Ever get a worrisome eMail that causes you to want to do something about it right away?
First answer: STOP! Think!
Consider the following attempted scam eMail I received:
Wow, I might think, I need to click through that link because I didn’t set any hold on my mail service. I need to go see what’s up.
But wait, let’s stop and think about this for a moment…
– Who sent it? MailHold@sujacsewing.com? That’s certainly not the US Postal Service! They spoofed the name as “USPS” and maybe some eMail clients wouldn’t show the reply eMail address, but most clients allow you to see it if you look for it. Even the reply eMail address itself is likely spoofed, using some hapless business’ domain. BIG RED FLAG here.
– Would someone in the United States format dates in Day/Month/Year format? No, and certainly not the government. Another red flag.
– I must have Microsoft Word installed on my PC? Why? Do we really think the postal service would require that?
– I wouldn’t use my business’ support eMail address for any legitimate hold mail request.
– There are several mildly alarming phrases, such as “cannot be canceled” and “Dont call me” that are put there to try to get me to react, not think.
– If it’s the real United States Postal Service, shouldn’t my name, physical address or at least some more information that would personalize this notification appear in the message?
– The message seeks (subtly in this case) to get us to click through a link.
When we look this over in general, we start to realize that it’s really quite an amateurish attempt to manipulate a recipient into a knee-jerk reaction, to follow a link and presumably (I didn’t click through it) download a document that likely attacks Microsoft Office / Word to try to infect the recipient with something.
Morals:
NEVER react quickly without thinking to something you’ve received, no matter how important you may feel it is to deal with it quickly.
ALWAYS think first, seek to verify authenticity of the source, look for odd inconsistencies, and seek alternate means to contact your legitimate service institutions.
Treat anything that seeks to grab your attention with suspicion and even contempt. Don’t do what THEY want you to do. Do what YOU think makes sense.
-Noel