This Phishing Scam Looks Legit
I received an email this morning "Invoice CY061093 from crypto wallet" from "crypto wallet mailer@waveapps.com" claiming I'd just authorized an $832.48 payment for 0.014 BTC using PayPal Credit, and "Disclaimer:- If you did not authorized this transaction or have any question regarding this purchase you can call on our Toll Free on :- +1-888-428-7631."
The invoice link sent me to "https://accounting.waveapps.com/invoices/..." and claimed my BTC would be transferred in 2-4 hours.
The sender information in Gmail is as follows:
from: crypto wallet mailer@waveapps.com
reply-to: walletcrypto05@gmail.com
to: [my email address]
date: Nov 1, 2021, 11:04 AM
subject: Invoice CY061093 from crypto wallet
mailed-by: pm.waveapps.com
signed-by: waveapps.com
It appears to have come from the app legitimately, but I've never heard of this company, can't contact them via support, I'm not about to call a phone number listed in a suspicious email, and even if I did want to buy BTC with USD, I use Coinbase and my bank account - not PayPal (I don't even have PayPal Credit!)
My concern is for 1) other individuals who don't have the common sense not to call a strange phone number in a phishing email, and 2) the WaveApp platform that is being used by a scammer who either signed up legitimately and hasn't been stopped by the devs, or hacked the system to send really convincing scam invoices.
Comments
Do not click on anything. If I could I would load a screenshot of it.