Hello all,
As we manage our businesses online, we are bound to interact with scammers of some sort. They are getting better day by day and I would like to share an experience that I encountered today in the hopes of increasing awareness on this.
I will copy our conversation below in blue :
[removed] - due to private conversation
Summary of Scammer Modus Operandi - a custom print on POTTERY was requested, and an infected file/zip provided as a design to be evaluated. When I refused to open it, they insisted on persistently.
Before flagging spam, I check the user for any favorites , follows or proof , and it is all blank. For a seller which usually does custom print work, it would be a no brainer to check the requested file and you could be downloading a keylogger, a session cookie extractor or some other form of malware onto your phone or PC.
This was one of the smoothest attempts that I have received in a long time and I was wondering if any of you have had similar experiences?
Or alternatively, do you think I wrongly flagged this buyer?
Just happened to me now as well. Figured it was spam once they sent me a download file to unzip and I immediately marked it as spam. It would be good to have a way to report it - just putting it as spam doesn't seem sufficient.
Hi! I am slightly freaking out. I run a business where I DO need photos from customers and they send them via Etsy for my custom work.
I received a weird message about needing rainbow ornaments, etc etc. They sent an image (PDF file), as an attachment via Etsy Messenger. I opened it because again, this is not unusual for my business. As soon as I read the image I knew it was a scam. I told them I won't be opening it (they said they're on vacation and can't access files etc etc) and reported it as spam.
I just changed my Etsy password and have text verification on for logging in. Am I at risk for opening the image they sent? I wasn't sure if Etsy had a built in scanner to protect sellers. I am terrified. The file name I could see once I clicked it was a "cam scanner" generated PDF. To my knowledge from a quick google, this seems to be an app that allows people to create PDF files. I need to know if I am at risk just for opening that file. PLEASE HELP!
Im so sorry for this. Log out of etsy and relog in immediately to refresh your session cookie. Then change your passwords on your browser.
There are quarantine tools that help such as Dangerzone. Im exploring this and am no expert on cybersecurity but this situation has got me mad.
There is an interesting article on dangerzone on wired.com. Worth a read. Just google it!
@KimArt Excellent question. Many Sellers do Custom Work (as you). You should not be terrified doing your job. Sellers never had to worry about this before, certainly not to the extent that we see Hacked Accounts popping up (and that is only those Sellers who come to the Forum, begging for help). Safeguards should be in place; there is an obvious problem and it needs to be addressed.
@RAAQUU
Thanks for chiming in! I logged out of Etsy on my browser, went to a different browser to change my password. Went back to Chrome and wiped all cookies and cache from the last 24 hours. Logged back into my Etsy account and hoping for the best. I hope that since I have text verification on as a two step authentication that helps as well. I AM TERRIFIED!
Also, the same user just messaged me AGAIN. Message is the same as the first one they sent me before, it says "I don't know if your store has products like this or similar products" and I immediately sent it to spam.
I am really hoping someone from Etsy can reply and let me know if my account is at risk for clicking the PDF image
@KimArt really hoping for the best for you. Possibly the security team can check if a foreign IP had tried to access your account in these past two days. It would be from a place that is completely different from your usual log ins.
They will likely reach out personally to you if they do so at all.
My turn today. Got a message yesterday asking for discount and asking how many of a certain item I had. I was suspicious from the start but just gave a polite 'sorry no discount' response.
Today they're back with a sob story about how another seller let them down and please don't tell them to just add what they want to the basket, with a PDF detailing everything they want.
Obvious scam but leaving this here as a reminder to others.
Thanks for sharing this.
I've had people send me 'spec sheets' or links to spec sheets several times. I used to get excited because they implied they wanted to buy a lot of items. My antivirus/security program would warn me about a risky site or the file. I'd message the person letting them know that I was unable to access the information ... and usually would never hear back. When I did hear back it was never with an offer to provide the information in a safe manner. So no gain but no loss. But I do think its a good thing to warn sellers about this scam.
Sigh.
@WantableDesigns "Today they're back with a sob story about how another seller let them down and please don't tell them to just add what they want to the basket, with a PDF detailing everything they want."
Yes, I had that one last night. Moved to spam. I do wish there was a more definite 'report phishing' button, I know Etsy apparently looks at the Spam folders, but it feels a report would move stuff sooner. Also, if there is a rush of the same type of scam going around it would be good if it appeared in the dashboard.
Well Kudos to Etsy I guess. The messages I received and marked as spam are totally gone, even from my spam folder. Other messages I've marked as spam in the past are still there so it looks like Etsy has removed the 'person' from the site.
I had one of these recently too - reported as spam but the messages are still there. Very persistent, wanting me to open a pdf to look at a 'product' (no details even when I asked for them, and I could see the thumbnail of the file bore NO relation to what I sell). On a busier day I might well have clicked on it without thinking...
Glad you managed to avoid this. They are persistent as a badger.
There are various types and variations of scams on the internet. I'm going to post this list again of Red Flags to watch for. Hopefully it will help other sellers. Once you hit 3 or more red flags, shut down the conversation.