Don't click YES or NO in unexpected
You are not logged in. Access is limited. Login or see membership information. • Streetwise Security Zone Community

The Streetwise Security Zone Discussion Forums are a great way to see what other managers are doing about security and what problems they have faced. You can find a lot of helpful hints and tips that could save you time and money.

You must join The Streetwise Security Zone (click HERE) in order to reply or post new items in the forums.

Author Message

ScottWright
Group Administrator

Subject: Don't click YES or NO in unexpected "Please confirm... " emails
Risks in the News
posted by ScottWright on Sunday, December 7th 2008 @ 9:35 AM

Here's why it's often not enough to have one simple security guideline for dealing with SPAMMERS, SCAMMERS and PHISHERS. I always say to turn off "Automatic Image Loading" in your email account. This is because as soon as you load the image, it sends a request to the sender that tells them your email account is valid, and that you read their messages.

So What?

If they know your account is active, they will put it on a PREMIUM spam list that they can sell to others because it has been recently validated. This probably means you will get a fresh new wave of spam in the near future.

However, as people turn off image loading, now the SPAMMERS are countering that defence by creating emails that simply ask you to "Please confirm that you know Audrey Woijcik-Sharpley" (apparently sent from reunion.com) - they think you might want to reconnect with somebody you probably didn't remember anyway.

Watch out for compelling YES or NO choice buttons or links in unexpected email messages.

They give you a choice of two buttons, which can be done without you loading images from the message, if you view messages in HTML format. But as soon as you click on either button, they can once again tell that your account is valid.

DON"T CLICK THAT BUTTON!

________________________________
Scott Wright
The Streetwise Security Coach

Would your organization be interested in obtaining the right to use my lessons or articles in your enterprise security awareness program? Please email me at the address below...

Email: scott@streetwise-security-zone.com
Twitter: http://www.twitter.com/streetsec
Phone: 613-693-0997
Podcast: http://www.streetwise-security-zone.com/podcast.html