Rule #1: Never click on email links. You should always go to your Web browser and type the site name directly. Links are easily forged, and clicking bad links allows viruses to bypass your security and silently install themselves on your computer. Remember our motto: Think Before You Click.
We’re going to dissect three of the most common email scams: fake social-media messages, phony antivirus warnings, and counterfeit account statements. But first, let’s talk about how these scams work. All of them bear similarities: use of real logos, colors, and addresses; realistic-sounding language; and links that look like they lead one place when they actually go somewhere else.
Don’t rely on poor grammar or punctuation to tell a scam from the real deal. Some scams may be amateur efforts, but others are so convincing that it’s almost impossible to detect them. It’s best to err on the side of caution and never click links in any email messages.
(Click the screenshots below to enlarge them and see how these email scams try to trick you.)
The Facebook Fake-Out
What It Is: False messages from popular social media sites like Facebook, LinkedIn, and Twitter are a popular way to harvest passwords and sneak viruses onto your computer. People are used to getting email from these sites, so they will click without a second thought. As a result, social media has become the top method of computer virus infection.
How To Avoid It: Never click on links in email. Go directly to Facebook, LinkedIn, Twitter, and other social media sites by typing the site addresses into your Web browser. Don’t try to reset your password via instructions or links in email – and shame on LinkedIn for encouraging people to do exactly that in their recent password breach. See, even real companies get security wrong sometimes, so don’t listen to bad advice no matter who it’s from.
The Phony Antivirus Program
What It Is: Rogue antivirus is fake software that tricks you into installing it, usually by displaying phony infection warnings or upgrade notices. I’ve discussed rogue antivirus before; you can read about it here and here. Once a rogue antivirus program commandeers your computer it will disable legitimate antivirus, regenerate itself if deleted, and even hold your data for ransom.
How To Avoid It: Don’t install software on your computer unless you know where it’s from. When in doubt buy a packaged program from a store. Go directly to security software makers’ sites to buy and download software rather than relying on links in email.
The False Billing Statement
What It Is: Counterfeit billing statements attempt to harvest your password and account credentials. This information can be used to gain access to other accounts including your bank accounts and credit cards.
How To Avoid It: If you receive electronic statements, don’t click links in them. Visit the site directly to enter your account information. Never believe a password reset email or instructions to “verify” your account.
These are not the only scams in town. Fake package delivery notices, marketing surveys, and other scams abound on the Internet. It’s up to you to learn how to recognize and avoid them, but hopefully this has given you a head start.