A number of Scamicide readers have sent me copies of phishing emails that appear to come from Wells Fargo. One of them is reproduced below. It makes for compelling reading, but it is a scam. Phishing emails, by which scammers and identity thieves attempt to lure you into either clicking on links contained within the email which will download malware or providing personal information that will be used to make you a victim of identity theft, are nothing new. They are a staple of identity thieves and scammers and with good reason because they work. As always, they lure you by making it appear that there is an emergency that requires your immediate attention or else dire consequences will occur. Copied below is a new phishing email presently being sent to unsuspecting people that appears to come from Wells Fargo. This particular one came with a Wells Fargo logo and was sent from an email address that, while not a real Wells Fargo email, did appear to be legitimate, which makes the scam even more tempting to more people.
Here is the email.
Secure message from Wells Fargo Online®
We posted a new notice or letter to your “Statements & Document” on your account
We recently detected an activity which seems unusual to your normal account activities.
Therefore as a preventive measure we have limited your access to sensitive account functions.
Please use your online access to sign on.
If you have questions about your account, please refer to the contact information on your statement. For questions about viewing your statements online, Wells Fargo Customer Service is available 24 hours a day, 7 days a week. Call us at 1-800-956-4442 or sign on to send a secure email..
|wellsfargo.com | Security Center
Please do not reply to this automated email. Sign on to send a secure email.
Legitimate emails from your bank would include the last four digits of your account and include your name. This email had neither. Often such phishing emails originate in countries where English is not the primary language and the spelling and grammar are poor. However this one appears grammatically correct. Obviously, if you are not a Wells Fargo customer, you will recognize immediately that this is a scam. As with most phishing emails, they lure you into clicking on a link (We have blocked the link and inserted xxx) by attempting to trick you into believing there is an emergency. However, if you hover on the sign in link contained in the actual phishing email, you will find it does not go to Wells Fargo.
As with all phishing emails, two things can happen if you click on the links provided. Either you will be sent to a legitimate looking, but phony webpage where you will be prompted to input personal information that will be used to make you a victim of identity theft or, even worse, merely by clicking on the link, you will download keystroke logging malware that will steal all of your personal information from your computer and use it to make you a victim of identity theft. If you receive an email like this and think it may possibly be legitimate, merely call your bank or other institution from which the email purports to originate at a telephone number that you know is accurate and you will be able to confirm that it is a scam.
For those of you receiving the Scam of the day through an email, I just want to remind you that if you want to see the ever increasing list of Coronavirus scams go to the first page of the http://www.scamicide.com website and click on the tab at the top of the page that indicates “Coronavirus Scams.” Scamicide was recently cited by the New York Times as one of three top sources for information about Coronavirus related scams.
If you are not a subscriber to Scamicide.com and would like to receive daily emails with the Scam of the day, all you need to do is to go to the bottom of the initial page of http://www.scamicide.com and insert your email address where it states “Sign up for this blog.”