Until a fellow parishioner came up to me recently asking me to write another column on phishing scams I had more or less written off the topic as being somewhat passé. 

However, I’ve run across several people who I would describe as being very aware and generally careful who have been victimized, or nearly so. 

Recently Ken Burns shared with me his own experience of a scam, one that fortunately had a good outcome. 

This scam was a pretty basic one, depending on a somewhat believable text message that related to an event of possible relevance to the recipient. Burns was expecting a parcel through Canada Post. He received a text message that at a glance appeared to be from Canada Post and that made general references to an anticipated parcel.

Of course that is how many of these scams work. They depend on the possible relevance to at least some of the recipients of the scam text message or email. Even if 95 per cent of recipients discard the message or, even better, their spam filters ensure they never see it, what of it? The ones who do see the scam represent potential gold for the scammers.

In the case of the scam text message received by Burns there was a follow-up reference to expedited tracking of the parcel for a small fee, in this case $2.50. I hear you now: $2.50 is a trivial amount. But it is used precisely because it is small and the recipient may be willing to pay.

Here’s where the scam hits pay dirt. The $2.50 payment amount requires a credit card, dutifully supplied by the victim along with number, expiry date, and CVV (card verification value) code. That’s all the scammer needs.

Fortunately, Burns immediately felt uneasy about having made the payment. He decided to drive to the local post office to make an inquiry about his expected parcel. An employee told him that Canada Post simply does not communicate with users by email or text message, and furthermore does not charge for tracking.

At this news Burns drove to his bank. An employee he knew took immediate steps, getting the credit card office on the phone. A good thing because as they were looking at the account, a purchase for several thousand dollars was underway. The scammers were using the credit card data provided through the $2.50 payment.

Immediately the credit card was frozen, although the purchase had already gone through by that point. Burns was assured that the transaction amounts would be reversed, and he was issued a new card.

In retrospect Burns said there were red flags in the text that triggered the scam. He noted that the email domain name in the message didn’t look quite right and that he should have questioned why tracking of a parcel should have a fee.

The “1” in the URL of this scam text message is a giveaway, writes Peter Vogel.  

If we look at the text message screenshot we see that the internet service provider displayed a warning about possible phishing and smishing (both terms referring to being “hooked” by a scam, originating either through email (phishing) or SMS text (smishing). The body of the message is fairly innocuous, with reasonable grammar and spelling. There is one case error where a sentence leads with a lowercase letter.

It’s the link URL that is problematic; the “1” is a giveaway. The use of http as opposed to https is also a red flag. 

In any case an after-the-fact check on the “postca1.site” domain shows it was registered Nov. 24, 2022. Burns received his fake text barely two weeks later. When I checked on the domain it was no longer functioning.

Burns is satisfied with how his bank and the credit card issuer handled his issue but wonders how it would have turned out had he not acted as expeditiously as he did. Moreover, he is worried that these scams particularly prey on older recipients. 

Follow me on Facebook (facebook.com/PeterVogelCA), or on Twitter (@PeterVogel)

pvogel@outlook.com

Share your thoughts by sending us a letter to the editor.