I knew immediately that the email appearing to be from U.S. Airways was actually a phishing attempt because it asked me to confirm a flight I had not booked from a city near which I do not live.
But despite that instantaneous recognition of a scam, alarm bells began clanging anyway for one simple reason: I had flown on USAir on vacation less than two weeks ago – for the first time in, well, close to if not forever — and so I assumed that the scammer copped by email address from the airline since that transaction.
And, if they got my email address, who’s to say they didn’t get my credit card? (Beads of sweat begin to pool on forehead.) Might this obviously spoofed email also be an indicator that someone has commandeered my plastic privileges?
A little Googling quickly made matters worse, as it turned up an April story in USA Today that confirmed that USAir customers were being targeted in this exact manner. The phishing email cited in the story was almost identical to one that I received, and that was almost identical to the authentic one that USAir did send me only recently.
Moreover, USAir acknowledged in April that its customers were being targeted, and the airline had posted this warning notice on its website.
Since the news story was from April and I booked my flight mid-June, two conclusions seemed probable if not escapable: My address was grabbed just recently … and USAir was not only the victim of a data breach, but what appeared to be an ongoing one (OK, that last part would be the silver lining, professionally speaking, in that at least I’d get a good story out of the whole mess).
Oh, sure it could be a corker of a coincidence, but what are the odds when the alternative is that my life is about to become a roiling cauldron of identity-theft hell. (Just to be sure, I had emailed our IT department asking if they’d seen any USAir-related phishing internally.)
Then I decide to run all of this by one of my colleagues – a level-headed sort – and he agrees that things looked grim me, if not the good story that I would get to write. We discuss the coincidence possibility, briefly, but I can tell that he’s just offering what meager comfort he can.
Next I start looking for contact information for the USAir public relations department, determined as all get-out to at least get that story cooking before cancelling my credit card.
But before I could even find the PR contact, into my inbox drops this reply from our IT guy: “We have been seeing an increase with USAir Phishing attempts within the past few days. This follows on recent phishing attempts from other airline brands like American, Delta and Virgin.”
Oh.
And then my level-headed colleague pops his head in my office door: “Just got three of them — USAir phishing emails – right in a row.”
Oh.
Seems it was all a big coincidence after all. Yes, my big phishing story had wriggled off the hook, but I wouldn’t need to be cancelling my VISA.
And then I smiled, both out of relief and the recollection of a great Seinfeld scene where Elaine is told there’s no such thing as a big coincidence. YouTube obliges:
