DiscoverCard users hit with e-mail scam
Computerworld -
Users of Discover Financial Services Inc.'s DiscoverCard were targeted by an e-mail scam this week designed to trick them into giving out their personal information, including user identifications, account numbers, passwords, Social Security numbers, mothers' maiden names, card numbers and expiration dates.
But this scam differed from the e-mail scams that have targeted users of companies such as PayPal Inc., eBay Inc. and Yahoo Inc.
Yesterday, a reader e-mailed Computerworld saying she had received a suspicious-looking HTML e-mail that purported to be from DiscoverCard.
The e-mail, which actually came from someone whose e-mail address was secure19@warshawsales.com said: "Due to your inactivity your account has been put On Hold. To remove this status you have to Log In to your account and review Discover Privacy Policy."
Usually, scam artists set up a spoof Web site to try and trick users into providing their personal information. Spoofed sites look official and generally mimic a company's actual site.
But whoever sent out the bogus e-mail linked directly to content on DiscoverCard's actual Web site and wrapped the form seeking users' information in a hidden submission. That redirected the information to an e-mail address at warshawsales.com, according to Russ Cooper, a security consultant at TruSecure Corp. in Herndon, Va. Cooper said Discover is one of TruSecure's clients.
By setting up the scam that way, the contents of the form -- a user's personal information -- went to the scammer and weren't submitted to the DiscoverCard site. "I've never seen this done before," Cooper said.
The Warshaw Sales domain name was registered with Mountain View, Calif.-based domain name registrar Verisign Inc. on March 10 and taken down on March 13 at the request of the registrant, a wholesaler that sells domain names to other parties, according to Verisign spokesman Pat Burns.
The domain was originally hosted by Fort Lauderdale, Fla.-based Web hosting company, Affinity Internet Inc. Affinity spokeswoman Michelle Van Jura said the company was made aware of the Warshaw Sales site and shut it down early March 12.
Cooper said he tracked the Warshaw Sales e-mail to IP addresses in Newfoundland and Ontario.
Cathy Edwards, a spokeswoman for Riverwoods, Ill.-based Discover, confirmed that the e-mail was a scam. Edwards said Discover is aware of the situation and is taking steps to combat it, although she wouldn't go into detail for security reasons.
"Discover has now modified the graphics that were being linked to in the e-mail so that now when you view the Web page, what you see is a big flashing yellow 'Alert'and the words 'Fraudulent e-mail call 1-800-DISCOVER,' and the two buttons that used to say 'Log In' and 'Password Reset' now say 'Fraud' and 'Don't Click,'" TruSecure's Cooper said.
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
How Controlling Access to Privileged Accounts Can Keep Insider Threat from Hurting Your Bottom Line
This white paper explores insider attacks and insider risk, and shows how to control them by controlling and monitoring access. The paper describes...
How to Reduce Eclipse BIRT Development Effort for Data Visualizations
Web applications can come with a long list of visualization requirements for structured data. By delivering your output through the BIRT Interactive Viewer,...
Eliminate Spam, Gain Productivity
In this exclusive whitepaper, learn all about the dangers of spam and the cost to your business....
Accelerating Your Mobile Workers: Controlling the Uncontrollable
Today's workforce is truly mobile. Unlike the managed environment of the office LAN, remote users face many challenges to being productive while out...
Best Practices in Lifecycle Management: Comparing KACE, Altiris, LANDesk, and Microsoft SCCM
Learn key best practices in lifecycle management....
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...
IBM Systems Consolidation Evaluation Tool
Just enter your unique IT server and storage environment data into the IBM Systems Consolidation Evaluation Tool and get product recommendations along with...
Best Practices for Model-based Systems Engineering
Based on a small set of key principles and practices from the IBM®Rational® Harmony library of best practices, the Harmony for Systems Engineering...
IBM BladeCenter HS22 Blade Server
Introducing the new generation IBM BladeCenter® HS22 blade server featuring the blazing fast Intel® Xeon® Processor 5500 Series and the revolutionary new IBM...
Systems and Software Product Line Engineering with SysML, UML and the Rhapsody/Gears Bridge
One of the great challenges and opportunities in systems and software delivery today is Product Line Engineering - creating, evolving and maintaining a...
Subscribe to Computerworld


