New OOTS products from CafePress
New OOTS t-shirts, ornaments, mugs, bags, and more
Results 1 to 9 of 9
  1. - Top - End - #1
    Troll in the Playground
     
    PaladinGuy

    Join Date
    Mar 2012
    Location
    UK
    Gender
    Male

    Default Hijacked Email Addresses

    As I think all of us know, email spammers often spoof the "From" address on an email to make it look legitimate, this is particularly used for sending fake invoices (either phishing or malware).

    Well I used to have a company (when I was an IT Contracter) and when I went back to being an employee I passed the company to my brother (who had just stopped being an employee) and he has just received an "undeliverable" message for a fake invoice from our company (I am still a director).

    So, is there anything one can do about someone spoofing your email address and sending invoices that purport to be from you?

    I rather think the answer is "no", but I also thought that the folks here will know if anyone does!

  2. - Top - End - #2
    Colossus in the Playground
     
    BlackDragon

    Join Date
    Feb 2007
    Location
    Manchester, UK
    Gender
    Male

    Default Re: Hijacked Email Addresses

    No, you can't. The thing that shows up in the "From" address in an e-mail is literally just a chunk of text in the e-mail header which can be set to literally anything the sender desires.

  3. - Top - End - #3
    Ettin in the Playground
     
    Kobold

    Join Date
    May 2009

    Default Re: Hijacked Email Addresses

    If you have your own domain and website, you can put up a public notice there saying "someone has been sending out fake invoices in our name, it's not us and there's nothing we can do to stop it, but this is how you can tell a real invoice, don't open any attachment that doesn't meet these rules."

    But that's about the only thing you can do.
    "None of us likes to be hated, none of us likes to be shunned. A natural result of these conditions is, that we consciously or unconsciously pay more attention to tuning our opinions to our neighbor’s pitch and preserving his approval than we do to examining the opinions searchingly and seeing to it that they are right and sound." - Mark Twain

  4. - Top - End - #4
    Troll in the Playground
     
    PaladinGuy

    Join Date
    Mar 2012
    Location
    UK
    Gender
    Male

    Default Re: Hijacked Email Addresses

    That's pretty much what we thought, but I felt it worth checking. Thanks guys for the confirmation.

  5. - Top - End - #5
    Firbolg in the Playground
     
    Vinyadan's Avatar

    Join Date
    Nov 2009
    Gender
    Male

    Default Re: Hijacked Email Addresses

    Quote Originally Posted by veti View Post
    If you have your own domain and website, you can put up a public notice there saying "someone has been sending out fake invoices in our name, it's not us and there's nothing we can do to stop it, but this is how you can tell a real invoice, don't open any attachment that doesn't meet these rules."

    But that's about the only thing you can do.
    I think I have recently seen this on the homepage of a large company. Maybe it was a smartphone manufacturer. Random people were receiving emails asking for CV, sent by someone pretending to be the company, or using a deceivingly similar company name. So they put up this banner.
    Quote Originally Posted by J.R.R. Tolkien, 1955
    I thought Tom Bombadil dreadful — but worse still was the announcer's preliminary remarks that Goldberry was his daughter (!), and that Willowman was an ally of Mordor (!!).

  6. - Top - End - #6
    Troll in the Playground
     
    PaladinGuy

    Join Date
    Mar 2012
    Location
    UK
    Gender
    Male

    Default Re: Hijacked Email Addresses

    As a simple Electrical Engineering contractor (which is what my brother is) the company doesn't have a web-page, but thanks for the suggestion.

  7. - Top - End - #7
    Orc in the Playground
     
    RedWizardGuy

    Join Date
    Feb 2016

    Default Re: Hijacked Email Addresses

    Quote Originally Posted by Khedrac View Post
    So, is there anything one can do about someone spoofing your email address and sending invoices that purport to be from you?
    Creating an SPF record for your domain will take care of your obligation.
    It is up to the recipient to have a mail gateway that actually checks them.

    If you want to get a bit more secure, you can use DKIM/DMARC, but that's a bit more complicated.
    -
    What is dead may never die, but rises again, harder, stronger, in a later edition.
    -

  8. - Top - End - #8
    Troll in the Playground
    Join Date
    May 2007
    Gender
    Male

    Default Re: Hijacked Email Addresses

    If someone is distributing phony invoices for your brother's company, they may be preying on your customer base. His company must reach out to customers immediately and warn them about this scam. Change their email logo and graphics. Invite customers to contact them if they receive any suspicious communication, and ask them to forward anything questionable to you.

    Anyone invoicing these folks will provide a means to collect payment. Forward this to the FTC.

  9. - Top - End - #9
    Troll in the Playground
     
    PaladinGuy

    Join Date
    Mar 2012
    Location
    UK
    Gender
    Male

    Default Re: Hijacked Email Addresses

    Quote Originally Posted by Leewei View Post
    If someone is distributing phony invoices for your brother's company, they may be preying on your customer base. His company must reach out to customers immediately and warn them about this scam. Change their email logo and graphics. Invite customers to contact them if they receive any suspicious communication, and ask them to forward anything questionable to you.

    Anyone invoicing these folks will provide a means to collect payment. Forward this to the FTC.
    Not that sort of company, and I think there is a good chance that the so called "invoice" will be a ransomware app. My brother mainly invoiced the agency through which he worked as a contractor for another company; he just had a couple of other clients where he did work paid for directly (and it was the same when I was an IT contrctor - that's how a lot of the contracting market works here in the UK).

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •