Forum Moderators: buckworks

Message Too Old, No Replies

Serious Earmark of Fraud ? "Digital Signature Invalid"

New form of ecommerce fraud from military base?

         

jsinger

1:56 pm on May 15, 2009 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Received an email inquiry from a US military base in Asia to buy a suspiciously large quantity of products. It had other earmarks of fraud in that it didn't ask the normal questions about the product but was only interested in whether we could ship to the specified APO address. We clearly state on our site that we do ship to APOs. The APO address is valid as it appears in many online sources.

Phoned the base today (it was late at night there) and person answering verified that they have such a person there.

The email headers appear ok but Outlook 2007 displays a warning saying "The signature is invalid because you have either distrusted or not yet chosen to trust the following Certificate Authority."

I can't recall ever getting such a warning on an email before. Nor have we ever had a fraudulent product inquiry from a .mil address.

We're not going to ship without A LOT more verification. I'm about 80% certain this is fraudulent. I'm just trying to figure out how such a scam would work.

Would appreciate your thoughts on this.

webdoctor

2:09 pm on May 15, 2009 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



"The signature is invalid because you have either distrusted or not yet chosen to trust the following Certificate Authority."

I can't recall ever getting such a warning on an email before

Just out of interest, have you ever had *any* signed emails before?

You ought to be able to work out why the certificate authority isn't trusted, this doesn't necessarily indicate fraud...

As a 'for example' - go search for 'NOTAM' and you'll find the site [notams.jcs.mil...] which publishes all kind of official airspace info... and guess what? The certificate authority isn't recognised by any of my browsers... <sigh>

MrHard

10:52 pm on May 15, 2009 (gmt 0)



Sounds like a problem between you email program and some server somewhere.

What about payment details? That's what really matters for potential fraud. Asking to be connected to the person and then asking "who is this? first, getting the right answer, then mentioning the order, would settle the matter for me as being ok if the payment looks legit.

[edited by: MrHard at 10:55 pm (utc) on May 15, 2009]

jsinger

2:41 am on May 22, 2009 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



We're not going to ship without A LOT more verification. I'm about 80% certain this is fraudulent.

Never figured out what the digital signature problem meant but after calling the military base overseas and speaking with the person placing the order we're 99+% sure it's legit.

Rugles

8:51 pm on May 22, 2009 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



We got 2 of those digital signature invalid emails this week. I figured it was not right because we get sales from the military and emails from .mil people all the time and that digital signature thing never happens.