Phishing targeting domain registrants

We’ve recently become aware of a phishing scheme targeting customers of various registrars. Since this is targeting administrators directly, I felt it was worth of a mention even though it’s not MDaemon specific. This is a little difference from most phishing as it’s targeted to domain owners, and specifically mentions their domain registrar by name.

An example message sent to one of my own addresses is below, noting that I am using “TUCOWS, INC.” as my registrar for the domain in question.

Dear Dave Warren,

The Domain Name HIREAHIT.COM have been suspended for violation of the TUCOWS, INC. Abuse Policy.

Multiple warnings were sent by TUCOWS, INC. Spam and Abuse Department to give you an opportunity to address the complaints we have received.

We did not receive a reply from you to these email warnings so we then attempted to contact you via telephone.

We had no choice but to suspend your domain name when you did not respond to our attempts to contact you.

Click here and download a copy of complaints we have received.

Please contact us for additional information regarding this notification.

Sincerely,

TUCOWS, INC.

Spam and Abuse Department

As with all phishes, you should simply ignore and delete it without any further action (or report it to the sending network, if you have the time and energy to hunt it down)

CC BY-NC-ND 4.0 Phishing targeting domain registrants by Dave Warren (everything-mdaemon.com) is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.

Leave a Reply

Your email address will not be published. Required fields are marked *

*