Phishing / Social Engineering on Community Forums

Options
Sunna_W
Sunna_W Posts: 744 Member
I wanted to make you aware of a Phishing / Social Engineering thing that I experienced here on MFP.

It goes like this:

A person posts a question in the Community space.

You reply to the question. That person begins to email you (via MFP) for additional advice.

Being a nice person, you reply.

Soon, they ask for your personal email, because they want to email you something (like a picture).

Even if you have a "throw-away" email, and everyone should have one of these just so you don't use your real email when going to websites that ask for an email, DO NOT RESPOND.
  • (Never click on a link embedded in an email, even if it's from an email or company you recognize. Go to the website manually.)

Still they might persist.

They may offer to "share the cost" of some product (like an e-book). DO NOT RESPOND.

The first give away is that they have only been on MFP a few days or made very few posts before they reach out to you.

This is not to say that someone with a hundred to 1000 posts isn't doing phishing or social engineering, but, if it looks like they have invested some time and energy on their page, they are probably "less likely" to be phishing you / setting you up with a virus / or botnet.

The second tip off is the two data points mentioned above.

He/she 1) asked for your email; and, 2) wants to share something with you.

If anyone from a community post does either of these two things - just block them.

What they are doing is also in violation of the MFP terms of service.

I am not sure that reporting them will do any good, because they will just come back with another username / email for registration purposes; it's better to just delete them / not respond / block them.

Replies

  • usmcmp
    usmcmp Posts: 21,220 Member
    Options
    Yes, people do attempt to sell garbage products through this site. Make sure to contact a staff member about this to ensure those people are removed from the site. Even if they come back they'll end up banned over and over again for the same thing, but in between that you are saving others from dealing with them. Beyond that I would not share any sort of personal information with someone, including name or a throw away email address.