Bitcoin Forum

Economy => Service Discussion => Topic started by: Wusolini on July 22, 2017, 08:28:37 PM



Title: bitit.io - email phishing link - Scam? CONFIRMED - be aware
Post by: Wusolini on July 22, 2017, 08:28:37 PM
I've just received email from: sales@bitit.io about some sort of unpaid invoice. I have never registered in this site and can't find any relevant info about them here. So be aware.

Part of the email is a phishing link masked as "bitit.gift" but redirecting to goo.gl shorted link (I had not enough courage to click it)

https://imghost.io/images/2017/07/22/image.png


Just wanted to warn others

EDIT: realized I would rather not to be linked to my email so shaded the invoice nr. and removed the goo.gl link.


Title: Re: bitit.io - phishing link - Scam?
Post by: TryNinja on July 22, 2017, 08:40:03 PM
-snip-
Hmm... Looks like an phising scam attempt. Could you check the shorted link?

You can see where the URL will lead you to doing any of the options bellow:

First option: https://goo.gl/#analytics/goo.gl/XXXXXX/all_time - change the X with the code after goo.gl
Second: put a "+" at the end of the link. Will lead you to the same url as the first option. e.g: goo.gl/XXXXXX+
Third: Use http://www.checkshorturl.com

Edit: Looks like the URL was disabled by Google for violating their Terms of Service. Probably because it was indeed a phising link.


Title: Re: bitit.io - phishing link - Scam?
Post by: Catmony on July 22, 2017, 08:41:57 PM
I have also never heard about that bitit.io and I am also getting scam emails with different names which are asking me to send bitcoin or login into my web wallet for security reason or similar bullshit.

Its better to not use same email address/personal email address in multiple sites.


Title: Re: bitit.io - phishing link - Scam?
Post by: Wusolini on July 22, 2017, 08:46:06 PM
-snip-
Hmm... Looks like an phising scam attempt. Could you check the shorted link?

You can see where the URL will lead you to doing any of the options bellow:

First option: https://goo.gl/#analytics/goo.gl/DzHnre/all_time - change the X with the code after goo.gl
Second: put a "+" at the end of the link. Will lead you to the same url as the first option. e.g: goo.gl/XXXXXX+
Third: Use http://www.checkshorturl.com

Edit: Looks like the URL was disabled by Google for violating their Terms of Service.

Great, I have never heard of those options. Though I know goo.gl is removing obvious scam site links I had not enough courage to click it.
Thanks for hints.

EDIT. Yea, tried it as well and shortened link seems to be already disabled. So scam attempt confirmed.


Title: Re: bitit.io - email phishing link - Scam? CONFIRMED - be aware
Post by: streazight on July 26, 2017, 07:28:36 AM
Thank you for the warning. This is the reason I never click any link from my emails.
As it is not so hard to fake ip and email addresses, scammers take advantage of this, and also the dirt cheap domain promotions, to spread their nasty work.


Title: Re: bitit.io - email phishing link - Scam? CONFIRMED - be aware
Post by: klaaas on July 26, 2017, 07:32:01 AM
Thanks for letting us know.
I did receive this mail twice with a minute in between.


Title: Re: bitit.io - email phishing link - Scam? CONFIRMED - be aware
Post by: hello_good_sir on July 26, 2017, 09:27:01 AM
Well Bitit.io is a real site itself(i'm not sure if it is actually legit, but it is not a phishing site.)

If you see any sort of shortened link in an email that was supposed to be sent from the company itself then do not click it. You're likely going to land in a phishing site or a malware site, if not both of these possibilities at the same time.

Check the grey bar that comes up at the bottom left corner to see what the link actually is.

Stay safe guys...