RAAQUU
Post Crafter

Beware this method of scamming by using a custom PDF

Jump to solution

Hello all,

As we manage our businesses online, we are bound to interact with scammers of some sort. They are getting better day by day and I would like to share an experience that I encountered today in the hopes of increasing awareness on this.

I will copy our conversation below in blue :

[removed] - due to private conversation

Summary of Scammer Modus Operandi - a custom print on POTTERY was requested, and an infected file/zip provided as a design to be evaluated. When I refused to open it, they insisted on persistently.

Before flagging spam, I check the user for any favorites , follows or proof , and it is all blank. For a seller which usually does custom print work, it would be a no brainer to check the requested file and you could be downloading a keylogger, a session cookie extractor or some other form of malware onto your phone or PC. 

This was one of the smoothest attempts that I have received in a long time and I was wondering if any of you have had similar experiences?

Or alternatively, do you think I wrongly flagged this buyer?

 

 

 

Labels (3)
Translate to English There was a problem fetching the translation.
15 Likes
1 Solution

Accepted Solutions
ModFabio
Community Specialist
Community Specialist

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Hello,

For situations like this, please flag the message as spam; do not engage with anyone who attempts to convince you to click links/open attachments of any sort, either. 

It is worth mentioning that these messages may be coming from a legitimate account that's been recently compromised - which is why it is important to flag them, so our team can manually review the account and its contents.

If the nature of your work causes the need for you to open files sent by potential customers (e.g.: made-to-order products, graphic design, and suchlike), make sure your device's security settings and preventive measures are up-to-date (including, but not limited to antivirus and firewall software, VPN, etcetera).

Otherwise, check this article from our Help Center for additional information: https://help.etsy.com/hc/en-us/articles/115015654008-What-to-Do-if-You-Suspect-Fraud-in-Your-Etsy-Ac...

PS: Our team is verifying the account/messages in question - thanks for flagging, @RAAQUU.

Edit: For everyone else who flagged similarly suspicious messages, these have also been acted on.

View solution in original post

Translate to English There was a problem fetching the translation.
17 Likes
Reply
Loading...
61 Replies
nineteen27
Community Maker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

yes that is why so many etsy sellers accounts are hacked.

by clicking on links.

and opening zip files.

Translate to English There was a problem fetching the translation.
10 Likes
Reply
Loading...
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

This is a known problem? There should be something done about this. It is so easy to get someone to download a spec sheet.

Translate to English There was a problem fetching the translation.
2 Likes

Re: Beware this method of scamming by using a custom PDF

Jump to solution

What can be done? 

You can't stop buyers from sending messages. 

Some sellers do require files from the buyer, so you can't stop them from sending files/attachments. I have certain products that require the buyer to send me images for printing. 

All you can do is warn people and hope they take heed. There is normally at least a post each week with some sort of warning. Like yours here. Hopefully your warning will get the attention of some people in the forums and may help stop at least a few of these scams from happening. 

Translate to English There was a problem fetching the translation.
3 Likes
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

@audreytherese I think firstly .zip files should never be allowed to be uploaded. Secondly a PDF/jpg/mov/avi previewer should be built into the messaging system so no file needs to be downloaded. If these two could be evaluated as a security upgrade, it would help greatly!

 

Translate to English There was a problem fetching the translation.
11 Likes

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Ummmm....ok. Sounds so simple. Good luck with that. Pretty sure it would actually be easier to continue warning people.

Does that include zip files that digital creators sell? Because I've definitely opened probably hundreds of zip files through here that were purchased as digital downloads. Most digital sellers already have enough trouble with the maximum file size limits on here, even when zipping them, and many customers don't like having to go off site to download their purchased files. 

Translate to English There was a problem fetching the translation.
0 Likes
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

@audreytherese I think you are definitely right. It would be easier to warn.

I hope to clarify my statement. I dont want to stop sharing files. Just block .zip files or .rar files that can hide anything.

Let sellers and buyers upload multiple files within the ETSY ecosystem somewhat like google drive and have the ability to preview them without downloading. You can still download if needed but at least a secondary warning can be put in place or even better, a malware scanner. ( btw these are things that are done on other file sharing/hosting platforms )

I'm going to do my part and propose the technical upgrade as a security measure. Im sure its something ETSY already knows but if more voices are heard, resources can be allocated. AND im going to continue warning as per your recommendation!

Translate to English There was a problem fetching the translation.
3 Likes

Re: Beware this method of scamming by using a custom PDF

Jump to solution

It's just a good general rule to not click links in emails or open attachments if you don't already know the person. But many newbies, and even some people who should know better, but do it any way when they think there is financial gain for them,  do it every day, and the spammers and hackers count on it.

Translate to English There was a problem fetching the translation.
6 Likes
Reply
Loading...

Re: Beware this method of scamming by using a custom PDF

Jump to solution

I think you were right to flag this. The entire conversation screams scam to me.

Translate to English There was a problem fetching the translation.
2 Likes
Reply
Loading...
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Etsy is an amazing ecosystem and some of the custom orders I get are a privilege. I nearly clicked this link but then the warning signals of "too good to be true" kicked in. So close...

 

Translate to English There was a problem fetching the translation.
1 Like

Re: Beware this method of scamming by using a custom PDF

Jump to solution

That last sentence of not being able to unzip the file. If the buyer has a legit problem, they should be contacting the seller of the file for help, not you. Even when you told them no, they kept pushing. Good catch. This one was well written.

Translate to English There was a problem fetching the translation.
2 Likes
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Urggh. So angry right now about this. They are getting so good at this. I know so many people who if faced with this would lose their account just for being nice trusting human beings.

 

Translate to English There was a problem fetching the translation.
3 Likes
PinkBirdCottage
Conversation Maker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Awareness like this really helps. Even the most savvy of us can get taken in under the right circumstances and on an off day. You probably saved someone so thank you for this.

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

I count myself as savvy and I nearly fell for it. Especially in these economic times. A business opportunity makes us gullible to offers and that is what these vultures prey upon. We have to keep reminding ourselves and be vigilant.

Translate to English There was a problem fetching the translation.
0 Likes
ChillwolfArt
Conversation Maker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Thank You for sharing.  With the practically daily Threads containing Sellers with Hacked Accounts coming to the Forum begging for help, one can never be too careful.  A Seller could also receive a link in Etsy Messages which "appear" to be from one of their listings ("Any more of these"?)  And they could click onto malware, thinking this link is one of their items.    You would also think Etsy would have safeguards in place re: things like this. And have a 24/7 knowledgeable Support Team to take care of these matters. It's become a problem.  Thanks again.

Translate to English There was a problem fetching the translation.
6 Likes
Reply
Loading...

Re: Beware this method of scamming by using a custom PDF

Jump to solution

I had a similar experience today. I was very excited to hear from a buyer after so long. They were asking me questions about a link that I thought was one of my products. It was a very natural conversation. I clicked it and it downloaded a zip file. I did not understand. But upon replying to the person, the account was invalid. I immediately learnt from the forum that it is a scam, deleted the file, the chats and scanned my phone. I am still feeling anxious about it. 

Translate to English There was a problem fetching the translation.
0 Likes
ModFabio
Community Specialist
Community Specialist

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Hello,

For situations like this, please flag the message as spam; do not engage with anyone who attempts to convince you to click links/open attachments of any sort, either. 

It is worth mentioning that these messages may be coming from a legitimate account that's been recently compromised - which is why it is important to flag them, so our team can manually review the account and its contents.

If the nature of your work causes the need for you to open files sent by potential customers (e.g.: made-to-order products, graphic design, and suchlike), make sure your device's security settings and preventive measures are up-to-date (including, but not limited to antivirus and firewall software, VPN, etcetera).

Otherwise, check this article from our Help Center for additional information: https://help.etsy.com/hc/en-us/articles/115015654008-What-to-Do-if-You-Suspect-Fraud-in-Your-Etsy-Ac...

PS: Our team is verifying the account/messages in question - thanks for flagging, @RAAQUU.

Edit: For everyone else who flagged similarly suspicious messages, these have also been acted on.

Translate to English There was a problem fetching the translation.
17 Likes
Reply
Loading...
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Appreciate it @ModFabio . I did not want to reveal the username here as it may be a breach of the customers privacy if I was wrong. You can see it in my flagged messages. I have already done so and did not reply to the scammer.

Translate to English There was a problem fetching the translation.
0 Likes
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

I dived into this for the moment but do the security measures secure against session token copiers? That was a most scary revelation to me that your access can be taken away without your passwords or auth keys being compromised.

Translate to English There was a problem fetching the translation.
1 Like
ModFabio
Community Specialist
Community Specialist

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Anytime! I'm just gonna remove the excerpt from the conversation, however - technically it qualifies as a private conversation, hence I mentioned the gist of this bad actor's MO.

Translate to English There was a problem fetching the translation.
1 Like
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Got it. I added a non verbatim summary for the benefit of others who browse through. More need to know of this situation. I just read so many posts where people have lost their livelihoods when their account gets hacked. heartbreaking.

Translate to English There was a problem fetching the translation.
6 Likes
lalarossa
Conversation Maker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

I had the same situation a week ago. I was urged to click on the link. Where can I report this user?

Translate to English There was a problem fetching the translation.
1 Like
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

@lalarossa I believe reporting as spam is sufficient. They get flagged removed and I do hope IP blocked.

Translate to English There was a problem fetching the translation.
1 Like
lalarossa
Conversation Maker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

@RAAQUU
No, that's not enough. No one at Etsy checks spam. Besides, sending spam messages does not block the user. Sometimes it happens that a client sends me two of the same messages. I'm sending one to spam so I don't have to reply to both. the client can still send me messages. I am asking how can I report this account to etsy to check it.

Translate to English There was a problem fetching the translation.
1 Like
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

@lalarossa I stand corrected. I too would like to know @ModFabio 

Translate to English There was a problem fetching the translation.
1 Like
Reply
You must log in to join this conversation.
Remember that posts are subject to Etsy's Community Policy.