CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 927
Comments: 25
block bottom
spacer spacer
image Advisories!: Beware 800-320-9807 is a Verizon VOIP Phish image
Phishing
The normal definition for a Vish or VOIP Phish is a dialer which has been set up on a VOIP line and is calling out to numbers in a given area. In this case the Vish was not a call that was made, but a text message which was sent to the phone. Wikipedia says VOIP Spam is "as-yet non-existent problem". Given what transpired today I tend to believe it is the next up and coming abuse in a wave of what is to come as technology grows.

Anyone who has a cell coverage through Verizon and gets text messages from Verizon knows the subject line of the message says: Free VZW MSG. When you see that you expect it has something to do with your account. I generally get a message when our bill is ready to be reviewed and also again to confirm payment has been received. When we get a txt message from Verizon, both Paul and I get it, as my phone is the secondary line on the account. Had he also gotten a message, I would not have checked my phone until much later, but since he didn't and the subject line made it appear to be from Verizon I was curious. I was very surprised to read I had exceeded our text messaging quota despite the fact that we have unlimited txt messaging in our package.

The following is the actual txt message I received on my phone:
From:900080003360
Free VZW MSG. U have exceeded ur TXT allowance. Have acct. holder call 2 day@ 800-320-9807 & increase ur messaging pkg 2 help u save. Rply Q 2 opt out.
Call:8003209807
4:55 pm 2/8/07
Red Flags:

1. When you get a text message from a Company, they don't generally text you in computereez shorthand.

2. If they want you to call back they will use a number which is actually registered to them. This number isn't listed in any state as belonging to Verizon.

So if you get a text message on your phone telling you to call because you are over limit, what do you do?

First you can look up toll free numbers which are supposed to be registered to major companies online. If it doesn't show up there, go ahead and call up the company. You will want to report the text message to them. Don't delete it. Deleting the text message is actually getting rid of evidence. The company will need the information from the text message to be able to file a complaint with the FBI. Keep the message (evidence) at least until after you talk to them, so you have it if they want you to forward it to them.

What you should not do is call the number back. It is possible, through social engineering techniques, for them to get other information out of you which they could exploit, even if you don't give them your credit card number. By calling them back you are also alerting them to the fact that your phone number works. VOIP Spam is no different then email spam, once they know there is someone on the other end, your address or in this case phone number will start to be circulated, thus opening you up to many more scams.

Update: While I was writing this article, Paul actually called the number and discovered there is a human being on the other end of the phone. We didn't want to ask anything because Verizon and Law Enforcement are looking into this, but we did take a recording of the person answering the phone which is attached here as wav file.

I also called Verizon Tech support and had them confirm that we do indeed have unlimited text messaging. They looked up the number in an effort to confirm whether or not it was a Verizon number and were unable to find a listing.

Note: Updated 7:16 PM EST
Posted on Thursday, 08 February 2007 @ 18:39:37 UTC by Robin (5695 reads)
[ Trackback ]
image

"Advisories!: Beware 800-320-9807 is a Verizon VOIP Phish" | Login/Create an Account | 6 comments | Search
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

INCORRECT: 800-320-9807 is not a Verizon VOIP Phish (Score: 1)
by JNels  on Thursday, 22 February 2007 @ 16:41:35 UTC
(User Info | Send a Message)
As the PR guy for Verizon Wireless (you can email me directly if you need to, at Jeffrey.Nelson@verizonwireless.com) let me note:

The following is a legitimate Verizon Wireless text message and not a phishing scam:

Primary Line Message:

Free VZW MSG: 1 of UR lines has exceeded UR TXT msg allowance. Call 2day @ 800-320-9807 2 increase UR msg bundle 2 help U save. Reply Q 2 opt out.

Secondary Line Message:

Free VZW MSG: U have exceeded UR TXT msg allowance. Have acct holder call 2 day @ 800-320-9807 2 increase UR msg bundle 2 help U save. Reply Q 2 opt out.

Maybe we tried to be too cool with the TXT shorthand lingo. But:

The 800 number is a Verizon Wireless number that currently rings to a call center working on our behalf. If you call, you will be advised of the fact that you have exceeded your current TXT message allowance (for messages to non-Verizon Wireless customers) and given the opportunity to adjust your TXT package based on your usage to avoid unexpected overage fees.

In addition, please note that text messages between Verizon Wireless subscribers are unlimited, however, limits do apply to messages between subscribers.

JNels



Re: Beware 800-320-9807 is a Verizon VOIP Phish (Score: 1)
by Paul  on Wednesday, 23 May 2007 @ 17:17:47 UTC
(User Info | Send a Message | _JOURNAL) http://www.laudanski.com
To this day Verizon has never officially confirmed this number as being legit. Beware this number.



Recording text message records (Score: 1)
by benjaminwright  on Thursday, 10 April 2008 @ 16:33:54 UTC
(User Info | Send a Message) http://hack-igations.blogspot.com/2008/04/text-message-investigations.html
Robin: People can use voice signatures to preserve electronic records (such as text messages) as potential evidence [hack-igations.blogspot.com] for legal proceedings. --Ben


 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· HotScripts
· W3 Consortium
· Spam Cop
· More about Phishing
· News by Robin


Most read story about Phishing:
False PayPal Charges!

block bottom
Article Rating
spacer
Average Score: 3.75
Votes: 8


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer