Why don't they exactly replicate what a Google or Chase email looks like? I don't see how I wouldn't fall for that.
Why don't they exactly replicate what a Google or Chase email looks like? I don't see how I wouldn't fall for that.
The exception (and a potential attack vector) is when a phone call or other live interaction ends in an email being sent as part of the process. There you have to weigh the risk I suppose; obviously i have replied to such emails. But i would never reply to a bulk email even if it came form my banks domain.
At this point if they manage to have the correct caller ID and I'm more or less expecting the call, it can't hurt to divulge my DOB. Scammer's going to find that out easily anyway.
Savvy users who will become wise to the grift somewhere along the way are the ones they want to weed out. Early in the process ideally.
Having totally convincing emails fails to weed out these savvy users - you get to discover who they are a bit further down the line, after you've invested some time.
Since their time they can spend is finite, they want to only spend time on sure bets. This is why it is important to take a few moments to lead on scammers - you're damaging their ROI the more of their time you can take up.
Using a proper spelling would improve the conversion but also would add a lot more work for the scammer and therefore he can miss a real doofus who can be scammed, so the overall KPI (heh) would be lower.
Yes, it still the same, but with an additional key part.