Hello all,

As we manage our businesses online, we are bound to interact with scammers of some sort. They are getting better day by day and I would like to share an experience that I encountered today in the hopes of increasing awareness on this.

I will copy our conversation below in blue :

[removed] - due to private conversation

Summary of Scammer Modus Operandi - a custom print on POTTERY was requested, and an infected file/zip provided as a design to be evaluated. When I refused to open it, they insisted on persistently.

Before flagging spam, I check the user for any favorites , follows or proof , and it is all blank. For a seller which usually does custom print work, it would be a no brainer to check the requested file and you could be downloading a keylogger, a session cookie extractor or some other form of malware onto your phone or PC. 

This was one of the smoothest attempts that I have received in a long time and I was wondering if any of you have had similar experiences?

Or alternatively, do you think I wrongly flagged this buyer?

 

 

 

RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Im so sorry for this. Log out of etsy and relog in immediately to refresh your session cookie. Then change your passwords on your browser. 

There are quarantine tools that help such as Dangerzone. Im exploring this and am no expert on cybersecurity but this situation has got me mad.

There is an interesting article on dangerzone on wired.com. Worth a read. Just google it!

 

Translate to English There was a problem fetching the translation.
1 Like
ChillwolfArt
Conversation Maker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

@KimArt  Excellent question. Many Sellers do Custom Work (as you). You should not be terrified doing your job.  Sellers never had to worry about this before, certainly not to the extent that we see Hacked Accounts popping up (and that is only those Sellers who come to the Forum, begging for help).  Safeguards should be in place; there is an obvious problem and it needs to be addressed.

Translate to English There was a problem fetching the translation.
0 Likes
KimArt
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

@RAAQUU 

Thanks for chiming in! I logged out of Etsy on my browser, went to a different browser to change my password. Went back to Chrome and wiped all cookies and cache from the last 24 hours. Logged back into my Etsy account and hoping for the best. I hope that since I have text verification on as a two step authentication that helps as well. I AM TERRIFIED!

Also, the same user just messaged me AGAIN. Message is the same as the first one they sent me before, it says "I don't know if your store has products like this or similar products" and I immediately sent it to spam. 

I am really hoping someone from Etsy can reply and let  me know if my account is at risk for clicking the PDF image  

Translate to English There was a problem fetching the translation.
2 Likes
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

@KimArt really hoping for the best for you. Possibly the security team can check if a foreign IP had tried to access your account in these past two days. It would be from a place that is completely different from your usual log ins.

They will likely reach out personally to you if they do so at all. 

Translate to English There was a problem fetching the translation.
1 Like
WantableDesigns
Conversation Maker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

My turn today. Got a message yesterday asking for discount and asking how many of a certain item I had. I was suspicious from the start but just gave a polite 'sorry no discount' response.

Today they're back with a sob story about how another seller let them down and please don't tell them to just add what they want to the basket, with a PDF detailing everything they want.

Obvious scam but leaving this here as a reminder to others.

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Thanks for sharing this.

 

Translate to English There was a problem fetching the translation.
0 Likes

Re: Beware this method of scamming by using a custom PDF

Jump to solution

I've had people send me 'spec sheets' or links to spec sheets several times. I used to get excited because they implied they wanted to buy a lot of items. My antivirus/security program would warn me about a risky site or the file. I'd message the person letting them know that I was unable to access the information ... and usually would never hear back. When I did hear back it was never with an offer to provide the information in a safe manner. So no gain but no loss. But I do think its a good thing to warn sellers about this scam.

 

Sigh.

 

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...
ReginaldSpleen
Conversation Maker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

@WantableDesigns "Today they're back with a sob story about how another seller let them down and please don't tell them to just add what they want to the basket, with a PDF detailing everything they want."

Yes, I had that one last night. Moved to spam. I do wish there was a more definite 'report phishing' button, I know Etsy apparently looks at the Spam folders, but it feels a report would move stuff sooner. Also, if there is a rush of the same type of scam going around it would be good if it appeared in the dashboard.

Translate to English There was a problem fetching the translation.
6 Likes
Reply
Loading...
WantableDesigns
Conversation Maker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Well Kudos to Etsy I guess. The messages I received and marked as spam are totally gone, even from my spam folder. Other messages I've marked as spam in the past are still there so it looks like Etsy has removed the 'person' from the site.

 

Translate to English There was a problem fetching the translation.
3 Likes
Reply
Loading...
nemeton
Conversation Maker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

I had one of these recently too - reported as spam but the messages are still there. Very persistent, wanting me to open a pdf to look at a 'product' (no details even when I asked for them, and I could see the thumbnail of the file bore NO relation to what I sell). On a busier day I might well have clicked on it without thinking...

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...
RAAQUU
Post Crafter

Re: Beware this method of scamming by using a custom PDF

Jump to solution

Glad you managed to avoid this. They are persistent as a badger.

Translate to English There was a problem fetching the translation.
0 Likes
bradgoodell
Community Maker

Re: Beware this method of scamming by using a custom PDF

Jump to solution

There are various types and variations of scams on the internet.  I'm going to post this list again of Red Flags to watch for.  Hopefully it will help other sellers.  Once you hit 3 or more red flags, shut down the conversation.  

  1. New seller
  2. High dollar item or large sale amount
  3. They want to take the conversation off Etsy
  4. They want to take the sale off Etsy
  5. You go back to their account, and it's gone
  6. They ask if something is "still available" when it's obviously for sale in your shop
  7. They ask about the condition of an obviously new item
  8. They ask if you are honest
  9. They send you a link to a "Shopping List" of items they want, or a custom design they want.  DO NOT CLICK ON THE LINK
  10. Odd language
  11. There is some urgency, such as a birthday or anniversary
  12. They claim they are in the Navy, an oceanographer, on a cruise ship, on a research vessel in Antartica
  13. They claim they cannot check-out through Etsy due to their location
  14. They claim your Etsy checkout isn't working, and they send you a link to "fix it"  
  15. They ask you to buy a high dollar gift card and include it in the order
  16. They claim you need to buy a high dollar pre-paid Visa or American Express card to get your Etsy account working
  17. They claim they are Etsy and and want to to buy a pre-paid gift card or click on a link to get your account approved
  18. They will pay you extra for the inconvenience
  19. They claim to have their own shipping company or pick-up agent
  20. They claim an uncle is paying
  21. They want to pay by money order or Cashier's check
  22. They send you payment for far more than the order total
  23. They want you to send the overage through Western Union, Venmo, etc.
  24. They send you a (fake) PayPal email that says PayPal will release the payment after you send them the overage.
Translate to English There was a problem fetching the translation.
2 Likes
Reply
Loading...
Reply
You must log in to join this conversation.
Remember that posts are subject to Etsy's Community Policy.