numansyed2212 Posted March 2, 2016 Share Posted March 2, 2016 I receive 2 emails from Fiverr that i have Got orders, but nothing in my Dashboard… I got emails from this email address, noreply@e.fiverr.com And the link provided in that ishttp://www.five**.com.ru/linker/?order_id=FO4B836727&view=orderhttp://www.five.com.ru/linker?order_id=FO4**B836727&view=orderIf i open the Root domain It redirects to Payoneer Account Page. While opening above link takes me to a login page. I m attaching the screenshots for both Emails. Order numbers provided in emails areOrder #FO466B836727Order #FO466B836727Beware of this kind of Emails, that might be a phishing attack. Keep Your Email address Safe, and Report instantly if you found any Email related to it.Moderator Note: The exact links have parts removed to ensure no one will go to an unsafe link. Link to comment Share on other sites More sharing options...
theratypist Posted March 2, 2016 Share Posted March 2, 2016 Thank you for sharing this! Hope everyone will be informed so no one will fall victim to this. Link to comment Share on other sites More sharing options...
numansyed2212 Posted March 2, 2016 Author Share Posted March 2, 2016 The Login Screen is just same as of Fiverr original one. Have a look at the attached screenshot for the Phishing Page.http://i.imgur.com/f3Dqbsg.jpgf3Dqbsg.jpg1531×761 Link to comment Share on other sites More sharing options...
jonbaas Posted March 2, 2016 Share Posted March 2, 2016 The “.com.ru” domain extension is a dead giveaway to the spam nature of those links. This places the copy-cat domain in Russia, as “.com.ru” represents the Russian Federation. Legitimate Fiverr links will always be “fiver.com” – nothing else. Subdomain elements might exist before the name, but nothing after the .com…Don’t fooled by pretenders. Fiverr is not a Russian company, nor does it have a Russian domain. Link to comment Share on other sites More sharing options...
adsensewizard Posted March 2, 2016 Share Posted March 2, 2016 Thanks for the heads up! Wonder how they got your mail address that is associated to your Fiverr account? You might want to change that address, if possible. Link to comment Share on other sites More sharing options...
Anna Posted March 2, 2016 Share Posted March 2, 2016 You should consider submitting a ticket to CS to let them know. Just in case! Thanks for sharing. Link to comment Share on other sites More sharing options...
magellon Posted March 2, 2016 Share Posted March 2, 2016 Thanks for sharing numansyed2212 and for the additional details jonbaasIf I may ask a question, what happens if you follow through? I clicked on the links and it just goes to my dashboard. Perhaps CS has already done something about it. Link to comment Share on other sites More sharing options...
misscrystal Posted March 2, 2016 Share Posted March 2, 2016 I see no way to tell the difference aside from the message: “You session has expired. Please login again.” The links I am seeing do not end in com.ru. Maybe they’ve been change recently. Thanks for the warning. Link to comment Share on other sites More sharing options...
jonbaas Posted March 2, 2016 Share Posted March 2, 2016 I’m guessing that Fiverr put a redirect in place to protect users. Link to comment Share on other sites More sharing options...
frostypinkyph Posted March 2, 2016 Share Posted March 2, 2016 Main website has SSL (Secure Socket Layer) the green lock icon besides the address… except for its subdomain. Link to comment Share on other sites More sharing options...
signature19 Posted March 3, 2016 Share Posted March 3, 2016 Thank you for the heads up.BTW, here is a piece of advice. I never ever click a link from the emails that I get from fiverr. If I receive an email saying I have a new order/inquiry, I would directly login to my account from fiverr.com and check it. Or if I’m on mobile, I will always to go the app to see what’s up.That’s the simplest thing everyone can do to protect yourself from phishing attacks.Hope this helps. 🙂 Link to comment Share on other sites More sharing options...
lesmeursault Posted March 3, 2016 Share Posted March 3, 2016 Thank you for the heads up! Link to comment Share on other sites More sharing options...
magellon Posted March 3, 2016 Share Posted March 3, 2016 Yes, that´s wise. I do the same as well 🙂 Link to comment Share on other sites More sharing options...
numansyed2212 Posted March 3, 2016 Author Share Posted March 3, 2016 Already notified Fiverr Safety Team, and they told that will look after this Phishing attempt. Link to comment Share on other sites More sharing options...
numansyed2212 Posted March 3, 2016 Author Share Posted March 3, 2016 Just don’t enter your Login Credentials on this Page, as they will stole your Private information and they can Misuse about it. Link to comment Share on other sites More sharing options...
numansyed2212 Posted March 3, 2016 Author Share Posted March 3, 2016 As you can See Moderator Note on the Post, that they have Changed the links to protect users from Going to unsafe site. Link to comment Share on other sites More sharing options...
mudasir84 Posted March 8, 2016 Share Posted March 8, 2016 thanks for sharing '‘Beware of Phishing Attack’'today i also receive a fake order e-mail from fiverr.com.ru Link to comment Share on other sites More sharing options...
catharine0940 Posted March 25, 2016 Share Posted March 25, 2016 I click on the link and it ask for login. To my surprise I got the email to email address which is not associated with Fiverr.Can they steal credentials which are saved in my browser? Link to comment Share on other sites More sharing options...
catharine0940 Posted March 25, 2016 Share Posted March 25, 2016 Update: Below are Email details which I received. Hope it will help.========================================Subject: Fiverr: Congrats! You have a new order from ashley19s.X-PHP-Script: www.djamaa-el-djazair.com/site/rsp.php for 41.142.167.86From: Fiverr <noreply@e.fiverr.com>Received: from suzuki.websitewelcome.com ([192.185.2.175])by cm4.websitewelcome.com withid aBql1s00J3mZUjk01Bqmwy; Fri, 25 Mar 2016 06:50:46 -0500Received: from djamaa by suzuki.websitewelcome.com with local (Exim 4.86_1)X-AntiAbuse: Primary Hostname - suzuki.websitewelcome.comX-AntiAbuse: Original Domain - gmail.comX-AntiAbuse: Sender Address Domain - suzuki.websitewelcome.comX-Source-Dir: djamaa-el-djazair.com:/public_html/siteX-Source-Sender:X-Source-Auth: djamaa Link to comment Share on other sites More sharing options...
adelinewinata Posted March 26, 2016 Share Posted March 26, 2016 Wow, is this why when I go to Fiverr a few days ago it asked me to log in again? (I never log out of my account). Thankfully I didn’t check the URL in the email, I directly went to fiverr.com and logged in. Thanks for the tip! Link to comment Share on other sites More sharing options...
heatherwrites Posted March 26, 2016 Share Posted March 26, 2016 This is Serious! Link to comment Share on other sites More sharing options...
z_farrukh Posted March 26, 2016 Share Posted March 26, 2016 Wow! This is bad! Thanks for the warning. Link to comment Share on other sites More sharing options...
seochick786 Posted March 26, 2016 Share Posted March 26, 2016 We can’t thank you enough for sharing this thing. We’d no idea it could happen here at fiverr. Link to comment Share on other sites More sharing options...
seochick786 Posted March 26, 2016 Share Posted March 26, 2016 If you’d clicked on the phishing link then you have already been hacked I guess. Because your password reaches to a hacker as you click on any phishing link. Link to comment Share on other sites More sharing options...
numansyed2212 Posted April 24, 2016 Author Share Posted April 24, 2016 Hope that you didn’t click anywhere on that email, and report it as Phishing. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.