Remember: Yahoo!will NEVER send out emails asking for your password or account details
February 16th, 2010 Filed in: General, Hints & Tips, Security Add comment
This is not the first post we’ve written about online account security and I am sure it won’t be the last one either… Unfortunately, this subject matter keeps coming back to us as one of our top drivers in customer feedback.
I will try to provide more practical info about online scams here. In return, please, please, please be sure to share this post with everyone you consider at risk of falling victim to one of the many scams around. And there are so many people at risk… According to the NSW Fair Trading website “every year 1 in 20 Aussies fall victim to scams.”
“Scams target everyone regardless of background, age and income and they come in many forms and reach you in many ways – by mail, online through e-mail, telephone and door-to-door. Scams are often designed to trick you into giving away your money or your personal details. Scams succeed because they look like the real thing. Scammers are manipulative – they push the right buttons to produce the response they want.”
The Australian Competition and Consumer Commission run the SCAMwatch website, which provides information to consumers and small businesses about how to recognise, avoid and report scams. One common type of online scam is called ‘requests for your account information’ or ‘phishing scams’.
“Phishing refers to emails that trick people into giving out their personal and banking information; they can also be sent by SMS. These messages seem to come from legitimate businesses, normally banks or other financial institutions or telecommunications providers. The scammers are generally trying to get information like your bank account numbers, passwords and credit card numbers, which they will then use to steal your money. Phishing emails often look genuine and use what look to be genuine internet addresses—in fact, they often copy an institution’s logo and message format, which is very easy to do. It is also common for phishing messages to contain links to websites that are convincing fakes of real companies’ home pages. The website that the scammer’s email links to will have an address (URL) that is similar to but not the same as a real bank’s or financial institution’s site. For example, if the genuine site is at ‘www.realbank.com.au’, the scammer may use an address like ‘www.realbank.com.au.log107.biz’ or ‘www.phoneybank.com/realbank.com.au/login’.”
The following information was extracted from the SCAMWatch site:
Warning signs
- You receive an email or SMS claiming to be from a financial institution, telecommunication or email provider. This message may seem to be from your bank, service or email provider or a business you don’t have an account with. The email contains a link that leads you to a website where you are prompted to enter your bank account details or email account details.
- The email does not address you by your proper name.
- The email might contain typing errors and grammatical mistakes.
- The email might claim that your details are needed for a security and maintenance upgrade, to ‘verify’ your account or to protect you from a fraud threat. The email might even state that you are due to receive a refund for a bill or other fee that it claims you have been charged.
Protect yourself from phishing scams
- NEVER send money or give credit card or online account details to anyone you do not know and trust.
- Do not give out your personal, credit card or online account details over the phone unless you made the call and know that the phone number came from a trusted source.
- Do not open suspicious or unsolicited emails (spam)—ignore them. You can report spam to Australian Communications and Media Authority. If you do not wish to report the message, delete it.
- Do not click on any links in a spam email or open any files attached to them.
- Never call a telephone number that you see in a spam email or SMS.
- If you want to access an internet account website, use a bookmarked link or type the address in yourself—NEVER follow a link in an email.
- Check the website address carefully. Scammers often set up fake websites with very similar addresses.
- Never enter your personal, credit card or online account information on a website if you are not certain it is genuine.
- Never send your personal, credit card or online account details through an email.
As well as following these specific tips, find out how to protect yourself from all sorts of other scams. Download our Phishing scams fact sheet for more information.
Do your homework
If you receive an email claiming to be from a bank, other financial institution, telecommunications or email provider that asks you to enter your details—delete it! A legitimate bank or financial institution will NEVER send an email like this.
If the email appears to be from your bank or financial institution and you think it might be genuine, telephone your bank or financial institution to let them know about the email and ask their advice. DO NOT call any telephone number listed in the email; instead, use a phone number that appears on your bank statement or card or in the telephone directory. Many banks and financial institutions now have specialised internet security staff that can help you.
Decide
You should NEVER give your personal or bank account details to people you don’t know and trust. Don’t be fooled by an email that looks legitimate or appears to link to a genuine website. If you think the email may be genuine, ALWAYS contact your bank to confirm an email’s legitimacy before replying. Your best defence is to delete the email straight away.
For me, this paragraph summarises everything:
“My top advice is to be mindful of any Web page that requests your Yahoo! password. The #1 way people get their passwords stolen is by typing them into lookalike “phishing” web sites, pages that pretend to be Yahoo! or another trusted Web site but actually are run by the bad guys. Scrutinise carefully any page that requests your Yahoo! password.” – Mark Risher, Director of Product Management for Mail.
For more tips and information on how to keep yourself and your computer safe online, check this post on our Yahoo!7 Answers Blog.
If you’ve reached this post and you’ve already fallen victim to a phishing scam with your Yahoo!7 Mail account, read this post to find out what to do next.
Finally, please report any suspicious emails to Yahoo!7 Customer Care via this form.
Cheers,
Tasla – Yahoo!7 Mail Team


(10 votes, average: 3.70 out of 5)
Subscribe to the blog!
Leave a Comment
Some HTML allowed:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>
Trackback this post | Subscribe to the comments via RSS Feed