cancel
Showing results for 
Search instead for 
Did you mean: 

Phishing Emails

pvmb
Pro
Posts: 793
Thanks: 117
Fixes: 3
Registered: ‎12-02-2014

Phishing Emails

Anyone else getting SPAM/Phishing emails to their Plusnet email account?

In last two days, allegedly from genuine US companies:

RingCentral
LinkedIn

18 REPLIES 18
Marsh
Plusnet Help Team
Plusnet Help Team
Posts: 76
Thanks: 88
Fixes: 6
Registered: ‎18-11-2024

Re: Phishing Emails

Hey @pvmb,

I am sorry to hear you are being targeted for phishing emails we do have a security team that investigates these types of email if you can forward the email to abuse@plus.net then they will investigate and take action

If this post resolved your issue please click the 'This fixed my problem' button
Josh
Plusnet Help Team
Townman
Superuser
Superuser
Posts: 24,611
Thanks: 10,564
Fixes: 182
Registered: ‎22-08-2007

Re: Phishing Emails

…. Which works until Plusnet’s anti spamming service recognises the email’s profile and refuses to process it!!

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

outcast
Pro
Posts: 290
Thanks: 109
Fixes: 6
Registered: ‎11-01-2025

Re: Phishing Emails


@Marsh wrote:

 

... you can forward the email to abuse@plus.net then they will  investigate and take action


 

Really !  has that EVER worked ?

My Plusnet email address was leaked to spammers by Plusnet  back in 2007

for the next sixteen years (until I left) I received typically 3300 to 3600 SPAM emails EVERY DAY !.

Fortunately being a programmer, I built a email filtering system that intercepted almost 100% of unwanted messages and then automatically forwarded them to  abuse@plus.net  and then filed them for Bayesian pattern recognition to identify patterns of risk for messages received in the future.

Despite automatically forwarding typically 25000 SPAM emails every week to abuse@plus.net , the rate of receiving SPAM emails never reduced,  and therefore I assumed that Plusnet didn't actually attempt blocking anything from reported sources.

.

pvmb
Pro
Posts: 793
Thanks: 117
Fixes: 3
Registered: ‎12-02-2014

Re: Phishing Emails

...My experience is completely different. I usually receive essentially zero (genuine) SPAM/Phishing emails. And this has been true for decades. Naturally, I have made no attempt at any kind of direct response or reply to these recent emails.

I think at this point I will simply monitor and, if the emails are repeated, will pass them on to Plusnet abuse.

pvmb
Pro
Posts: 793
Thanks: 117
Fixes: 3
Registered: ‎12-02-2014

Re: Phishing Emails


@outcast wrote

My Plusnet email address was leaked to spammers by Plusnet  back in 2007

for the next sixteen years (until I left) I received typically 3300 to 3600 SPAM emails EVERY DAY !.

Fortunately being a programmer, I built a email filtering system that intercepted almost 100% of unwanted messages and then automatically forwarded them to  abuse@plus.net  and then filed them for Bayesian pattern recognition to identify patterns of risk for messages received in the future.

Despite automatically forwarding typically 25000 SPAM emails every week to abuse@plus.net , the rate of receiving SPAM emails never reduced,  and therefore I assumed that Plusnet didn't actually attempt blocking anything from reported sources.

 


You MUST be doing something wrong!

In over 30 years on the Internet that must be at least two orders of magnitude more SPAM than I have ever received in total.

outcast
Pro
Posts: 290
Thanks: 109
Fixes: 6
Registered: ‎11-01-2025

Re: Phishing Emails


@pvmb wrote:

You MUST be doing something wrong!

 

Did you read the link I quoted ?  - I don't think there was anything I could have done to protect my email address.

 


@outcast wrote:

My Plusnet email address was leaked to spammers by Plusnet  back in 2007

 

PlusNet has accepted blame for its latest email blunder, having previously fingered vulnerabilities in third party webmail software for last week's security flap.

The Sheffield-based ISP admitted late yesterday that it was its implementation of @Mail's webmail code which exposed thousands of subsciber email addresses and contacts to spammers. The firm made the mea culpa in an detailed incident report posted on its website

 

As well as stealing customer data, the attackers loaded pop-up malware on to one of PlusNet's six email servers. The frame linked to a Russian video site which loaded a Trojan on to the user's machine. Beyond the Russian connection, PlusNet has not released any details of the ongoing criminal investigation into the hack.

 

Champnet
Aspiring Hero
Posts: 2,952
Thanks: 1,113
Fixes: 16
Registered: ‎25-07-2007

Re: Phishing Emails

@outcast  25,000 Spam emails per week for 16 years ?  I suspect a slight exaggeration....

 

pvmb
Pro
Posts: 793
Thanks: 117
Fixes: 3
Registered: ‎12-02-2014

Re: Phishing Emails


@outcast wrote:

@pvmb wrote:

You MUST be doing something wrong!

 

Did you read the link I quoted ?  - I don't think there was anything I could have done to protect my email address.

 


@outcast wrote:

My Plusnet email address was leaked to spammers by Plusnet  back in 2007

 

PlusNet has accepted blame for its latest email blunder, having previously fingered vulnerabilities in third party webmail software for last week's security flap.

The Sheffield-based ISP admitted late yesterday that it was its implementation of @Mail's webmail code which exposed thousands of subsciber email addresses and contacts to spammers. The firm made the mea culpa in an detailed incident report posted on its website

 

As well as stealing customer data, the attackers loaded pop-up malware on to one of PlusNet's six email servers. The frame linked to a Russian video site which loaded a Trojan on to the user's machine. Beyond the Russian connection, PlusNet has not released any details of the ongoing criminal investigation into the hack.

 


And in those 30 years I include the time my then email address was revealed by a commercial company (not Plusnet) via a faulty advertising email - to be followed by the main period of my SPAM email in all that time.

grumble
Rising Star
Posts: 104
Thanks: 17
Registered: ‎15-09-2024

Re: Phishing Emails

My version of history

Plusnet had a breach where account names were obtained by a '3rd party' by some method. (I am being overly polite?)

Anyone with a knowledge (easy to obtain or assume) of how customer-based e-mailing worked came to a correct conclusion that <random-string>@<account-name>.plus.com would result in a successful e-mail delivery.

Plusnet responded by having the ability to 'black hole' addresses, but managing that became somewhat time consuming. Then came specific aliases with everything else black-holed. Which raised the possibility of a real person (i.e. not spammy) making a typo and thinking that their e-mail was successfully delivered, but the recipient was obviously ignoring them.

Plusnet also offered free renewals of domains registered via them as a sweetener.

Such are the delights of catch-alls.

Specific mail addresses/'aliases' are (IMO) the original design intentions for e-mail. I can begin to understand why some ISP mail systems do not adhere to such. It saves on overheads (hardware, software and wetware costs).

Just my tuppence-worth.

CW84
Newbie
Posts: 4
Registered: Wednesday

Re: Phishing Emails

Hi, I've rec'd the following email a couple of times, it contains some odd characters in the word "its", has links to addresses that are http (not https) and If I log in via the member centre I can find no trace of either this message or oversize folders. Is this a scam or a genuine communication? If a scam how have they got both my email addresses and am at any risk? I have not clicked on any of the links. Thanks in advance. Please forgive if I'm doing this wrong - I'm new here!


Your username: Hello CW We're letting you know you have now used more than 75% of your mailbox capacity, and you need to take action to reduce the size of your mailbox. If your overall mailbox size is larger than the 1GB allocated amount, we may have to archive your largest mailbox to bring you under the 1GB limit. The reason we do this is because large mailboxes can have an adverse effect on other users on the platform. To help you reduce the overall size, here's a list of your largest mailboxes - Mailbox Size ***** 684.856 MB ** 79.46 MB default 0.184 MB Total 764.508 MB It’s easy to keep track of your usage on Webmail. Just follow these steps 1. Click Personal Settings. 2. Then choose Folders. 3. Click on the folder you want to check. 4. To see the size of the folder, choose Click to get folder size. Please don't hesitate to get back in touch online at http://contactus.plus.net or by phone on 0800 432 0200 if we can be of help. Best wishes, Plusnet Network Operations Team http://www.plus.net
jab1
Legend
Posts: 19,884
Thanks: 6,574
Fixes: 293
Registered: ‎24-02-2012

Re: Phishing Emails

@CW84 That is a perfectly legitimate message from Plusnet.

John
Townman
Superuser
Superuser
Posts: 24,611
Thanks: 10,564
Fixes: 182
Registered: ‎22-08-2007

Re: Phishing Emails

http vs https is not the issue many would have you believe.

Regardless of that http://plus.net automatically redirects to https://www.plus.net/

This is a standard "You are using over 75% of your 1GB FUP email storage space" weekly email.

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

CW84
Newbie
Posts: 4
Registered: Wednesday

Re: Phishing Emails

Well that's a relief, thank-you. May I steal a little more of your time and ask why I can find no trace of the email in my webmail when logged into the member centre, nor can I find the 'my folders' and following links to reduce the contents of these folders. I can find the main webmail folder (I have two addresses) but this only contains 5 emails, nowhere near quantity in the email. I'm probably being daft so thanks for your patience and help.

Townman
Superuser
Superuser
Posts: 24,611
Thanks: 10,564
Fixes: 182
Registered: ‎22-08-2007

Re: Phishing Emails

That email will have been sent to the ACCOUNT’s contact email address. Is that your Plusnet email address, is it the one you are looking at?

It’s not just the inbox you need to be concerned about, but also the sent items folder.

In webmail (and an IMAP) client you also need to ensure that you are subscribed to all folders.

Some clients screw up their use of server folders, thus there could be more than one for each of sent and deleted items. The SYSTEM deleted items folder is culled on a weekly basis of anything deleted more than 8 days previously. The same does not happen with a folder which happens to be called deleted, but is not the system trash folder.

Look at folder settings within webmail - it’s the easiest way to look at what is really there. Make sure they are all subscribed to.

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.