Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

Scam warning by email supposedly from Eir.

Options
  • 20-01-2017 4:33pm
    #1
    Closed Accounts Posts: 18,268 ✭✭✭✭


    I received an email which at first glance seems to come from Eir asking me to confirm login details for my eircom.net email account. using a link which is not to eircom or eir

    It comes from support@eicom.net

    Note the difference in domain name!


    Be alert people!


Comments

  • Closed Accounts Posts: 186 ✭✭eir: Stacey


    I received an email which at first glance seems to come from Eir asking me to confirm login details for my eircom.net email account. using a link which is not to eircom or eir

    It comes from support@eicom.net

    Note the difference in domain name!


    Be alert people!
    Hi Joslyn Ashy Tic-tac-toe

    thanks for getting in touch. I'm afraid this is a scam. We have been made aware of this & this has been reported to our fraud team. They have put a block on this. We would never contact you & ask you to log into your computer or ask you for personal information. I would recommend deleting this email. You can view further information on the scam emails/ calls online here;http://support.eir.ie/article/phishingalert.

     - Stacey


  • Closed Accounts Posts: 18,268 ✭✭✭✭uck51js9zml2yt


    I received an email which at first glance seems to come from Eir asking me to confirm login details for my eircom.net email account. using a link which is not to eircom or eir

    It comes from support@eicom.net

    Note the difference in domain name!


    Be alert people!
    Hi Joslyn Ashy Tic-tac-toe

    thanks for getting in touch. I'm afraid this is a scam. We have been made aware of this & this has been reported to our fraud team. They have put a block on this. We would never contact you & ask you to log into your computer or ask you for personal information. I would recommend deleting this email. You can view further information on the scam emails/ calls online here;http://support.eir.ie/article/phishingalert.

     - Stacey
    Thanks for the post Stacey, but to be fair, I already said it was a scam.
    I cant see how your tech people can "block" this. Its not going through your servers.

    A message on your email login page would be a lot better for people.


  • Closed Accounts Posts: 9,700 ✭✭✭tricky D


    They're still coming at 18.37

    Fyi Header;

    Return-Path: <cxuvivebwsesjornxsfauzrqkcocyk@eir.ie>
    Delivered-To: zzzzzzzzzzzzzzz
    Received: (vpopmail 18144 invoked by uid 16); 20 Jan 2017 18:38:03 +0000
    Received: (qmail 18142 messnum 1183288 invoked from network[213.94.190.11/avas00.vendorsvc.cra.dublin.eircom.net]); 20 Jan 2017 18:38:03 -0000
    Received: from avas00.vendorsvc.cra.dublin.eircom.net (HELO avas00) (213.94.190.11)
      by mta03.svc.cra.dublin.eircom.net (qp 18142) with SMTP; 20 Jan 2017 18:38:03 -0000
    Received: from mail70c50.megamailservers.eu ([91.136.10.86])
        by Cloudmark Gateway with SMTP
        id Ue4ZcQb9AffWiUe4ZcKs4t; Fri, 20 Jan 2017 18:38:03 +0000
    X-Spam-Flag: NO
    X-CNFS-Analysis: v=2.2 cv=O4tJhF1W c=1 sm=1 tr=0
     a=SCRA/MjBM35N9jUC0OcGRA==:117 a=/hJzsJLz0t784hKpdl/3yw==:17
     a=AVFUS5DYfp8A:10 a=8nJEP1OIZ-IA:10 a=7sm_W_NKea8A:10 a=IgFoBzBjUZAA:10
     a=RdjynAUwAAAA:8 a=rh08WfW_AAAA:8 a=FHGNZrRrXlpd-_6NaywA:9
     a=ZGrLLr_BN_7rUuib:21 a=UDdm48F-j9BVKOtF:21 a=wPNLvfGTeEIA:10
     a=CB5MAOBFb8oA:10 a=xoLLaDOqeQYA:10 a=18IJFmU5PgMA:10 a=bOpcCc0fBxwA:10
     a=JhzJ2syGTwuZ0RYgeBai:22 a=yvL8BCALSOEqLevPDfpV:22
    X-Authenticated-User: dan.avocatpantoiu.ro
    Received: from eir.ie (wsip-24-234-197-35.lv.lv.cox.net [24.234.197.35])
        (authenticated bits=0)
        by mail70c50.megamailservers.eu (8.14.9/8.13.1) with ESMTP id v0KIbrk6011437
        for <zzzzzzzzzzzz>; Fri, 20 Jan 2017 18:38:03 +0000
    From: Eircom <sshvslkigppzkydoynxfjhshhihgnk@eir.ie>
    To: zzzzzzzzzzzzz
    Subject: I need to confirm your E-mail Address.
    Date: 20 Jan 2017 10:27:54 -0800
    Message-ID: <20170120102754.30FD491B75FBC957@eir.ie>
    MIME-Version: 1.0
    Status:  U
    Content-Type: text/html;
        charset="iso-8859-1"
    Content-Transfer-Encoding: quoted-printable
    X-Originating-AUTH: dan.avocatpantoiu.ro
    X-Originating-IP: 24.234.197.35

    X-CTCH-RefID: str=0001.0A0B0205.5882590B.0108,ss=1,re=0.000,recu=0.000,reip=0.000,cl=1,cld=1,fgs=0
    X-CTCH-VOD: Unknown
    X-CTCH-Spam: Unknown
    X-CTCH-Score: 0.000
    X-CTCH-Rules:
    X-CTCH-Flags: 0
    X-CTCH-ScoreCust: 0.000
    X-CSC: 0
    X-CHA: v=2.2 cv=VZyHBBh9 c=1 sm=1 tr=0 a=/hJzsJLz0t784hKpdl/3yw==:117
        a=/hJzsJLz0t784hKpdl/3yw==:17 a=AVFUS5DYfp8A:10 a=8nJEP1OIZ-IA:10
        a=RdjynAUwAAAA:8 a=rh08WfW_AAAA:8 a=FHGNZrRrXlpd-_6NaywA:9
        a=ZGrLLr_BN_7rUuib:21 a=UDdm48F-j9BVKOtF:21 a=wPNLvfGTeEIA:10
        a=CB5MAOBFb8oA:10 a=xoLLaDOqeQYA:10 a=18IJFmU5PgMA:10 a=bOpcCc0fBxwA:10
        a=JhzJ2syGTwuZ0RYgeBai:22 a=yvL8BCALSOEqLevPDfpV:22
    X-CMAE-Envelope: MS4wfCtdkPU9xicK3NkHsJ3Bb0WaoJZZKEmathcCR1VwmFSyLxu96Kp17qHe67rt4gd6WvEtXXRGM5bgIT/NG0jmmeVqh5OQWWy9p1GIw5U1KaTT8ajFwzN0
     /Dgq0cEEDjuceMkXq0nfIQ667bvIJ6kZ1CybAafVxgatRrPIhjEVMjeoYa/0jpGedWdN++ymMw1n9a7h32ogVDhJvHoDL8QrU/0778WndnBb1iJjLZYvwzXF
    X-PMFLAGS: 34095744 0 65537 PZWVL0D4.CNM                   

    Link in body points to foodwoodotcom domain - not putting path in and delinkyed


  • Closed Accounts Posts: 2,797 ✭✭✭Eir: Pamela


    tricky D wrote: »
    They're still coming at 18.37

    Fyi Header;

    Return-Path: <cxuvivebwsesjornxsfauzrqkcocyk@eir.ie>
    Delivered-To: zzzzzzzzzzzzzzz
    Received: (vpopmail 18144 invoked by uid 16); 20 Jan 2017 18:38:03 +0000
    Received: (qmail 18142 messnum 1183288 invoked from network[213.94.190.11/avas00.vendorsvc.cra.dublin.eircom.net]); 20 Jan 2017 18:38:03 -0000
    Received: from avas00.vendorsvc.cra.dublin.eircom.net (HELO avas00) (213.94.190.11)
      by mta03.svc.cra.dublin.eircom.net (qp 18142) with SMTP; 20 Jan 2017 18:38:03 -0000
    Received: from mail70c50.megamailservers.eu ([91.136.10.86])
        by Cloudmark Gateway with SMTP
        id Ue4ZcQb9AffWiUe4ZcKs4t; Fri, 20 Jan 2017 18:38:03 +0000
    X-Spam-Flag: NO
    X-CNFS-Analysis: v=2.2 cv=O4tJhF1W c=1 sm=1 tr=0
     a=SCRA/MjBM35N9jUC0OcGRA==:117 a=/hJzsJLz0t784hKpdl/3yw==:17
     a=AVFUS5DYfp8A:10 a=8nJEP1OIZ-IA:10 a=7sm_W_NKea8A:10 a=IgFoBzBjUZAA:10
     a=RdjynAUwAAAA:8 a=rh08WfW_AAAA:8 a=FHGNZrRrXlpd-_6NaywA:9
     a=ZGrLLr_BN_7rUuib:21 a=UDdm48F-j9BVKOtF:21 a=wPNLvfGTeEIA:10
     a=CB5MAOBFb8oA:10 a=xoLLaDOqeQYA:10 a=18IJFmU5PgMA:10 a=bOpcCc0fBxwA:10
     a=JhzJ2syGTwuZ0RYgeBai:22 a=yvL8BCALSOEqLevPDfpV:22
    X-Authenticated-User: dan.avocatpantoiu.ro
    Received: from eir.ie (wsip-24-234-197-35.lv.lv.cox.net [24.234.197.35])
        (authenticated bits=0)
        by mail70c50.megamailservers.eu (8.14.9/8.13.1) with ESMTP id v0KIbrk6011437
        for <zzzzzzzzzzzz>; Fri, 20 Jan 2017 18:38:03 +0000
    From: Eircom <sshvslkigppzkydoynxfjhshhihgnk@eir.ie>
    To: zzzzzzzzzzzzz
    Subject: I need to confirm your E-mail Address.
    Date: 20 Jan 2017 10:27:54 -0800
    Message-ID: <20170120102754.30FD491B75FBC957@eir.ie>
    MIME-Version: 1.0
    Status:  U
    Content-Type: text/html;
        charset="iso-8859-1"
    Content-Transfer-Encoding: quoted-printable
    X-Originating-AUTH: dan.avocatpantoiu.ro
    X-Originating-IP: 24.234.197.35

    X-CTCH-RefID: str=0001.0A0B0205.5882590B.0108,ss=1,re=0.000,recu=0.000,reip=0.000,cl=1,cld=1,fgs=0
    X-CTCH-VOD: Unknown
    X-CTCH-Spam: Unknown
    X-CTCH-Score: 0.000
    X-CTCH-Rules:
    X-CTCH-Flags: 0
    X-CTCH-ScoreCust: 0.000
    X-CSC: 0
    X-CHA: v=2.2 cv=VZyHBBh9 c=1 sm=1 tr=0 a=/hJzsJLz0t784hKpdl/3yw==:117
        a=/hJzsJLz0t784hKpdl/3yw==:17 a=AVFUS5DYfp8A:10 a=8nJEP1OIZ-IA:10
        a=RdjynAUwAAAA:8 a=rh08WfW_AAAA:8 a=FHGNZrRrXlpd-_6NaywA:9
        a=ZGrLLr_BN_7rUuib:21 a=UDdm48F-j9BVKOtF:21 a=wPNLvfGTeEIA:10
        a=CB5MAOBFb8oA:10 a=xoLLaDOqeQYA:10 a=18IJFmU5PgMA:10 a=bOpcCc0fBxwA:10
        a=JhzJ2syGTwuZ0RYgeBai:22 a=yvL8BCALSOEqLevPDfpV:22
    X-CMAE-Envelope: MS4wfCtdkPU9xicK3NkHsJ3Bb0WaoJZZKEmathcCR1VwmFSyLxu96Kp17qHe67rt4gd6WvEtXXRGM5bgIT/NG0jmmeVqh5OQWWy9p1GIw5U1KaTT8ajFwzN0
     /Dgq0cEEDjuceMkXq0nfIQ667bvIJ6kZ1CybAafVxgatRrPIhjEVMjeoYa/0jpGedWdN++ymMw1n9a7h32ogVDhJvHoDL8QrU/0778WndnBb1iJjLZYvwzXF
    X-PMFLAGS: 34095744 0 65537 PZWVL0D4.CNM                   

    Link in body points to foodwoodotcom domain - not putting path in and delinkyed
    Thanks for flagging this tricky D


    -Pamela 


  • Registered Users Posts: 68 ✭✭wailim_2002


     I reckon there may be a data breach at Eir or Bonkers or Vodafone. Just a thought because I received a call Today which was well thought out scam / fraud / phishing and the timing is impeccable as well as the info they already knew about me. 

    Just got a Phishing scam call purporting to be from Eir. She called my landline and asked was she speaking to me, so firstly they knew my name and number!.


    Then she boldly informed me in very poorly phrased english that my broadband would be shut down for 2 weeks. Confusingly, I am moving service provider so initially I thought she simply was confirming that my broadband would shut down in two weeks rather that for 2 weeks. So I queried if thats what she meant.....


    When she insisted it was due to malicious activity comming from my router and began the 'Phish', i became suspicious and asked her to confirm my address....which to my surprise she knew!!!


    So they had my name, address, phone number and knew I was an eir customer.


    Folks, im thinking someone has a data breech?... possibly Eir, possibly Bonkers, possibly Vodafone... because this call came within 2 days of using Bonkers to switch between the two providers!


    I dont know what she was really after. Perhaps access to my router or credit card so be alert


  • Advertisement
Advertisement