I'm an email luddite. I use a text-only mail reader. It doesn't show pictures. It doesn't play audio. It just shows me text.
Phishing relies a lot on appearance – and I don't see that appearance. All I see is the text. So even the best phishing attempts never quite pull it off. Especially if you're suspicious of any email that's asking you for information or that wants you to click on a link.
From support@comcast.com Tue Apr 10 20:45:28 2012
Date: Tue, 10 Apr 2012 12:19:29 -0500
From: XFINITY <support@comcast.com>
Subject: Update Your Billing Information!
Well, they actually got one key point right – this
is my ISP. (Yes, I have received phishing attempts for other ISPs. Sending them seems dumb to me, but if people are also dumb enough to respond to them....)
Oh, wait – my ISP is comcast
.net, not
.com. So they
didn't get that right. comcast.com is a valid domain, but all the
real Comcast email has come from comcast.net.
Also, Comcast allows 7 email addresses per account. A real query from Comcast would have gone to my primary address; this email was sent to one of the secondary mailboxes.
image
I guess there was supposed to be a picture there to make the spam look more convincing.
Dear Valued Customer,
This is a major fail. My ISP knows my name.
During our regular update and verification of the Comcast online services, we could not verify your current information. Did you recently change your bank, phone number or credit card?
None of that info has changed recently, but Ms./Mr. Phisher never had that info in the first place. (Heck, Phisher doesn't even know my
name.)
To ensure that your service is not interrupted
Click Here [aaronmiler.com] to update your billing information today
This is one of the strengths of my dumb, text-only mail reader: it shows the domain the link goes to. (Hint: it
doesn't go to my ISP, the alleged source of the email.)
After a few clicks, just verify the information you entered is correct. ! ,
Thank You.
--------------------------
Comcast
One Comcast Center, 10th Floor
1701 JFK Boulevard
Philadelphia, PA 19103-2838
Attn: CHSI
My dumb mail reader has other nice features, like easily switching into the raw display mode so I can see the full headers (showing all the servers that handled the message) and unprocessed HTML. So I can see that Comcast received this from Earthlink – rather suspicious for a Comcast billing query.
I forwarded it (with full headers – another easy feature of my dumb mail reader) to Comcast's fraud and abuse addresses.