Hello all,

As we manage our businesses online, we are bound to interact with scammers of some sort. They are getting better day by day and I would like to share an experience that I encountered today in the hopes of increasing awareness on this.

I will copy our conversation below in blue :

[removed] - due to private conversation

Summary of Scammer Modus Operandi - a custom print on POTTERY was requested, and an infected file/zip provided as a design to be evaluated. When I refused to open it, they insisted on persistently.

Before flagging spam, I check the user for any favorites , follows or proof , and it is all blank. For a seller which usually does custom print work, it would be a no brainer to check the requested file and you could be downloading a keylogger, a session cookie extractor or some other form of malware onto your phone or PC. 

This was one of the smoothest attempts that I have received in a long time and I was wondering if any of you have had similar experiences?

Or alternatively, do you think I wrongly flagged this buyer?

 

 

 

bradgoodell
Community Maker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

A variation of:

Buyer:  I want to make a large purchase of 50 items.  Here is the list of items:  (link given)  

SCAM 

While plenty of the old scams are still going around, they add twists and get more sophisticated. 

Another new one they want to buy X as a gift, but want the buyer to buy an $500 Visa Gift Card and include it in the order.  And they are willing to pay the seller an additional $100 for the trouble!  

I appreciate it when someone brings up a new scam, because we all need to stay abreast of them.  Thank you.

Translate to English There was a problem fetching the translation.
5 Likes
Reply
Loading...
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Oh! I have received the large order guys. And they say here is a list of my order and then attach a suspicious looking file. I have spam reported few of these.

Translate to English There was a problem fetching the translation.
1 Like

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Just got a similar thing to this now, coincidentally after posting in these forums for the first time in ages. Some vague mssage and then when I reply and ask what it is they are enquring about they send an attachment then ask me to click something on it. Anyway, into the spam folder it went.

But I get the feeling some are using this forum to pick their ‘victims’. 

Translate to English There was a problem fetching the translation.
5 Likes
Reply
Loading...
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

I think one of many. For trying-to-build brands like myself, we have representation on social media on most platforms on brand name. It is not difficult to find us as well. I dread the intelligent hacker who scams on the side to keep the electricity running while the million dollar heists are in progress. He would wipe us clean.

 

Translate to English There was a problem fetching the translation.
0 Likes
ReginaldSpleen
Conversation Maker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

I had one of those too on Wednesday... From a guy whose name (allegedly) began with 'A'.

He asked if I did custom orders. I said yes. Then he sent me the picture he wanted engraved as a zip file. I said no, he got antsy, I moved him to spam.

Checking today his messages have been redacted by Etsy security. 

Translate to English There was a problem fetching the translation.
0 Likes

Re: Beware this method of scamming by using a custom PDF

Jump to solution

I just want to say that not following anyone, or any shop, and not having any favorites has nothing to do with being honest or not. Many people just don’t do that, I’m one of them. There have been many posts over the years that say the same thing and I have yet to figure out why not favoring or following shops has to do with how trustworthy a person is. 

Translate to English There was a problem fetching the translation.
3 Likes
Reply
Loading...
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

This was my concern as well hence why I did not name the person as I was concerned that I was being over cautious. Even if I was right, I think you have a valid point. I guess, it is the combination of the request and also the lack of history/credibility plus asking me to download a file that did it.

Translate to English There was a problem fetching the translation.
1 Like
bradgoodell
Community Maker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

@OmasFabricStash Good point.

I have all my favorites private, because, well, privacy.  

Translate to English There was a problem fetching the translation.
1 Like
SugarTaffySoap
Conversation Maker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

I think a warning message should be sent to everyone's shop manager dashboard. 

Translate to English There was a problem fetching the translation.
3 Likes
Reply
Loading...
bradgoodell
Community Maker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Every security article on the internet has said for the last 2 decades "do not click on links from people you don't know".

 Yet every day, someone out there is clicking on a link from unknownweirdo(at)qmail.comor clicking on the "hot lonely girl who wants to be friends"  message they get through Instagram, or believing that caller who claims their car warranty has expired, or otherwise clicking on all sorts of shady stuff.  

Translate to English There was a problem fetching the translation.
5 Likes
ChillwolfArt
Conversation Maker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

@SugarTaffySoap   Absolutely agree with this. Too many Hacked Accounts; it's good to share information to keep people safe.

@bradgoodell   When links come through Etsy Messages, Sellers who do Custom Work (or even those who don't), may receive a link, "Can you make this for me"?  OR
A link which "appears" to be from one of your items (which may be sold out, or it's available but they want 2 of them).  So they send a link, "Do you have any more of these"?  Or "Can I get two of these"?  That link may very well look legit, but (as another Seller stated a while ago), it's a malicious link.  Seller clicks onto it in Etsy Messages and there you go; another Hacked Shop.

I'm referring to Etsy Messages.  But this link clicking includes emails from Etsy (I get them all the time).  They contain a Tab to "Learn More", "Read about it here", etc.  Or click onto photos of items.  I do not click period.

Translate to English There was a problem fetching the translation.
1 Like

Re: Beware this method of scamming by using a custom PDF

Jump to solution

I just received the same issue. Someone asking for me to download a zip file to make custom coins. I asked them to send me the unzipped photos and they said they were on vacation and did not have a computer to please download. I said I would not be able to do that but could help them when they return from vacation and they stopped messaging. Man, they are everywhere!

Translate to English There was a problem fetching the translation.
3 Likes
Reply
Loading...
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Stay vigilant and safe man

Translate to English There was a problem fetching the translation.
0 Likes

Re: Beware this method of scamming by using a custom PDF

Jump to solution

This happened to me a few days ago and now I just received another one from "different" user.  No favorites or following on their profile.  I was skeptical too and marked as spam.

Translate to English There was a problem fetching the translation.
2 Likes
Reply
Loading...

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Just out of curiosity, why does someone with no favorites and not following anyone make you suspicious?

Translate to English There was a problem fetching the translation.
1 Like
ModFabio
Community Specialist
Community Specialist

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Thanks for flagging, @ColorfulRecoveryShop and @BelovedFromAboveLLC - Both are under investigation right now.

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...
ReginaldSpleen
Conversation Maker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

@ModFabio Same for me... I think it's already been addressed as I spammed the messages and some of his have been redacted. But just in case!

Translate to English There was a problem fetching the translation.
0 Likes
Reply
Loading...
ModFabio
Community Specialist
Community Specialist

Re: Beware this method of scamming by using a custom PDF

Jump to solution

It has, indeed! 

Translate to English There was a problem fetching the translation.
1 Like

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Thanks for sharing, just happened to me this morning and they wanted me to unzip a file. I said no and they haven't responded. Marked as spam...

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

awesome!

 

Translate to English There was a problem fetching the translation.
0 Likes
RocketboyGifts
Inspiration Seeker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

I've had this a few times now. I must admit the first time I was almost caught out by it. Who wouldn't be tempted by the prospect of a large order inside a folder.  However we shouldn't be calling it spam which although annoying is usually harmless. It's a downright blatant scamming attempt.  I have reported it before to Etsy as such but it keeps coming back.  If I'm not too busy I sometimes play along with them for a bit just to waste their time before calling them out. 

It's a shame we cant report a user in the same way we can report a shop if we think there's something dodgy going on.  It would make it easier for Etsy to track those out to cause mischief. 

Translate to English There was a problem fetching the translation.
4 Likes
Reply
Loading...
ChillwolfArt
Conversation Maker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

@RocketboyGifts   @PARTYbyLUCY   Agree.  This is beyond mischief.  It's a case of deliberately sending over malicious files with the intent to Hack an Account.

Translate to English There was a problem fetching the translation.
0 Likes
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Agree with this. Also my thoughts was a way to preview file without downloading it and banning .zip and .rar completely

Translate to English There was a problem fetching the translation.
1 Like
PARTYbyLUCY
Inspiration Seeker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Just happened to me now as well. Figured it was spam once they sent me a download file to unzip and I immediately marked it as spam. It would be good to have a way to report it - just putting it as spam doesn't seem sufficient. 

 

Translate to English There was a problem fetching the translation.
2 Likes
Reply
Loading...
KimArt
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Hi! I am slightly freaking out. I run a business where I DO need photos from customers and they send them via Etsy for my custom work.

I received a weird message about needing rainbow ornaments, etc etc. They sent an image (PDF file), as an attachment via Etsy Messenger. I opened it because again, this is not unusual for my business. As soon as I read the image I knew it was a scam. I told them I won't be opening it (they said they're on vacation and can't access files etc etc) and reported it as spam. 
I just changed my Etsy password and have text verification on for logging in. Am I at risk for opening the image they sent? I wasn't sure if Etsy had a built in scanner to protect sellers. I am terrified. The file name I could see once I clicked it was a "cam scanner" generated PDF. To my knowledge from a quick google, this seems to be an app that allows people to create PDF files. I need to know if I am at risk just for opening that file. PLEASE HELP!

Translate to English There was a problem fetching the translation.
2 Likes
Reply
Loading...
Reply
You must log in to join this conversation.
Remember that posts are subject to Etsy's Community Policy.