August 13, 2026, 07:12 AM
architectNew (maybe just to me) twist in identity theft attempts
Recently, some malefactor got access to one of my credit cards. The issuer caught it right away, and nothing came of it.
However, it appears that the thief, or somebody who bought my data is now using my e-mail address to sign up for multiple sketchy websites. I am getting "confirm your e-mail address" messages from multiple sites I've never visited, much less entered identifying information.
I think what is happening is that, sooner or later, I will get one of these "confirm" messages with an accompanied "if this is an error" link that, if clicked, goes to phase 2 of an identity theft attempt. The multiple signups are just to get me complacent about receiving the bogus confirmation e-mails.
Needless to say, I am not replying to any of these, nor am I following any links in the messages. But this appears to be a fairly new tactic the sub-humans are using to steal identities. I haven't seen mention of this sort of tactic in the security forums I follow regularly.
I thought that others here might want to be aware of this new form of malfeasance.
As far as how the card was compromised, I have a theory about that too. I recently got a re-isue for an expiring card. Part of the process was to return the old card to the issuer in a provided mailer. I suspect the mailer was intercepted. But I have no explanation for how they associated my e-mail address with the card.
August 13, 2026, 07:30 AM
Redleg06Perhaps the return of the old card was part of the scam. I don't know how many cards we've had in the past 55+ years, but we've have never been asked to return an expiring (or possibly compromised) card.
August 13, 2026, 07:39 AM
MuddflapSeveral years ago I got a new titanium Apple card. They sent a Fed Ex envelope to return the old one.
That's the only time I've been asked to return an old card.
August 13, 2026, 07:44 AM
Pipe Smokerquote:
Recently, some malefactor got access to one of my credit cards. The issuer caught it right away, and nothing came of it.
However, it appears that the thief, or somebody who bought my data is now using my e-mail address to sign up for multiple sketchy websites.
How did they get your email address from your credit card?
August 13, 2026, 08:28 AM
ExodusIt could be the beginning of a subscription bomb attack. If so they will ramp up and you'll get hundreds of subscriptions a day (if not thousands). The idea is to create so much noise that you can see legitimate emails warning of fraud from your banking companies. Monitor your credit and bank account carefully. It might be a good idea to proactively change your passwords on all of your critical accounts.
August 13, 2026, 09:01 AM
mark60I get several emails a week confirming my order for something from somewhere. I see the subject and delete without even opening the email.
August 13, 2026, 09:18 AM
joel9507quote:
Originally posted by architect:
As far as how the card was compromised, I have a theory about that too. I recently got a re-isue for an expiring card. Part of the process was to return the old card to the issuer in a provided mailer.
Yeah, no.
That'd be where I tell the bank, "Lots of banks issue cards. I'm shredding the old card like always, I'm not sending anything anywhere. Do I need to find a new card-issuer, or are you good with that?"
August 13, 2026, 09:22 AM
HRKquote:
Originally posted by Exodus:
It could be the beginning of a subscription bomb attack. If so they will ramp up and you'll get hundreds of subscriptions a day (if not thousands). The idea is to create so much noise that you can see legitimate emails warning of fraud from your banking companies. Monitor your credit and bank account carefully. It might be a good idea to proactively change your passwords on all of your critical accounts.
Might be time to open up a new email for your financial and medical accounts, don't give it out to anyone but these companies, go back in with your old email and change it to the new email. Setup 2FA on everything financial using your cell phone as the 2FA contact.
This way any currently compromised email has no access to anything important. Keep the old email and just use it to scan periodically for anything important and use it for signing up on any web pages, SF, FB, Instagram, US Midget Wrestling Association, whatever you're into or don't really want contact from....
quote:
Originally posted by joel9507:
quote:
Originally posted by architect:
As far as how the card was compromised, I have a theory about that too. I recently got a re-isue for an expiring card. Part of the process was to return the old card to the issuer in a provided mailer.
Yeah, no.
That'd be where I tell the bank, "Lots of banks issue cards. I'm shredding the old card like always, I'm not sending anything anywhere. Do I need to find a new card-issuer, or are you good with that?"
Kind of hard to shred a Titanium card.....
August 13, 2026, 09:28 AM
SpinZoneChanging e-mail addresses is a surprisingly huge amount of work, but if you think this is the beginning of. An escalating attack, you should move everything off that address to a new one now, before the scam progresses.
August 13, 2026, 09:47 AM
911Bossquote:
Originally posted by Muddflap:
Several years ago I got a new titanium Apple card. They sent a Fed Ex envelope to return the old one.
That's the only time I've been asked to return an old card.
That is because the Apple Card is made out of titanium and Apple prides itself of recycling old products. Returning is totally optional.
August 13, 2026, 09:49 AM
slosigquote:
Originally posted by joel9507:
quote:
Originally posted by architect:
As far as how the card was compromised, I have a theory about that too. I recently got a re-isue for an expiring card. Part of the process was to return the old card to the issuer in a provided mailer.
Yeah, no.
That'd be where I tell the bank, "Lots of banks issue cards. I'm shredding the old card like always, I'm not sending anything anywhere. Do I need to find a new card-issuer, or are you good with that?"
I had one of those. It was a hard metallic card that like would have abused the crud out of if not broken my shredder. I used heavy duty tin snips to cut into small pieces, put them into the postage paid return envelope and sent them back. I’m not sure everyone has heavy duty tin snips around and I doubt customers would be happy if the expired cards killed their shredders.
August 13, 2026, 10:31 AM
architectquote:
Originally posted by Redleg06:
Perhaps the return of the old card was part of the scam. I don't know how many cards we've had in the past 55+ years, but we've have never been asked to return an expiring (or possibly compromised) card.
No, the return was legit. The stated reason they wanted it returned rather than destroyed was because it was a metal card, not shreddable. The return mailer was easily identifiable. Not going to mail back the compromised one I have in hand, I have tools...