PDA

View Full Version : Pay attention to your eBay accounts



Scott Shepherd
01-16-2015, 11:18 AM
Last month we bought a piece of equipment off eBay. It had 1/2 a dozen photos or so, the transaction went smooth, we paid, got the items, no issues at all. Last week, when I searched under the name of the machine, I saw a listing for the same machine. Same photos, same description, everything, except it was a different user and it had some note at the bottom, which was a JPEG, saying you needed to email him before bidding. I sent the seller a message, and reported it to eBay as fraudulent. The selling sent me a message back, telling me they didn't list it and didn't know how it got there. The seller had a 100% positive rating with over 500 sales, so I'm guessing he was telling the truth.

This morning, I searched again, found the same thing, different seller, different part of the country. All our machines photos are all there, same descriptions, everything. Again, I sent the seller a message, then contacted eBay about it being a fraud. The seller sent me a message back, thanking me, telling me that there are now 3 things listed under his account that he didn't list, and that he doesn't visit eBay very often so he wouldn't have even known had I not sent him a message.

I'm not sure how they are compromising accounts, but if you have an eBay account, you might want to check it from time to time.

I'm not a big eBay user either, but it's worth paying attention to even if you aren't a steady user.

Dan Hintz
01-16-2015, 11:36 AM
Easiest way? Send out a mass email that looks like it was from the eBay Security Team telling people about such instances and they should log into their accounts to make sure they haven't been compromised. Classic phishing. Plenty of people fall for it. A self-fulfilling prophecy, so to speak.

Jim Koepke
01-16-2015, 1:08 PM
Easiest way? Send out a mass email that looks like it was from the eBay Security Team telling people about such instances and they should log into their accounts to make sure they haven't been compromised. Classic phishing. Plenty of people fall for it. A self-fulfilling prophecy, so to speak.

Usually those have a link to click. The unaware click the link and they are toast.

Phishing always has a hook, don't bite.

jtk

Doug Ladendorf
01-16-2015, 1:30 PM
Bad stuff. I'm curious what other red flags there might be with these false listings. What types of payment do they ask for?

Bert Kemp
01-16-2015, 1:31 PM
Right these emails have a link DO NOT!! CLIC A LINK FROM ANYONE Ebay and any honest retailer will never put a link in an email. Go directly to the site and log in there.


Usually those have a link to click. The unaware click the link and they are toast.

Phishing always has a hook, don't bite.

jtk

Duane Meadows
01-16-2015, 1:54 PM
Right these emails have a link DO NOT!! CLIC A LINK FROM ANYONE Ebay and any honest retailer will never put a link in an email. Go directly to the site and log in there.

Does any company send emails without links? Can't recall any, or at least many.

Honest companies don't ask you to verify login info via email, though.

Also seem to remember not long ago, eBay being hacked. I changed my password, and have not had any issues. I f you have not recently changed your eBay password, I'd recommend doing that!

Brian Elfert
01-16-2015, 2:38 PM
When Ebay was hacked they forced everyone to change their password before they could get into their account. It doesn't help if the hacker logged into your account first and changed your password first. I don't know if the hackers actually got clear text passwords or if they were encrypted.

I had my account hacked once years ago and I don't have any idea how. I had certainly never clicked on a link in an email as I never do that.

Scott Shepherd
01-16-2015, 4:01 PM
Bad stuff. I'm curious what other red flags there might be with these false listings. What types of payment do they ask for?

This guy has a number of things listed. In contacting the seller, he had 3 other items for sale and they all have this JPEG in the description at the bottle :

304400

ken masoumi
01-16-2015, 4:47 PM
I know for a fact ebay sellers can easily block all sorts of buyers from bidding ,ie,buyers with low purchase count,buyers with more than two unpaid purchases,buyers with too many claims for "item not as described",etc,etc so I don't think this seller needs to ask the potential "buy it now"buyers to check with him before buying unless he/she is a rookie and doesn't know how to use ebay features to block "bad" buyers .

Scott Shepherd
01-16-2015, 5:56 PM
I know for a fact ebay sellers can easily block all sorts of buyers from bidding ,ie,buyers with low purchase count,buyers with more than two unpaid purchases,buyers with too many claims for "item not as described",etc,etc so I don't think this seller needs to ask the potential "buy it now"buyers to check with him before buying unless he/she is a rookie and doesn't know how to use ebay features to block "bad" buyers .

That's the thing, the "seller" didn't list it at all. It's someone getting into their accounts and listing things. In both cases, both sellers I contacted had 100% ratings and neither one knew how the items got posted.

ken masoumi
01-16-2015, 6:07 PM
That's bizarre, if it was a phishing scam the the seller would know about it but apparently they don't.

Victor Stearns
01-17-2015, 9:52 AM
We have seen this also happen on CL. You might be looking for "blank" and you find several listings with the same pictures but by different sellers. Just practice buyer-beware.

Brian Elfert
01-17-2015, 11:52 AM
There is a somewhat common scam of people renting out houses and apartments that they have no rights to rent. The copy Craigslist ads and substitute their contact information. The prospective tenants pay the deposit and first month's rent to the con artist. Somehow the con artists convince the current tenants to let their prospective tenants in to look at the place. The new tenants find out they got taken when it is time to move in.

ken masoumi
01-17-2015, 12:06 PM
Everytime I buy something on ebay,I get a fake paypal invoice (for something else) within 24 hours of my purchase ,it is so predictable nowadays that as soon as I see it I delete it.

Jim Koepke
01-17-2015, 12:12 PM
Everytime I buy something on ebay,I get a fake paypal invoice (for something else) within 24 hours of my purchase ,it is so predictable nowadays that as soon as I see it I delete it.

That is something you should forward to Paypal or ebay (same people, different cubicle).

The only way to stop fraud is to let those who can do something about it know about it.

Before the internet there was a scam of sending small amount invoices, less than $50, to companies for vague things such as building maintenance or other repair. For many companies it was easier to pay the bill than to track down whoever was the one who called in an outside contractor. In a large area if a few paid it was free money.

jtk

ken masoumi
01-17-2015, 12:43 PM
That is something you should forward to Paypal or ebay (same people, different cubicle).

jtk
I have done that many,many times,paypal kept sending me a generic reply advising me on how to recognise "fake paypal emails" and how to protect myself!
I guess I wasn't reporting anything new.

Roger Feeley
01-19-2015, 10:55 PM
I think when Paypal wants you to do something, they don't send you a link. They instruct you to log into your account and tell you how to take whatever action they are suggesting. I vaguely remember a while back when PP was hacked. They were very proactive about it. They went public pretty fast. They publicly cooperated with the FBI. They hired the guy who designed the security scheme for the inter-bank monetary transfers. To my knowledge, they have been ok since.

Ed Aumiller
01-20-2015, 7:55 PM
http://www.sawmillcreek.org/images/misc/quote_icon.png Originally Posted by ken masoumi http://www.sawmillcreek.org/images/buttons/viewpost-right.png (http://www.sawmillcreek.org/showthread.php?p=2362221#post2362221)
Everytime I buy something on ebay,I get a fake paypal invoice (for something else) within 24 hours of my purchase ,it is so predictable nowadays that as soon as I see it I delete it.

Since this is happening everytime, you probably have either malware or something on your computer that detects ebay purchases and causes the fake invoice...

I would delete ALL cookies and delete then reload my browser....

Try doing a virus scan also..

Dan Hintz
01-20-2015, 8:39 PM
http://www.sawmillcreek.org/images/misc/quote_icon.png Originally Posted by ken masoumi http://www.sawmillcreek.org/images/buttons/viewpost-right.png (http://www.sawmillcreek.org/showthread.php?p=2362221#post2362221)
Everytime I buy something on ebay,I get a fake paypal invoice (for something else) within 24 hours of my purchase ,it is so predictable nowadays that as soon as I see it I delete it.

Since this is happening everytime, you probably have either malware or something on your computer that detects ebay purchases and causes the fake invoice...

I would delete ALL cookies and delete then reload my browser....

Try doing a virus scan also..

Unlikely. Ken may have been using a bit of hyperbole when he said "every time" (or maybe he wasn't), but this would be a very odd (and new to me) bit of malware.

Also, should a bit of malware actually be the cause... deleting your browser and cookies will do zero to resolve the issue as malware is rarely tied to cookies or the browser directory structure.

But a virus scan is always a good measure...

ken masoumi
01-20-2015, 11:48 PM
Also, should a bit of malware actually be the cause...

But a virus scan is always a good measure...
I know it sounds odd or exaggerated but often when I buy something online,(ebay,lowes,etc.),I kinda expect one or two types of phishing emails the next day or so ,one is a fake paypal (something about "Dear customer:rolleyes:,your PP account needs to be updated" or if you have not made this purchase,please click on the link below to correct it) ,the other is a fake Fedex"Package Delivery failure",I don't know exactly how they know I'm expecting a package and therefore(so they think) I'm more likely to fall for their scam.

I do need to use "malwarebytes"/virus scan soon ,haven't done that for a while but I find it easier to just delete these emails since it doesn't take a genius to figure out they are fake ,here's(a small portion of) Paypal's Reply to my last report to spoof@paypal :




Dear ken masoumi,
Thank you for being a proactive contributor by reporting
suspicious-looking emails to PayPal's Abuse Department. Our security
team is working to identify if the email you forwarded to us is a
malicious email.
Paypal Will Always:
• Address our customers by their first and last name or business name of
their PayPal account
Paypal Will Never:
• Send an email to: "Undisclosed Recipients" or more than one email
address
• Ask you to download a form or file to resolve an issue
• Ask in an email to verify an account using Personal Information such ........