Tuesday, November 17, 2015

Phishing Email - Wells Fargo Online Banking Alert

Phishing Email - Wells Fargo Online Banking Alert

Recently an email with "Note:This is a service message with information related to your Wells Fargo account(s). It may include specific details." email is circulating.
It's a  phishing email. But I walk you through how to tell for sure. 
What to do? 
Report them

Report Phishing
 URLs at Google now 

If you have recievied this email take further action now by click these links

  1. https://www.google.com/safebrowsing/report_phish/?hl=en&url=updatewells.net

Text of the phishing email; 

Dear Wells Fargo Online Customer:
We're writing to let you know that your account needs to be updated and verified immediately.

To proceed, Click on to Update

If this is not done your account may be disabled or blocked.
Please don't reply directly to this automatically-generated e-mail message.


Online Banking Team

How to tell this is a Phishing email ?

  1. Is email is from you to you, then it's phishing.
  2. Hover over all links in email, if it's not from the wellsfargo.com site then forget it.

    In above example, the Online Privacy Policy link points to wellsfrago.com, but the action link Update is to updatewells.net which is a spam collecting site.

  3. The best way is to look at message source, see below.

How to examine Email Message Source ?

Now lets look at message source
  1. Outlook.com->Actions->View Message Source. 
  2. Gmail.com->More (down arrow to top right)->Show original.

For this phony email, well look at the top 50 lines of the message, known formally as the "message header".

At line 50 you have Return-Path: 233571@service-node-13.ng.hostnet.nl
and is suspect because domain was registered in Neatherlands (
Why look at "Return-Path"? When the e-mail is put in the recipient's mailbox, a new mail header is created with the name "Return-Path:" containing the address on the MAIL FROM command. So it's a quick hit to determine authenticity.

Report Phishing Email (not as Spam)

  1. Outlook.com->Junk (at Top)->Phishing Scam
  2. Gmail.com->More (downarrow to top right)->Report Phishing 

Report Phishing URLs at Google now 

If you have recievied this email take further action now by click these linksHover over the iforgot.apple.com link and match the URL and click on the match link to report them as phishing to Google.

  1. https://www.google.com/safebrowsing/report_phish/?hl=en&url=updatewells.net
If you don't see your URL here add a comment below.

Report phishing at Microsoft and government agencies

  1. http://www.microsoft.com/security/online-privacy/phishing-faq.aspx