What is Spoofing?

by special invitation only

We have recently identified someone attempting to impersonate somebody else through an email address. This is called Spoofing. It is quite easy to do this. There are two pieces of information for an email address, there is the email address itself, and then there is a name associated with the email address.

Constructing a Spoofed email address

It is possible to construct email addresses so that they show a name of the sender, which is different to the actual sender. The people that do this are pretending to be the sender who is visible in the email as in the example below.

Depending on how your email client or application is set up you may see the full email line, or just the alleged name of the person that sent it. The view above is from Outlook.

The view below is the same message using a web based email client.

This message actually came from me and sent to me. However we cannot tell by looking at the message where it actually came from. It just says Donald J Trump. 

I can check where it originated from by hitting reply. Note I am hitting reply but with no intention of replying at the moment.

At the moment the full email address is not exposed, so I could be fooled that I am actually replying to Donald J Trump. However the name is in a pale grey box. If I place my cursor over it, you can see the full email address as well as the name exposed. 

If you are using Outlook, although it depends on how it is set up, a spoofed email will be more obvious as in this case.

Why is this important?

In the example I have shown it is obvious that I would not be expecting an email from Donald Trump. So it would be immediately consigned to the bin. However there are lots of examples where hackers will attempt to win someone’s confidence by pretending to be someone else in an organisation. I have come across this several times with my clients, and even with the now “ex” security company that used to look after my burglar alarm system.

Several messages were sent in to various members of HAC today (30/11/23) with a spoofed email address on it. It looks like HAC is being targeted for some reason because there were several of them. They all came from the same source email address which was deskmail544@gmail.com

If you received a message from someone you recognised in the club with a short simple request, you might reply and answer the request. If you do, whatever information the alleged person was asking for has now been sent to the hacker by accident.

Please be especially vigilant

Any emails that are sent out trying to get a response back are usually very short. They are short because the more information that is added into the body of the email is likely to alert the reader that something is not quite right.  In the case today the same email was sent to multiple people and contained this simple message:

Could i have a brief moment to talk to you about something?

Please, let me know what time works for you.

Kind Regards

………

This email is trying to gain your confidence, and get you to connect with the person. Once connected, they may ask for more information. The motive at the moment is unclear. However I have seen cases where email accounts have been taken over by hackers.  Note the inappropriate grammar in this message, and the presence of i vs I. 

Things to look out for and what to do

  • If it seems odd, it probably is. Be wary.
  • Very short and ambiguous emails asking you to do something with no context.
  • Emails that have a sense of urgency panicking you into responding quickly
  • Someone addressing you in an uncharacteristic manner.
  • Email address does not look right.
  • Asking you to click on something in an email either an attachment, a link or a graphic in an email
  • Asking for security related information
  • Asking for information about another person in the organisation
  • Clearly made an error in the grammar, spelling or something else

If you are sure it does not look right, then independently contact the person either by phone or open a new email and ask them if they just sent you something. Do not however hit reply and send the message back to the person that sent you the email.

Do not click on any of the contents in the email. These mails are usually constructed using HTML and can carry images and links. Do not download any images either, as this will confirm that someone has opened the email.

If you process your email using Outlook, you can generally hover over an email address or web address and find out where it is really going to. You could also hit “reply” to create the email and headers for the reply message and then check the real email address, but not send the message. This is a useful sanity check.

Right now all we know is the person that is behind this email address: deskmail544@gmail.com has no name associated with the gmail address. They are anonymous. So we should assume that they are targeting HAC for some reason.

It is better to independently check whether something is legitimate rather than quickly reply.

Please take care.  Can you report all instances if any more are found to Adnan so we can keep track of what is coming in? 

 

 

 

Halton Aero Club
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

You can review our privacy policy on this page. (opens in a new window)

You can review our cookies policy on this page. (opens in a new window)