Skip to content

Fake 'abuse department' emails look real now

General Discussion by uma 6 replies 359 views
11 #1

Got an email this morning claiming to be from my host's abuse team. Exact template match, same footer, same ticket formatting. Nearly clicked the "resolve dispute" link until I checked the graphs. : my status page showed zero alerts, no abuse flags, nothing on the monitoring dashboard. Checked headers. Return-Path was off by one character. But the scary part: they referenced an actual ticket ID I opened six months ago. That ticket was with a different provider, Hostinger, which had a breach last spring. Has anyone else seen these? The visual fidelity is way beyond the old grammar-mess scams.

436 days. reboot is surrender.
2 #2

Oh my. The young people think their cloud nonsense makes them safe. But the templates. The templates travel so far these days. I remember when a fake email had broken images and wrong fonts. Now they scrape your history. Your old tickets. Your fears. Three dots used to mean hesitation. Now they mean the scammers have learned patience. Check your SPF records too. They forge those now. Not just the pretty html...

#3

How do I check the headers? I got one of these last week and I just deleted it. Should I be worried? I use OVHcloud for my shop site and I dont want to break anything by clicking wrong. 😬

frames, tables, still valid HTML
#4
wilmaethqn44 said:
How do I check the headers?

In most mail clients, "View Source" or "Show Original" reveals the full header block. Look for Received: lines, which build bottom-to-top. The first Received (nearest your server) and Return-Path are most telling. SPF, DKIM, and DMARC results often appear in Authentication-Results headers.

The ticket ID correlation suggests either a breach correlation database or, more likely, the Hostinger incident exposed email-to-ticket mappings that attackers now cross-reference against provider templates. This is not header forgery per se but reconnaissance augmentation.

RPKI for email when?

iBGP, eBGP, don't care, just peer
#5

Return-Path off by ONE char? That's the least scary part honestly

#6

Which mail client, and what version

#7

I had the same thing with a fake invoice last month

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft