Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Tuesday, August 11, 2026

AI Security Threats - Is It Time to Panic?

Introduction

It’s been over nine years since my last post about how to stay secure online. A lot has changed since then, particularly with Artificial Intelligence making everybody more effective at everything. (At least, this is what Corporate America is telling itself, and in the case of fraudsters, it’s actually true.) In this post I’ll briefly highlight some of the most pressing AI-driven threats, and then focus on what you can actually do to protect yourself, vs. what we’ll have to hope “they” can protect us from. Short version: be extra wary of phishing and spear-phishing attacks. (Oh, and no point in panicking … yet … as far as I know. I put “panic” in the title of this post just to grab your attention—and look, it worked!)


Major AI-driven security threats

Here are some of the top Internet security threats presented by AI:

  1. Autonomous attacks: Fraudsters are using agentic AI to unleash fully automatic phishing and other attacks, greatly speeding up their campaigns.
  2. AI systems as attack surface: As companies build AI into email, documents, and workflows, attackers are targeting the AI stack directly rather than going around it. (Some call this “AI supply chain compromise.”) Malicious instructions can be hidden inside the content that an AI reads as it goes about its job, and training data can be poisoned.
  3. Deepfake-driven identity collapse: AI can produce realistic voice, face, video, and document forgeries cheaply and at scale. This can undermine authentication systems across corporate, banking, and consumer platforms.
  4. Data leakage from ordinary use: As corporate employees use AI normally, and get very specific in providing context for their prompts, they often share more info than they mean to, giving bad actors access to sensitive data without even having to steal it.

(Why four threats, instead of a nice round number like three or five? I based my assessment on queries I made to ChatGPT, Gemini, Copilot, and Claude, and these are the four top threats that all these models agreed on.)

On top of these threats, and overlaying them, is Open Source Intelligence (OSINT), which in the context of Internet security refers to personally identifiable information (PII) that over time has become public due to voluntary posting of it, such as on social media (e.g., Facebook users sharing info about themselves, their activities, and their families, assuming it’s only seen by friends and online “friends” and not realizing how easily shareable it is across the entire Internet). All this data has been increasingly well indexed by Google and other Internet tools, and now web scrapers and other generative AI tools can easily harness this sensitive data to create targeted phishing (i.e., spear-phishing) attacks.

An example of an OSINT hack

This will all make more sense, I think, if I provide an example. It occurred to me recently that anyone with a Gmail account could create a Gemini Notebook into which they could feed large batches of albertnet posts, to turn this very blog into a chatbot. They then could query this chatbot for any and all PII that could be used to answer security questions when trying to impersonate me. To identify such vulnerabilities, I did this exact exercise myself (employing a tactic called Defensive OSINT—basically beating hackers to the punch). I fed the most likely categories of albertnet posts (e.g., Parenting, Bits & Bobs) into a Notebook and asked the chatbot to build a comprehensive “public knowledge index” of PII based on the categories most often used for website authentication security questions. Then I had it produce a report describing the vulnerabilities it found.

Did it come up with anything? Well, yes: it found one item of rather sensitive information based on a bit of handwritten text that was included on a picture that was posted. I found that pretty embarrassing, but it was easy enough to remove since this is my blog and I manage the content directly. (Also, because I own the domain used by my blog, I can go to web.archive.org and have the original version of the post removed forever.)  Fortunately, I’ve had an eye on privacy and security for the whole time I’ve been blogging, so other than some pet names and schools I attended, I’m overall in pretty good shape. Here’s a particularly amusing excerpt from the Gemini Notebook security audit report:

Category V: Workplace & Career

The author’s career trajectory is extensively documented, providing a roadmap for Business Email Compromise (BEC) and “Career Gate” attacks.

Security Risk Assessment: Attacker groups scrape metadata from Blogger sidebars (e.g., the “Specialist” title) to craft highly targeted BEC lures. By referencing past roles like “underwear canner” or “radio station receptionist,” an attacker can establishing [sic] a false commonality to bypass corporate security screenings or impersonate a former HR representative for the purpose of credential harvesting. 

As you can see, when you share personal information on the Internet, it’s highly advisable to bullshit a lot. I have a feeling that the above career information, even in the hands of the most devious hacker, isn’t going to get me in a lot of trouble. I do need to warn family members not to use any of the PII in my report (e.g., a pet’s name, a school name) as security answers, though I’ve already cautioned them—as I’ll now caution you—to not use real PII for security questions in any case; after all, you can’t change your mother’s maiden name or the city you were born in, so once somebody hacks a website and gains these answers, you’re pretty much hosed. And good luck remembering what security questions and answers you’ve set up over the years across all the sites that use them for authentication.

So can everyone run this kind of audit? Well, any blogger can, but if you’ve been active on multiple social media platforms over the last ten or fifteen years, it’s gonna be really tough. And remember, in many cases (e.g., Facebook) you do not actually own that information. Probably the best thing you can do is keep an eye out for spear-phishing attacks.

Some updated anti-phishing basics

In my previous post on phishing, I pointed out that you could often spot fraud based on bad spelling or grammar (e.g., “Security fraud alerted corporate card!” or “Account info updating needs!”). This is no longer a reliable rule of thumb, because AI has gotten so good at grammar and even at matching the style of the supposed sender. It’s more likely to produce a realistic subject line as well (as opposed to something generic like “Hello”) and isn’t so prone to excess emoticons, weird fonts, and/or tacked-on numbers (e.g., “✅  𝙋𝙡𝙚𝙖𝙨𝙚 𝙘𝙤𝙣𝙛𝙞𝙧𝙢 if you're qualified for a compensation✅  5078227).” My previous advice still stands: don’t click on any link in an email unless you completely trust the sender, and have hovered your cursor over the link to make sure the domain matches what you’d expect based on what your contact purports to be sending you.

For example, if a cycling buddy sends you an email that says, “You’ve got to check out this Tour de France blow-by-blow report from albertnet,” and the link says “Tour de France Stage 15,” and you hover over the link and see the URL “https://www.albertnet.us/2026/07/biased-blow-by-blow-2026-tour-de-france.html, ” that would be safe. But if you get an email from $CashApp$  (nxaqlvxcvm@ekgkx1ylmv.co.us via arbeitsstellepro.com) with the same message (or any message, actually), you shouldn’t click on any link in it. Or, let’s say you get the same aforementioned Tour de France email from a trusted pal, but hover over the included link and see “https://www.xtremecloudmontzer.xyz/encryptvictimHD” … you obviously shouldn’t click it. Now let’s say you got a legit albertnet link to the Tour de France post, but from a friend who constantly bags on my blog and/or on the Tour de France. Valid-looking URL aside, you might reasonably decide the message fails the sanity test, and you should send a separate email to that friend asking, “Did you really send me a link to an albertnet post?”

Always be especially careful with any email that conveys a sense of urgency and wants you to take immediate action. Fraudsters will employ that to try to get you to bypass your normal habit of being careful and deliberate with your email. It isn’t always the foreboding kind of urgent; it could alternatively be the upbeat kind of urgent, like a party invitation, which gets us excited because hey, fun, party! 

Anatomy of a spear-phishing attack

A friend of mine fell prey to a spear-phishing attack recently because an email she received was from a friend who’d been on a volunteer board of directors with her, who quite reasonably could be hosting a reunion. The email looked like a standard punchbowl.com invite, with the right logo, etc. My friend, due to a momentary lapse of reason, clicked the link without hovering over it. If she had bothered to hover, she’d have seen this (click to enlarge):


Since my friend doesn’t use Outlook, she wouldn’t have been falsely comforted by the “Protected by Outlook” indication and in fact would have found it suspicious—had she hovered over and seen it! Meanwhile, even if the fraudster had lucked out and my friend were on Outlook, she would have been wise to suspect the “roves.sbs” because a) it isn’t the punchbowl.com domain, b) it isn’t anything recognizable, and c) that .sbs top-level domain is automatically suspicious because that’s an extremely cheap domain, perfect for hackers. (They love a cheap domain they can set up to snare as many victims as possible before the fraudulent site is identified and flagged by security community filters like Google Safe Browsing or Norton.) On top of all this, the URL shown above isn’t even itself the real URL—it’s a bogus tooltip set up by the hackers. You need to look in the lower left of your browser screen to see the real URL, which in this case was “accounts.lifeofastartryfghjgd.icu,” which a) also isn’t the punchbowl.com domain, b) also isn’t recognizable, c) looks like somebody started to type something plausible but lost patience, and d) has another disposable, cheap, very phishy landing page domain. Alas, my friend missed all of this, delighted as she was to be invited by a friend to a party, and just clicked the link.

From here, things went even more sideways. First, she was presented with a CAPTCHA she had to solve to prove she was human. This was employed by the attacker for three reasons:

  1. It stymied her security software, hiding the phishing page and thereby preventing the software from blocking it;
  2. It established a sense of trust, because users associate CAPTCHA screens with security (i.e., it made my friend think the site was establishing that a bot wasn’t trying to accept the invitation);
  3. It confirmed to the attackers that a real human—i.e., a dupe—had actively taken the bait, and they probably added my friend to a list of suckers who should be actively phished again in the future.

Then, the page went in for the kill, saying that to accept the invitation and add it to her calendar, my friend should log in to her Google account. It helpfully provided the input fields to do so. Only at this point did my friend smell a rat, and closed the page instead of serving up her Gmail address and password to the hackers. Probably there was no harm done, but man, what a close call! (It’s possible the site could have meanwhile instigated a “drive-by” malware download, but this probably wouldn’t have worked without her browser asking her to explicitly approve a file download or browser extension installation.)

As you can see, phishing has gotten more sophisticated. And the worst part of the phishing email my friend received was that it did come from a known person, and (whether through luck or knowledge of the person’s work experience) created a plausible scenario: this was exactly the kind of invitation my friend would expect to receive from this person. This is one of the ways spear phishing attacks are engineered.

Incidentally, my friend contacted the sender, and sure enough, this person’s PC had been compromised and the attack mounted against everyone in her address book. Why she hadn’t warned anyone is a mystery to me, and I hereby implore you to let all your contacts know if your system ever gets hacked. It’s no different than the responsibility a sexually promiscuous person has to notify his or her paramours about testing positive for a venereal disease. (For a charming comedy series on this theme, you might check out “Lovesick” on Netflix.)

AI and spear-phishing

Getting back to AI, it changes the game by making phishing attacks more realistic than ever, and at a lower cost to hackers. In the past, spear phishing was time- and labor-intensive, and thus reserved for people who are (no offense) bigger targets than you. But now, with AI, producing a bespoke attack with maximum plausibility has gotten easy, fast, and cheap. Gemini describes it thus:

Traditionally, gathering intelligence on a target required significant manual effort. If an attacker wanted to map out a corporate hierarchy, scrape executive social media, identify software stacks, or build custom spear-phishing personas, it took days or weeks of painstaking human research.

AI-driven OSINT compresses that timeline from weeks to seconds:

  • Automated Harvesters: AI tools can scrape public records, forum posts, code repositories, blog archives, and dark web dumps simultaneously.
  • Instant Synthesis: LLMs [large language models] parse millions of lines of unstructured text, connect disconnected data points across 15 different platforms, and output a clean, actionable “target profile” with zero fatigue. 

This means that instead of a person employing just a few methods to get the target to let his or her guard down (e.g., crafting a realistic-looking, well-written email seemingly from a friend who might plausibly have written it), AI can generate a hyper-personalized attack, presenting specific contextual details designed to boost the sense of authenticity, with a high likelihood of dissolving the recipient’s natural defenses of skepticism and caution.

Imagine if my blog were less slippery, and the career info I posted were actually relevant and factual. I could get an email from someone purporting to have served with me in the Artillery Regiment in the late ‘80s, who has announced he’s become very successful in the underwear canning business; understands my frustration with modern corporate America; and would like to talk to me about an executive position at his startup with great pay, a signing bonus, and stock options—and all I have to do is go to this website and upload my CV! The specificity of this email might dupe me, if I actually had served in the same Artillery Regiment, and if canning underwear had been a bigger part of my career. And imagine if the fraudster spoofed the identity of a guy I actually knew (“it’s your old pal Fred, from the Hot Chillys cannery!”) … the email would seem pretty legit. Somebody harvesting LinkedIn PII instead of albertnet might actually get somewhere.

The ABC mnemonic

To protect yourself from spear-phishing attacks, I recommend borrowing a concept from police detective training: the investigative doctrine of “ABC.” Across the UK and Commonwealth, detective trainees are taught to “Assume nothing; Believe nothing; Check everything.” Adapting this for Internet security:

  • Don’t assume an email is safe, just because it has proper formatting and logos, good grammar and spelling, etc.
  • Don’t believe an email is really an intentional communication from your friend, even when the source email address checks out, if there’s anything even slightly phishy about it
  • Check for any sign that the email could be fraudulent.

Here are things to watch for in that third “check everything” step:

  • The email has a mismatched “From” vs. “Reply-To” address (e.g., purports to be from Bank of America but the reply-to address has a phishy domain like banksupport@bank.sbs)
  • It includes a link it wants you to click, especially from an unusual top-level domain (basically anything other than .com, .gov, .edu, or .us and especially the johnny-come-lately TLDs like .xyz and .biz or anything you don’t recognize—always remember to hover over a link before clicking it)
  • It includes a link with a shortened URL like bit.ly (which can be used to hide a phishy domain)
  • It has a file attachment, especially something besides a PDF or JPG
  • It conveys a sense of urgency (especially from a bank or other business telling you they’re going to have to block your account, or already have, or will have to close it unless action is taken such as updating your payment details, etc.)
  • Is from a business but has emoticons in the subject line (I mean, really?!)

Is albertnet safe?

Yes, albertnet is perfectly safe. This website doesn’t run any scripts; doesn’t employ cookies or tracking pixels or Google Analytics; won’t try to install anything; and never includes links to unsafe websites. I won’t serve you ads, don’t want your money, and respect your privacy. About the only risk you’ll run is believing I served in an artillery regiment, or that Strava has a new nighttime KOM category, or that the Tour of Sweden was held in 2020 at the height of the COVID-19 pandemic. And at least when I bullshit you I always fess up.

—~—~—~—~—~—~—~—~—
Email me here. For a complete index of albertnet posts, click here.

Tuesday, February 21, 2017

How to Survive a Phishing Attack


Introduction

This post describes a super easy way to avoid falling prey to phishing and spear-phishing.  While I’m at it I’ll explain about ransomware and botnets so you can sound impressive during fishing  trips and/or ladies’ luncheons.  I’ll even provide a real-life example of a recent situation requiring me to apply my method.

Couple quick notes:  1) You cannot get a virus by reading this blog or clicking on any link within it, ever; and 2) I actually did my homework on this post, and ran my anti-phishing technique past the Chief Information Security Officer of a giant corporation, who gave it her blessing.

Some terminology

In a previous post, I covered plain old spam, which is simply unsolicited e-mail that doesn’t even pretend to be personal.  For example, the subject line is “Enhance your male member!”  The sender hasn’t targeted you based on knowing anything about your, uh, membership … from the sender’s perspective, every man should enhance his mail member!  (And if a woman receives this message, no harm done—she can just forward it to the man in her life.)  Spam is basically electronic junk mail.

Phishing is an attack on your computer which relies on you clicking on an embedded link or opening an attachment, which either loads a virus directly on your computer or takes you to a bogus website that attempts to lure you into disclosing personal information.  Phishing messages are usually blasted out like spam, though the sender will often pretend to be a company you do business with, such as your bank.  There’s usually a sense of urgency, something like “Account locked – update password!” (i.e., “Tell us your old password, sucker!”).

Spear-phishing is more targeted and requires the sender to find out stuff about you in advance (e.g., thru social media) to make the e-mail look more realistic.  Is it important to differentiate between regular phishing and spear phishing?  Probably not.  I think the latter term was contrived mainly to help security experts sound cool.

Ransomware is a computer virus that encrypts your computer’s entire hard drive, so that only the fraudster can decrypt it, which he or she will only do upon being paid a ransom.  (A criminal with no hacking skills can actually buy “exploit kits” from the fraudsters to carry out his own attacks.)  Ransomware is one of the biggest reasons to be careful with your e-mail.

You know how vampires and zombies can make you one of their own by biting you?  Similarly, computer viruses can take over your computer and use it in a separate attack.  Such an infected computer is called a bot, and when hundreds or thousands of them are herded together to mount a large-scale attack, you’ve got a botnet.  (Think of it as an online zombie apocalypse.)  Note that as more devices—not just computers and phones but thermostats, security cameras, DVRs, etc.—are connected to the Internet, they become targets for botnet attacks as well.  In fact, they’re ideal candidates because they’re often cheaply made, poorly designed, and lack security.  They’re like really dumb zombies.

How to survive phishing attacks

My phishing survival technique employs a single simple rule:  if an e-mail appears to be from any bank (even yours), or any other business with which you have an account (e.g., a utility), automatically assume it is a phishing attempt and just delete the e-mail.  You can apply this rule even before opening the message.  It’s that simple.  The decision tree looks like this:


 There is a very small risk, with such a broad rule, that you’ll miss a legitimate e-mail from your bank, but a) it’s better to be safe, and b) remember, your bank knows how to reach you!  They have your money and are very resourceful about getting their business done.  In general, they prefer to phone you or send postal mail because they hate phishing as much as you do and have no interest in training you to fall prey.

The one blanket exception would be account statements.  If you signed up for electronic statements and receive them on a predictable schedule every month, and these statements provide account information without asking you to do anything, you’re probably fine.

As for these “Oh, no, you need to do something!” messages, keep in mind that if there’s really something wrong with your account—like your card number has been compromised, for example—that’s ultimately the bank’s problem.  They are on the hook for the cost of the fraud, so let them do the heavy lifting.  If they can’t be bothered to pick up the phone or mail you a postcard, they can face the consequences.  (For what it’s worth, my card number has been compromised a number of times, and in no case did I get an e-mail.)

All of this being said, I recently decided to amend my very simple rule.  If you’re interested in my amendment, read on.  If you’re already bored and/or have no problem with the simple rule outlined above, you’re done—goodbye!  Go get on with your life!

Sometimes it’s not quite that simple

What if you made a purchase that falls well outside your normal pattern of behavior?  For example, you just made a purchase for $2500, and the largest purchase you’ve ever made previously with this card was $1000?  Or what if you normally shop at J. Crew and Brooks Brothers, and one day get a ghetto impulse and buy something at J.C. Penney?  If you do something outside of your norm and then immediately receive an e-mail purporting to be from your bank, you might consider evaluating it further.

I got an e-mail recently from slcfraud@aexp.com titled “Your Corporate Card.”  This “From” address and subject line didn’t look obviously wrong.  The capitalization in the subject line, “Your Corporate Card,” was a bit odd, but not obviously wrong (e.g., it wasn’t “Security fraud alerted corporate card!!” or “Account info updating needs!” or some other butchered English).  The return address, slcfraud@aexp.com, struck me as feasible, though these things can be spoofed.  Only because I half-expected Amex to choke on a recent transaction, I decided to open the e-mail:


Note how it’s in plain text with no logos or anything.  That might seem a bit odd, but actually it’s completely okay.  Fancy logos and formatting are methods hackers use to make their e-mails look legit.  Don’t be fooled!  It’s far easier to manipulate graphics and logos and such than to say the right things, in perfect English, in an e-mail. 

This brings us to my analysis of the grammar etc. in the e-mail itself.  There is a stray bracket in the message (toward the end:  “Corporate Payment Services}”).  That’s a bit spotty, and such things should be considered suspicious.  There’s also a dangling participle:  “In order to assist you in a timely manner, please call us at the numbers provided rather than responding to this message.”  (The first clause refers to them—i.e., they would be assisting you—but the second clause refers to you; i.e., here’s what you should do.)  Certainly this is bad grammar, but it’s the kind of error a native speaker would make—even an Amex employee.  It’s not the kind of error made by dastardly foreign hackers who hate America.  Even still, as a general rule I would normally delete this e-mail on the basis of this, or any, grammatical error.  If this makes extra work for your bank, shame on them for filling corporate communications positions with people who can’t write a decent sentence.

All of this aside, there was one fundamental characteristic of this e-mail that caused me to take it seriously:  it didn’t ask me to click on anything, and it suggested I call the toll-free number on the back of my Amex card.  That is exactly the kind of action a bank would legitimately ask you to take, and dialing this number is an inarguably safe thing to do.  (I cannot imagine how a hacker could print a fraudulent toll-free number on the back of my card.  He would need physical access to my wallet, in which case he would presumably have no need to do anything online.)

I did note that the number provided in the e-mail didn’t match the number on my card, but it’s not uncommon for a financial entity to have multiple toll-free numbers.   You should never dial a toll-free number provided in an e-mail.  While that’s not as obviously dangerous as clicking on a link in an e-mail, it could still get you in trouble.  What if you reach a voice-response system that sounds authentic, and asks you to enter your card number?  That would be an easy way for a fraudster to hack your account.  Always go with the phone number printed on your statement or card.

Based on the e-mail above I called Amex, and sure enough, they had locked out my card because my last transaction looked suspicious to them.  During the call they authenticated me based on my caller ID, and accurately described the suspicious transaction.  I told them it was legit, they unfroze my account, and all is well. 

So:  does this mean opening the e-mail was a good idea?  No, not really.  If I had my life to live over, I’d probably have deleted the e-mail and just called Amex.  The slightly more complicated decision tree is this:


How common is all this, anyway?

Is this much ado about nothing?  Actually, I think this stuff is important because phishing is so rampant.  Looking in my junk mail (i.e., messages my ISP determined were fraudulent), I see the following: 
  • 2 messages from Apple on 2/11 saying “Your account is locked”
  • 3 messages from my regular bank between 2/3 and 2/9 saying “Action Required”
  • 1 message from my Visa card issuer on 12/21 saying “Notification ID: 2591912…”
  • 1 message from Apple on 11/07 saying “Apple Inc | Security notice”
  • 1 message from PayPal on 10/27 saying “Your PayPal account ha…”
Along with this, I see messages seeming to be from friends of mine that somehow triggered my ISP’s junk mail filter.  What if my ISP hadn’t filtered these?

Address book phishing

I’m not aware that the phrase “address book phishing” has any widespread meaning, but I’m talking about viruses etc. that replicate by forwarding themselves to everybody in the victim’s e-mail address book.  If your ISP lets these through, it can be tricky spotting them.  Here are a few ways.

Message is unexpected – Often I’ll get an e-mail from somebody I know, but who very seldom e-mails me.  For example, my friend’s wife e-mails me every so often and has done so for years.  Why would she?  Either her PC’s got a virus, or she’s trying to start an affair.  Either way, my reaction is the same:  delete that message!  If she really needs to contact me she’ll surely find another way.

Here’s a true story:  my wife e-mailed my brother several times to ask about some bike thing she wanted to buy me for my birthday.  My brother didn’t respond, either because he suspected phishing, or was just really behind on e-mail.  So the next time my brother called me on the phone, my wife intercepted the call and, before fetching me, said to my brother in a low voice, “Call me!”  He was totally perplexed, and she eventually had to call him herself.

Subject line is missing or suspicious – Of the four bogus messages I received recently purporting to be from friends, three have no subject line at all and the fourth has the subject line “RE: ” with nothing else.  The lack of a subject line is usually a giveaway unless you have really lazy friends.  Other suspicious subject lines would be the sender’s name, your name, or something insanely generic like “Hello.”  (If I e-mail a friend just to say hi, I’ll say something a bit more specific, perhaps involving an inside joke.)

Text of message doesn’t read right – Say you’re fooled into opening such an e-mail and now have text to look at.  The hardest thing for fraudsters to get right is grammar (either because they’re foreigners or because they’re stupid).  If your friends use terrible grammar and spelling, I recommend you find some better friends.  Otherwise, be very careful with messages that don’t read right.

If, for whatever reason, you decide not to open an e-mail that appears to be from a friend, it never hurts to create a new message, address it to the friend, give it a subject like “Suspicious e-mail…” and ask if he or she e-mailed you recently.  You can leave the original message in your Inbox while awaiting a response (unless you’re afraid you’ll open it by accident, like if your software is set up to automatically move from one message to the next).

So, here’s a more complete flowchart of how to handle messages:


Will this approach keep me safe?

Actually, avoiding phishing scams is not enough to keep you safe.  We’re probably all eventually doomed, because data breaches of giant databases have become so common.  For example, an insurance company I do business with was hacked awhile back, and had over 70 million customer profiles compromised, including mine.  So, if you screw up and disclose personal information and/or help a virus to spread, you shouldn’t feel too bad. 

Still, I guess it’s nice to have a methodology for not being a complete sucker, and that’s what I’ve endeavored to provide.

--~--~--~--~--~--~--~---~--
For a complete index of albertnet posts, click here.

Tuesday, April 30, 2013

An Open Letter to Spammers


NOTE:  This post is rated PG-13 for mild strong language.

An open letter to spammers

A natural way  to start this letter would be to rail against you spammers for being scumbags, but that’s really beside the point.  Everybody knows you’re scumbags, including you.  Perhaps you justify your behavior by feeling utter contempt for those who actually open your e-mails, and who even sometimes click on the link within, or (gasp) open the attachment.  It really does amaze me that there are people who fall for this, and I don’t exactly admire them either. 

What really bothers me, though, is that your methods—which you probably think of as “crude but effective”—are mostly crude and couldn’t possibly be very effective.  Frankly, “crude” doesn’t cover it:  your methods are monstrously stupid.  If you weren’t so stupid—that is to say, if you weren’t such absolute shit-for-brains types that it probably stinks when you think hard—there wouldn’t be so much collateral damage:  that is, we wouldn’t have the sheer volume of spam messages your non-victims nonetheless have to clear out on a daily basis.  If you had any brains at all, you could get the same results without clogging up the Internet nearly so badly.

It’s natural to be lured toward a grudging respect for the really cunning criminal, like the jewel thief who slips into a museum during the dark of night, outwits all the laser-beam motion detectors, and makes off with the big diamond.  Roald Dahl wrote a story that painted a pickpocket in a positive light.  The cool French movie “Diva” featured an attractive character who was, among other things, an expert shoplifter.  But, vile spammer, your methods are so grossly ineffective, the fitting criminal analogy would be the last guy who stole gas from my old Volvo, who was too lazy or stupid to pick the lock on the gas cap and instead did hundreds of dollars in damage prying it open, just for about $20 worth of gas.  Sure, H.L. Mencken was right when he said “Nobody ever went broke underestimating the intelligence of the American public,” but that doesn’t mean anyone can get rich doing a really stupid scam.

I’m going to detail here all the ways in which your methods are really lame.  In doing this I hope to help you understand that you are just barely smarter than that tiny fraction of a percent of your recipients who actually give you want you want.  Perhaps some people reading this will by miffed that I could be helping you improve your game, but a) real spammers are probably not reading this, and b) this post also serves as a way to help people see through spammers’ absurdly unsophisticated schemes and be better at evading them.

Stock tips

I got an e-mail recently titled “My Huge New Pick!!!”  At first I misread it and thought it said “My Huge New Prick!!!” and I assumed it was from a congressman showing off his new male enhancement.  But no, it was just another stock tip from a complete stranger.  (At least, I assume it was.  Needless to say I didn’t open it.)  In the last week I’ve also received “Huge Day For Our Latest Pick,” “This Stock in our new SUBPENNY,” “A Breaking Bull That's Ready To…” and “It Looks Strong on Solid News.”  My favorite?  “The Upside Potential is Unbelievable.”  That last example is almost certainly accurate:  the potential is truly not to be believed.

Look, just give it up guys.  Why would anybody accept a stock tip from a complete stranger, a tip which is obviously broadcast completely indiscriminately?  What could be the motive:  altruism?  Yeah, right … an altruistic spammer.  Surely it’s a way to get people to buy stock in a company just to boost that company’s stock.  But why would anybody invest in a company with such a pathetic strategy?

Yeah, yeah … “There’s a sucker born every minute.”  But how many of these suckers actually have the know-how to complete a stock purchase online?  If they fell for your e-mail, there’s a pretty good chance they’d spell the ticker wrong.

Sequential messages from the same sender

Often I get bursts of spam where the pretend name of the sender is the same several times in a row.  Look at this:


I can’t imagine these are from different senders.  Something is clearly wrong with this spamming system—it should detect duplicate “send to” addresses.

And how do you come up with the fake names?  Why not choose something more common?  I suppose it’s possible I could actually know somebody named Marina, or that I’d at least think it possible that there was a Marina in my past I’ve temporarily forgotten about, who has bubbled up on the Internet to reconnect.  But look at the putative addresses of these various senders.  Could I really forget a Marina whose e-mail address is "snugglebunny"?  Or could I actually believe I’ve forgotten about a Marina from Russia?

I’m tempted to take you to task for the transparency of having senders’ names not match their addresses (e.g., the Marina whose address starts “laura_c” or the Marina whose address starts “tjr), but I acknowledge that popular e-mail platforms like Gmail and Outlook mask the sender’s address.  Well, you’re not fooling me.  And anybody who finds an e-mail suspicious can look at the Internet headers in Outlook, as shown here.


Sequential messages with the same subject:

Here’s another burst of obvious spam I received recently:


I don’t have six different bank accounts, and I’m pretty sure it would take a major life event for all of them to be put at risk simultaneously.  Clearly this is another problem with a spam distribution mechanism. 

Transparent phishing

Taking another look at the snapshot above, there’s another obvious sign these messages are bogus:  since when do banks use an individual sender’s name when they contact you?  And even if they did, given that most of these customer service folks are probably in India, wouldn’t they pick more generic-sounding fake American names than “Bella Flowers”? 

Yes, there are some people out there who might actually believe a bank would contact them via e-mail due to an account problem.  But for every phishing success story there are probably thousands of would-be phishers coming up with an empty hook, every time.  Your success rate is probably dismal, and just remember:  the other, better phishers are probably laughing at you.

For those readers looking to avoid getting scammed, here’s an easy rule of thumb:  if an e-mail claims to have anything to do with any account you hold at any institution of any kind, delete it.  Banks and such don’t like your account to go away, and they’ll figure out how to reach you.  Believe me. 

I’ve only ever known of one false positive:  way back in 1999, I got an e-mail from some no-name outfit called PayPal titled, “Joe Blow has sent you money!”  Except it wasn’t Joe Blow, it was a guy I know who’d left Visa to help start PayPal.  They wanted me to enter my checking account information, and I’d get money right in my account.  Amazingly, this ended up being legit, but since I hadn’t heard about it through the guy I knew, I didn’t bite.  What am I, stupid?  Of course, had I accepted I’d have made a buck or two, plus the right to brag about being one of the first-ever users of PayPal.  But you know what?  Bragging about being wary of phishing before anybody had ever heard of phishing isn’t so bad either.

Errant capitalization

What do these subject lines have in common?

Huge Day For Our Latest Pick
My Huge New Pick!!!
It Just Issued More News Momen...
A Breaking Bull That's Ready T...
It Looks Strong on Solid News

Well, despite the title of this section, I’ll bet you didn’t get it, you moron, so I’m just going to tell you:  these phrases all have words that are unnecessarily capitalized.  Sure, this used to be standard, back in the 18th century.  But unless you’re pretending to be Ben Franklin e-mailing from beyond the grave, give it a rest.  Real humans don’t use capitals like that, and if my friends start doing it, they’ll just have to start phoning me because I’m not reading any more of their e-mails.

Nonsensical subject lines

Look at these e-mail subjects:

It Expected to Move Higher
my, (YOU) asked...
Be the women' h...

How could “it” have any expectations?  I think “It’s” was meant, but maybe the spammer couldn’t remember the “it’s” vs. “its” rule and just deleted the “s” entirely.  The second example … who knows where that went wrong.  Sure, there are people who don’t understand punctuation, but I hardly think most of them sprinkle around commas and parentheses like so much garnish.  And the apostrophe after “women” is completely bizarre.  A good many people might stumble when trying to remember whether an apostrophe goes before or after an “s,” but after an “n”?  Really?

This example of patently obvious spam needs no explanation:


Discount pharmacy and Viagra

The market in black-market Viagra has got to be well and truly saturated by now.  Keep in mind that it’s fairly widely known that Viagra isn’t an aphrodisiac, so by sending a man a Viagra offer you’re insulting his manhood.  This has always been a narrow market and very well served by the several offers per day everybody has been receiving for the last fifteen years.  Just stop.

I receive lots of other “online pharmacy” messages, of course; the most recent was from “Love” and was titled “Online pharmacy buy cheap disc…”  (Surely “discount” was the truncated word there, and the redundancy of “cheap” and “discount” surprises me not at all.)  Again, this has got to be a really tiny niche.  In my experience, the less educated Internet users tend to be the more paranoid ones.  How many would actually toss the dice on illicit prescription meds online?  After all, if they get ripped off they can’t exactly bring in the cops (nor will anyone cry for them).  How can they possibly establish the trustworthiness of the seller?  This is the online equivalent of the college roommate I had who kept getting shafted by dudes in People's Park selling him oregano they said was pot.

Quasi-spam

This isn’t quite as stupid, of course; I’m talking about outfits I once gave money to who now pester me relentlessly.  There are so many reasons quasi-spam is smarter than the Gatling-gun-shots-in-the-dark strategy your lowly ilk employs.  For one thing, these outfits know I have money, and for another, they know I know who they are.  But still, it’s annoying.

For example, I have set foot in The Walking Company exactly twice.  The first time was during Christmas shopping, and I bought some slippers that were half off and a couple of blankets that were 80% off.  Since then I’ve been getting an e-mail solicitation from them practically every day.  Most of them are totally pointless—“NEW Cork Sandals For Spring!”—but one offered some amazing blowout sale on a pair of shoes that I miraculously had actually already had my eye on.  (Miraculous because I’m a typical guy and buy a pair of shoes every few years.)  So I went there, found out the shoes were mail-order only, vowed on the spot to boycott The Walking Company for life on principle, and went to a competing shoe store in the same mall where I bought a nice pair of shoes and like 15 pairs of socks.  A spiteful purchase?  Possibly.

Then there’s the former Presidential candidate who continued to e-mail me asking for money for years after he’d wasted the money I already gave him (i.e., after he failed to get elected).  Pretty shameless.  Which brings us to the poster child for quasi-spam, “Ranger Rick” magazine, which keeps up a constant barrage:


Such lies.  “Limited Time Offer”—there’s always another offer.  “Last Chance!”—really?  If I don’t renew my subscription, they’ll never let me subscribe again?  Yeah, right.  The kicker here is that I would never, ever renew my subscription, for the simple reason that “Ranger Rick” punishes its loyal subscribers by giving them really crappy renewal rates.  I let the subscription expire and then signed up as if I were a totally new subscriber, for about half the price.  I thought they’d figure that out but I guess they haven’t.

Alternatives to spam

Of course, you could argue that the flip side to spam is targeted ads, like Google’s AdSense nonsense.  As I’ve explained at length, I’m no fan of that, either.  But it doesn’t clog up my Inbox, and at least there’s a very simple way to kill it.  More insidious is the way social networks are contriving to get people to essentially advertise things to their friends.  That makes me sick.  (It brings to mind the non-virtual pyramid schemes that have been around forever.  A friend of mine once tried to bring me in on a Super Blue Green Algae deal and I never talked to him again.)

But the real flip side to spamming is simply not spamming.  Has that ever occurred to you?  To just go find something more constructive to do?  Of course it hasn’t.  You scumbags.