Not all phishing expeditions are well planned.
Recently, I received an email purportedly sent by the American electronic toll-collection agency, E-ZPass.
It was entitled “Notice to Appear.”
“You have a debt to pay for using a toll road,” I was told. “You are kindly asked to service your debt in the shortest time possible. You can find the invoice in the attachment.”
It was supposedly sent to me by the manager of E-ZPass Support.
Now, I have travelled on many American highways that accept E-ZPass. In fact, it is available on most tolled roads, bridges, and tunnels in the northeastern United States, south to North Carolina, and west to Illinois. It allows motorists to use a transponder to electronically record their toll charges.
It is also accepted at Ontario border crossings, such as the Peace Bridge, Queenston-Lewiston Bridge, Rainbow Bridge and the Whirlpool Rapids Bridge.
So I might have been tempted to open the attachment, which could have been disastrous, since most phishing expeditions have one thing in mind. These online fraudsters want to gather as much personal information as possible from your computer so they can financially ruin you.
But these guys went phishing in the wrong pond.
I’m legally blind. Haven’t driven since October 9, 1991, when E-ZPass was still in the planning stages.
The Better Business Bureau and other agencies have posted warnings about this scam, as has E-ZPass itself.
“E-ZPass will never send an email or contact you requesting sensitive personal information such as credit card number, social security, user names, passwords, etc.,” the firm’s website states. “If you are contacted by anyone stating they are from E-ZPass and they are seeking personal information, call 1-800-333-8655 to report you have been contacted by someone attempting to obtain personal information or ask the caller/email sender to provide their contact information so you can call them back.”
Here’s what the Better Business Bureau has to say.
“Did you receive an email that appears to be from E-ZPass? It uses the correct colours and logo and appears to be collecting money from an unpaid toll. The message says you have ignored previous bills and urges you to pay immediately by downloading an attached ‘invoice.’
“You download the attachment, but nothing seems to happen. Not true! You just downloaded a virus to your computer. These viruses scan your machine for personal and banking information, which opens you up to identity theft.”
It’s a wonderful new world.
Phishing is dangerous to your financial health. It’s the illegal practice of sending fraudulent emails with links to websites that appear to be legitimate. The fraudulent emails appear to be from a trustworthy source, but are designed to trick the consumer.
There are many variations. Some emails appear to come directly from your financial institution or telephone company. Some long shots come from firms you’ve likely never heard of, claiming your bill is overdue.
The vigilant consumer should watch for look-alike URLs. Carefully compare the one identified on the email to the firm’s real one.
Here are some other ways to not take the bait of phishing scams:
• Don’t open attachments from unfamiliar sources. Legitimate businesses rarely send unsolicited emails with attachments.
• Confirm an email is real by contacting the business before downloading anything. In the case of E-ZPass New York, the instructions were to call the customer service centre.
• Consider how the business normally reaches you. Most businesses send invoices by regular mail, or by telling you to log into your secure account.
