• TalkBass has been independent since 1998. Add your voice.
    Create a free account to reply to discussions, view embedded media, and browse with fewer display ads.
    Join freeLog in
    Want zero display ads or expanded classifieds tools? Compare plans.

Am I being scammed?

I get bogus FedEx, Amazon, Netflix, Facebook, Twitter, and PayPal e-mail all the time.

They go straight into Spam.

I've even had fake e-mail from U.S. Homeland Security, and the F.B.I. that looked totally authentic.

I notified both organisations (though deliberately didn't forward the fake emails to them, knowing how draconian those types of institutions can be, I didn't want to fall afoul of a legal technicality, whereby I had actually sent them fraudulent materials).

Neither organisation could give a damn, and weren't in the least bit interested.
 
This morning I found in my e-mail something from this sender
">"FedExShipping..." <[email protected]>, purporting to be a notification of impending delivery and requesting a customs fee of $1.95. I went through the sequence of steps and got as far as filling in my personal information in the boxes, but then common sense took over and I did not submit the information but instead closed the e-mail. But it got me thinking.

I do have a weekend bass purchase through Reverb on which I am awaiting delivery, but it ships out of Moultrie, GA, and why would there be a customs fee on an item shipped from one adjacent state to another? And what kind of customs fee is a charge of only $1.95? And that sender address was starting to look suspicious.

So I logged into FedEx.com and ran my tracking number through their system. FedEx
could find no such number in their files. So, is this a scam, and did I compromise my personal information by filling in the boxes even though I did not hit "Submit"?
It's a scam dude
 
  • Like
Reactions: DJ Bebop
Sweet bass! Sorry about the scam thing. It’s easy to fall prey to these things.
My company’s IT department sends fake phishing emails to see if we’ll bite.

Two of the companies I've worked for in the last 10 years made us all do antiphishing training then send a confirmation from an outside email or use a self signed certificate and require us to submit info to get credit.

Did you not just tell us not to do this? Several of us thought it was a trick. No, IT confirmed we had to do it for credit on the required training
 
The website that the scam e-mail directed you to, was no doubt logging your keystrokes - thus capturing all the info you typed in, even though you didn't submit it.

For certain things, I usually have a text document with an innocuous name, saved somewhere on my computer, with a bunch of mundane text, but hidden amongst it my pertinent data, which I copy, and paste into the relevant fields in a random order, before reassembling it correctly.

I've been doing that for years, but I wouldn't be surprised if these days the spyware can track your clipboard, and the copy/paste sequences - So I'm probably wasting my time, and it's actually more secure to have your browser auto-fill out those kinds of forms???

Even though it was undoubtedly the website that captured your keystrokes, it's still worth you running a system-wide scan of your computer, for any spyware.


Anyway, the most important thing is that you've introduced me to a potential alternative to my Gretsch 6072 quest.

Thanks!

I have a bit (not much) of experience with Javascript which is likely how input is captured without submitting - I'm not sure this is doing much for you. I can think of three ways they might do this:
  • A script that responds to key events - it waits for keys to be pressed, and when that happens it grabs the data entered so far and sends it to their server. And yes, Ctrl-c Ctrl-v are keys.
  • A script that responds to paste events - I think there's a specific paste event that a script can listen for (which will include right-click paste), then grab input.
  • Even without event listeners, you could probably just run a timer at a small interval (seconds, milliseconds), that periodically grabs whatever has been entered so far.
I'm sure someone else on here could tell you a dozen other ways this could be done, because again, minimal experience. Or maybe I'm wrong. Still, I think at the point where you're filling in input boxes on a website, you've already lost. The best way to avoid your info being stolen really is just to be cautious from the get go, have good judgement, and not open links that are suspicious.

There are more drastic things you can do, like disabling javascript except on trusted websites, but that's generally more of a pain than most people want to go through.

Stay safe out there!
 
Last edited:
this one i got this morning from "IPS" was laughably bad :whistle:
Screenshot_20230301_233619_IPS.png
 
Just as a follow-up and a word of warning. Even though I did not "submit" my personal information, somehow the scammer obtained it anyway and made a charge on the card today. Fortunately my credit union's fraud protection unit caught it and tipped me off. The transaction was cancelled and my card expunged. I will be sent a new card. So it looks like scammers do have a way to harvest our information even if we do not submit it.

My Reverb transaction from the 25th did go through and will be honored, which to me is a big deal because of the nature of the purchase.
Be sure to run a virus scan. There are quite a few "Key Logger" viruses that will log every key you hit and send it to the hacker. If he knows what time you opened his e-mail, it's easy to see your personal info. These key logger viruses usually arrive as a Trojan Horse, where you download an app you want and the key logger infects it. Then when you install your new program, it also installs the key logger program with it. So be sure to run a scan on your hard drives.
 
They look decorative, just like a real 6072.

Presumably there's and access panel on the back (maybe even the padding too).

Weirdly, it looks like it might actually have a bolt-on neck...

The screws would have to be about 3" long!!!

It is short-scale and it does indeed have a bolt-on neck, which may make set-up easier than on a real 6072.

The f-holes on real Gretsches have bound f-holes, whether painted on or real. (I just looked.) Those f-holes to me look real. I doubt there is a rear access panel, so if those f-holes *are* fake, I'm in a world of trouble.
 
  • Like
Reactions: Wood and Wire
...a good rule of thumb for all, is if you want to "check it out" DO NOT click on any links in emails, texts, messages, etc.

Instead, go directly to the website, and log in from there. You will not find the item being referenced in the "emergency" notification.
1000 X this.

Anytime "someone" sends you a request for information, never follow a link in an email or fill out a form in that email. Close the email and go directly to the site in question where you can check on the actual status of your actual account. If there's a real problem, you will see it there. Odds are extremely good that there is no problem.

I get fake emails all the time, everyone does. Usually it's pretending to be from a company I have no relationship with and those are easy to dismiss as fake. Now and then it happens to be a company I actually do business with that they are pretending to be. If I have any doubt, I check at the website. Easy.
 
Just as a follow-up and a word of warning. Even though I did not "submit" my personal information, somehow the scammer obtained it anyway and made a charge on the card today. Fortunately my credit union's fraud protection unit caught it and tipped me off. The transaction was cancelled and my card expunged. I will be sent a new card. So it looks like scammers do have a way to harvest our information even if we do not submit it.

My Reverb transaction from the 25th did go through and will be honored, which to me is a big deal because of the nature of the purchase.

It's probably a different scanner who has also obtained your details as they are now for sale. Change your passwords, use services to check which of your email addresses may be compromised and be prepared to change ones you use for important things. Years ago, my email provider allowed me to create almost unlimited aliases and I wish I had created more as it allows me to use different ones or change them. Also, check you don't reuse passwords, and/or use long ones that are hard to decipher. YMMV as I can remember arbitrary strings of letters, numbers and symbols better than I can the chords of a song, but there are a number of techniques for creating seemingly random strings that mean something to you. It might even be something like the first letters of the names of the flowers in your garden, in order.
 
  • Like
Reactions: yodedude2
This morning I found in my e-mail something from this sender
">"FedExShipping..." <[email protected]>, purporting to be a notification of impending delivery and requesting a customs fee of $1.95. I went through the sequence of steps and got as far as filling in my personal information in the boxes, but then common sense took over and I did not submit the information but instead closed the e-mail. But it got me thinking.

I do have a weekend bass purchase through Reverb on which I am awaiting delivery, but it ships out of Moultrie, GA, and why would there be a customs fee on an item shipped from one adjacent state to another? And what kind of customs fee is a charge of only $1.95? And that sender address was starting to look suspicious.

So I logged into FedEx.com and ran my tracking number through their system. FedEx
could find no such number in their files. So, is this a scam, and did I compromise my personal information by filling in the boxes even though I did not hit "Submit"?
It's a scam. FedEx wouldn't have an email of that address.
 
"emergency notices"
This.
Since when has a major transportation company been concerned that your package will not be delivered on time? They work with an estimated time of delivery, deviations from this are factored in.

I ignore all emails from " shipping companies", I regularly look at the track and trace of my shipments, if no problem reported here, I will not take any actions.
 
  • Like
Reactions: JRA
I get texts of these kind of things. Sometimes companies I deal with, sometimes not.

Here's the thing: if you get something asking you to click anything or provide any information, it is a scam. And most legit companies now use two step authentication, where you get a temporary code.
 
This morning I found in my e-mail something from this sender
">"FedExShipping..." <[email protected]>, purporting to be a notification of impending delivery and requesting a customs fee of $1.95. I went through the sequence of steps and got as far as filling in my personal information in the boxes, but then common sense took over and I did not submit the information but instead closed the e-mail. But it got me thinking.

Good reminder. Email, text and even phone calls can be after your money.
I still have a rubber band around my wallet..