13 ms·
The clever reason scammers can’t spell (2019)
- danielodievich 4y agoClose to 20 years ago I got an email that in it's entirety said "I have a powful tool. I suspect youd like it", exactly as written. No links, no attachments, just plain text. I showed it to my then girlfriend and now wife and since then we have adopted "powful tool" as a term we apply to really great devices or machinery of impressive heritage or even some good software. Warms my heart.
- colejohnson66 4y agoI’ve also gotten mysterious scam emails that contain no information. What’s their purpose?
- cjglo 4y agoIf I had to guess, it’s a trick to get people engaged. There’s no link or request for money, so people probably respond more often. I imagine like many areas of persuasion (like interrogation), getting someone to start talking is the “foot in the door” that starts to snow ball, even if it’s not about anything relevant.
- thehappypm 4y agoLaying the groundwork to beat a spam filter, probably. If a series of emails are read and not deleted, that does not seem like spam.
- amatecha 4y agohuh, that's an interesting point! Seems like a good idea to mark those as spam even if they are "harmless", in that case...
- yucky 4y agoIt's called "IP warming". When you send bulk emails, there are throttling limits and other things meant to decrease the ability of scammers. So to warm the IP up you have to send on it for awhile. These sorts of blank emails aren't the best way to do it, it's sloppy. But that's the goal.
- nonbirithm 4y agoA cursory search gave back this gem. Same spam email in 2003 except it goes off on a tangent about a Symantec deal worth a lot of money (since someone mentioned they used Norton 2003) that someone used to buy a company sports car. Then people just keep talking about sports cars. https://www.mail-archive.com/membersozdat@datascribe.com.au/msg39596.html https://www.mail-archive.com/membersozdat@datascribe.com.au/...
- bad416f1f5a2 4y ago> From: "Neateye" <NitaiGouranga@aol.com> > Subject: Gouranga > Call out Gouranga be happy!!! > Gouranga Gouranga Gouranga .... > That which brings the highest happiness!! It’s been, fuck, two decades and this is still in my mbox. My wife and I still shout Gouranga at each other some days and, hell, who am I to argue that it doesn’t bring the highest happiness!!
- Lammy 4y agoGrand Theft Auto 1 taught me that one :) https://gta.fandom.com/wiki/Hare_Krishna https://gta.fandom.com/wiki/Hare_Krishna > In GTA, the player received a 'GOURANGA' bonus for running over an entire procession of Hare Krishna. 'GOURANGA' is actually a term that was popularized as use by the Hare Krishna movement during the 1970s. It is often used to describe happiness. This is also a cheat code in the PC version of GTA 2.
- hn_go_brrrrr 4y agoMine is "Only Spicy food gives me an Explosive Gain.", from https://thedailywtf.com/articles/Only-Spicy-Food-Gives-Me-an-Explosive-Gain https://thedailywtf.com/articles/Only-Spicy-Food-Gives-Me-an..., from back when TDWTF wasn't made up.
- pbj1968 4y agoAh yes, “smart people don’t get scammed, you’re smart aren’t you?” Very smarmy line of thinking. Unfortunately on the rise in recent years. We are all vulnerable to scams and victim blaming doesn’t help the conversation any.
- soneil 4y agoIt irks me that this is the bulk of what we're taught of phishing training - just to look for the obvious mistakes. We've been seeing a rise in attacks that are launched from compromised accounts, where the email is a reply to a previous thread. So you have the context, name and address of someone you're presumably already familiar with. The last one I looked at had the body "What do you think of this?", their signature was missing, and the payload was a html file that delivered a passworded zip via a data: blob, and the password was in the html file. "for security". The attachment was the only real tell. Also noticed the sending server was in the wrong country, but since the thread they were replying to had to come from compromised access, I wouldn't trust that either. If the attachment was an office doc, the payload would have been delivered before I heard anything about it. It's not quite spear-phishing (you're still a target of opportunity rather than a selected target), but it's effective and convincing. But trainings haven't got much past the nigerian princes yet.
- dreamcompiler 4y agoSame reason Nigerian 419 scammers continue to make it clear they're from Nigeria: If you're unaware enough not to know that "Nigeria" is a red flag for "scam," you're exactly the mark they want.
- notahacker 4y agoThere's a much, much simpler reason. The object of the scam is to persuade you to send money to the only country they can collect it, which is Nigeria. Most of the people who haven't heard of Nigerian prince scams have spam filters which have. I suspect their spam-filter evasion rates are so low they really, really wouldn't want to filter those people out if they knew what they were doing (I suspect the reverse is actually true: a lot of the people running the scams have heard legends about how much their fellow countrymen made from using certain email templates, but have no idea how much of a running joke they are in Western discourse and how consistently they're filtered out)
- neilknowsbest 4y agoMicrosoft has an amusingly academic take on this idea here (PDF): https://www.microsoft.com/en-us/research/wp-content/uploads/2016/02/WhyFromNigeria-1.pdf https://www.microsoft.com/en-us/research/wp-content/uploads/...
- LASR 4y agoIt’s the same reason why it’s always a Nigerian prince who needs you help in moving money out of the country. If you’ve never heard of the Nigerian prince scam by now, you’re their target. It’s unfortunate that these guys end up siphoning money from fixed-income seniors disproportionately more than any other demographic.
- mrjin 4y agoWasn't the spelling itself ringing an alarm bell?
- 734129837261 4y agoThe same trick is applied to trick potential customers into going through a sales funnel and convert to a paying customer. "There are 42 people watching this hotel right now! Only 3 rooms available for your dates! We'll murder ANOTHER puppy if you don't book right now!" Yes, I worked for Booking.com. They don't do it everywhere, in some places it's illegal, and sometimes they simply change the words slightly to make it suggest urgency.
- GycDH6mb 4y agoIs this why when I'm on Etsy, some obscure, niche item that I'm looking at will always say "13 people have this in their carts right now"? Etsy doesn't seem like the type to me, or maybe that code is just flawed
- hobbitstan 4y agoI’ve been suspicious of Etsy for years for this very reason. Either Etsy is scamming or the sellers are playing games.
- justsomehnguy 4y agoYou can test it yourself: Become an Etsy seller and sell something what wouldn't be even show up in search Observe if "N people have this in their carts right now" shows up ... PROFIT
- maxfurman 4y agoI think they just include abandoned shopping carts in this number
- pulse7 4y ago...and those abandoned shopping carts are from Google Search Bot which checked the product prices...
- 4y ago
- djmips 4y agoThe real reason scammers can't spell and use good grammar is because they are not proficient at spelling and grammar.
- roberttod 4y agoThis. I recently got approached by a scammer on Facebook marketplace. It was never going to work but the spelling/grammar issues instantly made me think something fishy was going on. They put plenty of investment into scamming me before I called them out, and I don't think their grammatical errors would have served to filter anyone (because it also could have just been someone wanting to buy something who happens to have bad English).
- connordoner 4y agoTo be honest, a lot of them seem to just copy from other scammers... I do wonder if it started off as this (and, potentially, to bypass spam filters in the early days, when many of them did face the keyword problem), but it's now simply a copy-and-paste job?
- hanoz 4y agoThis is bollocks. Speaking for Britain, and I think I can, there are hoards of would be victims to this kind of scam, particular of the current retirees generation, who are extremely vulnerable to having the wool pulled over their eyes about technical and internet security best practice matters, but for whom just so much as a poor turn of phrase or some unusually laid out punctuation is an absolute dead giveaway. If the scammers got their act together on this front they'd be mopping up huge swathes of these people, but they don't, because at the end of the day they don't speak English very well and don't have access to anyone who can.
- mikhmha 4y ago100%. This article is a popular “Reddit” theory I’ve seen float around for a while now and it’s just not true! I’ve worked IT help desk before and have seen lots of phishing emails. If scammers tightened up their spelling and grammar skills a tiny bit they would catch many more victims effortlessly. The bar is insanely low. Most users could spot obvious phishing emails. But emails with even just a little more effort put into spelling and grammar were insanely successful. I worked at a University - I’ve seen professors, students, admin fall for these ones. Why can’t they spell? Because most scammers are operating from the developing word and don’t have great English. That’s it. There’s no elaborate theories beyond that.
- jrgoff 4y agoI think all of the obvious scam emails are part of what makes the higher effort scams so much more effective. People (myself included) are used to being easily able to spot the scams so aren't naturally wary when seeing emails that don't have those obvious indicators.
- SturgeonsLaw 4y agoI am another data point that would agree with you on this. I would classify myself as a sophisticated computer user (if I don't say so myself), and I fell for a phishing page once. They recreated a pixel-perfect copy of the Steam login page in a fake browser window with a pretend address bar etc. I entered not only my creds, but also my 2FA code, before realising that it was not legit. Got an email shortly afterwards about a login from Russia, however I was able to change my password and kick out all other sessions before any damage was done. The worst part was that I was doing a favour to a Steam "friend" who asked me to vote for his clan in some kind of competition. I will give him the benefit of the doubt and assume it wasn't really him, but someone who had hacked his account, but either way, Steam support were utterly disinterested in doing anything about it when I reported it. As were Cloudflare. I checked on the site a few days later and the safe browsing list had flagged it, so at least those maintainers still seem to give a shit.
- sergius 4y agoThis is one of the best analysis for this: https://www.microsoft.com/en-us/research/publication/why-do-nigerian-scammers-say-they-are-from-nigeria/ https://www.microsoft.com/en-us/research/publication/why-do-... It is a filter strategy!
- garbagetime 4y agoI don't see the value in articles like these that don't even attempt to convince you what they are saying is true. Sure, I've heard this claim 1,000,000 times on sites such as Hacker News and Reddit - but I've yet to find any reason to believe it. In the spam e-mail I get, the misspellings are clearly there to get around spam filters. In fact, the e-mails I get look quite convincing, and just have two or three strategic misspellings. A lot of the text will be in the form of an image, and will be spelled and formatted perfectly. But instead of saying "garbagetime" it will say "garbagetim". And instead of saying "18+" it will say "19+". Looking at one spam e-mail I received recently, I see it even has an "unsubscribe" button, which leads to a vaguely convincing but - after some investigation - certainly non-functional unsubscribe page. That's a lot of effort to go to if you're trying to filter out vaguely clever people. Maybe there really is a whole other genre of spam e-mail that simple doesn't get sent to me, or is caught by my spam filter. But this article gives me no reason to suspect this to be the case. And for various reasons it seems unlikely.
- Markoff 4y agoLet me guess two reasons: 1. to avoid keyword detection (reason I write to myself garbled sensitive notes online, so potential hacker with online translator won't be able to read them since it's highly unlikely he will be my maybe language speaker) 2. to filter out smart people avoid wasting time with them edit: article says it's number 2
- christkv 4y agoDon’t worry with tools like ChatGPT and others I’m sure text quality will soon improve for scams.
- xg15 4y agoSounds like a perfect use case for text generators to me. If you receive a mail that you're 100% sure is a scam or phishing attempt, you could pass it to ChatGPT and have it teergrube the scammer into some endless conversation that binds as many resources on the scamner's side as possible. (emphasis on "100% sure" though. If such a system was widely deployed, it could also quickly turn into a Kafkaesque horror show if legitimate messages get caught in it)
- Derbasti 4y agoI always thought they're just doing that to circumvent spam filters. Seems more plausible to me.
- 752963e64 4y ago
- majikandy 4y agoIn personal interaction scams, spelling mistakes are also endearing and help you believe you are talking to the real person. Even if they “work for” a known company.
- deleted 4y ago[deleted]
- RustLove 4y agoWhile we've all heard the theory that poor spelling can be a tactic used to make their communication seem less credible and make it easier for them to trick people, I'm skeptical. Many scammers may not be native English speakers and may not have a strong grasp of the language. Another possibility is that scammers simply don't put a lot of effort into their spelling and grammar because their primary focus is on making money, rather than creating well-written communications.
- yesplorer 4y agoThis is not true. The scam are usually carried out by highly illiterate young boys who simply carry a file containing files labeled as first letter, second letter, third letter and so on. Then they go phishing with these. I’ve seen this idea of they’re trying to filter out educated people so often that it makes me laugh. They aren’t , they’re simply dumb.
- xtiansimon 4y agoI believe this, because I see it happen. I get a text saying my package is delayed because of address error, AND I’m expecting a package AND I spent my morning cleaning up emails and putting out fires, AND the link opens to an exact copy of the USPS website… BUT THEN, I notice the URL, BUT THEN I realize my package is coming from UPS, and not USPS, BUT THEN I realize this is like another scam _that I correctly identified_ previously. If your scamming objective is to get high-level permission, authorization or otherwise to actually get PAID you need a very special someone. What you don’t need is to waste resources and expose yourself to, now I say, intelligent people who will try to take you down. Even more, you want to avoid special someone with the resources and knowledge to actually scan you. That’s not a ‘crazy theory’, it’s common sense in the age of advertising and marketing. Or, if it’s too ‘complicated’, then let me ask you this, have you ever experienced a ‘street hustle’? In a bar trying to buy weed (pre-legal) or a person on the street confronts you for money. Clever tricks working on personality types. If you can convert your awareness of spelling errors into distrust so fast, we don’t want to talk to youz.
- rickreynoldssf 4y agoI'm sure most of the scammers are actually stupid and the fact that their stupidity works for them in this case is just luck.
- deleted 4y ago[deleted]
- quickthrower2 4y agoBest to assume they are sophisticated though. Some are gangs/organisations. They can get pretty professional.
- heavyset_go 4y agoJust because they're organized doesn't mean they aren't incompetent in other aspects of what they do. There are plenty of dumb organized criminals sitting in prisons.
- RajT88 4y agoThe people writing the playbook I am sure are clever. The scammers I've talked to are often dumb as rocks. And probably are not the primary beneficiaries of the grift.
- quickthrower2 4y agoSome of them are slaves too.
- zoklet-enjoyer 4y agoI started asking scam callers if they're slaves. Nobody has responded yet, they just hang up
- raincom 4y agoNo, most of the scammers are run through call centers of sorts--be in Africa or India.
- johndhi 4y agoI was wondering that recently. But I don't know -- I feel like they'd catch even the discerning people if they did a better job of it. Why don't they exactly replicate what a Google or Chase email looks like? I don't see how I wouldn't fall for that.
- thisiscorrect 4y agoI'd buy the argument made in the article more if they could explain what harm the scammers are avoiding by weeding those of us who can spot a misspelling as early as possible. Do they immediately start investing a great deal of time in a possible "mark" right after one reply from them?
- version_five 4y agoI get phone calls sometimes that are almost certainly legitimate, such as from my insurance company, and if they ask me to give them any information (like my address for "security purposes") I always refuse and tell them I can call back. The same is true with email. You should never be giving any information away, even if it appears to be a completely legit communication from your bank or whatever. The exception (and a potential attack vector) is when a phone call or other live interaction ends in an email being sent as part of the process. There you have to weigh the risk I suppose; obviously i have replied to such emails. But i would never reply to a bulk email even if it came form my banks domain.
- Eleison23 4y agoWhen the doctor's office phones me, they must immediately learn my DOB or they can't reveal any information. Unfortunately the person calling is sometimes a nurse who's working on test results or some followup and they don't have a direct number. But it's kind of a stalemate if I won't reveal anything to them, and they won't reveal anything to me. At this point if they manage to have the correct caller ID and I'm more or less expecting the call, it can't hurt to divulge my DOB. Scammer's going to find that out easily anyway.
- RajT88 4y agoThink of it this way: Savvy users who will become wise to the grift somewhere along the way are the ones they want to weed out. Early in the process ideally. Having totally convincing emails fails to weed out these savvy users - you get to discover who they are a bit further down the line, after you've invested some time. Since their time they can spend is finite, they want to only spend time on sure bets. This is why it is important to take a few moments to lead on scammers - you're damaging their ROI the more of their time you can take up.
- ioblomov 4y agoAnd I always thought it was because misspelling threw (early) spam filters off.
- jwmcq 4y agoI remember about about 15-20 years ago, I noticed that a bunch of spam emails would open using multiple disjointed snippets of public-domain poetry before the dodgy links to try and get around these sorts of filters. I used to love reading through them to see a few words of Yeats jammed together with a bit of Coleridge or something, looking at it as some sort of weird outsider art.
- fsckboy 4y agothis idea has been kicking around for a long time, and sounds nice, but is there any data to support it? A lot of the most visible misspelling seems designed to avoid spam filter detection.
- yen223 4y agoThis idea was made popular by the Microsoft paper that was linked in the article. https://www.microsoft.com/en-us/research/wp-content/uploads/2016/02/WhyFromNigeria.pdf https://www.microsoft.com/en-us/research/wp-content/uploads/... However the paper itself doesn't present any evidence around the scammer's intention. Rather it presents a mathematical model under which it would make sense for a scammer to intentionally exclude a large swathe of victims, and it posited that misspellings is a way to achieve it.
- bigDinosaur 4y agoThere is no concrete evidence for it e.g. someone that we can trust who was a scammer who can confirm this was a conscious strategy.
- heavyset_go 4y agoI used to buy into the idea, but it increasingly grates my intuition as time goes on. I'm at a point that I believe much of the misspelling, poor grammar, etc are not intentional. If the same scammers were better at what they did, they'd snare more marks. I think these scammers are only capable of exploiting the bottom of the barrel when it comes to discerning audiences, though.
- miohtama 4y agoThe article misses one of the most common misspelling reason: getting thru Bayesian filters. It has more to do with tech and less with psychology.
- deleted 4y ago[deleted]
- anon_cow1111 4y agoThis is true but also... In my experience[1] a large majority of facebook-level romance scammers use the same copypasta messages when possible, because they actually are from (e.g.)Nigeria and really do have poor English. This is especially relevant to your point because facebook could EASILY be flagging people based on known pasta messages, for review or shadowbanning etc. They presumably don't do this because "not my problem". 1.Actually the experience of someone I know who's turned screwing with scammers into a personal hobby, who frequently shares notes on this with me.
- walderf 4y agosource: ^ his brother is a Nigerian prince!
- colejohnson66 4y ago> They presumably don't do this because "not my problem". They don’t care. It’s that simple. I’ve (on Facebook/Instagram) reported scams, and they always say it doesn’t violate their community guidelines. But it turns out the computer “reviewed” my report, so I appeal it, and it’s always “sorry, but we don’t have enough people, so we’re ignoring this appeal. Here’s the report ID for the ‘review’ board.” On the rare chance a human does review it, they say “a human reviewed your report, and you’re right.” They so much don’t care that, now, reporting scam/spam just says, “thanks for letting our system learn” without a way to make an actual report. I’ve given up reporting scam/spam. For a real kicker, I’ve reported a literal terrorist threat-like post, and it was still “pending” after a week.
- 4y ago
- AlbertCory 4y agoThere's actually a building in Lagos where the Nigerian Prince scammers all work. Hugh Sinclair has seen it: https://www.youtube.com/watch?v=rhdZ2RfmiXo&list=PL4ugKP-T4LYu0UyTzj3FeSDW1zSZUADju&index=6 https://www.youtube.com/watch?v=rhdZ2RfmiXo&list=PL4ugKP-T4L... I would think they do know exactly what they're doing. There's no reason to think it's just to get past email filters or just to skip the smart people. It's probably both, plus other reasons we haven't even thought of.
- robocat 4y ago> skip the smart people I am not sure smart people are scammed less often than the average person. Perhaps smart people get sucked in by different scams (like buying altcoins, or complex speculation)?
- deleted 4y ago[deleted]
- AlbertCory 4y agoThe John Podesta - Hillary phishing leak is out there on Wikileaks. This doesn't fit into any category I've seen: 0) Podesta got a letter-perfect message from "Google" asking him to change his password. 1) Podesta asked his IT guy if it was legit. 2) The IT guy said, "Yes, it is, but please set up 2FA." 3) Podesta clicked on it, ignoring the 2FA part (I think he ignored it).
- robocat 4y agoYour reply hits a very high 68% fakeness score, according to https://huggingface.co/openai-detector/ https://huggingface.co/openai-detector/ I am guessing because you are cutting and pasting text?