The following is a common email scam I receive. Since I don't have a World of Warcraft account I know this is a scam right away, but if I did have an account this might be fairly convincing. For those that do, this is a heads up.
Original Email Message:
Hello,
This is an automated notification regarding your World of Warcraft account. Your account options was recently modified through the Account Management website.
If you made this change to your subscription type, please disregard this automatic notification.
*** If you did NOT make any changes to your account or subscription, we recommend you login to Account Management at the following link to review your account settings:
http://www.worldofwarcraft.com/account/billing/
If you cannot sign into Account Management using the link above, or if unauthorized changes continue to happen, please contact Blizzard Billing & Account Services for advanced assistance.
Billing & Account Services can be reached at 1-800-59-BLIZZARD (1-800-592-5499 Mon-Fri, 8Am-8PM Pacific Time) or at billing@blizzard.com.
Account security is solely the responsibility of the accountholder. Please be advised that in the event of a compromised account, Blizzard representatives will typically lock the account. In these cases the Account Administration team will require faxed receipt of ID materials before releasing the account for play.
Regards,
The World of Warcraft Support Team
Blizzard Entertainment
http://www.blizzard.com/support/wowindex/
-message end
Note: I have not include the actual links form the email to prevent incidental visits to the phishing site.
Scam Details:
1.Legitimate looking - The message looks fairly legitimate and even uses legitimate data.
2.Fake URLs – The first link in the message is designed to look like a client generated link that takes you to the presented text. It, however, takes you to a different site:
http://www.battle.net-wowsuppormanagement.com/login/...
I did not visit this site, but my guess is that there is a very legitimate looking login form waiting there. At first glance the domain name part looks to be “battle.net” which is Blizzard's actual domain name, however, the real domain name is “net-wowsuppormanagment.com” which has the following Whois data:
Domain Name ..................... net-wowsuppormanagement.com
Name Server ..................... dns23.hichina.com
dns24.hichina.com
Registrant ID ................... hc285425837-cn
Registrant Name ................. zhou ping
Registrant Organization ......... zhou ping
Registrant Address .............. henansheng zhengzhoushi
Registrant City ................. zhengzhou
Registrant Province/State ....... HA
Registrant Postal Code .......... 213654
Registrant Country Code ......... CN
Registrant Phone Number ......... +86.037165862108 -
Registrant Fax .................. +86.037165862108 -
Registrant Email ................ sss1234567@qq.com
Clearly this is falsified data and has nothing to do with Blizzard.
3.Deceptive Header Information – The message's from field says it is from Blizzard Entertainment but if you look at the actual header it says:
From: Blizzard Entertainment "elharkin@googlemail.com"
To: myemail
Subject: Worldofwarcraft Account login
I am pretty sure Blizzard employees don't use googlemail.com accounts. Also a more knowledgeable spammer could have faked the return mail address and made it read a legitimate email, however a quick look at the message source would have revealed the message came from a googlemail.com account, which by the way is not owned by Google but rather some German company.
Watch out people, and know what to look for.