CNN and other major news sources are reporting that there is a very new and highly dangerous Facebook scam being employed.  This is a fake e-mail from Facebook asking users to open an attachment to receive a new password. Once opened, this attachment infects the user’s computer with a password stealer, which can give these criminals access to your banking, credit card, and other personal financial information.

The fake email may appear somewhat as like this:

Hey [user's name]:

Because of measures taken to provide safety to our clients, your password has been changed. You can find your new password in attached document.

Thanks,
The Facebook Team.

It is likely that those distributing this scam will change what this message says or use different variations in wording. So be advised, Facebook IS NOT changing passwords. DO NOT OPEN any such attachments. DELETE this message immediately upon receipt!

From: Matt McGlynn
Date: 11/11/2009 9:23:12 PM
To: barry@writerpro.biz
Subject: response from Care2
Hello,
I’m writing in regards to your recent blog post about
the credit card scam you received via a Care2 ecard.
I am sorry you received that ecard, and sorrier still
to see our good name featured in an article on HighRiskWebsites.
What you received is certainly a scam. What was not clear in
your piece is that Care2 was not the scammer, but the victim.
The criminals behind this attack organized a botnet of over
400 hijacked PCs all around the world; these computers were
submitting dozens of these scam ecards (all with subtle
variations in the messaging) per second. Our warning
bells went off, and we were able to shut down the
attack — but not before some of the ecards were sent out.
Care2 has offered a free ecard service for over 10 years.
We have some of the best ecards on the web, and we make
donations to save a square foot of rainforest for every
ecard sent.
Millions of people use Care2 to send ecards to friends and
family every day. Sadly, like any free service, our site is
occasionally abused, resulting in issues like the one you described.
If you visit the URL you published, you’ll see that the
scam ecard has been deleted. What you received is strictly
prohibited by our Terms of Service. And we’re putting additional
systems in place to prevent a recurrence of this sort of attack.
Care2.com was founded to help make the world a better place.
That is literally our mission. I invite you to come check out
Care2.com again. I think you’ll find out where are hearts and
minds are if you do.
Thanks for reading. Feel free to contact me if you have
any questions.
matt.
CTO, http://www.care2.com/

Here’s a new wrinkle in e-mail scams. It plays on your curiosity to find out who has a secret crush on you. If you click on the care2.com link, you will be taken to a personal message that is shown after this e-mail:

917595 sent you an eCard from Care2! Click on the following link to view your eCard, or paste it into your browser:

http://www.care2.com/send/pickup/1311-62411-134424-2729

This Care2 eCard was sent November 8, 2009 and will be available for 14 days.

Warm wishes,
www.Care2.com
Where spreading love & laughter helps save the world.
Every time you send a FREE Care2 eCard you save a square foot of rain forest. Learn More.

Here is the e-card message you will receive. Note that it informs you that you “may have to use a CC (Credit Card) or a debit card for verification. THIS WILL END UP BEING A SURPRISE CHARGE ON YOUR ACCOUNT. DO NOT SUPPLY ANY FINANCIAL INFO TO THIS TYPE OF SCAMMER. Here’s what the card will say:card-scam

The next e-Card message will display this personal message:

n4y7h4r

Hi Barry… This is difficult for me to do because I’m shy..but I have a crush on you. I’ve never been able to tell you for reasons which you would quickly identify as obvious if you knew who this was. With that said I want you to guess who I am and approach me yourself.

To help you out with your guessing I made a few pictures and videos with Barry written on my body. They’re kind of risque photos so I had to make a profile at www.megafriendly.com (copy & paste or type www.megafriendly.com into your web browser). My username in the members area is BarryandME09. It’s a free website but you might need a CC or Debit to verify your age because I had to. Sigh.

But anyway sign up at www.megafriendly.com and once you are inside search for me. I want you to guess who I am and then approach me yourself. I’m shy and this is the bravest thing I’ve probably ever done but you need to do the rest.

Kisses
Secret Admirer

p4b2e0k5q8m1u9e1v8g0

If you now enter the www.megafriendly.com URL into your browser and click search, it will quickly make the scam clear: This is a web cam girl’s site. And their goal is to get your financial info so they can charge you later!!

sexcam-scam


The thing to remember here is NEVER to provide any further actions. DO NOT fill out the financial info even though it says “$0 charge for age verification”.

There has been a rash of Internet frauds perpetrated by offshore Porno websites in Great Britain. Marks are selected from ‘casual encounter’ ads appearing on Craig’s List and a few other sites. This fraud is presented here in detail.

Here’s How These Scammers work:

The fraud begins with a response to an ad on Craig’s List and, at least initially, appears to be a legitimate response from an interested party. The first response looks like this:

** CRAIGSLIST ADVISORY — AVOID SCAMS BY DEALING LOCALLY

** Avoid:  wiring money, cross-border deals, work-at-home

** Beware: cashier checks, money orders, escrow, shipping

** More Info:  http://www.craigslist.org/about/scams.html

Hey!  Just checking if the ad is real. I was very interested. Please get back to me as soon as possible.

——————————————————————

This message was re-mailed to you via: pers-5gywq-1438659929@craigslist.org

——————————————————————

If you respond to this ad (NOT RECOMMENDED) Here’s what comes next:

Hi  (your name), glad to hear you’re real! I’m interested in hearing more about you and possibly us, hehe. How does that sound? (your name), it’s Tuesday and I need to find someone quick. I hope you are the one.  I have one concern though. Before we go any further I’d like to make sure you’re at least eighteen. I am a little uneasy about

meeting up  with  someone who I haven’t check’d out. My friends use a

service that verifies that men are ok to meet and are of age.

So (your name), I’m at the site now and they generated a link for me to send to you:

http://www.vernow.com/?=1068

You will be able to see my pic on there too. I have more pics for

you, but only after  you verify your age. Btw, older guys is a

turn-on. As soon as you  do  it,  will  e-mail  u  my  phone  number and we’ll make plans. I

promise… thky  for  understanding.  I hope to be talking on the phone with you soon! Later.  (Some grammar corrected for easier readability).

Now, if you click on the blue link she supplies, you will be taken to a website called:

Vernow.com

Someone you met online has sent you here to verify your age. Vernow.com is a service that helps you verify the age of anyone you come in contact with online, FOR FREE.

Step One – Please Verify Your Information

Please wait while we verify your information.

Click the Submit Button below when you are finished!

Your friend, Jennifer Bensen is online and waiting to receive the confirmation email that we will send once you finish this last step!

Sender’s Details

Note from Sender:
Scam-AlertHey, thank you for verifying your age for me. My friend uses this site all the time and says it helps her feel safer. I’ll feel more comfortable talking dirty and sending you my *other* pics once I receive confirmation that you are at least 18. You never know who you’re chatting with online! I’m glad you understand my prediciment and I hope to talk to you soon. I’ll email you once this site sends me the confirmation email that you’ve verified. xoxoxo – Jennifer
Name:
Jennifer Bensen

Gender:
Female

Age: 20 – 30
City: N/A
State: N/A
Zip: N/A
Area Code: 562

Request Sent:
Wed, Oct 28, 2009

Testimonials (show)

“Vernow.com was so easy to use and kept me safe when chatting with men online. I am confident that I am speaking with an adult every time I use Vernow.com”

Mary G. Saratoga Springs, NY

“These days you can never be too safe. Vernow.com is extremely easy to use. All I have to do is send a link to a guy I’ve met online and Vernow.com takes care of the rest. After he verifies his age, Vernow.com alerts me via email. My potential date and I can be adults and not worry about what we talk about. Thank you Vernow.com!”

Jessica F. Boise, ID

“When I posted a personals ad to Craigslist for the first time I was bombarded with responses. Even guys who sent pictures and claimed to be 18+ didn’t convince me. I use Vernow.com every time!”

Jim M. Cincinnati, OH

“You never know who you’re chatting with online. Age is a huge concern for me that’s why I use Vernow.com.”

George L. Fresco, CA

“The internet is filled minors. You would be stupid not to protect yourself with Vernow.com. It only takes a few minutes of your time and might even save your ass one day!”

Kelly J. Tallahassee, FL

© Vernow.com 2009 | All Rights Reserved

Filling in this simple form and pressing NEXT brings you to a page that

Asks you again to submit your credit/debit card info for age verification purposes only. (DON’T EVEN CONSIDER IT UNLESS YOU WANT TO THROW AWAY SOME HARD EARNED MONEY!!)

Once you do submit that info, you will receive a confirmation telling you that your info has been accepted. It looks like this:

(YourName),

Member ID:      34134089

Cost:           $0.00 (NOTE THIS)

Your membership has been activated.

Site name:      Amateur Site HD

Members URL:    http://www.maingateway.com/lockdown/159/

Username:       gg9pbke7u

Password:       hx3mneg3q

Any charges appearing on your credit card statement will be discretely billed as: WEB-FEECHECK.COM

—————————————————

Have questions? Need help? We are here to help 24/7.

Web Site: http://www.web-feecheck.com

E-mail: help@web-feecheck.com

Toll Free: 888-811-2544

Should you click on the www.maingateway.com link above, you will immediately be taken to a porno website that you probably didn’t expect on their sign-in page. The pictures of videos offered are NOT reproduced here. However, at the very bottom of that page, there is the name and address of the owner in the U.K.:

Perkindale LTD
15 RoseberryTerrace
DH85RT Consett
United Kingdom

By now, the realization that you’ve been had hasn’t settled in quite yet. You may even write to Jennifer again and ask, “what’s up with the porno stuff?” Don’t be shocked. You’ll never hear from her again!! In about an hour, you will discover that your bank account or PayPal account has been charged for $37 +. This lovely-looking lady that was falling all over her e-mail to get with you is nothing but bait—a “shill” for the U.K. folks in Consett. Your only hope now is if you saved copies of all this documentation and file a fraud claim with PayPal. But it will take time.

The moral here is: If something seems too good to be true on the Internet, it undoubtedly is. Your money is now in their pockets and you can’t do anything much about it!

NOTE: These scams abound on the web. They will play on your lust, naivety or anything else they can think of to get you to fill-in that form. DON’T!!

AGE VERIFICATION THAT REQUIRES YOUR FINANCIAL INFO IS ALMOST ALWAYS AN OUT-AND-OUT SCAM!

SCAM ALERT—SCAM ALERT—SCAM ALERT

Here’s a new e-mail scam alert in the name of the International Monetary Fund.

Note how the scammer seeks to obtain your personal information and $175.00 of your hard-earned money (highlighted in RED).  Never reply to an e-mail of this type.

FROM THE DESK OF DOMINIQUE STRAUSS-KAHN

PRESIDENT INTERNATIONAL MONETARY FUND (IMF)

ATTN: BENEFICIARY.

This is to officially inform you that ATM card number: 5428 0500 1100 4432 worth Three Million United States Dollars ($3 Million USD) has been credited in your favor in bid to compensate you on your winning sum since you are next on our compensation file for the second part of this fiscal Year 2009.

Your personal identification is ATM-5379. Contact the verification officer in African Region (Dr. Paul Omego) E-mail: atm.paymentdept2341@gmail.com

Tell: (+234) 1 4315436 with the below details for proper verification and immediate delivery of your prize via ATM CARD:

1) Your full Name…………….

2) Your Delivery Address………

3) Country………………

4) Your Telephone Number………….

5) Age and Occupation…………..

Most importantly, you are also required to send him the sum of $175 fee for your ATM CARD delivery.

NOTE: be aware that US$3,000,000.00 (Three Million United States Dollars Only) was awarded to you as a compensation payment and be also informed that the Fund Approvals and authorization documents have been handed over to DR. PAUL OMEGO.

Best Regards

DOMINIQUE STRAUSS-KAHN

PRESIDENT INTERNATIONAL MONETARY FUND (IMF)