View Full Version : New Phishing attack vector - "Easyjet"


Daysleeper
17th November 2006, 13:29
or am I getting paranoid....

Update your details and allow us to update you
- we'll give you £5 off your next booking!

Dear Customer,

Have you changed your mobile number recently? Moved house? Got a new
email address? We're currently reviewing our records to ensure that
our customers get the best and most accurate service possible - we'd
be grateful if you could take a minute to check your details and amend
as necessary.

Your preferences are currently set as opted out of receiving our email
newsletter. If you would like to be kept informed about new routes, be
the first to hear about our service initiatives and receive exclusive
special offers, it's worth signing up (we respect our customers'
privacy and never pass on information to third parties).

Please visit
XXXXX REMOVEDXXXXXXXXX

to update your details and to register for our email newsletter. If
you sign up by 27 November 2006, you will receive a promotional code
entitling you to £5 off your next booking*.

Thanks for your time.

Your easyJet Team

* The discounted booking period is from 1 - 15 December 2006 and the
flying period is from 1 December 2006 - 31 January 2007. Full terms
and conditions can be found at
XXX REMOVED XXXX



Mercenary Pilot
17th November 2006, 13:40
Pffff..For a fiver I wouldn't bother even if it was Kosher. :ok:

Speechless Two
17th November 2006, 14:57
My reaction was identical, Daysleeper - it's probably genuine but it got deleted right away. If it's genuine it's a pretty stupid way of going about things as most folk are aware of phishing and would probably have the same reaction.

Mercenary Pilot
17th November 2006, 15:28
Most companies are telling their customers "We do NOT ever request personal information via E-mail" so for EZY to be contradicting this advice is pretty silly! Also, it could leave the brand wide open for a "reputation damaging" phishing scam!

The last thing they need is for customers to lose confidence in their online business model. :bored:

PPRuNe Pop
17th November 2006, 16:49
I got one too and as far as I am concerned if I ain't asked for it and I don't know about it it gets binned.

TheOddOne
17th November 2006, 17:34
I got one too and as far as I am concerned if I ain't asked for it and I don't know about it it gets binned.

Ditto, just to add to the stats.

Daft way of going about things. Bet FR don't do this!

TOO

ps just goes to show, we've all used EZY! People I know in Big Airlines say they often use EZY 'cos it's easier AND cheaper than an ID90...

ChocksAwayUK
17th November 2006, 18:28
Assuming that you can get to your details page directly through the easyJet website - why don't you do that and see if it has the same URL as the one in the email? It's often the URL that is the giveaway with phishing attempts.

Also the email seems to written in passable English which often means it is genuine! And it seems that the £5 offer just requires that you sign up for the newsletter (?) so you won't be giving any personal details. Looks genuine to me but I don't have the original email so can't be sure.

PPRuNe Pop
17th November 2006, 22:39
Couldn't agree more Mike. This kind of thing puts the frighteners on people and is not healthy. Good that you put the effort in.

PPP

guestpost
22nd November 2006, 18:20
or am I getting paranoid....

I too, was wondering if this was a phishing scam. However, I don't think it was. Firstly, the email arrived with my correct first name at the top, and that name isn't part of my email address. Secondly, if you do a whois search on the domain easyjetmail.com, then this is what you get:

> whois easyjetmail.com

Whois Server Version 2.0

Domain Name: EASYJETMAIL.COM
Registrar: REGISTER.COM, INC.
Whois Server: whois.register.com
Referral URL: http://www.register.com
Name Server: NS1.SAVVIS.NET
Name Server: NS6.SAVVIS.NET
Status: ACTIVE
EPP Status: ok
Updated Date: 07-Nov-2005
Creation Date: 07-Nov-2005
Expiration Date: 07-Nov-2007

Registrant:
Easy Group IPLicensing Ltd
The Rotunda
42-43 Gloucester Crescent
London, NW1 7DL
GB
Email: domains@<hidden>

Registrar Name....: REGISTER.COM, INC.
Registrar Whois...: whois.register.com
Registrar Homepage: www.register.com (http://www.register.com)

Domain Name: easyjetmail.com

Created on..............: Mon, Nov 07, 2005
Expires on..............: Wed, Nov 07, 2007
Record last updated on..: Tue, Nov 08, 2005

Administrative Contact:
easyGroup IP Licensing Limited
Eddy Whatt
The Rotunda 42-43 Gloucester Crescent
London, NW1 7DL
GB
Phone: 44--2072419026
Email: domains@<hidden>

Technical Contact:
Register.Com
Domain Registrar
62 Rcom Drive
Yarmouth, NS B5A 4B1
CA
Phone: 1--9027492792
Email: admin@<hidden>
Admittedly, this could all be nicely falsified by a hardworking phisher, but registering domains cost money, and being this thorough costs effort. Most phishing scams run on unregistered servers with numeric URLs.

Still, it's very stupid to send emails out like this. If you did fall for it, simply change your password via the website.