ABSA Phishing Scam - Scariest I've seen

[/QUOTE] This is not at all what you were saying before.[/QUOTE]

I acknowledged that I omitted a lengthy response for the sake of brevity.
My response was based on the main underlying fact stated by Mike_E that ABSA had stated that the phishing emails CAN originate from the ABSA domain and not just spoofed. In his statement he effectively nullified the discussion point around it being sent from another source and pretending to be from ABSA.

On rereading his point I also see that he quoted the emails as being from @absa.co.za with the only spelling difference being in the part preceding the domain name - however in his words he indicated that the domain name was preceded by an "e".

It is easy to spot the emails where the domain name is different - they are also normally flagged as spam / suspect by mail servers for this very reason.

Yes, some people are not aware of it - but that wasn't my argument. I had moved past that point due to it being addressed in the post by Mike_E
 
Last edited:
i just tell people never to respond to any banking thing on the net or email, ever, even phone calls, dont give any information ever, if they say its something of concern, tell them you will go to the closest branch and put the phone down. and then go do that.

they phone me and ask me if its me, so stupid.

ive even sat with someone while they are phoned and they are given the "security" information and asked to confirm if the info is correct. told them to put the phone down and go to their branch.
 
Last edited:
Really? You're telling me I can't send a mail to anybody and make it look like it came from [email protected] using nothing but telnet?

Or did I misunderstand you?

It largely depends on how the domain is setup DKIM and SPF records obviously help and the configuration of the SMTP server would require you to log into it to send a mail via telnet on its behalf.
 
Wait, there are people out there that still fall for these?
 
Spoofing an email address is one of the easiest tricks in the book. Hell to make my life easier I have my firewalls send out emails using a fake email address. In my case I am using [email protected] which makes it easy for my to filter and organise my mails.

Yep. The only way to really tell is to check the first helo/ehlo in the header and if it's not consistent with other mails from that addy then red flag it... but that's not something joe soap will be doing.
 
Wait, there are people out there that still fall for these?

Nah, the real issue is not people's behaviour IMO, it's the banks. Your bank should NOT be sending you PDF attachments or URLs to click anymore. They should simply say "To view your statement, log in to your online banking profile and click blah blah blah"
They can provide those pdfs via the portal if you want a file. Seriously.
 
Nah, the real issue is not people's behaviour IMO, it's the banks. Your bank should NOT be sending you PDF attachments or URLs to click anymore. They should simply say "To view your statement, log in to your online banking profile and click blah blah blah"
They can provide those pdfs via the portal if you want a file. Seriously.
Agreed. I think Allan Gray does that.
 
This scam is still going. They got the last 4 numbers of my ID right, but the account number was wrong... Scary indeed. "Absa Saving Account.emc" was attached and I will not fall for that.

The "sent from" email address is not necessarily the one it actually came from... Be careful out there
 
I really wish the banks in SA would implement DMARC policies. A proper DMARC policy set to reject, along with the correct SPF/DKIM records will very quickly kill a lot of phishing mails that abuse the domain name, i.e. [email protected]. Spammers and phishers will simply then misuse another domain name, but at least it kills junk from the official domain.
 
Top
Sign up to the MyBroadband newsletter
X