This will be a quick post. We have received a phishing mail to our info@lemmy.world mail address telling that they are “lemmy.world Security Team”, telling that they will “disconnect” your account from our instance. This is ofc, not us. Do not fall for it! The attached image is how the mail looks like.

~Lemmy World Team.

  • @NOT_RICK@lemmy.world
    link
    fedilink
    English
    979 months ago

    Hello, it is I, John Security. Please respond to this message with your name and SSN or the FBI will arrest you for unpaid back taxes. Also, do you have any iTunes or Google play gift cards laying around?

      • @BeanEater@lemmy.world
        link
        fedilink
        169 months ago

        When’s the last time you checked your spam folder, 2003? I legitimately haven’t seen the 1337sp34k spam in 20 years. Lately it’s been Africans leaving me money at the embassy that I have to go pick up

        • Echo Dot
          link
          fedilink
          159 months ago

          For some reason I seem to be getting a lot of spam emails in French. And all of the links are pretending to be French Canadian postal service websites.

          I don’t know why because I’m neither French nor Canadian. Nor have I ever been to Canada.

        • @Eheran@lemmy.world
          link
          fedilink
          19 months ago

          The subject is sometimes a word with random capitalisation and potentially letters replaced with numbers or symbols.

  • Annoyed_🦀 🏅
    link
    fedilink
    659 months ago

    How do you guys know it’s not you guys?

    Joke aside, i wonder why they wanna phish for user account in lemmy? Unlike the exploit like a few months ago that specifically target admin, this one seems like it target anyone, it so random.

  • Isn’t it a waste of time trying these scams on lemmy.

    I could be wrong here but I would argue the vast majority of users are somewhat tech proficient since it’s not reached mass adoption and the user base is well, just us nerds?

    • NaN
      link
      fedilink
      English
      529 months ago

      Tech folks still fall for phishing. It takes a momentary lapse, failure to caffeinate, it happens.

      Lemmy is currently full of newly registered domains with weird suffixes, the kind that traditionally have been a phishing indicator. Lemmy.world is going to be harder to phish than some of the other ones where you have to read closely.

        • @sudo@lemmy.today
          link
          fedilink
          89 months ago

          I’m not “ignoring your emails” and “never responding”, I’m just security conscious

      • Karyoplasma
        cake
        link
        fedilink
        29 months ago

        This is the story how my Steam account got hacked:

        I was talking to a friend of mine at a party and I just bought a new game (forgot which one). He told me that he thought about buying the game as well and asked if I could let him try it out one time. I said “sure, just message me and you can log into my account and test it”. 2 days later, he wrote me on steam asking for my login data and I thought nothing of it since we spoke about it in person, so I gave him the info. Turned out, his account got hacked and the intruder basically got a two for one special by just asking lol

        Steam support rectified the situation and didn’t even scold me for sharing my account which is clearly a violation of their ToS.

        • @SgtAStrawberry@lemmy.world
          link
          fedilink
          1
          edit-2
          9 months ago

          It was Jim Browning, as another comment said. I can never remember his name more than Jim, so I settled for job description, as he is easy to find that way.

          But others have been through it also, Linus Tech Tips, The Spiffing Britt and Atomic Shrimp are the other big ones I know of, but there is plenty more. Of those Atomic Shrimp is also a scam hunter like Jim, so it definitely shows that just because you are very familiar with what it looks like you aren’t immune too it.

          I can’t remember if they all fell for the same or similar ones or if it was different ones, but that really doesn’t matter so much.

          And what happend was Jim and LTT got tricked into deleting there channels. LTT by a fake sponsorship and Jim I don’t remember someone else said it was fake YouTube support.

          Spiff had something of a similar thing happen but I don’t remember the means, and Atomic Shrimp I believe was a different typ of scam not related to YouTube.

          But everyone got their channels back in the end.

      • @Hazzia@discuss.tchncs.de
        link
        fedilink
        8
        edit-2
        9 months ago

        There’s also variable levels of sophistication for scam messages based on the desired target. If you’re looking for a whole lot of people who don’t understand technology enough to see through your premise, you go with the generic “hello sir and/or madame I am hackor send gift cards or I will delet ur phone”.

        If you’re after a very specific person who is well known to be privy to the normal red flags, you’re more likely to create a custom spear phishing campaign and mimic as closely as possible the format, lexicon, domain names, etc of something reputable to avoid setting off their BS detectors.

        With that said, yeah there’s enough people on lemmy that this low-effort take is worth a shot

  • Flying Squid
    link
    fedilink
    469 months ago

    I got an almost believable phishing text yesterday from a ‘collection agency’ that wanted me to download a PDF and go to their website. It looked very official and I’m having some debt issues, but it didn’t tell me who it was representing or what I owed or anything like that, so I could tell it was phishing. But a less-savvy person could have totally been fooled by it because it looked very real.

    • @henfredemars@infosec.pub
      link
      fedilink
      English
      219 months ago

      I got a spam message that was surprisingly well written until I realized wait a minute, if this is true, why do you need me to tell you who I am?

  • @Clbull@lemmy.world
    link
    fedilink
    379 months ago

    Why would they target Lemmy users?

    Your typical Lemming (for lack of a better term) is not technologically inept and would generally not fall for a phishing scam. They’d earn a lot more money from targeting Redditors.

    • @DudeDudenson
      link
      139 months ago

      That’s exactly how run of the mill phishing scams work. They prey on the people stupid or senile enough to not see anything wrong with this email and avoid wasting time on the people that easily spot the scam

  • Obinice
    link
    fedilink
    199 months ago

    Why are these sorts of things always written by somebody who can clearly barely speak English?

    • @Koen967@feddit.nl
      link
      fedilink
      169 months ago

      What is unclear? All you have to do is resolve the Lemmy world app on Android and install the errors on your iPhone mail.

      • Echo Dot
        link
        fedilink
        99 months ago

        Yeah I’m not actually quite sure I understand what the issue they are pretending is.

  • @cole@lemdro.id
    link
    fedilink
    English
    179 months ago

    I’ve gotten an email like this before for lemdro.id. I think it’s a generic phishing email since the community links look like email addresses (and actually often are)

    • Antik 👾
      link
      fedilink
      39 months ago

      Heya Cole, yeah I think it was a pretty generic fishing attempt. But we just wanted to get the word out. Normally Lemmy users are quite tech savvy but you never know. Cheers!

      • @cole@lemdro.id
        link
        fedilink
        English
        39 months ago

        Yeah no worries, all I’m saying is it’s a silly phishing attempt since it is only emailing admins!

  • @MicrowaveOvens@lemmy.world
    link
    fedilink
    119 months ago

    Hey, quick question. I’m assuming these emails are automated, so how do they know your account’s email? Is this part of a leak or are they sending email via “send notification to email” option in lemmy?

    • @jarfil@lemmy.world
      link
      fedilink
      59 months ago

      There are some commonly used emails by most domain owners, like: info, webmaster, security, reports, sales, etc. Some people also set their email with a catch-all address, so if someone sends an email to “cat.in.tights”, they’ll get it too.

      • @MicrowaveOvens@lemmy.world
        link
        fedilink
        -19 months ago

        Ah. so that “info@lemmy.world” is an email and this is not related to fediverse. Jus checked, there’s no such account here. No point in making an announcement about it here if its not related to fediverse and only gets sent to domain owners, imho. lol