This will be a quick post. We have received a phishing mail to our [email protected] mail address telling that they are “lemmy.world Security Team”, telling that they will “disconnect” your account from our instance. This is ofc, not us. Do not fall for it! The attached image is how the mail looks like.

~Lemmy World Team.

  • NOT_RICK@lemmy.world
    link
    fedilink
    English
    arrow-up
    79
    arrow-down
    3
    ·
    1 year ago

    Hello, it is I, John Security. Please respond to this message with your name and SSN or the FBI will arrest you for unpaid back taxes. Also, do you have any iTunes or Google play gift cards laying around?

  • TheGoldenGod@lemmy.world
    link
    fedilink
    arrow-up
    66
    ·
    1 year ago

    Jesus. Phishing emails like this have become so commonplace I actually miss the old Viagra spam emails in l33tspeak.

      • BeanEater@lemmy.world
        link
        fedilink
        arrow-up
        14
        arrow-down
        2
        ·
        1 year ago

        When’s the last time you checked your spam folder, 2003? I legitimately haven’t seen the 1337sp34k spam in 20 years. Lately it’s been Africans leaving me money at the embassy that I have to go pick up

        • Eheran@lemmy.world
          link
          fedilink
          arrow-up
          2
          arrow-down
          1
          ·
          1 year ago

          The subject is sometimes a word with random capitalisation and potentially letters replaced with numbers or symbols.

  • dependencyInjection@sh.itjust.works
    link
    fedilink
    arrow-up
    43
    arrow-down
    4
    ·
    1 year ago

    Isn’t it a waste of time trying these scams on lemmy.

    I could be wrong here but I would argue the vast majority of users are somewhat tech proficient since it’s not reached mass adoption and the user base is well, just us nerds?

    • SgtAStrawberry@lemmy.world
      link
      fedilink
      arrow-up
      22
      ·
      1 year ago

      Well one of the best scam hunters on YouTube lost his account to a scam. So not really a waste of time, trying Lemmy.

        • SgtAStrawberry@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          edit-2
          1 year ago

          It was Jim Browning, as another comment said. I can never remember his name more than Jim, so I settled for job description, as he is easy to find that way.

          But others have been through it also, Linus Tech Tips, The Spiffing Britt and Atomic Shrimp are the other big ones I know of, but there is plenty more. Of those Atomic Shrimp is also a scam hunter like Jim, so it definitely shows that just because you are very familiar with what it looks like you aren’t immune too it.

          I can’t remember if they all fell for the same or similar ones or if it was different ones, but that really doesn’t matter so much.

          And what happend was Jim and LTT got tricked into deleting there channels. LTT by a fake sponsorship and Jim I don’t remember someone else said it was fake YouTube support.

          Spiff had something of a similar thing happen but I don’t remember the means, and Atomic Shrimp I believe was a different typ of scam not related to YouTube.

          But everyone got their channels back in the end.

  • Flying Squid@lemmy.world
    link
    fedilink
    arrow-up
    34
    ·
    1 year ago

    I got an almost believable phishing text yesterday from a ‘collection agency’ that wanted me to download a PDF and go to their website. It looked very official and I’m having some debt issues, but it didn’t tell me who it was representing or what I owed or anything like that, so I could tell it was phishing. But a less-savvy person could have totally been fooled by it because it looked very real.

  • Clbull@lemmy.world
    link
    fedilink
    arrow-up
    27
    arrow-down
    2
    ·
    1 year ago

    Why would they target Lemmy users?

    Your typical Lemming (for lack of a better term) is not technologically inept and would generally not fall for a phishing scam. They’d earn a lot more money from targeting Redditors.

    • u/unhappy_grapefruit_2@lemmy.world
      link
      fedilink
      arrow-up
      1
      arrow-down
      2
      ·
      edit-2
      1 year ago

      Aren’t people who use lemmy already or had used reddit I mean lemmy was brought out as an alternative to reddit which many people on reddit flocked to when spezy wezy started doing his you-know-wut

      Plus I’m sure there’s alot of people here whom won’t be as informed about phishing emails

      • Clbull@lemmy.world
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        1 year ago

        It’s more like there’s a technical barrier for using Lemmy (or any fediverse social media for that matter) and for actually giving a shit about Reddit’s API policy.

        There’s a tendency for more tech-saavy people going to Lemmy.

  • dreadedsemi@lemmy.world
    link
    fedilink
    arrow-up
    20
    arrow-down
    1
    ·
    1 year ago

    It’s weird that they target Lemmy, what would they get? Access to account that shitposts? Only important accounts are admin, even communities are small here

  • Obinice@lemmy.world
    link
    fedilink
    arrow-up
    15
    ·
    1 year ago

    Why are these sorts of things always written by somebody who can clearly barely speak English?

    • bananabenana@lemmy.world
      link
      fedilink
      arrow-up
      38
      ·
      1 year ago

      I read that this was to weed out savvy people. People who aren’t skeptical of poorly written emails or messages are their target audience. Could be wrong though.

  • slazer2au@lemmy.world
    link
    fedilink
    arrow-up
    13
    ·
    1 year ago

    Do you have plans to enable DMARC, DKIM, and SPF to make the emais more likely to be flagged as spam by email filters?

  • MicrowaveOvens@lemmy.world
    link
    fedilink
    arrow-up
    8
    ·
    1 year ago

    Hey, quick question. I’m assuming these emails are automated, so how do they know your account’s email? Is this part of a leak or are they sending email via “send notification to email” option in lemmy?

    • jarfil@lemmy.world
      link
      fedilink
      arrow-up
      4
      ·
      1 year ago

      There are some commonly used emails by most domain owners, like: info, webmaster, security, reports, sales, etc. Some people also set their email with a catch-all address, so if someone sends an email to “cat.in.tights”, they’ll get it too.

      • MicrowaveOvens@lemmy.world
        link
        fedilink
        arrow-up
        1
        arrow-down
        2
        ·
        1 year ago

        Ah. so that “[email protected]” is an email and this is not related to fediverse. Jus checked, there’s no such account here. No point in making an announcement about it here if its not related to fediverse and only gets sent to domain owners, imho. lol

  • nodimetotie@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    1 year ago

    I wonder what they thought of when they wrote “Security Team.” I just think of security guards.