Identity Theft TipOff Reports

Scam ReporterScam Tips Received
No Name
Cricklewood, Brent, United Kingdom
2012-10-20 11:16:01
Identity Theft
UPS Scam with possible malicious script with link to sharif.es 
Attempted UPS scam alert! Highly suspicious email from powweb@resge.com (id 1TPN8N-0000Wf-J3);supposed sender is providing-us@postal-ups.com (NB: Delete email: do not open or click on any links) possibly also includes Malware or Suspicious embedded script( suspected) in this UPS scam email as subject text of email unconnected to Subject header. Email Subject: UPS shipment status ID#3452 Received: from resge.com ([82.146.63.199]) by COL0-MC2-F13.Col0.hotmail.com with Micr…
Read Full Report ⇒
Anonymous
Santa Rosa, CA, United States
2012-10-16 16:48:09
Identity Theft
Yahoo
This came by email..as if it were a friend in trouble 
 Scammer Information
This scam identfies themselves as a friend of mine in trouble in Spain and needs our help because they were mugged of all their money. They are asking for $1960.00 be wired to John McMahon, Comte d'Aiamans 14, Lloseta, Mallorca, Spain I can forward emails to someone if I know who. Thanks, Denise Hagy…
Read Full Report ⇒
F Clark
DuBois, PA, United States
2012-10-16 15:11:29
Identity Theft
900-080-004000 cell text 
 Scammer Information
Email Address:
Scam Website:
Fax:
Text recieved; VOICE USAGE ALERT: your acct used abt 50% of Anytime Min for the bill ending on the 22nd. Monitor at vzw.com. As of 10/16 09:33 AM EDT. FREE MSG Probably to entice reciever to reply to the 900 number. Tried to report to 7726 but it refused to recognise the full 900 number.…
Read Full Report ⇒
No Name
Cricklewood, Brent, United Kingdom
2012-10-14 10:33:30
Identity Theft
Santander Banking Scam; Subject: Important Customer Notice; seemingly from securityalert@santander.co.uk 
 Scammer Information
Email Address:
esc3@hermes.hood.edu
Scam Website:
Fax:
Santander Identity Theft Scam from blacklisted IP located in Fareham, UK. esc3@hermes.hood.edu , a HELO user of hermes.hood.edu sending phishing scam (with ESMTPA id 36711788) supposedly from securityalert@santander.co.uk with attached file link. NB. DO NOT OPEN FILE ATACHMENT! Originating IP: 88.212.147.234 ISP: Mailbox Networks Host Name: 88-212-147-234.rdns.as8401.net Organization: Mailbox Networks Country: Fareham, Hampshire F2, United Kingdom. Phish routed via IP 144…
Read Full Report ⇒
Monika Pletschke
Somewhere in South Africa
2012-10-12 14:03:17
Identity Theft
E-Mail regarding deduction from my bank account. Looks like authentic e-mail address from ABSA 
Raw message: Return-path: Envelope-to: mcalitz@absamail.co.za Delivery-date: Fri, 12 Oct 2012 14:53:16 +0200 Received: from mxl56v247.dotnetwork2.co.za ([41.77.56.247]:11179 helo=s11p02m011.dotnetwork2.co.za) by aia-mx-vm-04 with esmtp (Exim 4.76 (FreeBSD)) (envelope-from ) id 1TMejr-000E87-62 for mcalitz@absamail.co.za; Fri, 12 Oct 2012 14:53:15 +0200 Authentication-Results: s11p02m011.dotnetwork2.co.za…
Read Full Report ⇒
No Name
Cricklewood, Brent, United Kingdom
2012-10-09 13:32:47
Identity Theft
Barclays Bank phish; Subject: IMPORTANT SECURITY NOTICE; From: Barclays Bank Plc <customerservice@barclays.co.uk> 
Cyber fraudster (nobody@dabulyulinux.dabulyuhosting.com; id 1TLXi0-000414-5o ) sending phishing email seemingly from customerservice@barclays.co.uk with redirect link to phishing Url at blacklisted site goldotclothing.com. -------------------------------------- Email Details as follows: IP: 46.105.237.0 (IP address belongs to a High Risk Hosting Provider ). (refer to abuseipdb.com/check/46.105.237.0) ISP: Ovh Systems Host Name: mail.dabulyuhosting.com Organization: Ovh Sys…
Read Full Report ⇒
No Name
Gosport, Hampshire, United Kingdom
2012-10-05 13:00:28
Identity Theft
Paypal (paypal.com)
Paypal scam email from User ([24.187.43.197]); Subject: Email Alert; phishing url at www.king-hiss.com 
Paypal Scam email with verified phishing link to king-hiss.com ( refer http://www.phishtank.com/phish_detail.php?phish_id=1582085) sent by online@paypal.co.uk from IP 24.187.43.197 located in New Jersey, United States routed via SERVER.marcsolomon.local ([74.221.248.219]). IP: 24.187.43.197 ISP: Optimum Online Host Name: ool-18bb2bc5.dyn.optonline.net Organization: Optimum Online Location: Montauk, New York,NY11954, United States Received: from SERVER.marcsolomon.local ([7…
Read Full Report ⇒
No Name
Gosport, Hampshire, United Kingdom
2012-10-05 12:11:19
Identity Theft
Halifax Bank Plc <onlineservice@halifax.co.uk>; Subject: IMPORTANT MESSAGE ALERT 
 Scammer Information
User admin@ayyildizsesli.com sending fraudulent scam email supposedly from Halifax Bank Plc using originating source host ml82.128.1.68.multilinks.com in Nigeria. Scam email has possibly malicious script as well as redirect link to phishing Url at www.bluesend.ir email routed via server.uzmanpanel.com ([85.153.31.131]) Originating IP: 82.128.1.68 ISP: Multi-Links Telecommunications Limited Host Name: ml82.128.1.68.multilinks.com Organization: Mu…
Read Full Report ⇒
No Name
Gosport, Hampshire, United Kingdom
2012-10-03 09:22:24
Identity Theft
Yorkshire Building Society Scam; Subject: Yorkshire - Account Review Notification; 
SCAM: Authenticated User lesbrucepawsey@static-58-108-223-252.optusnet.com.au sending Yorkshire Building Society phish supposedly from online.account@yorkshire.co.uk , with fraudulent redirect link to phishing website sarperkara.com Received: from mail34.syd.optusnet.com.au ([211.29.133.218]) by BAY0-MC4-F8.Bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4900); Tue, 2 Oct 2012 11:40:33 -0700 Received: from User (static-58-108-223-252.optusnet.com.au [58.108.223.252] (may …
Read Full Report ⇒
Anonymous
Somewhere in United States
2012-09-25 13:00:30
Identity Theft
YOUR PACKAGE FUNDS $2.5M USD IN USA TODAY 
 Scammer Information
YOUR PACKAGE FUNDS $2.5M USD IN USA TODAY We wish to inform you that the diplomatic agent conveying the consignment box valued the sum of $2.5 Million United States Dollars misplaced your address and he is currently stranded at JFK AIRPORT NEW YORK USA now. We required you reconfirm the following information below so that he can deliver your consignment box to you today Because his flight ticket is about to expire. NAME: ========================= ============================…
Read Full Report ⇒
Nolan Belk
North Wilkesboro, NC, United States
2012-09-24 13:30:52
Identity Theft
Craigslist (craiglist.com)
Craigslist offer 
 Scammer Information
Email Address:
vvbnvfc@yahoo.com
Scam Website:
Fax:
Joseph William vvbnvfc@yahoo.com Thanks for your quick response, i'm okay with the presentcondition asstarted in the advert and the askingprice. i will not be able to cometo look at it due to thelong distant and the easiest way for me tomake thepayment is through a bank check, i'll wait until your bankclears the check before we proceed with the pickup.I'llalso takecare of the pickup and delivery when thecheck cleared, provide meyour name, address, city,state, zip code for m…
Read Full Report ⇒
RLD
Mount Vernon, OH, United States
2012-09-20 15:40:57
Identity Theft
ADPclientService - Message from ADP - Your Transaction Report 
 Scammer Information
Scam Website:
Fax:
I do not know the details as I do not open obvious Spam, But the info after the @ is attachet is a legitimate Government site. However, it is not their email.…
Read Full Report ⇒
Peacequester
Myrtle Beach, SC, United States
2012-09-19 21:50:08
Identity Theft
Yahoo
Yahoo member services 
Dear User, Your E-mail account has exceeded its limit and needs to be verified, if not verified within 24 hours, we shall suspend your account. click here to verify your email account now Thank you for being a loyal Yahoo! Mail user. Regards, Yahoo! Account Services …
Read Full Report ⇒
No Name
New London, CT, United States
2012-09-19 02:53:37
Identity Theft
Paypal (paypal.com)
+5 Untitled Identity Theft on Paypal (paypal.com), ref:5181 
 Scammer Information
Scam Website:
Fax:
Thank you for getting back to me.Can you assure me that it's in good state and i will not be disappointed with it.I'm ready to pay your asking price and to be honest, i wanted to buy this for my Son and i want it to be a surprise gift for him, but the issue is i am an oceanographer and i do have a contract to go for which starts tomorrow and am on my way right now.The contract is strictly no call due to the lack of reception on the sea area. But I'm able to access email anyti…
Read Full Report ⇒
No Name
Hastings, East Sussex, United Kingdom
2012-09-13 15:06:46
Identity Theft
Subject: IMPORTANT MESSAGE UPDATE From: Barclays Bank Plc <customerservice@barclays.co.uk> 
Barclays Bank phish from allergy@d02-29-1-12.centos-server.net , id 1TC6J4-0007sk-0J (with fraudulent link that redirects to phishing Url at mapki.com (refer http://www.phishtank.com/phish_detail.php?phish_id=1561002) IP: 68.171.215.27 ISP: Acenet Host Name: empireallergy.com Organization: Promitech-Technologies Country: Dearborn, Michigan, MI 48124, United States. …
Read Full Report ⇒
No Name
Gosport, Hampshire, United Kingdom
2012-09-12 12:57:28
Identity Theft
From: "The Co-operative Bank p.l.c"<noreply@co-operative.co.uk> Subject: Confirm & Update Your Account Profile. 
Co-operative Co-operative Bank phishing seemingly sent by noreply@co-operative.co.uk, but actually sent by User (static-58-108-187-172.optusnet.com.au [58.108.187.172] (may be forged)) (authenticated sender happydayskindy)with ESMTP id q8C9Djpj032524 Blacklisted IP 58.108.187.172 is source of numerous phishing attempts involving various UK financial institutions. IP: 58.108.187.172 (Blacklisted xbl.spamhaus.org, cbl.abuseat.org and bl.spamcop.net) ISP: Optus Host Name: sta…
Read Full Report ⇒
No Name
Gosport, Hampshire, United Kingdom
2012-09-11 12:04:44
Identity Theft
Tax Refund scam; Subject: Tax Refund Confirmation; From: "HM Revenue & Customs"<noreply@hmrc.gov> 
Tax refund scam from blacklisted IP 58.108.187.172 (may be forged))-(authenticated sender happydayskindy) Received: from mail01.syd.optusnet.com.au ([211.29.132.182]) by SNT0-MC4-F15.Snt0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4900); Tue, 11 Sep 2012 03:58:54 -0700 Received: from User (static-58-108-187-172.optusnet.com.au [58.108.187.172] (may be forged)) (authenticated sender happydayskindy) by mail01.syd.optusnet.com.au (8.13.1/8.13.1) with ESMTP id q8BAw59Q0217…
Read Full Report ⇒
No Name
Gosport, Hampshire, United Kingdom
2012-09-11 10:29:45
Identity Theft
Barclays Online Access Re-activation. ; 
Barclays Bank phishing scam supposedly from customerservice@barclays.co.uk sent by nobody@insigaa4.miniserver.com id 1TB5g2-0006gH-NP with link to http://research.uleth.ca/mahavidya/site/index.htm (DO NOT CLICK ON THIS LINK) IP: 89.200.137.149 ISP: Memset Ltd Host Name: insigaa4.miniserver.com Organization: Memset Ltd Country: London, City of London H9, United Kingdom (GB) Received: from insigaa4.miniserver.com ([89.200.137.149]) by COL0-MC4-F29.Col0.hotmail.com with Micr…
Read Full Report ⇒
No Name
Gosport, Hampshire, United Kingdom
2012-09-08 14:20:52
Identity Theft
From: "Santander" ( security@santander.co.uk ) Subject: Unauthorized Access: from IP:82.77.37.9 
 Scammer Information
Attempted scam sent by security@santander.co.uk with phishing link to http://217.219.20.51/Images/santander.htm IP 82.77.37.9 (82.77.37.9.cablelink.rdsar.ro ; Organization: Romania Data Systems)in Arad, Romania is involved in constant fraudulent emails usually involving banking or financial institutions. Link info: site : 217.219.20.51 ISP: Information Technology Company (ITC) Host Name: 217.219.20.51 Organization: Islamic AZAD Univeristy Yasooj Location: Yasooj, 05 Kohkil…
Read Full Report ⇒
No Name
Gosport, Hampshire, United Kingdom
2012-09-08 13:34:53
Identity Theft
Subject: You have 1 new Security Message Alert! From: Barclays Bank PLC <onlineservice@barclays.co.uk> 
Fraudulent email supposedly from Barclays with phishing link to url at lt2u.biz, a Malaysian site. IP 200.185.51.84 ISP: TIVIT TECNOLOGIA DA INFORMACAO S.A. Host Name: firenze.mundo.com.br Organization: TIVIT TECNOLOGIA DA INFORMACAO S.A. Country: Brazil Received: from firenze.mundo.com.br ([200.185.51.84]) by COL0-MC2-F35.Col0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4900); Fri, 7 Sep 2012 16:51:52 -0700 Received: from firenze.mundo.com.br (localhost [127.0.0.1]) by fir…
Read Full Report ⇒
No Name
Gosport, Hampshire, United Kingdom
2012-09-08 12:08:44
Identity Theft
From: "Halifax" (security@halifax.co.uk); Subject: Unauthorized Access 
 Scammer Information
IP 82.77.37.9 involved in constant phishing!! ISP: Romania Data Systems Host Name: 82.77.37.9.cablelink.rdsar.ro Organization: Romania Data Systems Located in Arad, 02 Arad,Romania unsafe phishing link in email:http://217.219.20.51/Images/halifax.htm ( NB:DO NOT CLICK on link which is connected to the Islamic AZAD Univeristy Yasooj in Yasooj, 05 Kohkiluyeh va Buyer Ahmadi,Islamic Republic of Iran. Received: from martel.biz ([89.174.1…
Read Full Report ⇒
No Name
Gosport, Hampshire, United Kingdom
2012-09-06 12:26:45
Identity Theft
UK Student Loan scam; From: "studentfinance.direct.gov.uk"<mail2stduent@protocol.slc.co.uk> 
Phishing by mail2stduent@protocol.slc.co.uk with link to xerex.com.ar- a site that is blacklisted for malware and phishing- sent from blacklisted IP. IP: 75.65.226.134 ISP: Comcast Cable Source Host Name: c-75-65-226-134.hsd1.ms.comcast.net Organization: Comcast Cable Location:Clinton, Mississippi, MS 39056, United States Received: from mail.tspspices.com ([76.12.10.210]) by COL0-MC4-F18.Col0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4900); Wed, 5 Sep 2012 10:18:13 -0700 …
Read Full Report ⇒
No Name
Gosport, Hampshire, United Kingdom
2012-09-04 13:22:22
Identity Theft
Subject: Unauthorized Access; From: "Nationwide"<security@nationwide.co.uk> 
Attempted Nationwide phishing scam with link to phishing site www.ilam-telecom.ir/public/. From: "Nationwide"; Subject: Unauthorized Access Received: from golden-shuttle.be ([91.183.33.109]) by COL0-MC4-F8.Col0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4900); Mon, 3 Sep 2012 18:55:36 -0700 Received: from User ([82.77.37.9]) by golden-shuttle.be with Microsoft SMTPSVC(6.0.3790.4675); Sat, 25 Aug 2012 10:01:03 +0200 From: "Nationwid…
Read Full Report ⇒
No Name
Hythe, Kent, United Kingdom
2012-08-29 12:21:55
Identity Theft
Subject: IMPORTANT SECURITY NOTICE From: Halifax Bank Plc <onlineservice@halifax.co.uk> 
'Halifax Bank' phish with link to US site flagworldinc.com sent by onlineservice@halifax.co.uk (Return-Path: www-data@www.agriok.it ) NB: both agriok.it and flagworldinc.com found to have phishing url by Safeweb.Norton.com IP: 62.149.210.190 ISP: Aruba S.p.A. Source Host Name: host190-210-149-62.serverdedicati.aruba.it Organization: Aruba S.p.A. - Housing and Colocation services. Location: Teramo, Abruzzi 01, Italy Received: from http://www.agriok.it([62.149.210.190]) …
Read Full Report ⇒
Pierre Bacquet
L'Aigle, Orne, France
2012-08-22 10:20:19
Identity Theft
Keeping track of your usage. 
Received the following email (as Bcc: since there isn't any To: or Cc: field) -------------------- This is the Help desk Program that periodically checks the size of your e-mail space is sending you this information. The program runs to ensure your inbox does not grow too large, thus preventing you from receiving or sending new e-mail. As this message is being sent, you have 2.5 gigabytes (GB) or more stored in your inbox. We are currently upgrading our data base and e-mail …
Read Full Report ⇒
« Previous 1 ...23 24 25 26 27 28 29 30 31 32 33 Next »
Ad Blocker Detected
Our website is made possible by displaying online advertisements to our visitors.
Please consider supporting us by disabling your ad blocker.
Thanks!
Scamdex
PING