• Hey there! Welcome to TFC! View fewer ads on the website just by signing up on TF Community.

CC PHISHING WEBSITE FRAUD

drabhishek90

TF Buzz
VIP Lounge
This thread is for the general information and help to the people out there.
I recently underwent a phishing attack. Let me give you a background first.
I had a couple of my Speed Post Mails returned. They were some important share documents. When I called the local postman, he said that the address was incomplete.
Fast forward a month or so, I received an SMS stating that my speed post has incomplete address. Kindly click on link to update the address.
Normally I don't click on such links sent on the SMS but since I was already on my edge due to the undue return of my mails, I clicked on the linked and entered my address.
It then asked for a 20 Rs. payment via CC as a penalty. I was skeptical again but I entered the credit card details for the payment.
I immediately received a message that an International Transaction was done on my CC (kindly note that many international transactions do not require OTP).
I immediately blocked the card.

But inspite of all the efforts, I got scammed by this phishing technique.
This is a reminder to all the people here to be aware of such scams.


Note : If anyone comments as to how can I be so foolish as to get into such a scam, I will delete the thread. This is just for the information of general public.
 
This thread is for the general information and help to the people out there.
I recently underwent a phishing attack. Let me give you a background first.
I had a couple of my Speed Post Mails returned. They were some important share documents. When I called the local postman, he said that the address was incomplete.
Fast forward a month or so, I received an SMS stating that my speed post has incomplete address. Kindly click on link to update the address.
Normally I don't click on such links sent on the SMS but since I was already on my edge due to the undue return of my mails, I clicked on the linked and entered my address.
It then asked for a 20 Rs. payment via CC as a penalty. I was skeptical again but I entered the credit card details for the payment.
I immediately received a message that an International Transaction was done on my CC (kindly note that many international transactions do not require OTP).
I immediately blocked the card.

But inspite of all the efforts, I got scammed by this phishing technique.
This is a reminder to all the people here to be aware of such scams.


Note : If anyone comments as to how can I be so foolish as to get into such a scam, I will delete the thread. This is just for the information of general public.
Kindly note, Always keep international transactions OFF on all your credit/debit cards.
 
This thread is for the general information and help to the people out there.
I recently underwent a phishing attack. Let me give you a background first.
I had a couple of my Speed Post Mails returned. They were some important share documents. When I called the local postman, he said that the address was incomplete.
Fast forward a month or so, I received an SMS stating that my speed post has incomplete address. Kindly click on link to update the address.
Normally I don't click on such links sent on the SMS but since I was already on my edge due to the undue return of my mails, I clicked on the linked and entered my address.
It then asked for a 20 Rs. payment via CC as a penalty. I was skeptical again but I entered the credit card details for the payment.
I immediately received a message that an International Transaction was done on my CC (kindly note that many international transactions do not require OTP).
I immediately blocked the card.

But inspite of all the efforts, I got scammed by this phishing technique.
This is a reminder to all the people here to be aware of such scams.


Note : If anyone comments as to how can I be so foolish as to get into such a scam, I will delete the thread. This is just for the information of general public.
How much did you lose?
 
It was the quite similar website. However the url mentioned https:
I remember reading somewhere that if https has double 't', it's safe. That's why I went ahead.
Https or http is only possibility for website. Both with tt. Other protocols like ws/wss or similar will not be visible in browser url field. Ftp is possible. But you will not see website with it.

Https means http over tls (ssl). Tls only provide data integrity and security over the network. There is no guarantee of site being authentic. About 10 years back, getting ssl cert used to cost and it was an effort to get it. But with letsencrypt, ssl certificate is free and easy to get. Many / Most hosting provider provide letsencrypt certificate on click of button.
 
Nowadays scammers can even get HTTPS certificates. I once almost fell for a scam during lockdown for ATM installation. They had a proper website with HTTPS and their website appeared first on Google search results. They were just stupid in their email response and made silly grammatical mistakes which caught my attention!
 
Back
Top