Sunday, March 9, 2025

The Power of Incompetence

I received an email inviting me to check my monthly PayPal statement.  PayPal does not issue monthly statements.   Out of curiosity, I clicked the link.  The URL was not to PayPal,  of course.   I was expecting something that looked like PayPal.   But it was not a valid URI!  

I have a theory that many of these criminals are technically ignorant.   They buy (or steal) scamming emails from other criminals,  but lack the basic intelligence to verify that these scams will work!

2 comments:

  1. It is an IQ test on the recipient too. Even with the best tools available including native speakers to write their messages they leave in broken English and the URLs unmasked to weed out the intelligent. If you click on the link they can be pretty sure you are dumb and gullible enough to fall for their scam AND not report it to the police until it is far too late.

    In 2007 the county clerk for Alcona County MI sent over $100,000 dollars of county funds to 419 scammers, and the criminals have only gotten more selective over time.

    It is a numbers game. They send out 10s of thousands of emails for essentially no cost, if they get one hit per batch send they still profit.

    ReplyDelete
  2. my dude... WTF! about the only thing worse than clicking random links is clicking one you know is bad. drive-by downloads of crapware is a thing. if you want to click a link to see where it goes, what the site looks like, etc... there are safer ways.
    the easiest is to go to browserling.com and use a virtual browser. on the server end, they're running it in a VM or docker instance so it's sandboxed and nothing runs locally.

    if you copy the link you can ping the domain. one could also whois the domain to see who owns it but since squatting is common, that's usually a waste of time.

    depending on how it failed, the site could have been already taken down. they try to obfuscate what's going on by polluting the URL and sometimes they're too clever for their own good.

    ReplyDelete