Office of Information Technology
September 23, 2022
Tags Phishing Email (on campus)

Thanks for using our services ORD_INV#REF429 (another fake invoice)

Phish Bowl Alerts

Following in the pattern of fake Geek Squad, Norton and PayPal invoices, this example notifies the recipient of a purchase made for one "BINANCE COIN (BNC)" for almost $500, to be deducted from their bank account within 12 hours (the urgent threat). It helpfully provides a phone number to discuss the matter, during which the con artist will attempt to collect various personal and financial details from the victim.

From: Invoicing Team <bradford76865@icloud.com>
Date: Fri, Sep 23, 2022 at 11:48 AM
Subject: Thanks for using our services ORD_INV#REF429
To: <josiah_carberry@brown.edu>

File enclose

Screenshot of attached "Invoice" from Binance Coin (BNC)

 

Above image is an Invoice from Binance Coin (BNC) with Invoice number, current and due date (both Sep 23, 2022) for $489.99. It is simply billed to "Customer" (no name specified), indicating that 1 "BINANCE Coin (BNC)" was purchased for $489.99. It includes a note that "The amount will deduct within 12 hours and the transaction may appear in 24-48 hours in your bank statement. If you do not recognise this transaction or want to raise a dispute..." and conveniently provided a phone number to call.