Tuesday, February 15, 2005

Phishing Trip

I just got my first phishing email. You would think with three email addresses, I would have been pegged before now, but I've gotten lucky. This particular phish was requesting that I confirm my account details for my Washington Mutual account, or else they would have no choice but to suspend my account. In addition to the helpful hints Washington Mutual provides on its website to help its customers avoid being taken by the phishers, there were several tipoffs that this email was a blatant scam.

1. "Washington Mutual" was contacting me by email about my account.
2. They threatened to close my account if I failed ot respond to one email.
3. No legitimate bank makes you confirm your personal account details on a non-secure website. I'm not sure any make you confirm your account details online at all. What is with this "confirming" thing, anyway?
4. The web address text they used for the link, which appeared to be a legitimate Washington Mutual website, was not the address you would get to if you clicked on the link, which was on some random alphanumeric domain.

and most telling of all:
5. I do not have an account at Washington Mutual.

No comments: