Privacy Ninja

Watch Out: These Unsubscribe Emails Only Lead to Further Spam

Watch Out: These Unsubscribe Emails Only Lead to Further Spam

Scammers use fake ‘unsubscribe’ spam emails to confirm valid email accounts to be used in future phishing and spam campaigns.

For some time, spammers have been sending emails that simply ask if you wish to unsubscribe or subscribe. These emails do not explain what you are unsubscribing or subscribing to and are being used by spammers to verify if the recipient’s email is valid and susceptible to phishing scams and other malicious activity.

The “confirmation” emails use mail subjects, such as “We_need your confirmation asap”, “Request , please confirm your unsubscription”, and “Verification.”

The email messages are very basic, with just colorful boxes containing links asking whether you would like to unsubscribe or subscribe, as shown below.

If you click on the embedded subscribe/unsubscribe links, it will cause your mail client to create a new email that will be sent to many different email addresses under the spammer’s control.

Also Read: Compliance Course Singapore: Spotlight on the 3 Offerings

New email created to verify your email address

When users send the above email, they expect to be unsubscribed from further emails. However, they are actually verifying for the spammers that their email address is valid and being monitored.

Responding leads to more spam

As a test, BleepingComputer created a new email address that we never used on any website or service. Using this email address, we responded to various confirmation emails that we received on another email account. 

After sending unsubscribe/subscribe responses from the new account, in only a few days our new account became bombarded with spam emails.

This test further confirmed that spammers are using these subscribe/unsubscribe emails to refine their mailing lists and verify email addresses susceptible to these types of scams and phishing attacks.

If you receive an email that just simply asks you to subscribe or unsubscribe, ignore it and mark it as spam.

Also Read: PDPA Singapore Guidelines: 16 Key Concepts For Your Business

No legitimate organization will send these types of emails without further explaining what the email is referencing.

Outsourced Data Protection Officer – It is mandatory to appoint a Data Protection Officer. We help our clients quickly comply with their PDPA & data protection requirements.

Vulnerability Assessment Penetration Testing – Find loopholes in your websites, mobile apps or systems.

Smart Contract Audit – Leverage our industry-leading suite of blockchain security analysis tools, combined with hands-on review from our veteran smart contract auditors.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Powered by WhatsApp Chat

× Chat with us