February 19, 2006
White City womans phish story spawns cautionary tale
By JOHN DARLING
for the Mail Tribune
Its pretty alarming when, using your debit card in the checkout line at the market, the clerk tells you the cards been rejected. Especially when you know you have more than $1,000
in your checking account.
After being "so embarrassed I could have died," Roseanna Boyce, 55, of White City, called her bank, Washington Mutual at Fred Meyer North and found that three withdrawals using PayPal
had drained her account.
PayPal, the international money-changing giant owned by eBay, found the funds had been changed to British pounds and transferred overseas and were no longer traceable.
Both PayPal and her bank promised to "make her whole," that is, cover money lost through any unauthorized transaction, said Boyce, though both took more than a week to do it
first the bank filling the gap, then PayPal refunding the money, which totaled $1,012.
Boyce, a Vietnam War widow now on Social Security disability, maintained she did not fall prey to any "phishing" e-mails, the ones that pose as PayPal, eBay or other financial
institution and ask for your password or account numbers so they can have illegal access to your accounts.
"I have no idea how it could have happened," said Boyce. "PayPal told me its getting to be more and more of a problem. I thought my information with PayPal was
secure."
However, PayPal spokesperson Amanda Pires, in San Jose, Calif., said theres virtually no other way it could have happened than by phishing.
"There is no way anyone can get in your account unless they have your password. Even we (at PayPal) dont know your password and cant find it out. Im sorry she had to go
through this, but for someone to get her password, she has to give it to them."
The only other way crooks get passwords is for you to be too obvious using your birthday or last name or other obvious words, Pires added.
"Absolutely be random in choosing your password and mix in random numbers and symbols, too," said Pires. "And change it often, like monthly."
Fraud such as Boyce suffered doesnt happen that often, because Internet users are becoming more and more suspicious and understand that such phishing e-mails as well as appeals for
cash from a Nigerian ambassadors nephew with the promise of a huge amount in return are good only for deleting, Pires said.
Shelly Miller of Evergreen Federal in Medford said phishers are "pretty sly" about getting information out of people and will even pose as legitimate local businesses.
One scam these days involves a merchant send you a check for $2,000, then asking you to send only $200 back to them, she notes. The check, of course turns out to be no good.
Be wary, said Miller, of addresses in Spain, Nigeria and Eastern Europe and dont comply with any merchants request to wire money.
Miller advises Internet shoppers to peruse their checking account statement often and make sure all purchases are theirs.
"A lot of people dont look at it because they dont want to balance it," she said.
While Washington Mutual will provide stopgap coverage for fraudulently drained accounts, if their investigation shows the client gave passwords or bank account numbers to phishers, the client
will suffer the loss, said WaMu spokesman Gary Kishner in Los Angeles.
PayPal, however, would cover all losses from fraud, even if the victim is responsible, Pires said.
Medford Police Detective Sue Campbell, who handled the case, said its a good idea to close dormant accounts at PayPal or anywhere else. Such hijacking of accounts through PayPal are rare
and this is the first one shes encountered, she said.
Brett Johnson of the Ashland Police Departments financial fraud unit, said he considers PayPal "about as secure as you can get" and notes that, even if you get e-mails with the
PayPal or eBay logo, that does not mean theyre genuine.
"If you make the mistake of clicking return, on such an e-mail, you will be linked to a Web site that may have the word "paypal" in it, but it wont be PayPal, he
said.
"Know who youre dealing with," said Johnson. "PayPal is not going to e-mail you and ask you to sign in. If you have any question, go to their Web site. Ive done
business with it and I know theyre safe."
Tips to avoid phishers
PayPal offers these tips on avoiding fraudulent e-mails that could lead to your suffering financial and security losses:
Look out for suspicious-looking e-mails. If you find an e-mail from what appears to be PayPal that you suspect may be fraudulent, forward it immediately to spoof@paypal.com.
Never provide personal or financial information in response to an e-mail request. PayPal will not ask you to supply your password, bank account number, credit card number or any other financial information in an e-mail.
Log in safely to your PayPal account by opening a new Web browser window (e.g. Internet Explorer or Netscape), and type in https://www.paypal.com, PayPals secure site.
Frequently check your PayPal account to ensure its security.
Change your PayPal password regularly. Your password is always encrypted and it is never shared with merchants. To be safe, you should regularly select a new PayPal password that uses a random combination of letters, numbers, or symbols. Avoid using
single names or words that can be found in a dictionary.
PayPal will never send you an e-mail attachment, or ask you to download anything in order to use the service or that of any partners.
The eBay Toolbar with the Account Guard feature protects PayPal account information by warning when a user is on a potentially fraudulent (spoof) Web site. The Account Guard feature also enables users to report a spoof Web site. Once a site has been verified
by PayPal to be fraudulent, PayPal will work to shut the site down.
Additionally, that information will automatically be distributed to all other eBay toolbar users, warning them about the spoof Web site. The toolbar can be downloaded through eBay at pages.ebay.com/ebay_toolbar on the Web.
John Darling is a freelance writer living in Ashland. E-mail him at jdarling@jeffnet.org.