email from "eBay"
Check out this email I got from "eBay" today. Of course I didn't click on any links and I forwarded it to spoof. Anybody else get this?
41 comments
Check out this email I got from "eBay" today. Of course I didn't click on any links and I forwarded it to spoof. Anybody else get this?
chapeau-noir
·3 years agoI've had pages in English come up with a French URL 🤔.
the_fancy_fox
·3 years agoAs long as there’s no click here links in the email, probably legit.
weird though
a_c_green
·3 years agoThere was one embedded link, the one I looked into that pointed to the User Privacy Notice (Thai version). You can cursor over it without clicking on it and your browser will show you the destination. (There were some other standard links visible in the page footer, such as for App Store or Google Play, but those aren't really the links of interest here.)
eburtonlab
·3 years agoAt least one other user got a very similar message in Thai:
https://community.ebay.com/t5/Ask-a-Mentor/Email-I-cannot-read/m-p/33651891/highlight/true#M400517
simply-the-best-for-you
·3 years agoLooks like a legit email from Ebay Thailand. Why you got it & in Thai, who knows, but every now & then our pages come up in German. I had Kanji in one of my messages from a buyer yesterday, though perhaps she had Kanji in her ID. I think it's legit & yet another glitch.
@evry1nositswindy If you hover over the email address, depending on your mail client, you can see full details on who it was sent from. I think this one is legit though & just misrouted.
evry1nositswindy
OP3 years ago@reallynicestamps I just did. It is Thai.
Dear evry1nositswindy,
We are updating User Privacy Notice in accordance with various changes
To make it easier for you to understand what personal information we collect. and to give you more control over your data This is part of our ongoing commitment to being transparent about how we use and keep your information safe. This new update will take effect on March 24, 2023 and you don't need to take any additional action.
Major changes:
Keeping your data safe and increasing transparency about how we use it is important to us.
You can read more about eBay's Privacy Principles and User Privacy Notice at the Privacy Center.
Thank you for being a part of eBay.
eBay Global Privacy Team
Once translated, it looks real. Weird.
a_c_green
·3 years ago...and the embedded link goes to https://www.ebayinc.com/company/privacy-center/th/#subsite-dropdown, which is the Thai version of that page. If you want to see it in French instead, for example, change the "/th/" in that URL to "/fr/" instead, and it will display in French.
I agree that it looks like a language-choice glitch of some sort. I can confirm what others have said about seeing eBay pages suddenly switch to German (in my own experience) for no apparent reason. I suppose there's no reason why they can't accidentally send out messages with a language error the same way. The Thai version of this message that @evry1nositswindy received would be sent out with the Thai language specified in the embedded link.
pburn
·3 years agoSo not a Doppelganger URL, then, eh?
a_c_green
·3 years agoNot that I'm seeing, no.
Incidentally, if you look at the main (English) version of this page at https://www.ebayinc.com/company/privacy-center/ and scroll down a ways there, you will find a list of 17 languages in which eBay offers their basic corporate rules in PDF form. I would say it's likely that most if not all of those 17 languages were used as a master list for the translated forms of the page that were embedded as links in those outbound messages. I was able to bring up a few other language pages in that link we're discussing by guessing the correct two-letter abbreviation in the third field of that link (e.g. "de" gets you German, "es" gets you Spanish and so on):
https://www.ebayinc.com/company/privacy-center/de/#subsite-dropdown
https://www.ebayinc.com/company/privacy-center/es/#subsite-dropdown
albertabrightalberta
·3 years agoThe major difference is that my notice (in English) said "Dear (my first name)" rather than my ebay ID.
reallynicestamps
·3 years agoDid you run the email through a translation program to see what it says?
It is possible that it is from eBay India,though why it would end up with a US seller I have no idea.
Actually, I'm not sure if that is Sanskrit or Thai.
Google has a "identify language" option.
byrd69er
·3 years agoI can't read the menu. Numbered dishes would help.
evry1nositswindy
OP3 years ago@chris13 I clicked around but couldn't find anything about a source code. This one was a no-brainer--can't read it anyway! Others have been quite clever and looked legit.
kensgiftshop
·3 years agoI received one on the 22nd, but it was in English, from Ebay.
ckimodog
·3 years ago@evry1nositswindy
Not me. Just one for me to sign up for a credit card...just what I (don't) need. 🙄
mtgraves7984
·3 years agoIt's the same message I got (only mine was in English) on March 23rd from eBay. Mine was sent to my name, though... not to my user ID.
evry1nositswindy
OP3 years ago@silverstatetreasureboxes Looks like a ransom note from eBay...but they called me love!
silverstatetreasureboxes
·3 years ago@evry1nositswindy
Windy, what the?? Here's a clear version of the translation
 
Good grief, any packages mentioned? 😆
chris13
·3 years agoBe extra careful out there. I worked last week with Trust and Safety regarding a set of URLs where scammers had created 'Doppleganger URLs' that essentially hijacked the top level ebay.com domain format. Its a NASTY tricky way to spoof a URL, and not easy for everyone to spot...it was the *leading* characters that gave it away e.g. "foo.bar.ebay.com/xyz" Sometimes this is called 'dot spoofing'
This email address uses the same technique I believe.
For years IT folks have been lobbying to get the domain registration authority to put a stop to this, but to no avail.
pburn
·3 years agoSo this and taking down a seller with 41,000+ listings?
Does Trust and Safety know you're posting about it on the public discussion boards?
chris13
·3 years agoSame issue. Doppleganger URLs in every listing directing people offsite to collect 'BIN' payments.
I showed how it looks, but not how it works or how to configure it. It requires a LOT of backend setup to make these work, its not a do-it-yourself kind of thing. There's also public info how to detect it, feel free to google 'Doppleganger Domain' it's on Wikipedia. I'd bet the seller's acct was hacked. I'm always happy to comply with any official request to be quiet about how scams work, FWIW. I did edit myself to not disclose specifics.
pburn
·3 years agoIs that what happened to the OP, because her thread is about the email s/he received.
It would be great if you'd post a new thread about your work with Trust and Safety, explaining all the ins and outs of your URL investigation and the takedown.
a_c_green
·3 years agoI think you mean "ebay.com.foo.bar.com/xyz" here, yes? The faked domain comes first. It appears at a glance to link to ebay.com, but actually goes to bar.com, where there's a server at ebay.com.foo that's ready to display a fake login page named xyz.html.
chris13
·3 years ago@a_c_green No, actually, I dont.
@pburn Did I do something to irritate you? You posted 'this came from ebay thailand" which was not correct, IMHO.
I replied with an explanation that the suffix 'ebay.th' does not indicate it comes from ebay. You have to evaluate the fully qualified domain name/address to be sure. The OP to answer your question, received an email showing a source that suggests this IS what was used to send the email he/she got.
When I raise technical issues I show my work and share my experience. I am not always right, but I have no agenda. Hopefully someone benefits from knowing more about the ever-evolving techniques being used to be dishonest. If not, my apologies for interrupting the thread. Have a great day.
chapeau-noir
·3 years agoI also wondered the same thing about source code, and found your post interesting and informative, and very germane.
evelyb30
·3 years agoWe old doggies know to spot it, but somebody on a phone..good luck with that. (old fart credentials: drum memory, computer tape reels, punch cards, and foo.bar as a generic filename.)
evry1nositswindy
OP3 years ago@evelyb30 **bleep** means something else to me!
evry1nositswindy
OP3 years agoalternate spelling of foo.bar is bleeped?? Really? You have to be old to know what it means.
evry1nositswindy
OP3 years ago@pburn
From:
ebay@communications.ebay.co.th
pburn
·3 years agoSo, you got your email from the eBay Thailand platform? How weird!
evry1nositswindy
OP3 years ago@chapeau-noir I'm not a techie--what is source code?
chapeau-noir
·3 years agoI'm assuming that came into your email, too - there you should be able to find a 'view source' button or link depending if you use webmail or a client like Thunderbird (say). It just shows the email origin domain and path - sometimes it can help figuring out where something came from and if it's legit.
evry1nositswindy
OP3 years ago@chapeau-noir Sorry I don't see anything like that. Yes, it came through my regular email account on my desktop (not gmail).
slippinjimmy
·3 years agoHaven't seen that one. I think my phishing friends have better skills and only correspond in English.
I run with zero spam filtering, I get a couple a week from "eBay" plus 10 - 20 more for other targets (Norton, Chase, Amazon, Coinbase etc.), a few times a year I still get the classic Nigerian 419 messages.
I forward all eBay related ones to spoof@ebay.com, I'm not that diligent on the others.
evelyb30
·3 years agoI miss the 419 scammers. They were funny. The one that still makes me laugh came from some guy taking apart a railroad in Sierra Leone or similar and wanted to sell me the scrap steel. I always wanted to write back and tell him sorry, full up; just bought an entire bridge closer to home!
itsjustasprain
·3 years agoNot looking like that, no. Anyway, here's your English translation, courtesy of Google Image Translation:
It's far from perfect and I'm not sure what language it's translated from (Thai? Cambodian?), but the results speak for themselves. (We couldn't even imagine this stuff just a few years ago.) eBay seems to have an odd idea about what country you're in.
chapeau-noir
·3 years agoOut of curiosity, what's the source code look like?
richard1rst
·3 years agoProbably in the same vein I have received 3 in the past month telling me that 5 of my listings had invalid http: coding (where of course it should be https:) along with a link telling which 5 they are,.
Like you I simply forwarded it to Spoof.
I do know that id you hover your mouse over the link then the lower left corner of your screen will show you the landing page of the link. Each one was different. Interestingly all of them said "5 listings" and the text seemed identical. I can only guess they are working off of some template.
The world is filled with charlatans.
pburn
·3 years ago@evry1nositswindy
What was the email address like? Was it from some spoofy domain name, etc.?
Did you, by any chance, copy/paste that into a translator? Google's probably the most accessible, even if it's not the very best translation software.
If so, tell us what it said! LOL!
dbfolks166mt
·3 years agoIt wouldn't have mattered if I had, which I didn't, I can't read it anyway. 😃
mtgraves7984
·3 years agoNo, I didn't. And I wouldn't have clicked links, either. Honest to Pete...