• About
  • $40K Challenge
  • Aunt Doris
  • Grandfather Says
  • Privacy
  • Archives
  • Disclaimer

Len Penzo dot Com

The offbeat personal finance blog for responsible people.

bullion star banner

The Embarrassing Anatomy of a Phishing Scam

By Len Penzo

You’ve got to hand it to scam artists. They often succeed in spite of themselves.

If I had a nickel for every time I retrieved a message from my inbox warning me that my PayPal account has been limited, or that my credit card has been suspended, well, I’d have at least a hundred bucks in my pocket right now.

Don’t scoff. That’s 2000 nickels!

Not too long ago it happened again. I got an “urgent” email from VISA and MasterCard — apparently they are now one company — to tell me that my credit card was suspended.

By the way, they didn’t identify whether they were referring to my VISA card or my MasterCard, but why worry about important details like that?

Of course, they wanted me to supply them with all my critical credit information, including my credit card number, mothers maiden name, social security number, security code, pin number and password.

So I gave it to them.

Just kidding.

You know … the whole episode would be funny, if only it weren’t so sinister. Which is why I thought I’d take a moment to point out just how lazy these thieves usually are when it comes to trying to make a quick buck, by showing you a screen shot at the bottom of this post from the aforementioned phishing scam that appeared my inbox.

The good news is the scammers’ laziness usually provides most folks with enough obvious clues to realize that something is probably amiss.

True, there are a few cyber criminals out there who make their phishing attempts much more professional, but if you stay vigilant it’s tough to get fooled. Remember, credit card companies and banks will never send you an email message that requests your personal information.

What are the major clues to look for? Well … there are quite a few of them. Here are some of the most common ones:

  • Unprofessional presentation
  • Using “Dear customer” instead of your name in the salutation
  • Broken English
  • Misleading links that direct you to a site that’s different than the company that is supposedly contacting you
  • Misspelled words or poor formatting
  • Requests that seem strange or out of the ordinary
  • Directing to you to reply to an email address that is different from the stated sender

And folks, if you ever have any doubts regarding the veracity of any message in your inbox regarding your credit or debit cards, call your bank or credit card company directly.

(click to enlarge)

Photo Credit: Iain Wanless

June 20, 2022

Question of the Week

What's your retirement magic number?
VoteResults

Comments

  1. 1

    Glen says

    Obviously people still fall for these tricks as otherwise the scammers would have stopped doing it a long time ago.

  2. 2

    Jason says

    All your base are belong to us!

    • 3

      Len Penzo says

      Ha ha! Indeed.

      Just in case some of you older readers out there don’t get Jason’s joke:

      http://en.wikipedia.org/wiki/All_your_base_are_belong_to_us

  3. 4

    Mindimoo says

    My favorites are the ones where a Nigerian prince offers me millions and millions of dollars. Of course he would choose me, of all the people in the world. 😀

  4. 5

    shanendoah says

    My favorites are the ones that tell me I won a European lottery- one where you don’t have to play, they just pull your “number” and you win. Considering I’m not a resident of any European country, I have no idea how I was assigned a number for the lottery, but by golly, my retirement plan is winning the lottery, so I should provide them with all my banking information so they can deposit my winnings…

  5. 6

    Bret @ Hope to Prosper says

    I read an article about phishing recently and the author claimed the misspellings and mistakes are in the phishing emails on purpose. The theory was that perps are looking for gulible people and try to weed out the people who won’t follow through with the scam. It saves them time.

    I’m not sure if this is true or not, but I thought it was interesting. I wish I had a link.

    • 7

      Len Penzo says

      That kind of makes sense, Bret — but I don’t buy it. 🙂

  6. 8

    John@MoneyPrinciple says

    My email client doesn’t parse the HTML unless I ask it to so I see the source. Scroll down a bit and you find where the form is posted to and it isn’t the people it should be to!

    Some are quite good though the Nigerian or whatever scams are getting quite boring now.

  7. 9

    deRuiter says

    A lot of successful scams of this type go through Craigslist. Tips offs are “I want bo buy your item, (never mentions what item is) please send info…” and about places for rent, “I’m a doctor moving from England and I need your apartment / house / condo, please send details, consider it taken, please remove advertising so i will know you are sincere in wanting to sell / rent to me.” In the end their “assistant” ACCIDENTLY sends you a check for more than the amount, and you must immediately WESTERN UNION WIRE THE OVERAGE back to them to cover some emergency, and the sheep to be shorn do that. Then of course the original check bounces and your bank wants the money or you go to jail.

  8. 10

    Doug Blasco says

    It absolutely amazes me that anyone in this day and age would actually open the email, let alone respond to it.

  9. 11

    Kleurplaten says

    Someone told me a while ago, that these people are smarter then you think… because there is a reason why there letters are so bad…. because they only want the retards….smart people won’t fall for a scam… dumb will.. and they are triggering the dumb to get a lot more cash….

    • 12

      Len Penzo says

      Well … you’re the second person to bring that up here. Although I was skeptical the first time I heard it, maybe there really is something to it.

    • 13

      Joe says

      I have heard this too. The thought being that if it looks super legit a lot of people will follow up on it, but not just instantly hand over the important information. The perps will spend a lot of time corresponding with people who will ultimately call the real company etc and figure out it is a scam long before handing over money/personal information/whatever. But if it is obviously fake to most, those who reply are only those without enough common sense to be tight with information needed to exploit them.

  10. 14

    deRuiter says

    With Craigslist you never know in advance which emails are legit. Some of the real emails from real customers end up in the SPAM folder, and some of the fake ones come through into your email box, so you need to open them all. I’ve sold a lot of things to customers whose Craigslist emails have been fished out of the SPAM folder. And I’ve ignored a lot which come through as regular emails. 99 times out of a hundred I don’t bother with those. On a slow day I might offer to write them a better email which will allow them to pluck more pigeons, for the modest sum of a hundred dollars. Or I inquire about how the weather is under the palm tree in Nigeria as they labor over a hot, bicycle peddal powered computer. Come to think of it I don’t kinow if they have palm trees in Nigeria. Money is meant to move around, it is productive that way, not productive to keep it under your pillow. Those who get scammed by these transparent ploys will either learn the hard way, or be scammed again. “The Government” will not protect you, even if you think “The government” will. It is up to the individual to protect themselves, whether from Internet scams, food shortages, or violent home invaders. Waiting for “The Government” to help you is whistling in the wind.

    • 15

      Len Penzo says

      Believe it or not, I’ve responded to almost a dozen of these Nigerian scammers over the past year to document exactly how they work. Our email exchange usually goes back and forth over a few iterations (at best) before they figure out that I’m not a legitimate mark. Then they stop responding to me.

      The longest exchange I had went on for a couple weeks (it was one of those “Secret Shopper” scams) but broke down after he refused to accept my blog’s PO Box as a mailing address. He insisted on my home address.

      I have kept all of these exchanges. I think I’ll share them here soon in a future post.

  11. 16

    Joe @ Retire By 40 says

    I rarely open these email anymore. I usually can tell just by the subject and ignore them. Great graphic.

  12. 17

    Lola says

    The best one I ever got went like this:

    I am an assassin and have been paid by your enemy to kill you. He has paid me (xxxx amount) to kill you. Unless you pay me the same amount, you will be dead within 7 days.

    It went on to say he knows where I live and work, threaten my family, etc. I was in giggles for HOURS! 🤣

    • 18

      Lauren P. says

      That’s hilarious, Lola! I’ve never heard of that one, but it’s even better than the ‘chain email’ where if you don’t forward it to 10 people within 7 days you’ll die.

  13. 19

    Slackerjo says

    I got an email from the head of the FBI which is odd since I live in Canada. At least make an effort. You claim to be the head of the FBI but you have a yahoo email account.

    • 20

      Earl W. says

      LOL! My favorite was similar. The email said that I owed thousands of dollars in back taxes and if I didn’t pay I would have my assets seized and be arrested. Luckily though for a limited time the government was offering to settle for only $400.

      Naturally, the IRS’s preferred payment plan was to send the money western union directly to the IRS agent who was emailing me. From his excite.com account. So apparently not only had the IRS agent hunted me down from his personal account, he had done so through the fabric of space-time and was hunting me from approximately 1997.

      Needless to say I was hesitant to send the full amount immediately, so I guess I have been on the lam ever since. Please don’t anyone turn me in 😉

  14. 21

    Doable Finance says

    Lucky for them, they have some of the best technology available to them, better than ordinary folks who just surf the Internet and cheaper too.

  15. 22

    Harry Meyen says

    When in doubt call the number on the back of your card.

    • 23

      Len Penzo says

      Great advice!

  16. 24

    Randy A says

    I haven’t heard from Nigeria lately. Maybe they ran out of money due to their generosity. Most of the frauds I have received lately have been the Best Buy Geek Squad annual renewal notice for about $400.00. I also received the “Microsoft has determined that your computer has been infected and you need to call the below number immediately or your computer will be locked permanently” sent from Microsoft’s Gmail account.

  17. 25

    bill says

    “Your package could not be delivered…”.

    It is because I didn’t order anything.

    • 26

      Len Penzo says

      Are you sure, Bill? I have an order here for a giant fruit cake. 🤣

      (Inside joke, folks.)

      • 27

        bill says

        We are giant fruit cakes.

Trackbacks

  1. 4 Ways Social Media Use Makes You Vulnerable to Identity Fraud - Len Penzo dot Com says:
    April 11, 2017 at 5:15 am

    […] posing as a legitimate company or business, scam artists often use social media as a phishing scam to get you to reveal sensitive information. Because your name, address and phone number may be […]

  2. How Businesses Limit Damage from Toxic Plugins, Software & Hardware - Len Penzo dot Com says:
    July 14, 2017 at 5:15 am

    […] but the reality is that infected USB drives, Remote Access Trojan (RAT) hijackings of webcams, and clickable scams are more common than you might […]

  3. Falling for This Tax Scam Will Have You Singing an Unhappy (i)Tune – Len Penzo dot Com says:
    April 12, 2018 at 4:15 am

    […] these scammers will stop at nothing to scheme Americans out of their hard-earned money. And millennials are actually more likely to […]

  4. Facebook Hack Was Even Worse Than Originally Realized – Len Penzo dot Com says:
    October 17, 2018 at 3:16 am

    […] States has been hesitant to stand up and regulate companies like Google and Facebook following data breaches (setting aside overly dramatic congressional hearings), the European Union is pushing pack against […]

  5. 5 Simple Ways to Avoid Online Fraud – Len Penzo dot Com says:
    July 26, 2019 at 4:15 am

    […] yourself is to know how to prevent such occurrence. That is the focus of this guide to teach you how to avoid being scammed […]

  6. 4 Ways Social Media Use Makes You Vulnerable to Identity Fraud – Len Penzo dot Com says:
    June 16, 2020 at 4:16 am

    […] posing as a legitimate company or business, scam artists often use social media as a phishing scam to get you to reveal sensitive information. Because your name, address and phone number may be […]

  7. Black Coffee: To Work, or Not to Work — That Is the Question. – Len Penzo dot Com says:
    November 21, 2020 at 3:56 pm

    […] The Embarrassing Anatomy of a Phishing Scam […]

Copyright © 2025 Len Penzo dot Com · All Rights Reserved · Designed by Nuts and Bolts Media

© Len Penzo dot Com 2008–2025

Get Len Penzo dot Com delivered weekly!

Join our family of more than 40,000 happy subscribers!

Invalid email address
We promise we'll never spam you. You can unsubscribe at any time. 
Thanks for subscribing!