728_header.jpg (23748 bytes)
Google  Web AuctionBytes  

Home
Subscribe
Blog
Podcasts
Forums
AuctionBytes TV
ABU Back Issues

Sponsor

COOL TOOLS

Calendar
eBay Fee Calculator
Collectors' Links
eBay Promo History
Bookshelf
Fraud Resources
Auction Site Fees
Auction Management
Payment Services
Storefronts Chart
Sniping Chart
Email List Hosting
Consignment Services
Drop-Off Store Laws
Ecommerce Resources
Photo Tips
Marketing Inserts
Yellow Pages
Classifieds

AUCTIONBYTES

Our Writers
Write For Us
Partners
Press
Advertising
About Us
Link To Us

Auctionbytes-NewsFlash, Number 1496 - March 16, 2007 - ISSN 1539-5065      | Next Story

Scammers Use eBay's Message System to Troll for Victims
By Ina Steiner
AuctionBytes.com
March 16, 2007
AddThis Social Bookmark Button

When an eBay seller opened an email received through eBay's message system this week, it read, "If you need additional income, we have an open position as a mediator for selling items on ebay. To learn more, open www.tradeportal1.org and enter (Code removed by editor) on prompt." The purported shopper who sent the email to the seller using eBay's "Ask Seller a Question" feature had zero feedback and had registered on eBay the same day the email message was sent.

The recipient, a concerned eBay seller, reported the suspicious email to eBay when she received the email on March 14. A search for tradeportal1.org on a search engine came up with a post on an anti-scam forum from someone who said they had reported a similar email - also linking to the site TradePortal1.org - to eBay on March 9. A WhoIs search on the domain "tradeportal1.org" reveals it was registered on February 13, 2007, using a domain registration company that lets resellers register a .ORG domain for just 99 cents.

What concerned the recipient most was that her name appeared in the message, and that the message showed up in her "My Messages" section of eBay, proving the sender used eBay's mail system. She felt this gave the email an air of legitimacy, and she said she was sure she was not the only one to receive the email. "You KNOW that newbies may (will) click that link and who knows what will happen."

The technique described above uses eBay's message system. Another technique seen this week on eBay uses an "Ask Seller a Question" form inside listings that are not actually going through eBay's message system at all, and harvests users' email addresses.

A reader complained on March 15 that someone was listing Plasma TVs in the Antiques category for $10, a ploy frequently used by fraudsters. While the seller had a high positive feedback rating with over 500 feedback points accumulated, fraudsters sometimes hijack seller accounts, commonly through phishing email scams.

In addition to using incorrect categories and listing expensive items for ludicrously low prices, there were other red flags with the Plasma TV listings. Fraudsters often include an email address at the top of the listing in a large font, hoping shoppers will send them emails directly. And in this instance, including the Ask Seller a Question form that requested shoppers fill it out and include their email addresses was another warning sign.

Upon filling out the non-eBay "Ask Seller a Question" form, users were directed to a website that appears to belong a legitimate company that offers "Web Form Handling Services." The service allows clients to place a form on their site, and when someone fills it out, the service forwards the information to the client - in this case, a suspected scammer.

Harvesting Email Addresses
What good are email addresses to scammers? In the first instance described above, they may be looking to "hire" sellers who think they are representatives of a legitimate company, but are actually participating in money laundering for the scammer, as described in this article from 2003 (http://www.auctionbytes.com/pages/abn/y03/m01/i29/s01).

In the second case, scammers may pose as legitimate eBay sellers of Plasma TVs (or other expensive items) and request the buyer send money to them via wire transfer (such as Wester Union), which is as good as sending cash.

eBay has been trying to limit scammers' ability to contact its buyers and sellers since as early as 2001, which is one of the reasons eBay instituted a message system that masks users' email addresses. Much eBay-related fraud takes place outside of the eBay system, and users who fall for off-eBay scams end up with no protection at all.


Email this story to a friend.

| Next Story

Related Stories
  • He's Baaack - Vladuz 'Hacker' Taunts eBay - February 23, 2007, Issue #1481
  • Romanian Hacker Vladuz Makes Another eBay Housecall - March 14, 2007, Issue #1494
  • FBI Cites Role in Arrest Related to Off-eBay Fraud - March 27, 2007, Issue #1503
  • Consumer Reports Releases Results of eBay Survey - July 03, 2007, Issue #1574
  • Spammers Harvest eBay Sellers' Email Addresses - August 21, 2007, Issue #1604
  • eBay Shuts Trust & Safety Board after Credit Card Numbers Exposed - September 25, 2007, Issue #1628
  • eBay Denies Security Breach after User Information Exposed - September 26, 2007, Issue #1630
  • eBay, PayPal and Yahoo Collaborate to Fight Phishing - October 04, 2007, Issue #1635



  • Discuss this story in our forums.

    Ecommerce Podcasts

    Site Index
    Copyright 1999-2008. Steiner Associates LLC. All rights reserved