-my-btc-crypto-wallet/#email-body" class="hash-link" aria-label="Direct link to Email Body" title="Direct link to Email Body" translate="no">​</a></h3>
<p>Good day!</p>
<p>Hello!</p>
<p>I want to apprise you about a very dreadful condition for you. However, you can gain from it, if you will react intelligently.</p>
<p>Have you learned about Pegasus? This is a spyware tool that places on computers and smartphones and allows hackers to monitor the activity of device users. It provides access to your webcam, messengers, email accounts, voice logs, etc. It works well on Windows, Android, iOS. I suppose, you by now figured out where I am going.</p>
<p>It's been some months since I installed it on all your machines because of you weren't quite discriminating about what URLs to click on on the internet. During this period, I've discovered about every dimensions of your intimate life, but one is of special significance to me.</p>
<p>I've recorded various videos of you jerking off to exceedingly dubious porn videos. Given that the "controversial" type is almost always the same, I can conclude that you have sick fetish.</p>
<p>I also stored each your important files - documents, pictures, videos, etc. - to a remote server.</p>
<p>I doubt you'd want your companions, loved ones, and co-workers to know about it. However, I can achieve it in a few clicks. All entry in your contact book will abruptly receive these videos - on Whats-App, on Telegram, on Skype, on message - anywhere. It is going to be a deluge that will erase everything in its course, and first of all, your past situation. Do not think of yourself as an innocent target. No one knows where your corruption might go in the future, so regard this a kind of merited punishment to halt you. Sooner delayed than forever. I'm some kind of Deity who observes everything. However, do not freak out. As we know, Deity is forgiving and pardon-giving, and so do I. Nonetheless my forgiveness is not free.</p>
<p>Transfer $1300 USD to my BTC crypto wallet:
1FZ8GCyQNjcwnbg98egE1vrE294Hb73SCo</p>
<p>Let's acknowledge it, that's a fairly insignificant sum in current environment.</p>
<p>At what time I obtain validation of the deal, I will irrevocably erase every clips jeopardizing you, uninstall Pegasus from all of your devices, and disappear from your life. You can be confident - my gain is only money. Otherwise, I wouldn't be writing to you, nonetheless destroy your existence without a statement in a second.</p>
<p>I'll be notified when you open my e-mail, and from that moment, you have exactly 48 hours to send the money. If digital currencies are new territory for you, don't worry; it is very simple. Just search "crypto market" and then it will be no more challenging than acquiring some pointless stuff on Amazon.</p>
<p>I firmly caution you against the following:</p>
<ul>
<li class="">
<p>Do not answer to this correspondence. I forwarded it from a disposable e-mail so I am invisible.</p>
</li>
<li class="">
<p>Do not get in touch with the authorities. I have control to each your devices, and whenever I find out you went to the cops, recordings will be disseminated.</p>
</li>
<li class="">
<p>Don't try to reset or eliminate your machinery. As I noted above: I am monitoring each your actions, so you either consent to these terms or the videos are published.</p>
</li>
</ul>
<p>Also on, do not neglect that digital currencies are discreet, so it's unlikely to trace me using the given address. Good wishes, my perverted friend. I trust you will arrive at the right choice and this is the final time we hear from each other.</p>
<p>And a couple of friendly guidance: from now on, don't be so careless about your digital security.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/sextortion-scam-intrusion-alert-transfer-1300-usd-to-my-btc-crypto-wallet/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="analysis-of-the-email-scam-and-extortion-attempt"><strong>Analysis of the Email: Scam and Extortion Attempt</strong><a href="https://secure-techie.com/blog/sextortion-scam-intrusion-alert-transfer-1300-usd-to-my-btc-crypto-wallet/#analysis-of-the-email-scam-and-extortion-attempt" class="hash-link" aria-label="Direct link to analysis-of-the-email-scam-and-extortion-attempt" title="Direct link to analysis-of-the-email-scam-and-extortion-attempt" translate="no">​</a></h3>
<p>This email is a classic <strong>sextortion scam</strong>, where the sender attempts to intimidate and blackmail the recipient by claiming they have compromising material. Let’s break down the red flags and provide a safe course of action.</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags-in-the-email"><strong>Red Flags in the Email</strong><a href="https://secure-techie.com/blog/sextortion-scam-intrusion-alert-transfer-1300-usd-to-my-btc-crypto-wallet/#red-flags-in-the-email" class="hash-link" aria-label="Direct link to red-flags-in-the-email" title="Direct link to red-flags-in-the-email" translate="no">​</a></h3>
<ol>
<li class="">
<p><strong>Use of Fear and Urgency</strong>:</p>
<ul>
<li class="">The sender claims to have compromising videos and threatens to share them with contacts. This is meant to pressure the recipient into paying quickly without verifying the claims.</li>
</ul>
</li>
<li class="">
<p><strong>Technical Jargon to Sound Credible</strong>:</p>
<ul>
<li class="">Mention of "Pegasus" spyware is intended to make the threat sound plausible. While Pegasus is real, it is not used in this way and would be far beyond the scope of an individual extortionist.</li>
</ul>
</li>
<li class="">
<p><strong>Unverifiable Claims</strong>:</p>
<ul>
<li class="">The sender has no proof of their allegations (e.g., no evidence attached to the email). This is typical in such scams.</li>
</ul>
</li>
<li class="">
<p><strong>Bitcoin Payment Demand</strong>:</p>
<ul>
<li class="">Requests for cryptocurrency payments are a hallmark of online scams because transactions are untraceable.</li>
</ul>
</li>
<li class="">
<p><strong>Disposable Email Address</strong>:</p>
<ul>
<li class="">The sender uses a temporary or fake email account (<code>greenpeace@jomablue.com</code>) and claims to be untraceable, further indicating fraudulent intent.</li>
</ul>
</li>
<li class="">
<p><strong>Threats to Avoid Contacting Authorities</strong>:</p>
<ul>
<li class="">Legitimate cases wouldn’t discourage recipients from reporting to authorities. This is an intimidation tactic.</li>
</ul>
</li>
<li class="">
<p><strong>Generic Content</strong>:</p>
<ul>
<li class="">The email doesn't include personal details (e.g., your name or specific identifiers), indicating it is mass-distributed.</li>
</ul>
</li>
</ol>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-you-should-do"><strong>What You Should Do</strong><a href="https://secure-techie.com/blog/sextortion-scam-intrusion-alert-transfer-1300-usd-to-my-btc-crypto-wallet/#what-you-should-do" class="hash-link" aria-label="Direct link to what-you-should-do" title="Direct link to what-you-should-do" translate="no">​</a></h3>
<ol>
<li class="">
<p><strong>Do Not Respond</strong>:</p>
<ul>
<li class="">Never reply or engage with the sender. This could encourage further harassment.</li>
</ul>
</li>
<li class="">
<p><strong>Do Not Pay</strong>:</p>
<ul>
<li class="">Paying will only confirm that you are a viable target, likely leading to more extortion attempts.</li>
</ul>
</li>
<li class="">
<p><strong>Verify Claims</strong>:</p>
<ul>
<li class="">Check your devices for any unusual activity. It's highly unlikely the claims are true, but run a trusted antivirus/anti-malware scan to rule out any compromise.</li>
</ul>
</li>
<li class="">
<p><strong>Strengthen Security</strong>:</p>
<ul>
<li class="">Change your passwords immediately.</li>
<li class="">Enable two-factor authentication (2FA) on all accounts.</li>
<li class="">Update your devices with the latest security patches.</li>
</ul>
</li>
<li class="">
<p><strong>Report the Email</strong>:</p>
<ul>
<li class="">Report this email to your email provider as phishing or spam.</li>
<li class="">File a complaint with your country’s cybercrime unit or local authorities.</li>
</ul>
</li>
<li class="">
<p><strong>Ignore Deadlines</strong>:</p>
<ul>
<li class="">The 48-hour countdown is fake. It is a scare tactic to prompt impulsive decisions.</li>
</ul>
</li>
</ol>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-notes"><strong>Additional Notes</strong><a href="https://secure-techie.com/blog/sextortion-scam-intrusion-alert-transfer-1300-usd-to-my-btc-crypto-wallet/#additional-notes" class="hash-link" aria-label="Direct link to additional-notes" title="Direct link to additional-notes" translate="no">​</a></h3>
<ul>
<li class=""><strong>This is a widespread scam</strong>:
Thousands of people worldwide have received similar emails. The sender has no actual evidence or access to your devices.</li>
<li class=""><strong>If you’re still worried</strong>:
Seek assistance from a trusted IT professional to check your systems for vulnerabilities.</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion"><strong>Conclusion</strong><a href="https://secure-techie.com/blog/sextortion-scam-intrusion-alert-transfer-1300-usd-to-my-btc-crypto-wallet/#conclusion" class="hash-link" aria-label="Direct link to conclusion" title="Direct link to conclusion" translate="no">​</a></h2>
<p>This email is an extortion scam with no basis in fact. Ignore it, enhance your digital security, and report it to authorities. You are not in any real danger.</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Extortion" term="Extortion"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Phishing: Unrecognized device signed in to your Stripe account]]></title>
        <id>https://secure-techie.com/blog/phishing-unrecognized-device-signed-in-to-your-stripe-account/</id>
        <link href="https://secure-techie.com/blog/phishing-unrecognized-device-signed-in-to-your-stripe-account/"/>
        <updated>2024-11-09T12:00:00.000Z</updated>
        <summary type="html"><![CDATA[We don't recognize the device that was just used to sign in to your Stripe account. If this was you, you don't need to do anything. If you don't recognize it, please let us know.]]></summary>
        <content type="html"><![CDATA[<p>We don't recognize the device that was just used to sign in to your Stripe account. If this was you, you don't need to do anything. If you don't recognize it, please let us know.</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/phishing-unrecognized-device-signed-in-to-your-stripe-account/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p>From: Stripe <code>&amp;lt;Do_Not_Reply@uhigherdev.com&amp;gt;</code><br>
<!-- -->Sender: <code>Do_Not_Reply@uhigherdev.com</code><br>
<!-- -->Subject: Unrecognized device signed in to your Stripe account</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-body">Email Body<a href="https://secure-techie.com/blog/phishing-unrecognized-device-signed-in-to-your-stripe-account/#email-body" class="hash-link" aria-label="Direct link to Email Body" title="Direct link to Email Body" translate="no">​</a></h3>
<p>We don't recognize the device that was just used to sign in to your Stripe account. If this was you, you don't need to do anything. If you don't recognize it, please let us know.</p>
<p>Platform: icon Edge browser on Windows device<br>
<!-- -->Device location: Salina, Kansas, United States (98.186.189.108)<br>
<!-- -->Time: Nov 05, 2024 at 12:50:33 PM CDT</p>
<p>I don't recognize this device</p>
<p>If you have any questions or need any help, please reach out to Stripe support and let us know.</p>
<p>Stripe, 354 Oyster Point Blvd, South San Francisco, CA 94080</p>
<p>Need to refer to this message? Use this ID: em_ikeihzdeoajksaue7f5wtaqqhmwhja</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/phishing-unrecognized-device-signed-in-to-your-stripe-account/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<p>This email is suspicious and likely a phishing attempt due to the following red flags:</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="1-suspicious-sender-domain"><strong>1. Suspicious Sender Domain</strong><a href="https://secure-techie.com/blog/phishing-unrecognized-device-signed-in-to-your-stripe-account/#1-suspicious-sender-domain" class="hash-link" aria-label="Direct link to 1-suspicious-sender-domain" title="Direct link to 1-suspicious-sender-domain" translate="no">​</a></h3>
<ul>
<li class=""><strong>Sender Address</strong>: The email address is <code>Do_Not_Reply@uhigherdev.com</code>, which is not a legitimate Stripe domain. Official Stripe notifications would come from a <code>@stripe.com</code> or a closely associated domain (like <code>@email.stripe.com</code>), not from <code>uhigherdev.com</code>.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="2-urgent-language-and-unrecognized-device-alert"><strong>2. Urgent Language and Unrecognized Device Alert</strong><a href="https://secure-techie.com/blog/phishing-unrecognized-device-signed-in-to-your-stripe-account/#2-urgent-language-and-unrecognized-device-alert" class="hash-link" aria-label="Direct link to 2-urgent-language-and-unrecognized-device-alert" title="Direct link to 2-urgent-language-and-unrecognized-device-alert" translate="no">​</a></h3>
<ul>
<li class=""><strong>Unrecognized Device Message</strong>: Phishing emails often try to create a sense of urgency to make recipients act quickly. This message mentions an unfamiliar location and device to prompt immediate action.</li>
<li class=""><strong>Location and IP Address</strong>: Although it includes location information (Salina, Kansas) and an IP address, this does not verify the email's legitimacy. Phishers often use random or spoofed IP addresses and locations to make emails seem real.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="3-generic-i-dont-recognize-this-device-link"><strong>3. Generic "I don't recognize this device" Link</strong><a href="https://secure-techie.com/blog/phishing-unrecognized-device-signed-in-to-your-stripe-account/#3-generic-i-dont-recognize-this-device-link" class="hash-link" aria-label="Direct link to 3-generic-i-dont-recognize-this-device-link" title="Direct link to 3-generic-i-dont-recognize-this-device-link" translate="no">​</a></h3>
<ul>
<li class=""><strong>"I don't recognize this device" Link</strong>: This phrase is often a hyperlink in phishing emails that directs the recipient to a fake login page to steal credentials. Stripe would typically prompt users to secure their accounts directly on their platform, not through suspicious links.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="4-unofficial-domain-and-lack-of-verification-details"><strong>4. Unofficial Domain and Lack of Verification Details</strong><a href="https://secure-techie.com/blog/phishing-unrecognized-device-signed-in-to-your-stripe-account/#4-unofficial-domain-and-lack-of-verification-details" class="hash-link" aria-label="Direct link to 4-unofficial-domain-and-lack-of-verification-details" title="Direct link to 4-unofficial-domain-and-lack-of-verification-details" translate="no">​</a></h3>
<ul>
<li class=""><strong>Domain</strong>: The <code>uhigherdev.com</code> domain has no association with Stripe and is likely used to disguise the phishing email.</li>
<li class=""><strong>Lack of Direct Contact Options</strong>: The email encourages users to "reach out to Stripe support," but it doesn’t include official Stripe contact information or secure options. Legitimate companies would provide verified contact methods, such as a link to their support page.</li>
</ul>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="recommendations"><strong>Recommendations</strong>:<a href="https://secure-techie.com/blog/phishing-unrecognized-device-signed-in-to-your-stripe-account/#recommendations" class="hash-link" aria-label="Direct link to recommendations" title="Direct link to recommendations" translate="no">​</a></h3>
<ol>
<li class=""><strong>Do Not Click Links or Reply</strong>: Avoid interacting with any links or buttons, as they may lead to a phishing website designed to capture login credentials or sensitive information.</li>
<li class=""><strong>Contact Stripe Directly</strong>: If you’re concerned about account security, log in to your Stripe account by manually typing <code>stripe.com</code> into your browser and checking for any security alerts.</li>
<li class=""><strong>Report and Delete the Email</strong>: Mark this email as phishing in your email client to help protect others, and delete it afterward.</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion"><strong>Conclusion</strong>:<a href="https://secure-techie.com/blog/phishing-unrecognized-device-signed-in-to-your-stripe-account/#conclusion" class="hash-link" aria-label="Direct link to conclusion" title="Direct link to conclusion" translate="no">​</a></h2>
<p>This email is likely a phishing attempt. The use of a non-Stripe domain, attempt to alarm the recipient with a security notice, and absence of verified contact information all suggest it is designed to steal sensitive account information.</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Phishing" term="Phishing"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Scam: Re: ⚖️Attend To FILE No. 2910-110/CPM-5/2024 ⚖️]]></title>
        <id>https://secure-techie.com/blog/scam-re-attend-to-file-no-2910-110-cpm-5-2024/</id>
        <link href="https://secure-techie.com/blog/scam-re-attend-to-file-no-2910-110-cpm-5-2024/"/>
        <updated>2024-11-05T12:00:00.000Z</updated>
        <summary type="html"><![CDATA[It has come to our attention that you have been in possession of and/or viewing material that depicts minors engaged in sexually explicit conduct.]]></summary>
        <content type="html"><![CDATA[<p>It has come to our attention that you have been in possession of and/or viewing material that depicts minors engaged in sexually explicit conduct.</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/scam-re-attend-to-file-no-2910-110-cpm-5-2024/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p>from: Vivek Phansalkar CP <code>&amp;lt;inccc.gov.units@dclicinddplcnews.store&amp;gt;</code>, AA <code>&amp;lt;ministryofwomenchilddevlopment-3@dclicinddplcnews.email&amp;gt;</code>, <code>cybercrime.police.gove.in-25@simmobilies.com</code><br>
<!-- -->reply-to: <code>"cp.vivek.mumbaipol@gmail.com"</code> <code>&amp;lt;cp.vivek.mumbaipol@gmail.com&amp;gt;</code><br>
<!-- -->subject: Re: ⚖️Attend To FILE No. 2910-110/CPM-5/2024 ⚖️<br>
<!-- -->mailed-by: <code>dclicinddplcnews.store</code></p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-body">Email Body<a href="https://secure-techie.com/blog/scam-re-attend-to-file-no-2910-110-cpm-5-2024/#email-body" class="hash-link" aria-label="Direct link to Email Body" title="Direct link to Email Body" translate="no">​</a></h3>
<p>Attend To FILE No. 2910-110/CPM-5/2024</p>
<p>Office Of The Commissioner Of Police</p>
<p>Cyber Crime Cell / Computer Centre</p>
<p>Mumbai</p>
<p>Police Investigation</p>
<p>This is to inform you of the alleged court order against your Internet IP traffic by the Central Bureau of Investigation, Department of Research and Anal</p>
<p>It is quite unfortunate to turn your official or private Internet into a juvenile pornographic movie cyber.</p>
<p>The Central Bureau of Investigation works in partnership with the Police Cybercrime Special Units in handling all complex and sensitive cases of cybercrime, especially when the victims are women and minor children.</p>
<p>Our laboratories are equipped with state of the art spider/crawling digital software and equipment, having forensic capabilities such as extraction of deleted data from hard drives and mobile phones, imaging and hash value calculation, forensic servers, and portable forensic tools for on-site examination, facility to extract data from latest Android or IOS as well as Chinese phones.</p>
<p>Based on the above, it is extremely difficult for any victim to consciously or unconsciously visit juvenile pornographic sites without being digitally captured.</p>
<p>More information or clarification on the court order will be made available to you upon receipt of your response within 24 hours; our office operates 24 hours / 7 days.</p>
<p>Be assured that serious legal action will be taken against you if you fail to respond to this notice within 24 hours of receipt.</p>
<p>Sincerely,</p>
<p>Vivek Phansalkar(CP)</p>
<p>Commissioner Of Police</p>
<p>Cybercrime Cell / Computer Centre</p>
<p>Mumbai</p>
<p>This email is highly likely a phishing attempt or scam designed to intimidate and coerce you into responding. Here’s a breakdown of the red flags that reveal it as suspicious:</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/scam-re-attend-to-file-no-2910-110-cpm-5-2024/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<p>This email is highly likely a phishing attempt or scam designed to intimidate and coerce you into responding. Here’s a breakdown of the red flags that reveal it as suspicious:</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="1-sender-information-and-domain"><strong>1. Sender Information and Domain</strong><a href="https://secure-techie.com/blog/scam-re-attend-to-file-no-2910-110-cpm-5-2024/#1-sender-information-and-domain" class="hash-link" aria-label="Direct link to 1-sender-information-and-domain" title="Direct link to 1-sender-information-and-domain" translate="no">​</a></h3>
<ul>
<li class=""><strong>Sender's Address</strong>: The email claims to be from "Vivek Phansalkar CP" (Commissioner of Police), but the email address is <code>inccc.gov.units@dclicinddplcnews.store</code>—an unusual and suspicious domain with no apparent connection to the official Mumbai Police or Indian government. Legitimate communication from the Mumbai Police would come from a <code>@gov.in</code> domain or other official government domain, not from a <code>.store</code> domain.</li>
<li class=""><strong>Reply-To Email</strong>: The reply-to address is <code>cp.vivek.mumbaipol@gmail.com</code>, a generic Gmail address. Official law enforcement agencies do not use free, public email domains like Gmail for sensitive or formal correspondence.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="2-subject-line-and-urgency-tactics"><strong>2. Subject Line and Urgency Tactics</strong><a href="https://secure-techie.com/blog/scam-re-attend-to-file-no-2910-110-cpm-5-2024/#2-subject-line-and-urgency-tactics" class="hash-link" aria-label="Direct link to 2-subject-line-and-urgency-tactics" title="Direct link to 2-subject-line-and-urgency-tactics" translate="no">​</a></h3>
<ul>
<li class=""><strong>Subject Line</strong>: The inclusion of a fake file reference number and legal symbols (⚖️) is designed to create a sense of urgency and legitimacy. Law enforcement agencies typically include case numbers without decorative symbols and use formal, official language.</li>
<li class=""><strong>Threat of Immediate Legal Action</strong>: The email uses urgent and intimidating language, stating that legal action will be taken within 24 hours. Real law enforcement would not use such aggressive, vague threats in an email without specific context or supporting documentation.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="3-vague-and-threatening-language"><strong>3. Vague and Threatening Language</strong><a href="https://secure-techie.com/blog/scam-re-attend-to-file-no-2910-110-cpm-5-2024/#3-vague-and-threatening-language" class="hash-link" aria-label="Direct link to 3-vague-and-threatening-language" title="Direct link to 3-vague-and-threatening-language" translate="no">​</a></h3>
<ul>
<li class=""><strong>Unusual Accusation</strong>: The message accuses you of illegal activity related to “juvenile pornographic movie cyber,” an odd and awkward phrase likely used to scare the recipient without specific accusations. Official correspondence would be clearer, citing specific alleged activities if necessary.</li>
<li class=""><strong>Detailed Description of Cybercrime Tools</strong>: The email attempts to sound technical by listing forensic tools, software capabilities, and investigative methods, which is highly unusual for a formal legal notice. Real legal notifications would not provide such details, as this is not relevant or necessary information for the recipient.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="4-lack-of-legal-or-official-documentation"><strong>4. Lack of Legal or Official Documentation</strong><a href="https://secure-techie.com/blog/scam-re-attend-to-file-no-2910-110-cpm-5-2024/#4-lack-of-legal-or-official-documentation" class="hash-link" aria-label="Direct link to 4-lack-of-legal-or-official-documentation" title="Direct link to 4-lack-of-legal-or-official-documentation" translate="no">​</a></h3>
<ul>
<li class=""><strong>No Supporting Documents</strong>: There are no attachments or links to any court order or official documentation. Real law enforcement agencies would include official case documents, file numbers, and court stamps if legal action were involved.</li>
<li class=""><strong>No Contact Verification</strong>: There is no contact number, office address, or other official means to verify the authenticity of the email. Legitimate communication would include multiple contact methods, including a government website or phone number.</li>
</ul>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="recommendations"><strong>Recommendations</strong>:<a href="https://secure-techie.com/blog/scam-re-attend-to-file-no-2910-110-cpm-5-2024/#recommendations" class="hash-link" aria-label="Direct link to recommendations" title="Direct link to recommendations" translate="no">​</a></h3>
<ol>
<li class=""><strong>Do Not Respond</strong>: Avoid replying or engaging with this email. This type of phishing email is designed to collect personal information or trick recipients into providing sensitive data.</li>
<li class=""><strong>Report and Delete</strong>: Mark the email as phishing or spam in your email client to help prevent future phishing attempts from similar sources.</li>
<li class=""><strong>Verify Directly</strong>: If you are concerned about any possible investigation, contact the Mumbai Police directly through their official website or phone numbers. Do not rely on any contact information in this email.</li>
<li class=""><strong>Stay Informed</strong>: Familiarize yourself with common phishing tactics, especially emails that use intimidation and vague legal threats to coerce victims into quick action.</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion"><strong>Conclusion</strong>:<a href="https://secure-techie.com/blog/scam-re-attend-to-file-no-2910-110-cpm-5-2024/#conclusion" class="hash-link" aria-label="Direct link to conclusion" title="Direct link to conclusion" translate="no">​</a></h2>
<p>This email is almost certainly a phishing scam. The strange email domains, threatening language, and lack of legitimate government contact details make it clear this is not from an official law enforcement agency. Report it and delete it to protect your information.</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Scam" term="Scam"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Phishing: New VM Recordlng Recelved - MSG 00:01:30 Ref:9b4e56919bf06b17b131774fd036e27fed8e7e00]]></title>
        <id>https://secure-techie.com/blog/phishing-new-vm-recording-received-msg-000130-ref-9b4e56919bf06b17b131774fd036e27fed8e7e00/</id>
        <link href="https://secure-techie.com/blog/phishing-new-vm-recording-received-msg-000130-ref-9b4e56919bf06b17b131774fd036e27fed8e7e00/"/>
        <updated>2024-10-31T12:00:00.000Z</updated>
        <summary type="html"><![CDATA[Missed Call Notification - New VM Recordlng Recelved - MSG 00:01:30 Ref:9b4e56919bf06b17b131774fd036e27fed8e7e00 from intrinsicvccdcsystem@i-ntrinsic.com.]]></summary>
        <content type="html"><![CDATA[<p>Missed Call Notification - New VM Recordlng Recelved - MSG 00:01:30 Ref:9b4e56919bf06b17b131774fd036e27fed8e7e00 from <a href="mailto:intrinsicvccdcsystem@i-ntrinsic.com" target="_blank" rel="noopener noreferrer" class="">intrinsicvccdcsystem@i-ntrinsic.com</a>.</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/phishing-new-vm-recording-received-msg-000130-ref-9b4e56919bf06b17b131774fd036e27fed8e7e00/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p>From: Missed CaII Notification0586693923{<code>&amp;lt;intrinsicvccdcsystem@i-ntrinsic.com&amp;gt;</code> via <code>sendgrid.net</code><br>
<!-- -->Subject: New VM Recordlng Recelved - MSG 00:01:30 Ref:9b4e56919bf06b17b131774fd036e27fed8e7e00<br>
<!-- -->Attachment: Email Item</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/phishing-new-vm-recording-received-msg-000130-ref-9b4e56919bf06b17b131774fd036e27fed8e7e00/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<p>This email is highly suspicious and likely a phishing attempt or malware attack. Here’s an analysis:</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="1-suspicious-sender-information"><strong>1. Suspicious Sender Information</strong><a href="https://secure-techie.com/blog/phishing-new-vm-recording-received-msg-000130-ref-9b4e56919bf06b17b131774fd036e27fed8e7e00/#1-suspicious-sender-information" class="hash-link" aria-label="Direct link to 1-suspicious-sender-information" title="Direct link to 1-suspicious-sender-information" translate="no">​</a></h3>
<ul>
<li class=""><strong>From Address</strong>: The sender's email address, <code>intrinsicvccdcsystem@i-ntrinsic.com via sendgrid.net</code>, does not match any legitimate or recognizable voicemail provider. The unusual characters in the email address are likely an attempt to mimic an official name or domain.</li>
<li class=""><strong>Use of SendGrid</strong>: While SendGrid is a legitimate email delivery service, scammers often exploit such platforms to send phishing emails. Official voicemail notifications would not come from such a third-party service but rather directly from a known provider.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="2-vague-subject-and-attachment-details"><strong>2. Vague Subject and Attachment Details</strong><a href="https://secure-techie.com/blog/phishing-new-vm-recording-received-msg-000130-ref-9b4e56919bf06b17b131774fd036e27fed8e7e00/#2-vague-subject-and-attachment-details" class="hash-link" aria-label="Direct link to 2-vague-subject-and-attachment-details" title="Direct link to 2-vague-subject-and-attachment-details" translate="no">​</a></h3>
<ul>
<li class=""><strong>Subject Line</strong>: The subject tries to create urgency with a "Missed Call Notification" and a fake voicemail reference number (<code>9b4e56919bf06b17b131774fd036e27fed8e7e00</code>). This is a common tactic to make recipients click on attachments without verifying legitimacy.</li>
<li class=""><strong>Attachment Named "Email Item"</strong>: The vague attachment name is unusual and is likely an attempt to hide malicious content. Legitimate voicemails or missed call notifications typically have specific details in the attachment name, such as the caller’s number or date.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="3-no-body-content"><strong>3. No Body Content</strong><a href="https://secure-techie.com/blog/phishing-new-vm-recording-received-msg-000130-ref-9b4e56919bf06b17b131774fd036e27fed8e7e00/#3-no-body-content" class="hash-link" aria-label="Direct link to 3-no-body-content" title="Direct link to 3-no-body-content" translate="no">​</a></h3>
<ul>
<li class=""><strong>No Message Content</strong>: Emails that are blank or lack a proper message body are often spam or phishing attempts. Legitimate voicemail notifications would provide information, such as the caller's number, message duration, and details on how to access the voicemail.</li>
</ul>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="recommendations"><strong>Recommendations</strong>:<a href="https://secure-techie.com/blog/phishing-new-vm-recording-received-msg-000130-ref-9b4e56919bf06b17b131774fd036e27fed8e7e00/#recommendations" class="hash-link" aria-label="Direct link to recommendations" title="Direct link to recommendations" translate="no">​</a></h3>
<ol>
<li class=""><strong>Do Not Open the Attachment</strong>: The attachment is highly likely to contain malware or a link to a phishing website. Avoid opening it, as it could infect your device.</li>
<li class=""><strong>Do Not Reply or Engage</strong>: Do not respond to the email, as replying could confirm your email address to scammers.</li>
<li class=""><strong>Mark as Spam or Phishing</strong>: Flag the email as spam or phishing in your email client to protect yourself and help prevent others from receiving similar messages.</li>
<li class=""><strong>Delete the Email</strong>: Once flagged, delete the email to prevent any risk of accidental interaction with the attachment.</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion"><strong>Conclusion</strong>:<a href="https://secure-techie.com/blog/phishing-new-vm-recording-received-msg-000130-ref-9b4e56919bf06b17b131774fd036e27fed8e7e00/#conclusion" class="hash-link" aria-label="Direct link to conclusion" title="Direct link to conclusion" translate="no">​</a></h2>
<p>This email is almost certainly a phishing or malware attempt, using a fake missed call notification to encourage you to open a dangerous attachment. It’s best to ignore, report, and delete this email to protect your device and data.</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Phishing" term="Phishing"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Phishing: [MetaMask] New Device Confirmation]]></title>
        <id>https://secure-techie.com/blog/phishing-metamask-new-device-confirmation/</id>
        <link href="https://secure-techie.com/blog/phishing-metamask-new-device-confirmation/"/>
        <updated>2024-10-27T12:00:00.000Z</updated>
        <summary type="html"><![CDATA[Your account and your wallet have been temporarily blocked to prevent you from losing your assets. Download the attached file to re-activate your wallet.]]></summary>
        <content type="html"><![CDATA[<p>Your account and your wallet have been temporarily blocked to prevent you from losing your assets. Download the attached file to re-activate your wallet.</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="complete-email">Complete Email<a href="https://secure-techie.com/blog/phishing-metamask-new-device-confirmation/#complete-email" class="hash-link" aria-label="Direct link to Complete Email" title="Direct link to Complete Email" translate="no">​</a></h2>
<p>From: MetaMask <code>&amp;lt;noreply@ncste.kz&amp;gt;</code><br>
<!-- -->Subject: [MetaMask] New Device Confirmation<br>
<!-- -->Attachments: RemovedDevice.html (86.19 KB)</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-body">Email Body<a href="https://secure-techie.com/blog/phishing-metamask-new-device-confirmation/#email-body" class="hash-link" aria-label="Direct link to Email Body" title="Direct link to Email Body" translate="no">​</a></h3>
<p>We noticed an attempted login to your Metamask from a location you have not used before, we want to verify that this was indeed you.<br>
<!-- -->To assist you with reactivating your wallet, we have provided detailed instructions in the attached file</p>
<p>Your account and your wallet have been temporarily blocked to prevent you from losing your assets.</p>
<p>How can I recover my account?<br>
<!-- -->Download the attached file to re-activate your wallet.<br>
<!-- -->After completing the process, enable Two-Factor Authentication.</p>
<p>© 2024 MetaMask. All rights reserved.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="red-flags">Red Flags<a href="https://secure-techie.com/blog/phishing-metamask-new-device-confirmation/#red-flags" class="hash-link" aria-label="Direct link to Red Flags" title="Direct link to Red Flags" translate="no">​</a></h2>
<p>This email shows several warning signs that it is likely a phishing attempt, designed to compromise your MetaMask wallet and potentially steal your assets. Here’s an analysis of the suspicious aspects of the email:</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="1-suspicious-sender-domain"><strong>1. Suspicious Sender Domain</strong><a href="https://secure-techie.com/blog/phishing-metamask-new-device-confirmation/#1-suspicious-sender-domain" class="hash-link" aria-label="Direct link to 1-suspicious-sender-domain" title="Direct link to 1-suspicious-sender-domain" translate="no">​</a></h3>
<ul>
<li class=""><strong>From Address</strong>: The email claims to be from MetaMask but is sent from <code>noreply@ncste.kz</code>, which is a <code>.kz</code> domain for Kazakhstan. Official MetaMask communications would come from a domain affiliated with MetaMask or ConsenSys (the company behind MetaMask), such as <code>@metamask.io</code> or <code>@consensys.net</code>.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="2-use-of-an-attachment"><strong>2. Use of an Attachment</strong><a href="https://secure-techie.com/blog/phishing-metamask-new-device-confirmation/#2-use-of-an-attachment" class="hash-link" aria-label="Direct link to 2-use-of-an-attachment" title="Direct link to 2-use-of-an-attachment" translate="no">​</a></h3>
<ul>
<li class=""><strong>Attachment</strong>: Phishing emails commonly include attachments (e.g., <code>RemovedDevice.html</code>) that prompt users to enter sensitive information on a fake page. MetaMask would never ask users to download an HTML file to recover their accounts. Instead, legitimate wallet recovery is handled within the app or on their official website.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="3-vague-language-and-immediate-call-to-action"><strong>3. Vague Language and Immediate Call to Action</strong><a href="https://secure-techie.com/blog/phishing-metamask-new-device-confirmation/#3-vague-language-and-immediate-call-to-action" class="hash-link" aria-label="Direct link to 3-vague-language-and-immediate-call-to-action" title="Direct link to 3-vague-language-and-immediate-call-to-action" translate="no">​</a></h3>
<ul>
<li class=""><strong>"New Device Confirmation" and Account Blocked Message</strong>: The email uses alarming language, claiming that your account is temporarily blocked and urging you to recover your account immediately. Scammers use these tactics to make recipients act without thinking.</li>
<li class=""><strong>Download Instructions</strong>: MetaMask would never ask you to download a file to restore access to your wallet. Legitimate wallet recovery involves using a <strong>seed phrase</strong> (recovery phrase) within the official MetaMask app, not an HTML file.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="4-generic-security-advice"><strong>4. Generic Security Advice</strong><a href="https://secure-techie.com/blog/phishing-metamask-new-device-confirmation/#4-generic-security-advice" class="hash-link" aria-label="Direct link to 4-generic-security-advice" title="Direct link to 4-generic-security-advice" translate="no">​</a></h3>
<ul>
<li class=""><strong>Two-Factor Authentication (2FA)</strong>: While enabling 2FA is good practice, MetaMask doesn’t offer 2FA on wallet access, as it’s a decentralized wallet that relies on the seed phrase and private keys. This mention is another indicator of a phishing attempt.</li>
</ul>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="recommendations"><strong>Recommendations</strong>:<a href="https://secure-techie.com/blog/phishing-metamask-new-device-confirmation/#recommendations" class="hash-link" aria-label="Direct link to recommendations" title="Direct link to recommendations" translate="no">​</a></h3>
<ol>
<li class=""><strong>Do Not Download or Open the Attachment</strong>: Opening the attached HTML file could expose you to a fake MetaMask login page designed to steal your seed phrase or other credentials.</li>
<li class=""><strong>Do Not Respond</strong>: Avoid replying to this email, as this could confirm your email address to scammers.</li>
<li class=""><strong>Log in Directly to MetaMask</strong>: If you’re concerned about your account security, open the official MetaMask app or go directly to <code>metamask.io</code>. Check for any suspicious activity there.</li>
<li class=""><strong>Report and Delete</strong>: Mark the email as phishing in your email client to help protect others from similar attempts.</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion"><strong>Conclusion</strong>:<a href="https://secure-techie.com/blog/phishing-metamask-new-device-confirmation/#conclusion" class="hash-link" aria-label="Direct link to conclusion" title="Direct link to conclusion" translate="no">​</a></h2>
<p>This email is highly likely to be a phishing attempt. The strange sender domain, attachment with instructions to “reactivate” your wallet, and suspicious instructions make it clear this is not from MetaMask. To secure your wallet, only use the official MetaMask app and be vigilant against phishing scams like this one.</p>
<hr>]]></content>
        <author>
            <name>Jagdish Kumawat</name>
        </author>
        <category label="Email Attacks" term="Email Attacks"/>
        <category label="Phishing" term="Phishing"/>
        <category label="Awareness" term="Awareness"/>
    </entry>
</feed>