|
|
Date Reported: 5th October 2009 |
Risk Level: MEDIUM |
|
|
|
|
|
Email Subject: |
Your Wells Fargo account has been locked! |
|
Apparent Sender: |
WellsFargo |
|
Return Address: |
accts@ssl-wellsfargo.com |
|
Email Format: |
HTML |
|
URL of Web Content: |
http://www.quatre-bornes.com/wellsfargo/index.html |
|
Anchor text of URLs: |
1) http://www.wellsfargo/signon/reactivate?CODE= ZXJyb3Iudm5hbWVsiZhbGlkRm9ybWF08 |
|
Location: |
Location not available |
|
Scam number: |
4744-65924-261588 |
|
Comments: |
- Email asks you to confirm/update/verify your account data at WellsFargo by visiting the given link. You will be taken to a spoof website where your details will be captured for the phishers.
- WellsFargo never send their users emails requesting personal details in this way.
- The anchor text appears as a legitimate URL, but don't be fooled - clicking on it will take you to a phishing site!
- The spoof website this email links to was not online at time of this report, but variations of the scam which link to working websites are bound to exist, so be wary! The website may have been taken down or disabled by the hosts, but quite often these websites are hosted on the personal computer of the phishers, so may only be online at certain times.
|
|
|
|
|
|
|
|
|
Dear WellsFargo client Your account has been locked and placed on hold due to too many attempts to sign in to your account with an incorrect password. In order to unlock your account please click the link below and log in with the correct password :
http://www.wellsfargo/signon/reactivate?CODE= ZXJyb3Iudm5hbWVsiZhbGlkRm9ybWF08 If you choose not to complete the request, you give us no choice but to suspend your account permanently. If you received this notice and you...
|
|
Click for full size image |
|
Website: |
|
|
|
|
Website was not online when we checked. It returned the error 500 |
|
|
Please send us any scam/phishing emails you have received by reporting them here
For access to our huge blacklist of domain names and to sign up to our live feed of ALL the scams we receive please take a look at our Honeytrap service
If you have received the email below, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content, such as a different subject or return address, or with the fake webpage(s) hosted on a different webserver.
We aim to report every variant of the scams we receive, so even if it appears that a scam you receive has already been reported, please submit it to us anyway.
|