6 ms·
> Each of these accounts is associated with a different stolen identity, but all email from these services are received by the same Gmail account. Thus, the gro
by wuunderbar 8y ago
> Each of these accounts is associated with a different stolen identity, but all email from these services are received by the same Gmail account. Thus, the group is able to centralize and organize their fraudulent activity around a small set of email accounts, thereby increasing productivity and making it easier to continue their fraudulent behavior.
I'm sure there are creative & compelling uses of Gmail dot addresses to commit fraud out there, but this one barely counts as fraud. I'm not sure what the point of the article is.
- SketchySeaBeast 8y agoYeah, it's a time saver for the fraudster, but that's really about it.
- ggggtez 8y agoThe fraudster indeed could just forward the netflix mail using their own mail server. This is just standard phishing (when you log in to netflix, wouldn't you notice it's not your account?)
- gruez 8y agoAgreed. You could write the same article about catchall forwarding services or disposable mail service.
- josteink 8y agoIf you use a disposable email, I guess you should consider the account disposable too? If you have catch-all service forwarding your email, you as a technically minded person made that choice for your domain and you have to consider the consequences and risks. Gmail has made this a default for everyone, including 99.999999% of its users who does not know scammers can automatically create aliases for them, so that the 0.0000001% which uses this feature doesn’t have to tick a checkbox first, or pre-register their aliases. Completely irresponsible and a world of difference.
- deweller 8y agoFraudsters are taking advantage of email aliases to get other people to pay for someone else's account. Example: 1) Fraudster create an account and put in a bogus card number. 2) Fraudster changes account email address to joe.smith@gmail.com. joesmith@gmail.com already exists in Netflix's DB - but joe.smith@gmail.com does not, so Netflix is ok with this. 3) Netflix emails joe.smith@gmail.com and says "hey your card is bad, please update it" by clicking here. 4) The real joesmith@gmail.com receives the email, clicks the link and is taken directly to a "update your card screen" and types in their credit card information. 5) Fraudster has their Netflix account paid for by the real Joe Smith. Granted, Netflix could fix this by requiring a login before updating billing details. But the dot aliases in Gmail are a part of the scam.
- SketchySeaBeast 8y agoYeah, the other link(1) is more interesting. That's still not exactly a world shattering level of fraud though. Unless they subscribe to the 4k package, then we're getting unreasonable. 1) https://jameshfisher.com/2018/04/07/the-dots-do-matter-how-to-scam-a-gmail-user.html https://jameshfisher.com/2018/04/07/the-dots-do-matter-how-t...
- koolba 8y agoNetflix would be at fault there for allowing the email change without confirmation. Rule #1 of security: trust nothing from the client!