Leave a comment

Fake confirmation emails contain nasty malware

Fake confirmation emails contain nasty malware
photo courtesy of SHUTTERSTOCK

You've just bought a sleigh full of gifts over the Internet. But before any of them arrive in the mail, you'll first be getting a series of order confirmations in your email inbox.

Beware. Some of them are not real and could contain viruses.

So far, infected emails have been acting like they are from Home Depot, Target, Walmart and Costco. They began around Thanksgiving, and with the holiday rush, scammers are trying capitalize on the craziness of the season.

These fake confirmation emails will generally tell you there was an issue with your order. The subject lines have been along the lines of: Acknowledgment of Order,” “Order Confirmation,” “Order Status,” “Thank you for buying from [insert merchant name here]”, and a “Thank you for your order,” according to Brian Krebs.

The emails also encourage you to clink on links within the email. Don't fall for it! The links contain malware that will steal your personal and valuable information.

If you get an email about a legitimate order you placed online, it's still a good idea to visit the merchant site directly. Don't give out any personal information, and don't forget the telltale signs of a fake email. 

For these emails in particular, their grammar isn't great, "From" lines don't necessarily match the name of the merchant, there are multiple recipients in the "To" line, and when you hover over the links, they don't go directly to the retailer sites.

More importantly, these emails don't include order confirmation numbers or any other information regarding the items purchased. Legitimate emails will contain information of that nature.

Here's what some of the fake emails circulating look like:

tg-asprox-600x373

wm-asprox-600x308

hd-asprox-600x273

cc-asprox-600x300

UPDATE: Walmart has confirmed the scam and published an example of the scam on its site. You can see the warning by clicking here. On top of the warning signs I already alerted you to, the warning also states:

If you were a victim of fraud via the Internet, you should file a report with your local law enforcement agency along with the Internet Crime Complaint Center (ICCC). The ICCC is a partnership between the FBI and the National White Collar Crime Center. You can make a report with the ICCC.

Next Story
Apple deleted non-iTunes songs from people's iPods
Previous Happening Now

Apple deleted non-iTunes songs from people's iPods

Kidnapped boy escapes through clever use of Facebook
Next Happening Now

Kidnapped boy escapes through clever use of Facebook

View Comments ()