I received this in an email yesterday. First of all, we don’t even have an account with Chase anymore (that was one of the first cards to get shredded, paid off and closed – in that order). But, there are some other things that make this an obvious phishing email.First of all, the return email address is a dead giveaway. “Chase Online [sfsbsa@mssffa.com]” What is mssffaa.com?! Sounds more like a sneeze than a major financial institution. But while this was an obvious giveaway – don’t rely on the return email address that Outlook (or another email client) displays because these can be spoofed.
The more obvious giveaway is that when I hover my mouse over the link “Click here to access your account” – it will show me the web address that this link would take me to (this works with all links - try it on the links in this post - in Internet Explorer the web address will be displayed in the bottom left corner of the window). Again we see the mssffaa.com address. If this was really from Chase, the web address would have been something more like "chase.com".But what if the web address had been http://chase.mssffaa.com? Nope, still a bad address. Web addresses are made of different parts. For example: http://subdomain.domain.com/directories (the “.com” part is called the top-level domain and could be other things like .net or .org). If I own a “domain”, I can have any “subdomain” under it that I want. So if I own the domain “tycen.com”, I could have anything under it like blog.tycen.com, pictures.tycen.com, mail.tycen.com…or even chase.tycen.com. It doesn’t matter what the subdomain is – what matters is what the domain is – the part right before the .com (or top-level domain). Everything after the .com (directories) is just different folders of information/pages on that site.
Once you’ve identified that it is a phising email, I would recommend not clicking on the link - you don’t know what kind of site it will take you to. They can also design the links in such a way that once you click on it it identifies to whoever sent the email that your email address is a valid one (out of the gazillions of emails they sent out) AND that they’ve got a clicker (you) – and this will likely not be the last email you get from them (spam).
But, I couldn’t resist – so I clicked on the link. It took me to a page that was designed to look just like Chase.com. If the unsuspecting person that went there proceeded to entered their Chase username and password, whoever runs that site would then have that information. I would be willing to bet that then the site would have tried to get more information from you – SSN, address, DOB, etc – all under the ruse of “confirming” your identity. (I just tried going to the site again and it looks like it’s been taken down since I went there yesterday)
I’m using Internet Explorer 7 (the most recent version) and it has a built-in phishing security feature and it warned me that this site was reported as a phishing site. But, don’t rely on phishing security alone – they may not always work.
What should you do about this? First of all, just realize there are bad people on the internet who want to steal your identity or personal information and be suspect of any emails like this – common sense is the rule of thumb. Second, if you get an email like this and you actually have an account with the company – don’t click on any links in the email – go directly to the company’s site (i.e., chase.com) and log in as you normally would. Or, better yet, call the 800 number and talk to a live person. Third, pull your credit report once a year to make sure accounts haven’t been opened in your name. Most states (if not all) allow that you get one free credit report every year – go to http://annualcreditreport.com. Fourth, and finally, I would recommend signing up for ID Theft Protection from Zander Insurance. Sonja and I signed up and for a couple it’s only $12.50/month ($6.50/month for singles). In the event that we are victims of ID theft, Zander will do a lot of the leg work and provide reimbursement for lost money/time to help us get everything cleaned up.
Something else you can do to check out emails like this (though not as reliable) is to pick some key phrases out of the email and Google them. If it is a phishing email, you will likely find information about other people receiving it.
Oh, one other thing you can do…get rid of the stupid credit cards! See how much hassle they cause!



