As I was sorting through my e-mail, I noticed a notification from “Wells Fargo” notifying me that my identity had been compromised. Right away, I knew it was a scam, especially since Wells Fargo sends my statements to my personal e-mail account. The email read as follows:
Dear Customer: As part of our security measures, we regularly screen activity in the credit and debit card system. During a recent screening, we noticed an issue regarding your account. Your account may have been accessed by an unauthorized third party. As a precaution, we are requesting additional verification of your payment and personal information in order to protect your Wells Fargo account against unauthorized transactions.
So this is all for my protection. Right. Moving on.
Please send a fax with your following information to remove any holds on this account. If we will not receive your fax within 24 hours your account will be temporarily suspended.
The e-mail closes with the kicker:
For your security, we deactivated your account.
Never mind that the e-mail previously stated that the account would be temporarily suspended if information is not received within 24 hours. This last plug is just intended to hoax you into frantically sending them your personal/financial information.
The dangers of online phishing
Have you received email or text with a similar message? It’s a scam called phishing. These are spam messages designed to lure personal information (credit card numbers, bank account information, or other sensitive information) from unsuspecting victims.
Many people get hooked by these emails because they warn consumers their identity or information has been compromised and needs to be verified, or because they include the logos of financial institutions. But remember, it’s easy to Google image search any company or organization and obtain an authentic logo.
How to avoid online phishing
Here are some tips from The Federal Trade Commission to avoid getting hooked by a “phishing” identity theft scam:
- Don't reply to emails that ask for personal or financial information, or click on any links. Phishers can make links look like they go one place, but that actually send you to a different site.
- Always verify that you're contacting an organization's official lines of communication. Scammers send emails that appear to be from a legitimate business, asking you to call a phone number to update your account or access a refund. If you need to reach an organization you do business with, call the number on your financial statements or on the back of your credit card.
- Use anti-virus software, anti-spyware software, and a firewall, and update them all regularly.
- Never email personal or financial information.
- Review credit card and bank account statements as soon as you receive them to check for unauthorized charges.
- Practice caution when opening attachments or files. Always double check files from emails you receive, regardless of who sent them.
- Forward phishing emails to spam@uce.gov – and to the company, bank, or organization impersonated in the phishing email. You also may report phishing email to reportphishing@antiphishing.org.
- Verify official communication channels. Organizations that are often impersonated in scams, like financial institutions, will often outline how they will reach out to you with important information. If you're unsure whether the correspondence is official, check the organization's website, or reach out to a representative directly.
- If you've already been scammed - visit the Federal Trade Commission’s Identity Theft website at ftc.gov/idtheft.
Still Have Questions?
Don’t hesitate to contact us with additional inquiries!