Alert! Very very sneaky phishing scam luring the charitable and the proud.!

in #scam6 years ago

The user @gtg.witnesses is a spoof scammer who tried to lure me into a phishing scam.

He gets to the ego part of the brain by posting on a thread that your work is plagiarized but the link he provides brings up a totally unrelated story, in steemit. Weird right? Oh then I am logged out for some reason. So it asks me to login again.

I looked up at the url in the browser and his link brought me to “steemil.com”. Which is an illegal spoof/ copy of steemit!!

Dangerous!

The worst part is he posted this on a heartfelt project of mine, one that has to do with helping others. This bozo is ruining it.

Check it out
🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨
6BD9E248-DC46-4628-936C-E63345BACB04.jpeg
🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨

Sort:  

A proverb in my local language says "When smart guys die smart guys bury them." I wonder why some people wont try to work hard to earn a name. Glad you caught him at it @lorilikes.

I posted a summary version:

https://steemit.com/steemit/@freedomshift/steemit-security-keys-and-scam-alert-how-to-be-safe-from-scammers-condensed-summary-version

These are the points for security to not suffer scams or attacks or losses:

  1. keep your master password safe - see FAQ
  2. keep your owner key safe - see FAQ
  3. do NOT log in with your master password <<< My recommendation from reading about the scam alert
  4. log in with your Private Posting Key only when you are posting or commenting
  5. provide your Private Active Key only when you are transferring or trading (buy or sell) Steem or SBD

dang I would have clicked on that. Thanks for the warning.

Hey Lori, there are too many of these scams on steemit right now. I learnt something yesterday which is to use our posting key to login on steemit and not to use our master password. I never thought about it before but we don't really need to use that master password on a daily basis and our account is safer! I am attaching a link to @simplymike post about being hacked that I think will be good for all users to read. If you don't want to click the link because this post is about clicking dodgy links you can just go to his blog and read it there.
https://steemit.com/mapsters/@simplymike/the-most-important-thing-i-ve-learned-from-getting-hacked

Thank you Lucy this is very helpful. 🎀

That's weird, We should all start flagging this user @gtg.witnesses. As this user causing the problems on Steemit.
If the reputation of that user will go below 10 then I don't think that anyone will pay attention to the comment he (that user) will post.
So I suggest all of you to please visit the blog of that user & flag his/her comments specialy whales please! So that other users will not get into a problem.
And thanks @lorilikes for updating us!

Good catch. My feed is full of people falling (or not falling) for these fake sites. It seems to have taken off in the last week.

A good rule of thumb is only login to the site if you directly type into the URL and be very suspicious if you are "logged off suddenly"

yes! Perfect.

I had a similar thing posted on one of my posts today. It said I plagiarized as well. Nope, my stuff is all original or sourced. Glad you caught it and didn't give the account away!

They play into the psychological soft spots in all of us. Of course someone writing good content will defend their originality, so it’s almost an easy hook, line and sinker. But not me!! Not my smart friends! Tell the scammers to take a hike. Right? 🎀

I tried posting a response, but Busy lost it.

I was upset about it too. I saw that link and I really wanted to click it, but I decided that wouldn't be a good idea.

wow.. thanks for sharing this it is really a great help of yours to aware us about that.

Resteemed so other people on steemit can also know about that.

that's Weird, The worst part is he posted this on a heartfelt project of your,

Thanks for your call i hope people don't fall in traps like that. Regards

We must be always be careful. Scammers already penetrated Steemit and we know that they are pain in the ass. We must always be vigilant and don't pay attention to people we don't know. Thanks for sharing this @lorilikes

Thanks for creating this awareness to all of us. Am glad you caught him

this is the person I mentioned in my post how many watches.
this is very unheard of.
this is a big offense.
I've reported some fake accounts.
hopefully no more accounts that damage the image of steemit.

a very good post @lorilikes.

this can help many people.

Thanks bud

You are welcome

I find it interesting that the same account has popped up in one of my last bits of research. Apparently, he's really getting around.

And what was the topic of that research?

Digging around in the upper echelons of the steem blockchain looking for accounts which show unusual patterns of transfer relationships, votes, actual funds transfers, etc. In this particular instance, it was specifically looking at patterns of power down transfers in the process of working out a historical measure of steem per mvests.

But you could pretty easily flip back a couple of days and read that whole article. Though I don't make any promises that your eyes won't glaze over.

Doh! 🤦🏼‍♀️ Yes I will read up. Now.

I am nothing if not a constant font of useless information. :P

this is very dangerous.
I've also had an account with a great person's name.
they should be reported
that they may be rewarded.
this is defamation.

thank you for your post @lorilikes.
this is very helpful.

Why should they be rewarded?

Geez .
what is their goal to create a fake account?
are they not afraid of punishment?
they are very dangerous ,, this can not be left
they must be removed from steemit

this is very evil

I am resteem your pos @lorilikes

Because of this post many steemian are able to protect themselves from this scam. You are saving many peoples accounts . Greate work @lorilikes.

oh no, they are very evil and dangerous, we must be careful friend, thank you for sharing the information

this is very dangerous and can not be tolerated.
there are still many bad people around us even though we are doing good deeds.

@gtg.witnesses account is a fake account and the account manager is irresponsible person.

Thanks a lot this is such a awareness post,people like you are doing awesome job and saving our community.

Nice post friend, thanks for sharing

Which part was the nicest?

With the posts he shares, we know that this has happened, so I am grateful

Fair enough. FYI, "he" is actually a "she" and doesn't prefer to be called a man. Just a heads up. ;)

False accounts of top named someone else very disturbing other users. Very dear, why should anyone with these heinous disfigure others?
We must mewaspadanya.
Thanks @lorilikes postings which are useful to be aware of him.

Dear @lorilikes
Visite to my blog me please

Wow awesome, I really appreciate your work. And you post is knowledgefull so I resteem it for other users. Thanks

@lorilikes steemit algorithm does'nt have plagiarism check?

Sometimes the cheetah is also doing the same thing.
My friends and I have experienced it.
Even my friends said plagiarsm, cheetah and bring my friends to link that is considered the source by cheetah.
But the funniest thing is a link that directed by the cheetah is youtube, and when on the go to youtube did not have videos of any kind.
Even my friends that wrote the article but why the cheetah says plagiarsm from youtube? Really very funny

I will now witness upvote you mam.

the reason why is this happen to you because you are a great woman. this will not happen to me because I am nothing. as wise word said" the taller trees will get more sun shine and also more hard blowing wind". Just keep smiling.

I have combined the security measures into this post:

https://steemit.com/steemit/@freedomshift/consolidated-security-measures-scam-alert-and-scammers-list-1

I have added:

6 do not click on a link before examining the URL - watch out for URL "look-alike" phishing attacks
7 always examine the URL that is showing (usually on the lower left of the browser panel) when you mouse over it without clicking it - i.e., "look before you leap" == "examine the true URL before you click"
8 in all instances, check out whoever sends you the URL - whether it is in an email or on your post in addition to #7 above. Here, reputation matters. One can check the reputation score and / or check out the stats on https://steemd.com first

6 is new and creative and need special care.

7 disguised URL's are very old tricks but are very effective or it will not be used any more.

8 - check out the reputation score and steemd.com are specificlly useful and important here.

All the best!