American Institute of CPAs BBB Email Phishing Scam

The latest phishing scam is going after CPAs. This email looks official with a normal looking return address and using the AICPA email address and referencing the Better Business Bureau. The subject line is threatening to say the least.

From: “Scotty Aguirre” <risk.manager@aicpa.org>
Subject: Your accountant license can be revoked.
Date: February 20, 2012 7:00:47 PM CST
The message tells the recipient that their CPA license is being terminated due to tax fraud allegations and encourages them to click on a link and reply to the charges. The link leads to a third party website that downloads a virus on to the recipient’s computer. Do not click on the link!
aicpa phishing scam American Institute of CPAs BBB Email Phishing Scam

This email scam primarily targets accountants, but the Better Business Bureau has gotten reports of other professionals receiving the emails. I received this email today and the only thing that links me to an accountant is that I did my own taxes recently. However, the email address this phishing scam was sent to is not the one I use for business and is in fact the one I use when I have to sign up for something online.

Steps to take:

Related articles

 American Institute of CPAs BBB Email Phishing Scam

Intuit Bank of America Phishing Scam

Screen Shot 2012 01 26 at 1.42.02 PM Intuit Bank of America Phishing ScamThe Intuit and Bank of America phishing scam is a little disturbing because at first glance it looks pretty authentic. I received this email scam from what looked like a real email address. Of course I don’t have an account with Bank of America but for a brief moment I wondered if my taxes were somehow routed that way as we did our taxes using Intuit software. It was enough to make me hesitate.

This email from Bank of America who use their free online tax services is a scam and if you click on it you might get your computer infected with malware or worse access you online accounts.

As with any questionable email please contact the company (if you do business with them) using contact information you already possess. Don’t call or click on the numbers in the email.

 

 Intuit Bank of America Phishing Scam

Scam Alert, Phishing Scam, Malware ACH Debit Transfer

The ACH Debit Transfer Alert has been making the rounds since at least last fall. Below is a copy  of the email with links disabled. As you can see the recipient is encouraged to click on the link to learn more fix the transaction. The link leads to a website where malware is hosted. The malicious code executes several Windows registry changes and establishes a connection with the attackers’ IP address

Dear Sir or Madam,

This message contains an important information regarding the ACH debit transfer sent on your behalf, that was kept back by our bank:

Transaction #: 195585243650521
Status of the transaction: under consideration

In order to resolve this matter, please review the transaction details using the link below as soon as possible.

Yours truly,
Shirley Meyer
Chief Accountant

This scam is particularly effective because there are so many people who are struggling financially. Many merchants have a store name and a business name that are different. Often their lesser known business name is used for online transactions. Usually the company lets the consumer know the name will be different on the online transaction but not always. Of course there is no phone number in this email which is a big tip off that the sender is sending malicious links.

Always check with Google before clicking on the links of any emails that are vague like this one is.

Internet Fraud

As disappointing as it is to acknowledge, it seems as though the human race has an unlimited capacity for greed and swindling. I like to think it is a small number of actual criminals who just garner an out of proportion level of publicity. 

But no matter what century you examine, you will find documentation of confidence crimes.

When the Internet came along and then took off like crazy, it became a prime, new target.  In the days before people grew more savvy and/or were not taking advantage of security software, Internet scams were common and, often, successful.   People are more aware now, but attempts to part you from your money are still out there.

online scams Internet Fraud

Email scams have a long history

I got my first home computer in 1997, although I had been using one at work for about three years it was never for personal use.  Once I got my home PC Ebay became a favorite site.  A few months after joining, I got an e-mail telling me there was a problem with my account that I needed to rectify immediately by clicking on the enclosed link. 

Now, I did not know anything about Internet scams at the time, but for some reason I hesitated at clicking the link and instead went directly to the site.  I e-mailed customer service about the message and received a reply that gave me my first Internet security lesson and an introduction to phishing.  The e-mail I had received was a fake.

Does phishing require a rod and reel?

Phishing is an attempt to rob you of data or, eventually, money by fooling you into believing you are dealing with a reputable company you have previously done business with.  The e-mail looks official, but if you take a second glance, some things will pop out at you.

Often the grammar and language in the body of the message is incorrect or sounds stilted, as though it were written by someone whose first language was not English.  Sometimes it is subtle, but other times it is blatantly obvious, as in a greeting that is oddly worded.

How to protect yourself from scams

If you check the return e-mail, you will frequently find a Yahoo address, or another free e-mail site.  That should be a red flag.  There will be extra wording in the address, it won’t be simply ‘Ebay.com’, for instance.  If you click on their link and complete the information they request, such as your password or credit card number, you will be sending that data directly to the criminals. 

Reputable sites never, ever ask you for your password.  If you get an e-mail from an organization requesting sensitive information, your best bet is to close the e-mail and go directly to the site.  Contact the customer service department and ask if they sent the message.  Companies want to track phishing attempts, so they will often ask you to forward the original e-mail to them.

Security has improved dramatically over the past fifteen years, but apparently a criminal’s motto is “never say die.”  As long as there are possible marks out there, they will be trying.

Another e-mail scam is the now famous African Bank Transfer.  There are dozens of variations, but it starts with you getting an impassioned e-mail from someone who usually claims to be a solicitor.  They have millions of pounds that need to be deposited in an American bank but they will offer several confusing reasons as to why they cannot do so without YOUR help!  And if you do help them, you will get some or maybe even all of the money! 

This will usually involve you sending them some money in ‘good faith’ and/or providing your bank account number.  Remarkably, some people still fall for this.

Snopes.com keeps track of scams

An excellent resource for determining if something is a hoax or not is Snopes.com. They have an entire article on this scam and its many variations.

Another recent banking related scam is an e-mail telling you your automatic payment failed.  But it doesn’t specify which one, which is your first clue it is not on the up and up. Snopes has an article about that one, too.

There are other hoaxes floating around out there that do not necessarily involve money.  Rather, they are designed to inflame political hatred or elicit sympathy for someone, usually a sick child, who often turns out to be non-existent.  Muslim bashing with preposterous allegations is a popular topic too. 

In one example, I have gotten e-mails forwarded by people who were incensed that the President was disrespectful to wounded soldiers.  The rage factor was high on this one. Only the facts weren’t straight. Another good source to verify political e-mails is Factcheck.org.  The last thing we need in this world are lies and half-truths tearing us farther apart.

Scams show up on Facebook, too

There is nothing more heart-rending than a picture of an infant encased in tubes in the ICU.  On Facebook last week a friend posted such a picture with the comment that if 100 people shared the link the child will receive a heart transplant for free.  Now as a former hospital executive, that set off alarm bells for me right away.  No hospital will just give away surgery, like a prize.  They will look for some source of payment, not a popularity contest on Facebook.  Sure enough, after checking Snopes, I discovered it was false.  I find these despicable because they take advantage of people’s good hearts and inspire cynicism when the hoax is discovered.  I hate the idea of anyone feeling foolish because they were compassionate.

Those are just a few of the scams floating around, really just scratching the surface.  There seems to be no end to the creativity of criminals and mischief makers.  The best rule of thumb when it comes to any unsolicited e-mail is to be wary and check it out at a reputable site.  If it seems too good to be true or if something about it appears not quite right, trust your instincts.

 

Resources:

http://www.google.com/goodtoknow/  (Somewhat self-serving, but contains some good information nonetheless.)

http://snopes.com

http://factcheck.org

Marie is a retired nurse and healthcare executive who currently does freelance writing.  She blogs at Nourish, MS Renegade and The Shore Bookworm.

 Internet Fraud
Page 1 of 212»
Sign Up for the FREE Tribal Blogs Newsletter!
Email:
For Email Marketing you can trust

Become a Guest Blogger

Be a contributor at Tribal Blogs - Get free links to boost SEO rank, traffic and readers for your site when you become a guest blogger.
Vista Print Calendars How smart is your Theme?  How good is your support? Check out ThesisTheme for WordPress.

Grab the Button

Tribal Blogs
Web Analytics