i-tunes phishing scam
Posted by: rodwsmith on 24 March 2010
I received an e-mail (series) that I think may be part of some ubër-elaborate phishing scam.
Although it might be genuine (that's how good it is). Takes the form of a receipt for a purchase (£0.99) that had nothing to do with me.
All looks very authentic, but has a 'report problem' link. Which I clicked. (I really don;t use the i-tunes store often enough to know whether these slick-looking e-mails are the real deal or not.
I am now in a dialogue with someone from i-tunes and it is beginning to sound just a bit fishy.
They're telling me the only way to get my money back is via my bank (which seems odd), and giving me the opportunity to change my password (sensible advice I am sure) but via a link in the e-mail, to:
http://iforgot.apple.com Which also looks genuine but seems odd.
I WILL change my i-tunes password (I don't have it on my computer at work), but this did actually prompt me to check and I haven't in fact been debited £0.99 from any of my accounts/cards.
Is this an established scam? Anyone else had it?
Rod
Posted on: 24 March 2010 by rodwsmith
This really doesn't ring true, does it?
_______________________________________________
Follow-Up: 100224291
Hello Rod,
It's Deborah with the iTunes Store. This is just a courtesy follow-up to your previous issue regarding the unauthorized activity on your account. My mother went through a similar experience with some questionable activity on her credit card , so I can certainly appreciate what you're going through and I wish you the best.
Again, I just wanted to let you know I'm only an email away and if you have any further questions or if I can be of any assistance, just let me know.
You're truly a valued asset to the iTunes Store Family, and as such, I don't want to leave you without any type of resolution.
I wish you the best in resolving this issue.
Have a great week!
Sincerely,
Deborah
iTunes Store Customer Support
Charlotte, NC
Tues- Sat 8:00AM-4.30P
_______________________________________________
Posted on: 24 March 2010 by David Scott
I think the password change link is genuine. I navigated to it from the a home page of the apple site and it's the same url.
But apart from this I think this is bollocks. The email you were sent seems odd to me. The bit about her mum sounds like a con. I don't think apple would ask for your bank details in and email and in any case you probably have a card associated with your itunes account so they could just credit that.
I wouldn't touch this and I probably wouldn't use their link to change my password just in case.
Posted on: 24 March 2010 by Sloop John B
Well I certainly never got service like that from Itunes
SJBPosted on: 24 March 2010 by Exiled Highlander
Rod
Hopefully you haven't changed your password using the link in the email...if you have you may find a reduced bank balance by now!
Only change passwords at the official site and never through links in emails would be my advice.
You should also send this Apple Security via links on the iTunes site I would have though and have them check it out.
Regards
Jim
Posted on: 24 March 2010 by rodwsmith
Well it turns out it is actually a fraud. Someone has got into my i-tunes and bought some song from the "Cast of Glee". I suspect this is very embarrassing. What I cannot understand is how they managed actually to download the music, (or indeed why they wanted to).
It's exceptionally unlikely but they may have been able to get my card details which were recorded on the site, so I have cancelled that. On i-tunes' advice I have actually removed payment details which I imagine means anything I do actually try and download (which I don't) will prompt me to input a payment method, and I've changed my password (obviously not a website per se, but only accessible once you have downloaded i-tunes).
First Direct, bless 'em, are going to give me back my 99p (which debited this afternoon), although I said I really didn't mind, just wanted to make sure it wasn't the thin end of a rip-off wedge.
Weird, but I still think Deborah's pally-pally e-mail sounds a bit non-Appley.
Thanks for the advice all. I would never change a log-in/password from a link in an e-mail.
Posted on: 24 March 2010 by David Scott
Do you have children? Or multiple personality disorder?