New phishing scam referencing a company called FrontStream
We received this realistic-looking email today claiming to be from a payment company called FrontStream. If you click the links, it tries to get you to active an account and provide bank details. However… We never requested an account from this company. Therefore, we label it phishing — and an attempt to defraud.
If you receive a message like this, delete it. Don’t click any of the links, and don’t reply to it either. You’ve been warned.
From: billing [email address at frontstream.com]
Sent: Wed, Mar 22, 2017 10:34 am
Subject: New Account Ready for ActivationDear [redacted],
Your account is now available at our FrontStream Invoicing Website for you to view your existing outstanding invoices and make payment. You can directly activate your account here:
[link redacted]
Or you can go to the FrontStream Invoicing website [link redacted], select ‘REGISTER’ option and go through the activation process. Below is your detailed account information from our record. They’re required in order to complete your account activation.
Customer Number: [redacted]
Phone Number: [redacted]
Activation Code: [redacted]
Sincerely,
Accounts Receivable
UPDATE MARCH 22
I tweeted about this blog post, and @FrontStream replied:
@zeichick Sorry for the confusion! The email was sent in error from our customer invoicing system. We’ll be following up with more details.
Given that we aren’t a FrontStream customer, this is peculiar. Will update again if there are more details.
UPDATE MARCH 27
Nothing more from FrontStream.