<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>This topic</title>
    <link>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2200446#M1193291</link>
    <description>&lt;P&gt;Yes I've just had this too, today. How do spammers know my account number? I checked my DD and it's still working.&lt;/P&gt;&lt;P&gt;Jude&lt;/P&gt;</description>
    <pubDate>Mon, 13 Dec 2021 11:21:55 GMT</pubDate>
    <dc:creator>judex</dc:creator>
    <dc:date>2021-12-13T11:21:55Z</dc:date>
    <item>
      <title>Phishing email received quotes part acc</title>
      <link>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2200342#M1193286</link>
      <description>&lt;P&gt;Hello. If this is not the correct place for the enquiry please feel free to move it.&lt;/P&gt;&lt;P&gt;I received a legit looking email stating my direct debit is no longer active. It contains actual BT links but BT confirmed on call it was not sent by them.&lt;/P&gt;&lt;P&gt;Also checked BT account and bank account online and DD still active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Issue is that mail correctly quotes last 4 digits of my BT account, which is concerning. Assuming this is all any scammer has but still an issue&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have forwarded to phishing@bt com.&lt;/P&gt;&lt;P&gt;Has anyone else had this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 16:55:00 GMT</pubDate>
      <guid>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2200342#M1193286</guid>
      <dc:creator>RPendrigh</dc:creator>
      <dc:date>2021-12-12T16:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing email received quotes part acc</title>
      <link>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2200343#M1193287</link>
      <description>&lt;P&gt;&lt;a href="https://community.bt.com/t5/user/viewprofilepage/user-id/297240"&gt;@RPendrigh&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The spammer would have sent thousands of these emails, changing the last four digits each time, in the hope of catching someone out. There would only be a certain combination of those four digits.&lt;/P&gt;
&lt;P&gt;Provided you did not click on any of the links, you should be fine.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 17:06:21 GMT</pubDate>
      <guid>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2200343#M1193287</guid>
      <dc:creator>Keith_Beddoe</dc:creator>
      <dc:date>2021-12-12T17:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing email received quotes part acc</title>
      <link>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2200345#M1193288</link>
      <description>&lt;P&gt;See links&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.bt.com/t5/Announcements-Guides-Community/Scam-Alert-Phishing-email-pretending-to-come-from-BT-Billing/td-p/2121966" target="_blank" rel="noopener"&gt;https://community.bt.com/t5/Announcements-Guides-Community/Scam-Alert-Phishing-email-pretending-to-come-from-BT-Billing/td-p/2121966&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.bt.com/t5/Bills-Packages/Scam-Alert-Phishing-email-related-to-updating-your-BT-payment/td-p/2102854" target="_blank" rel="noopener"&gt;Scam Alert! Phishing email related to updating you... - BT Community&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.bt.com/t5/Announcements-Guides-Community/Scam-Alert-Update-your-account-info/td-p/2071276" target="_blank" rel="noopener"&gt;Scam Alert! Update your account info - BT Community&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.bt.com/t5/Announcements-Guides-Community/Scam-alert-Phishing-attempt-related-to-BT-billing/td-p/2055546" target="_blank" rel="noopener"&gt;https://community.bt.com/t5/Announcements-Guides-Community/Scam-alert-Phishing-attempt-related-to-BT-billing/td-p/2055546&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.bt.com/t5/Announcements-Guides-Community/Scam-Alert-Update-your-account-info/td-p/2071276" target="_blank"&gt;https://community.bt.com/t5/Announcements-Guides-Community/Scam-Alert-Update-your-account-info/td-p/2071276&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 17:18:42 GMT</pubDate>
      <guid>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2200345#M1193288</guid>
      <dc:creator>gg30340</dc:creator>
      <dc:date>2021-12-12T17:18:42Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing email received quotes part acc</title>
      <link>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2200350#M1193289</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply. Thinking about it you're probably right.&lt;/P&gt;&lt;P&gt;I had a similar attempt about 6 months ago but the account they quoted was completely wrong (they tried quoting the whole thing)&lt;/P&gt;&lt;P&gt;Still seems quite scary that the scammers randomly managed to get my email and part of the acc number right though.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 17:30:31 GMT</pubDate>
      <guid>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2200350#M1193289</guid>
      <dc:creator>RPendrigh</dc:creator>
      <dc:date>2021-12-12T17:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing email received quotes part acc</title>
      <link>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2200352#M1193290</link>
      <description>&lt;P&gt;&lt;a href="https://community.bt.com/t5/user/viewprofilepage/user-id/297240"&gt;@RPendrigh&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;They could have "farmed" your email from anywhere you may have posted it, or one of your contacts has had their email account compromised and their contact list stolen.&lt;/P&gt;
&lt;P&gt;Its easy to create scripts to send out thousands of emails from a open SMTP server.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 17:39:07 GMT</pubDate>
      <guid>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2200352#M1193290</guid>
      <dc:creator>Keith_Beddoe</dc:creator>
      <dc:date>2021-12-12T17:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing email received quotes part acc</title>
      <link>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2200446#M1193291</link>
      <description>&lt;P&gt;Yes I've just had this too, today. How do spammers know my account number? I checked my DD and it's still working.&lt;/P&gt;&lt;P&gt;Jude&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 11:21:55 GMT</pubDate>
      <guid>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2200446#M1193291</guid>
      <dc:creator>judex</dc:creator>
      <dc:date>2021-12-13T11:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing email received quotes part acc</title>
      <link>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2200448#M1193292</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.bt.com/t5/user/viewprofilepage/user-id/79819"&gt;@judex&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;Yes I've just had this too, today. How do spammers know my account number? I checked my DD and it's still working.&lt;/P&gt;
&lt;P&gt;Jude&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;They do not need to know, all they do is to send out thousands of emails with different four digit numbers, and they are bound to catch someone out. And they would divulge their bank details.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 11:29:16 GMT</pubDate>
      <guid>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2200448#M1193292</guid>
      <dc:creator>Keith_Beddoe</dc:creator>
      <dc:date>2021-12-13T11:29:16Z</dc:date>
    </item>
    <item>
      <title>Phishing Attempt - contained valid account data</title>
      <link>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201253#M1193293</link>
      <description>&lt;P&gt;I have raised this issue with the BT Data Protection team at the start of the week, but thus far they have failed to respond.&lt;/P&gt;&lt;P&gt;Over the weekend I got a Phish asking me to update my direct debit details for BT, there were some obvious issues highlighting it was a phish, including mentioning the wrong ISP in the text. However the concerning thing is they included the last four digits of an account number, normally you'd notice these don't match but in this case they were the last four digits of a BT account I had until 2019 and it was sent to the e-mail address registered for that account.&lt;/P&gt;&lt;P&gt;Anyone else had this?&lt;/P&gt;&lt;P&gt;BT/BT Mods can you check this is being investigated? Unless it was sheer fluke they guessed the number then there are only two places those numbers could have come from BT or my e-mail provider.&lt;/P&gt;&lt;P&gt;Concerning that there is a potential data leak here and yet no response from BT in four days.&lt;/P&gt;&lt;P&gt;Screen shot below - numbers removed from image.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BT_phish.jpg" style="width: 480px;"&gt;&lt;img src="https://community.bt.com/t5/image/serverpage/image-id/75575i70F08C886AD08ED7/image-size/large?v=v2&amp;amp;px=999" role="button" title="BT_phish.jpg" alt="BT_phish.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 13:10:07 GMT</pubDate>
      <guid>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201253#M1193293</guid>
      <dc:creator>Adam_G</dc:creator>
      <dc:date>2021-12-16T13:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing Attempt - contained valid account data</title>
      <link>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201255#M1193294</link>
      <description>&lt;P&gt;Adam_G&lt;/P&gt;
&lt;P&gt;I have moved you onto this thread to save having to repeat everything.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 13:15:48 GMT</pubDate>
      <guid>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201255#M1193294</guid>
      <dc:creator>gg30340</dc:creator>
      <dc:date>2021-12-16T13:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing Attempt - contained valid account data</title>
      <link>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201264#M1193295</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.bt.com/t5/user/viewprofilepage/user-id/104648"&gt;@gg30340&lt;/a&gt;&amp;nbsp;I'd not noticed this one.&lt;/P&gt;&lt;P&gt;So there are others who have had the same thing on the same day by the looks of it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on that I do not buy the phisher got lucky, so lets ignore getting a valid e-mail for a BT customer (mine is not a BT e-mail address) there is a 1 in 10,000 chance of getting one right, so getting multiple ones right in the same day is more than just chance/luck.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So can we disregard the luck/chance and BT look into the fact that it looks like someone has got hold of this data from either their systems or an e-mail platform?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 14:10:42 GMT</pubDate>
      <guid>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201264#M1193295</guid>
      <dc:creator>Adam_G</dc:creator>
      <dc:date>2021-12-16T14:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing Attempt - contained valid account data</title>
      <link>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201302#M1193296</link>
      <description>&lt;P&gt;The type of email you have received has been circulating for years. It is not just BT customers who receive them nor is it only the BT ISP header that is used in the scam. Other ISPs also get named in the same type of email and or texts.&lt;/P&gt;
&lt;P&gt;It has been put to BT in the past that their systems have been compromised and that it may be that some of their staff may be selling/using customers details for illegal purposes. This was denied.&lt;/P&gt;
&lt;P&gt;I can not recall what the exact content of the denial was but it was along the lines of it being a coincidence.&lt;/P&gt;
&lt;P&gt;Looking at the email you received if the scammer actually had your account details why wouldn't the scammer use your name in the email which would make it look more genuine and as in your email why would they tell you to use a Vodaphone app or call free from your Vodaphone mobile if they clearly know that you are a BT customer.&lt;/P&gt;
&lt;P&gt;I also doubt that a human is actually sending out these emails, albeit that the program will have been set up and set to run by a human,&amp;nbsp;they will be computer generated in their thousands if not millions and given that they only have to generate four random digits, they are bound to come up with the right numbers for some of the six million BT customers account at some point.&lt;/P&gt;
&lt;P&gt;In any event, I am not hear to defend BT or any other ISP so I will look forward to hearing how you get on with your complaint.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 17:44:27 GMT</pubDate>
      <guid>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201302#M1193296</guid>
      <dc:creator>gg30340</dc:creator>
      <dc:date>2021-12-16T17:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing Attempt - contained valid account data</title>
      <link>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201306#M1193297</link>
      <description>&lt;P&gt;&lt;a href="https://community.bt.com/t5/user/viewprofilepage/user-id/104648"&gt;@gg30340&lt;/a&gt;&amp;nbsp; Perhaps I should have made it clear I work in the industry and I know a lot on this subject/area.&lt;/P&gt;&lt;P&gt;If you wish to believe that multiple people getting an email on the same day with the correct last four characters of the account number on is luck/random then I suggest you go and get a lottery ticket, the odds are similar.&lt;/P&gt;&lt;P&gt;The person or system sending these may only have some details but they clearly have some BT data. It seems the BT mods/BT wish to bury their heads in the sand too on this one. I have given BT 5 working days to respond that ends tomorrow so the ICO will be asked.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 17:50:12 GMT</pubDate>
      <guid>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201306#M1193297</guid>
      <dc:creator>Adam_G</dc:creator>
      <dc:date>2021-12-16T17:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing Attempt - contained valid account data</title>
      <link>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201309#M1193298</link>
      <description>&lt;P&gt;I don't believe one way or the other. I was just putting forward some information however as you have made it clear that you know a lot about this and the odds of winning the lottery I will happily bow out of this thread.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 18:03:29 GMT</pubDate>
      <guid>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201309#M1193298</guid>
      <dc:creator>gg30340</dc:creator>
      <dc:date>2021-12-16T18:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing Attempt - contained valid account data</title>
      <link>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201320#M1193299</link>
      <description>&lt;P&gt;&lt;a href="https://community.bt.com/t5/user/viewprofilepage/user-id/292738"&gt;@Adam_G&lt;/a&gt;&amp;nbsp;&amp;amp;&amp;nbsp;&lt;a href="https://community.bt.com/t5/user/viewprofilepage/user-id/297240"&gt;@RPendrigh&lt;/a&gt;&amp;nbsp;I've just come across your thread this evening and can fully appreciate your concerns. I'd like to highlight this matter and will send you both a private message in a moment so you can send over your details.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Neil&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 18:54:07 GMT</pubDate>
      <guid>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201320#M1193299</guid>
      <dc:creator>NeilO</dc:creator>
      <dc:date>2021-12-16T18:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing Attempt - contained valid account data</title>
      <link>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201349#M1193300</link>
      <description>&lt;P&gt;I have sent a reply to PM, hopefully this can be resolved quickly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ta&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 21:03:20 GMT</pubDate>
      <guid>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201349#M1193300</guid>
      <dc:creator>RPendrigh</dc:creator>
      <dc:date>2021-12-16T21:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing Attempt - contained valid account data</title>
      <link>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201378#M1193301</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.bt.com/t5/user/viewprofilepage/user-id/128692"&gt;@NeilO&lt;/a&gt; ,details sent in response to your private message.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Dec 2021 08:54:26 GMT</pubDate>
      <guid>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201378#M1193301</guid>
      <dc:creator>Adam_G</dc:creator>
      <dc:date>2021-12-17T08:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing Attempt - contained valid account data</title>
      <link>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201446#M1193302</link>
      <description>&lt;P&gt;I've been forwarding these emails to BT (I've received several similar over the last few weeks) but never had a response of course.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Dec 2021 13:48:55 GMT</pubDate>
      <guid>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201446#M1193302</guid>
      <dc:creator>judex</dc:creator>
      <dc:date>2021-12-17T13:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing Attempt - contained valid account data</title>
      <link>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201447#M1193303</link>
      <description>&lt;P&gt;&lt;a href="https://community.bt.com/t5/user/viewprofilepage/user-id/128692"&gt;@NeilO&lt;/a&gt;&amp;nbsp;- can you send a private message to &amp;nbsp;&lt;a href="https://community.bt.com/t5/user/viewprofilepage/user-id/79819"&gt;@judex&lt;/a&gt;&amp;nbsp; As well so you have the details from the three of us who have seen this issue?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Dec 2021 13:52:08 GMT</pubDate>
      <guid>https://community.bt.com/t5/Archive-Staging/Phishing-email-received-quotes-part-acc/m-p/2201447#M1193303</guid>
      <dc:creator>Adam_G</dc:creator>
      <dc:date>2021-12-17T13:52:08Z</dc:date>
    </item>
  </channel>
</rss>

