# They spammed the wrong guy....

**URL:** <https://boards.straightdope.com/t/they-spammed-the-wrong-guy/233586>\
**Category:** The BBQ Pit\
**Created:** [March 11, 2004, 12:43am UTC](https://boards.straightdope.com/t/they-spammed-the-wrong-guy/233586 "2004-03-11T00:43:45Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![MacTech](https://avatars.discourse-cdn.com/v4/letter/m/c0e974/32.png) [@MacTech](https://boards.straightdope.com/u/MacTech)\
**Post date:** [March 11, 2004, 12:43am UTC](https://boards.straightdope.com/t/they-spammed-the-wrong-guy/233586/1 "2004-03-11T00:43:45Z")

</div>

I just recieved one of those “someone stole your credit card/card number” spams this evening, i knew it was a fake right away, after all, since when does Visa use a Netcom/Earthlink ISP?, stupid, stupid spammer, you don’t want to cross me…

so, after i got a good laugh out of the e-mail, i forwarded a copy to Earthlink’s abuse department, _AND_ the Visa credit card company :evil:, hopefully both companies will come down on the spammer like a ton of bricks (or something equally heavy and unpleasant)

in case anyone doesn’t know, here’s how to determine a fraudulent e-mail…

> [@](#):
>
> From: Visa Service \<[security@visa-security.com](mailto:security@visa-security.com)\>  
> Subject; Visa Security Update  
> Reply-to:Visa Service \<[security@visa-security.com](mailto:security@visa-security.com)\>  
> Return-path; \<[kkf7n6@yahoo.com](mailto:kkf7n6@yahoo.com)\>  
> Recieved; from [postoffice.nospam.com](http://postoffice.nospam.com) ([unix socket]) by [postoffice.nospam.com](http://postoffice.nospam.com) (Cyrus v2.1.13) with LMTP; Wed, 10 Mar 2004 18:42:46 -0500  
> Recieved:from 24.238.156.76 ([user-0cet72c.cable.mindspring.com](http://user-0cet72c.cable.mindspring.com) [24.238.156.76]) by [postoffice.nospam.com](http://postoffice.nospam.com) (Postfix) with SMTP id DA887A77462 for \<[MacTech@nospam.com](mailto:MacTech@nospam.com)\>; Wed, 10 Mar 2004 18:42:44 -0500 (EST)
> 
> Dear Sir/Madam,
> 
> We were informed that your card is used by another person or stolen. It could happen if you have been shopping on-line, and someone got your “Billing information” including your card number. To avoid and prevent any billing mistakes and to refund your credit card, it is strongly recommended to proceed filling in the secure form on our site and applying for our Zero Liability program. This program is free and it will help us to investigate this accident.  
> Sincerely yours, Visa Support Assistant, Alwin Desagun.

look at the Return path and second recieved line, the spammer appears to be using a Yahoo e-mail address and is sending it from the Mindspring (Earthlink) servers, somehow i don’t think the monolithic Visa corporation is using a Yahoo account thru Netcom…

stupid spammer, hope they get shut down and sued

screw you, spammer!

---

<div class="post-metadata">

**Author:** ![Leaper](https://avatars.discourse-cdn.com/v4/letter/l/4bbf92/32.png) [@Leaper](https://boards.straightdope.com/u/Leaper)\
**Post date:** [March 11, 2004, 1:57am UTC](https://boards.straightdope.com/t/they-spammed-the-wrong-guy/233586/2 "2004-03-11T01:57:58Z")

</div>

What REALLY irritates me about spam (and partly because I’m a stickler for such things due to my education and chosen occupation) is the poor technical quality - the misspellings and typos. What’s sadder is that people seem to either ignore it or believe it to be right (or, worse yet, believe that _everyone_, even corporate workers whose words reflect directly on the company, are as poor writers as they).

---

<div class="post-metadata">

**Author:** ![Ale](https://avatars.discourse-cdn.com/v4/letter/a/f19dbf/32.png) [@Ale](https://boards.straightdope.com/u/Ale)\
**Post date:** [March 11, 2004, 3:10am UTC](https://boards.straightdope.com/t/they-spammed-the-wrong-guy/233586/3 "2004-03-11T03:10:48Z")

</div>

Alwin Desagun? huh? 😕

I give him some points in creativity (or drunkness) for that.

---

<div class="post-metadata">

**Author:** ![jackelope](https://avatars.discourse-cdn.com/v4/letter/j/a6a055/32.png) [@jackelope](https://boards.straightdope.com/u/jackelope)\
**Post date:** [March 11, 2004, 3:44am UTC](https://boards.straightdope.com/t/they-spammed-the-wrong-guy/233586/4 "2004-03-11T03:44:03Z")

</div>

I got spam on my fucking _cell phone_ recently. It was a text message about “I buy homes in the Memphis area” or something, with a hotmail e-mail address. This guy had also been using a message board where I’m an admin to attempt to lure clients to his site until we banned him.

So I went and opened up a Yahoo account, and I wrote a letter to the hotmail address, telling him that he’d done this to me three times (true) and to many of my friends as well (also true) and that if he did it again, here’s what I’d do (extremely fucking true):

I’d send him a polite e-mail and say “Your ideas intrigue me; how can I subscribe to your newsletter?” or something. Then I’d meet him and talk business for a while. I’d get his business card, presumably with a phone, address, and e-mail on it.

Then I’d give that information out to every fucking advertiser I could find. I’d post the e-mail (in a hidden spot) on the very, very busy Web site that employs me, so the spam robots would find it. I’d call every church and charity I could find and leave a message with his name and “I’m interested, please call me.” I’d call up every direct marketing outfit I could find and give them his address. I’d do everything I could to ensure that his phone would ring incessantly, his inbox would blow a fuse, and his postal carrier would need a goddam pack-horse to bring him his mail.

It was a lot of work to get rid of one spammer, but (a) it was for me a symbolic fuck-you to all spammers, and (b) _damn_, that was cathartic.

And no, I haven’t heard back from him.

---

<div class="post-metadata">

**Author:** ![Richard\_Pearse](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/richard_pearse/32/13144_2.png) [@Richard\_Pearse](https://boards.straightdope.com/u/Richard_Pearse)\
**Post date:** [March 11, 2004, 5:00am UTC](https://boards.straightdope.com/t/they-spammed-the-wrong-guy/233586/5 "2004-03-11T05:00:24Z")

</div>

We’ve been getting a lot of spam lately claiming to be from a bank (occassionally it is your own bank). The general gist of the message is that there have been security problems and they need you to go to their website (linked) and enter your username and password for internet banking.

You go to the website and it looks identical to the banks own website. All of the links go to the banks real website. The only hint is that the address will be slightly odd (eg www.westpac1.com.au rather than www.westpac.com.au).

The most recent ones have even had a heap of “beware of scams” content in the body!

It is not hard to see how people can be fooled by these.

---

<div class="post-metadata">

**Author:** ![htns](https://avatars.discourse-cdn.com/v4/letter/h/ba8739/32.png) [@htns](https://boards.straightdope.com/u/htns)\
**Post date:** [March 11, 2004, 5:01am UTC](https://boards.straightdope.com/t/they-spammed-the-wrong-guy/233586/6 "2004-03-11T05:01:52Z")

</div>

I once got a spam with the following subject line:

HOT TEEN LESBIANS WANNA CHOKE ON YOUR COCK!!!

Uhm…something a bit off kilter with that, or is it just me?

---

<div class="post-metadata">

**Author:** ![gotpasswords](https://avatars.discourse-cdn.com/v4/letter/g/c57346/32.png) [@gotpasswords](https://boards.straightdope.com/u/gotpasswords)\
**Post date:** [March 11, 2004, 6:49am UTC](https://boards.straightdope.com/t/they-spammed-the-wrong-guy/233586/7 "2004-03-11T06:49:04Z")

</div>

At least that Visa phish was, by the usual standards, very well-written.

An alert crossed my desk today that our customers are also being phished:

> [@Some lame scumball](#):
>
> Dear \<bank\> valued customer!
> 
> Please read this important message about security. We are working very hard to protect our customers against fraud. Your account has been randomly chosen for verification. This is requested to us to verify that you are the real owner of this account. All you need to do is to click on the link below. You will see a verification page. Please complete all fields that you will see and submit the form. You will be redirected to \<bank\> home page after verification. Please note that if you don’t verify your ownership of account in 24 hours we will block it to protect your money. Thank you. http://www.\<bank\>.com/verify/

For anyone that looked at the source code of the message, they’d really see a sly redirect to an IP address that’s not associated with us.

At least this slime got one thing right. My associates and I are working very hard to protect our customers against fraud. 🆒

---

<div class="post-metadata">

**Author:** ![Richard\_Pearse](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/richard_pearse/32/13144_2.png) [@Richard\_Pearse](https://boards.straightdope.com/u/Richard_Pearse)\
**Post date:** [March 11, 2004, 8:49am UTC](https://boards.straightdope.com/t/they-spammed-the-wrong-guy/233586/8 "2004-03-11T08:49:20Z")

</div>

The most recent one that came this way was very well written and contained such gems as (bolding added by me for emphasis, name of bank removed to protect the innocent):

> [@](#):
>
> Financial institutions around the world have always been subject to attempts by criminals to try and defraud money from them and their customers. These attempts can occur in a number of ways (eg credit card fraud, telephone banking or **Internet scams** ).
> 
> As a part of our ongoing commitment to provide the “Best Possible” service to all our Members, we are now requiring each Member to validate their accounts once per month.
> 
> To validate your personal [bank] online banking account follow the link below: [link]

And, it gets better:

> [@](#):
>
> Two examples of common Internet scams include:
> 
> **Attempting to steal a customer’s login details by sending out emails which appear to be from a financial institution, and requesting personal details (eg Customer number and password)**
> 
> Creating a website, which looks similar to a financial institution’s, but acts as a ‘ghost website’ capturing customer details and using them to transact on the customer’s account [bank] views all matters of security as serious.
> 
> Following are a number of quick and easy methods to help you protect your details online.
> 
> Check you are connected to a legitimate [bank] website  
> **Check your email has come from [bank]**  
> Protect your financial records  
> Protect your computer  
> Keep your password safe  
> Guard your privacy

There’s a lot more, it’s quite well done. I just showed it to my wife and other than being slightly confused by getting an email from a bank that we don’t use, she thought it was legitimate and said that she would have followed the instructions and “verified” her account details if she was a customer with this bank.

---

<div class="post-metadata">

**Author:** ![DeadlyAccurate](https://avatars.discourse-cdn.com/v4/letter/d/ac91a4/32.png) [@DeadlyAccurate](https://boards.straightdope.com/u/DeadlyAccurate)\
**Post date:** [March 11, 2004, 2:51pm UTC](https://boards.straightdope.com/t/they-spammed-the-wrong-guy/233586/9 "2004-03-11T14:51:05Z")

</div>

> [@jackelope](#):
>
> I got spam on my fucking _cell phone_ recently. It was a text message about “I buy homes in the Memphis area” or something, with a hotmail e-mail address. This guy had also been using a message board where I’m an admin to attempt to lure clients to his site until we banned him.
> 
> So I went and opened up a Yahoo account, and I wrote a letter to the hotmail address, telling him that he’d done this to me three times (true) and to many of my friends as well (also true) and that if he did it again, here’s what I’d do (extremely fucking true):
> 
> I’d send him a polite e-mail and say “Your ideas intrigue me; how can I subscribe to your newsletter?” or something. Then I’d meet him and talk business for a while. I’d get his business card, presumably with a phone, address, and e-mail on it.
> 
> Then I’d give that information out to every fucking advertiser I could find. I’d post the e-mail (in a hidden spot) on the very, very busy Web site that employs me, so the spam robots would find it. I’d call every church and charity I could find and leave a message with his name and “I’m interested, please call me.” I’d call up every direct marketing outfit I could find and give them his address. I’d do everything I could to ensure that his phone would ring incessantly, his inbox would blow a fuse, and his postal carrier would need a goddam pack-horse to bring him his mail.
> 
> It was a lot of work to get rid of one spammer, but (a) it was for me a symbolic fuck-you to all spammers, and (b) _damn_, that was cathartic.
> 
> And no, I haven’t heard back from him.

That was terrific! What’s great is that he (I assume) doesn’t know which of the people he spammed is going to do that, so any person he spams in this manner increases his risk of this reprisal.

---

<div class="post-metadata">

**Author:** ![KidCharlemagne](https://avatars.discourse-cdn.com/v4/letter/k/ed8c4c/32.png) [@KidCharlemagne](https://boards.straightdope.com/u/KidCharlemagne)\
**Post date:** [March 11, 2004, 4:06pm UTC](https://boards.straightdope.com/t/they-spammed-the-wrong-guy/233586/10 "2004-03-11T16:06:53Z")

</div>

> [@htns](#):
>
> I once got a spam with the following subject line:
> 
> HOT TEEN LESBIANS WANNA CHOKE ON YOUR COCK!!!
> 
> Uhm…something a bit off kilter with that, or is it just me?

HOLE-LESS WOMAN WANTS IT IN EVERY WHOLE!

---

<div class="post-metadata">

**Author:** ![5que](https://avatars.discourse-cdn.com/v4/letter/5/3bc359/32.png) [@5que](https://boards.straightdope.com/u/5que)\
**Post date:** [March 11, 2004, 9:00pm UTC](https://boards.straightdope.com/t/they-spammed-the-wrong-guy/233586/11 "2004-03-11T21:00:42Z")

</div>

> [@htns](#):
>
> I once got a spam with the following subject line:  
> HOT TEEN LESBIANS WANNA CHOKE ON YOUR COCK!!!  
> Uhm…something a bit off kilter with that, or is it just me?

I’m still trying to figure out why they think I need a bigger cock _AND_ bigger breasts…

Although the farm animal messages have started to level off.

---

<div class="post-metadata">

**Author:** ![Shodan](https://avatars.discourse-cdn.com/v4/letter/s/9f8e36/32.png) [@Shodan](https://boards.straightdope.com/u/Shodan)\
**Post date:** [March 11, 2004, 9:53pm UTC](https://boards.straightdope.com/t/they-spammed-the-wrong-guy/233586/12 "2004-03-11T21:53:27Z")

</div>

> [@htns](#):
>
> I once got a spam with the following subject line:  
> HOT TEEN LESBIANS WANNA CHOKE ON YOUR COCK!!!  
> Uhm…something a bit off kilter with that, or is it just me?

No, you are right.

They probably aren’t **real** teens.

Regards,  
Shodan

---

<div class="post-metadata">

**Author:** ![Frank](https://avatars.discourse-cdn.com/v4/letter/f/3d9bf3/32.png) [@Frank](https://boards.straightdope.com/u/Frank)\
**Post date:** [March 11, 2004, 10:07pm UTC](https://boards.straightdope.com/t/they-spammed-the-wrong-guy/233586/13 "2004-03-11T22:07:10Z")

</div>

[QUOTE=htns]  
HOT TEEN LESBIANS WANNA CHOKE ON YOUR COCK!!!  
QUOTE]  
Your ideas intrigue me; how can I subscribe to your newsletter?

I got one just yesterday claiming to be from MSN billing. It was quite well done, only one grammatical and NO spelling errors. However, since I cancelled my MSN account a couple months ago, I’m only going to be pleased that they’re having trouble processing my credit card! It was a nice try, though.

---

<div class="post-metadata">

**Author:** ![jackelope](https://avatars.discourse-cdn.com/v4/letter/j/a6a055/32.png) [@jackelope](https://boards.straightdope.com/u/jackelope)\
**Post date:** [March 11, 2004, 11:44pm UTC](https://boards.straightdope.com/t/they-spammed-the-wrong-guy/233586/14 "2004-03-11T23:44:19Z")

</div>

> [@DeadlyAccurate](#):
>
> That was terrific! What’s great is that he (I assume) doesn’t know which of the people he spammed is going to do that, so any person he spams in this manner increases his risk of this reprisal.

Exactly. As far as he knows, it came from a Mr. John Doe, and I got unknown\_memphian at yahoo as the address. I wonder if he’s stopped yet.

The only way he might be able to find out who it was is if he uses a bunch of different hotmail addresses, so that an e-mail to one of them will indicate what cell phone he texted it to. But that seems unlikely; the guy’s really pretty amateur as far as spammers go.

---

<div class="post-metadata">

**Author:** ![Manduck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/manduck/32/256_2.png) [@Manduck](https://boards.straightdope.com/u/Manduck)\
**Post date:** [March 12, 2004, 3:40am UTC](https://boards.straightdope.com/t/they-spammed-the-wrong-guy/233586/15 "2004-03-12T03:40:36Z")

</div>

> [@Leaper](#):
>
> What REALLY irritates me about spam (and partly because I’m a stickler for such things due to my education and chosen occupation) is the poor technical quality - the misspellings and typos.

Those are mostly deliberate. The spammers are trying to dodge keyword filters by using novel spellings.

---

<div class="post-metadata">

**Author:** ![Chairman\_Pow](https://avatars.discourse-cdn.com/v4/letter/c/838e76/32.png) [@Chairman\_Pow](https://boards.straightdope.com/u/Chairman_Pow)\
**Post date:** [March 12, 2004, 3:41am UTC](https://boards.straightdope.com/t/they-spammed-the-wrong-guy/233586/16 "2004-03-12T03:41:13Z")

</div>

> [@jackelope](#):
>
> The only way he might be able to find out who it was is if he uses a bunch of different hotmail addresses, so that an e-mail to one of them will indicate what cell phone he texted it to. But that seems unlikely; the guy’s really pretty amateur as far as spammers go.

I figured that’s why they use the “type the word in the box” graphic, so any auto-registration programs would be fooled. I’d imagine they instituted this precisely because of people doing that. I presume that it’s not too much trouble once one sets up the auto-registration program.

---

<div class="post-metadata">

**Author:** ![Thaumaturge](https://avatars.discourse-cdn.com/v4/letter/t/858c86/32.png) [@Thaumaturge](https://boards.straightdope.com/u/Thaumaturge)\
**Post date:** [March 12, 2004, 4:02am UTC](https://boards.straightdope.com/t/they-spammed-the-wrong-guy/233586/17 "2004-03-12T04:02:50Z")

</div>

The random letters to get past the spam detectors is self defeating. Seeing a message with the letters ‘akjhahdfajkhra’ randomly added into the title frees me from even having to think about whether or not the message is spam. It’s like putting a hole in the bottom of your fishing boat to fish better. Sure the fish get in the boat easier, but then you sink. Similarly, the message gets past the filters easier, but it goes nowhere fast.

Surely there can’t be people out there who actually open messages with random gobblygook in the title?! right? say it aint so, my faith in humanity rests on it!
