# Has anyone else been getting this type of suspicious email?

**URL:** <https://boards.straightdope.com/t/has-anyone-else-been-getting-this-type-of-suspicious-email/849737>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [March 18, 2020, 5:04pm UTC](https://boards.straightdope.com/t/has-anyone-else-been-getting-this-type-of-suspicious-email/849737 "2020-03-18T17:04:13Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![jebert](https://avatars.discourse-cdn.com/v4/letter/j/ec9cab/32.png) [@jebert](https://boards.straightdope.com/u/jebert)\
**Post date:** [March 18, 2020, 5:04pm UTC](https://boards.straightdope.com/t/has-anyone-else-been-getting-this-type-of-suspicious-email/849737/1 "2020-03-18T17:04:13Z")

</div>

I have now received 2 suspicious emails titled “Congratulations. Your order from xxxx was successful.” xxx in my 2 cases was Taco Bell and Kroger. Upon opening, the email says “Congratulations. Click here.”

Of course, I didn’t click, but I’m wondering if this is a case of my credit card misuse or just some sort of other scam. Since I have several credit cards, I haven’t checked them yet.

Is anyone familiar with this scenario?

---

<div class="post-metadata">

**Author:** ![Telemark](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/telemark/32/372_2.png) [@Telemark](https://boards.straightdope.com/u/Telemark)\
**Post date:** [March 18, 2020, 5:17pm UTC](https://boards.straightdope.com/t/has-anyone-else-been-getting-this-type-of-suspicious-email/849737/2 "2020-03-18T17:17:01Z")

</div>

It’s a scam, blindly sent out to mass audiences, not tied directly to your CC numbers.

---

<div class="post-metadata">

**Author:** ![cochrane](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cochrane/32/10441_2.png) [@cochrane](https://boards.straightdope.com/u/cochrane)\
**Post date:** [March 18, 2020, 5:56pm UTC](https://boards.straightdope.com/t/has-anyone-else-been-getting-this-type-of-suspicious-email/849737/3 "2020-03-18T17:56:14Z")

</div>

[Recent thread about the same type of scam.](https://boards.straightdope.com/sdmb/showthread.php?t=891661)

---

<div class="post-metadata">

**Author:** ![jaycat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/jaycat/32/3015_2.png) [@jaycat](https://boards.straightdope.com/u/jaycat)\
**Post date:** [March 18, 2020, 9:50pm UTC](https://boards.straightdope.com/t/has-anyone-else-been-getting-this-type-of-suspicious-email/849737/4 "2020-03-18T21:50:05Z")

</div>

> [@cochrane](#):
>
> [Recent thread about the same type of scam.](https://boards.straightdope.com/sdmb/showthread.php?t=891661)

I originated that thread, and they’re really not much alike.

---

<div class="post-metadata">

**Author:** ![Slash1972](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/slash1972/32/6461_2.png) [@Slash1972](https://boards.straightdope.com/u/Slash1972)\
**Post date:** [March 18, 2020, 11:31pm UTC](https://boards.straightdope.com/t/has-anyone-else-been-getting-this-type-of-suspicious-email/849737/5 "2020-03-18T23:31:10Z")

</div>

All people every day get suspicious emails. Don’t click any links in any emails unless you 100% know who the sender was. And then, probably don’t click the link because they could be forwarding you a scam email.

Not to be a dick, but how is this still even a question in this day and age? Yes, other people have got those emails. Yes, they are phishing, scam-laden emails. Don’t click the links in them.

Example from my work as a cybersecurity consultant:

A person received an email to their personal email account that contained a link to a .jpg. The link wasn’t even masked or anything, it was clear that it was a JPEG file. The subject was along the lines of “Coronavirus update!”

This brainiac copied the entire message from his personal account to his work account and then forwarded it to a bunch of people on our work network :smack:

Now we have to spend hours finding the emails throughout our network and deleting them.

DON’T CLICK LINKS IN YOUR EMAILS!

---

<div class="post-metadata">

**Author:** ![jebert](https://avatars.discourse-cdn.com/v4/letter/j/ec9cab/32.png) [@jebert](https://boards.straightdope.com/u/jebert)\
**Post date:** [March 19, 2020, 2:25am UTC](https://boards.straightdope.com/t/has-anyone-else-been-getting-this-type-of-suspicious-email/849737/6 "2020-03-19T02:25:25Z")

</div>

> [@Slash1972](#):
>
> Not to be a dick, but how is this still even a question in this day and age? Yes, other people have got those emails. Yes, they are phishing, scam-laden emails. Don’t click the links in them.  
> DON’T CLICK LINKS IN YOUR EMAILS!

Yeah, I get that. My main concern was that one of my credit cards was somehow compromised.

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [March 19, 2020, 2:41am UTC](https://boards.straightdope.com/t/has-anyone-else-been-getting-this-type-of-suspicious-email/849737/7 "2020-03-19T02:41:27Z")

</div>

> [@Slash1972](#):
>
> All people every day get suspicious emails. Don’t click any links in any emails unless you 100% know who the sender was. And then, probably don’t click the link because they could be forwarding you a scam email.
> 
> Not to be a dick, but how is this still even a question in this day and age? Yes, other people have got those emails. Yes, they are phishing, scam-laden emails. Don’t click the links in them.
> 
> Example from my work as a cybersecurity consultant:
> 
> A person received an email to their personal email account that contained a link to a .jpg. The link wasn’t even masked or anything, it was clear that it was a JPEG file. The subject was along the lines of “Coronavirus update!”
> 
> This brainiac copied the entire message from his personal account to his work account and then forwarded it to a bunch of people on our work network :smack:
> 
> Now we have to spend hours finding the emails throughout our network and deleting them.
> 
> DON’T CLICK LINKS IN YOUR EMAILS!

How is a jpg file a threat?

---

<div class="post-metadata">

**Author:** ![jtur88](https://avatars.discourse-cdn.com/v4/letter/j/e9c0ed/32.png) [@jtur88](https://boards.straightdope.com/u/jtur88)\
**Post date:** [March 19, 2020, 2:48am UTC](https://boards.straightdope.com/t/has-anyone-else-been-getting-this-type-of-suspicious-email/849737/8 "2020-03-19T02:48:50Z")

</div>

> [@jebert](#):
>
> Yeah, I get that. My main concern was that one of my credit cards was somehow compromised.

In this case, as I understand it, his scam email was coincidentally “from” a businrss where he had a recent CC transaction. Which would raise the suspicion that it was not a random robot.

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [March 19, 2020, 12:43pm UTC](https://boards.straightdope.com/t/has-anyone-else-been-getting-this-type-of-suspicious-email/849737/9 "2020-03-19T12:43:50Z")

</div>

> [@beowulff](#):
>
> How is a jpg file a threat?

There have been errors in the various libraries for decoding image files. Both gif and jpeg have had one serious error each. These errors could lead to heap overflow conditions which are a traditional exploit used in some malware.

I.e., one part of the “image” creates a heap overflow with another part containing the exploit code that gets put into the overflow area where it might end up getting executed.

Here’s a [mention](https://en.wikipedia.org/wiki/Heap_overflow) of a heap overflow in MS’s jpeg library.

Good news: these errors are very rare and once discovered quickly patched.

Bad news: if you have a device with an OS that is no longer supported, tough. Android devices, for example, quite rapidly fall into this category.

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [March 19, 2020, 3:54pm UTC](https://boards.straightdope.com/t/has-anyone-else-been-getting-this-type-of-suspicious-email/849737/10 "2020-03-19T15:54:43Z")

</div>

OK, I get that - if you are running some ancient unpatched system, that could be a (very theoretical) problem.  
But, in that case, wouldn’t an in-line image be just as bad? Does **manson’s** office have their email client set to not render in-line images? How crippled can you make it and still be useful? I request photos from clients all the time -it’s a necessary part of me doing my job.  
Seems like an enormous overreaction to me.

ETA: I’m running OS X, so I’m not concerned about looking at attachments (there are no known exploits currently), so I will often times open up attachments like that to see wha they are, and 100% of the time they are spam selling Viagra or Cialis.

---

<div class="post-metadata">

**Author:** ![Sigene](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@Sigene](https://boards.straightdope.com/u/Sigene)\
**Post date:** [March 19, 2020, 4:28pm UTC](https://boards.straightdope.com/t/has-anyone-else-been-getting-this-type-of-suspicious-email/849737/11 "2020-03-19T16:28:42Z")

</div>

> [@](#):
>
> I’ve got a number of these recently that make me irritated that my wife bought something…but it turns out she didn’t. If you look at the bottom of the email, does it take you to a [t.fubrites.com](http://t.fubrites.com) site to unsubscribe. Is the sending address [newsletter@fubrites.com](mailto:newsletter@fubrites.com)?  
> If so, thats the same as what I’ve gotten several times. The email says things like:  
> Amazon Order #105-1286891-641874 wiII be Placed in 2 hours.  
> Congratulations: Walgreens Order #18482012197 is arriving  
> Your Order at [www.kroger.com](http://www.kroger.com) was successful.
> 
> All point back to fubrites…I don’t know who this group is but its time to block them

THis is my response from the other thread…it seems more appropriate here.

---

<div class="post-metadata">

**Author:** ![Slash1972](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/slash1972/32/6461_2.png) [@Slash1972](https://boards.straightdope.com/u/Slash1972)\
**Post date:** [March 19, 2020, 4:53pm UTC](https://boards.straightdope.com/t/has-anyone-else-been-getting-this-type-of-suspicious-email/849737/12 "2020-03-19T16:53:12Z")

</div>

> [@beowulff](#):
>
> OK, I get that - if you are running some ancient unpatched system, that could be a (very theoretical) problem.  
> But, in that case, wouldn’t an in-line image be just as bad? Does **manson’s** office have their email client set to not render in-line images? How crippled can you make it and still be useful? I request photos from clients all the time -it’s a necessary part of me doing my job.  
> Seems like an enormous overreaction to me.
> 
> ETA: I’m running OS X, so I’m not concerned about looking at attachments (there are no known exploits currently), so I will often times open up attachments like that to see wha they are, and 100% of the time they are spam selling Viagra or Cialis.

If you request the files, and you know them, then yes, that’s okay.

Also, my work has html format emails turned on, even though they know the risks. Not my decision.

---

<div class="post-metadata">

**Author:** ![Just\_Asking\_Questions](https://avatars.discourse-cdn.com/v4/letter/j/ba9def/32.png) [@Just\_Asking\_Questions](https://boards.straightdope.com/u/Just_Asking_Questions)\
**Post date:** [March 19, 2020, 4:56pm UTC](https://boards.straightdope.com/t/has-anyone-else-been-getting-this-type-of-suspicious-email/849737/13 "2020-03-19T16:56:05Z")

</div>

It’s the links I’d worry about. Got an email talking about “my order” and it had a pdf image that was supposed to be a copy of my invoice. Hovering over it showed it to be an executable file. No one should be clicking anything on their emails without at least hovering.

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [March 19, 2020, 5:32pm UTC](https://boards.straightdope.com/t/has-anyone-else-been-getting-this-type-of-suspicious-email/849737/14 "2020-03-19T17:32:30Z")

</div>

> [@beowulff](#):
>
> OK, I get that - if you are running some ancient unpatched system, that could be a (very theoretical) problem.  
> But, in that case, wouldn’t an in-line image be just as bad? Does **manson’s** office have their email client set to not render in-line images? How crippled can you make it and still be useful? I request photos from clients all the time -it’s a necessary part of me doing my job.  
> Seems like an enormous overreaction to me.
> 
> ETA: I’m running OS X, so I’m not concerned about looking at attachments (there are no known exploits currently), so I will often times open up attachments like that to see wha they are, and 100% of the time they are spam selling Viagra or Cialis.

1. “Ancient”? What? Holes are found in _current_ systems all the time. There is _no way_ to know if there is currently a exploit-to-be in a brand new system with the latest software. If you think OS X is magic, you are really out of touch. And with phones, many people are finding out that the manufacturer stops doing updates, including security patches in 2 years (and some even less). I’d hardly call that “ancient”.

2. Right, the difference between an attached image and a hyperlink to an image in an email is important. With the latter, and depending on your email software and it’s settings, if you look at the email, the image could be downloaded. The filename may be unique to your email so they now know you looked at the email and they use/sell your email to other spammers. There’s some special tricks used to track people via email to really build up a lot of knowledge about the user.

With a purely attached (MIME encoded) image, no such problem. As long as that is what it really is. (MS, in it’s infinite wisdom likes to hide extensions by default. And even if you have that turned “off”, it still tries to hide certain ones, esp. .url extensions. So something that looks like “mom.jpg” might really be “mom.jpg.url” and you don’t want to touch that with a 200 meter pole. And MS is not alone in doing stupid stuff like this.) Most users aren’t sophisticated enough to understand and detect such nuances.
