spam

Sophisticated Spam

There are a few mistakes which make this junk mail stand out as a scam, but it's incredibly sophisticated by way of a social engineering attack compared to the 419 scams of old.

Dearest friend

I make this contact believing we will be of support to each other in developing a long-lasting cordial business relationship. I am moved by my inspiration to trust your sincerity and ability.

Email List Breach at Ticketline or cccampaigns.net / campaigncommander.com / emailvision.com

Both these emails were delivered to the same address, an address only shared with Ticketline and their mailing list providers. I can only conclude that there has been a security breach somewhere along the way. The same technique I use here was how I discovered the breach at iContact.

Spam Filtering Headers

It seems that most of the headers in emails are now for spam filtering:

Update: Likely Data Security Breach at iContact.com

On the day I posted Suspected Data Security Breach at iContact.com I was contacted via Facebook by someone with an email address @icontact.com. I forwarded them the same information that I sent to their abuse team. I’ve not heard anything back since.

Others have picked up on this likely breach at iContact.com:

Suspected Data Security Breach at iContact.com

I suspect iContact.com has suffered a data security compromise.

Summary

I have received four nearly-identical spams to four different addresses known only to myself and four distinct websites. These four websites all use iContact.com for newsletter mailing. I have also received this spam to a spam-trap address, but importantly, to no other unique addresses that I use with other websites. The evidence points strongly to a data breach at iContact.com.

Photonlight Email Leak

I bought a product from Photonlight in 2002, and have been on their mailing list ever since. I last received something from them on 30th December 2009. Alas, now I’m also receiving spam to the address previously only known to them.

Pages

Subscribe to RSS - spam