<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>thread HOWTO: Spot phishing emails in Archived Discussions (Read Only)</title>
    <link>https://community.squareup.com/t5/Archived-Discussions-Read-Only/HOWTO-Spot-phishing-emails/m-p/263188#M12352</link>
    <description>&lt;P&gt;Hello all! Recently a fellow seller got an email about Negative Feedback and was a little concerned about it. He forwarded the email to me, and it definitely looks like a phishing email! Since I haven't seen the phishing emails hit the feedback emails yet, I thought it would be best to show you what to look out for:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="phish.jpg" style="width: 931px;"&gt;&lt;img src="https://community.squareup.com/t5/image/serverpage/image-id/12904i3C124827BB5B562E/image-size/large?v=v2&amp;amp;px=999" role="button" title="phish.jpg" alt="phish.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ok, lets take a look at this:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;It's not in the screen shot, but the email was all wrong. All feedback emails come from &lt;EM&gt;&lt;STRONG&gt;feedback@messaging.squareup.com&lt;/STRONG&gt;&lt;/EM&gt;&lt;EM&gt;. &lt;/EM&gt;If it doesn't have that email address, it's a guaranteed phishing email.&lt;/LI&gt;&lt;LI&gt;On the subject line, it says &lt;STRONG&gt;Square Customer&lt;/STRONG&gt; and does not have the four digit ticket number at the end of the line. A valid feedback email will say &lt;STRONG&gt;A customer left you positive/negative feedback (#xxxx)&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Right below the From/To line, there is no instruction line. A valid feedback email will say &lt;STRONG&gt;Reply to this email to respond to your customer&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;This one is subtle: Note that the background color on the feedback text is different from the background of the email. Square's emails will have the feedback text in white with a light grey background everywhere else.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;View this dispute&lt;/STRONG&gt; is designed to make you panic a little and click on it. The real emails will say &lt;STRONG&gt;Respond&lt;/STRONG&gt; in this blue button.&lt;/LI&gt;&lt;LI&gt;Between the dispute button and the address, a valid email from Square would have a &lt;STRONG&gt;Purchase Overview&lt;/STRONG&gt; section saying how many items were bought, on what date, and at what price. There is then an option to preview the receipt.&lt;/LI&gt;&lt;LI&gt;Speaking of the address, Square isn't based in Tuscon. In fact, the legit emails only have the Copyright line at the bottom, not their address.&lt;/LI&gt;&lt;LI&gt;Unsubscribe? Another way for them to get you if you didn't click on the dispute button. If I click this, I won't get any more phishing emails, right? &lt;EM&gt;&lt;STRONG&gt;Wrong.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;Lastly, I'm pretty sure that Square can afford their own email servers and won't need to send free email from Hubspot.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;STRONG&gt;So what do you do if you get one of these emails?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; First and foremost, &lt;EM&gt;do not click/tap on any of the links and buttons in the email. &lt;/EM&gt;If you do, immediately run a virus check on your computer, and for the love of all things holy, don't enter any identifying information in any of the screens that pop up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Next, forward this email to &lt;EM&gt;&lt;STRONG&gt;&lt;A href="mailto:spoof@squareup.com" target="_blank" rel="noopener"&gt;spoof@squareup.com&lt;/A&gt; &lt;/STRONG&gt;&lt;/EM&gt;so their legal team can go knock some knees together.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And for the record, here is what a valid feedback email will look like:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="goodfeedback.jpg" style="width: 999px;"&gt;&lt;img src="https://community.squareup.com/t5/image/serverpage/image-id/12906iCE0955656DB75194/image-size/large?v=v2&amp;amp;px=999" role="button" title="goodfeedback.jpg" alt="goodfeedback.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Stay safe, sell a lot, and don't give any of your money to these filty phishers!&lt;/P&gt;</description>
    <pubDate>Mon, 12 Apr 2021 16:11:57 GMT</pubDate>
    <dc:creator>ryanwanner</dc:creator>
    <dc:date>2021-04-12T16:11:57Z</dc:date>
    <item>
      <title>HOWTO: Spot phishing emails</title>
      <link>https://community.squareup.com/t5/Archived-Discussions-Read-Only/HOWTO-Spot-phishing-emails/m-p/263188#M12352</link>
      <description>&lt;P&gt;Hello all! Recently a fellow seller got an email about Negative Feedback and was a little concerned about it. He forwarded the email to me, and it definitely looks like a phishing email! Since I haven't seen the phishing emails hit the feedback emails yet, I thought it would be best to show you what to look out for:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="phish.jpg" style="width: 931px;"&gt;&lt;img src="https://community.squareup.com/t5/image/serverpage/image-id/12904i3C124827BB5B562E/image-size/large?v=v2&amp;amp;px=999" role="button" title="phish.jpg" alt="phish.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ok, lets take a look at this:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;It's not in the screen shot, but the email was all wrong. All feedback emails come from &lt;EM&gt;&lt;STRONG&gt;feedback@messaging.squareup.com&lt;/STRONG&gt;&lt;/EM&gt;&lt;EM&gt;. &lt;/EM&gt;If it doesn't have that email address, it's a guaranteed phishing email.&lt;/LI&gt;&lt;LI&gt;On the subject line, it says &lt;STRONG&gt;Square Customer&lt;/STRONG&gt; and does not have the four digit ticket number at the end of the line. A valid feedback email will say &lt;STRONG&gt;A customer left you positive/negative feedback (#xxxx)&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Right below the From/To line, there is no instruction line. A valid feedback email will say &lt;STRONG&gt;Reply to this email to respond to your customer&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;This one is subtle: Note that the background color on the feedback text is different from the background of the email. Square's emails will have the feedback text in white with a light grey background everywhere else.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;View this dispute&lt;/STRONG&gt; is designed to make you panic a little and click on it. The real emails will say &lt;STRONG&gt;Respond&lt;/STRONG&gt; in this blue button.&lt;/LI&gt;&lt;LI&gt;Between the dispute button and the address, a valid email from Square would have a &lt;STRONG&gt;Purchase Overview&lt;/STRONG&gt; section saying how many items were bought, on what date, and at what price. There is then an option to preview the receipt.&lt;/LI&gt;&lt;LI&gt;Speaking of the address, Square isn't based in Tuscon. In fact, the legit emails only have the Copyright line at the bottom, not their address.&lt;/LI&gt;&lt;LI&gt;Unsubscribe? Another way for them to get you if you didn't click on the dispute button. If I click this, I won't get any more phishing emails, right? &lt;EM&gt;&lt;STRONG&gt;Wrong.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;Lastly, I'm pretty sure that Square can afford their own email servers and won't need to send free email from Hubspot.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;STRONG&gt;So what do you do if you get one of these emails?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; First and foremost, &lt;EM&gt;do not click/tap on any of the links and buttons in the email. &lt;/EM&gt;If you do, immediately run a virus check on your computer, and for the love of all things holy, don't enter any identifying information in any of the screens that pop up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Next, forward this email to &lt;EM&gt;&lt;STRONG&gt;&lt;A href="mailto:spoof@squareup.com" target="_blank" rel="noopener"&gt;spoof@squareup.com&lt;/A&gt; &lt;/STRONG&gt;&lt;/EM&gt;so their legal team can go knock some knees together.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And for the record, here is what a valid feedback email will look like:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="goodfeedback.jpg" style="width: 999px;"&gt;&lt;img src="https://community.squareup.com/t5/image/serverpage/image-id/12906iCE0955656DB75194/image-size/large?v=v2&amp;amp;px=999" role="button" title="goodfeedback.jpg" alt="goodfeedback.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Stay safe, sell a lot, and don't give any of your money to these filty phishers!&lt;/P&gt;</description>
      <pubDate>Mon, 12 Apr 2021 16:11:57 GMT</pubDate>
      <guid>https://community.squareup.com/t5/Archived-Discussions-Read-Only/HOWTO-Spot-phishing-emails/m-p/263188#M12352</guid>
      <dc:creator>ryanwanner</dc:creator>
      <dc:date>2021-04-12T16:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: HOWTO: Spot phishing emails</title>
      <link>https://community.squareup.com/t5/Archived-Discussions-Read-Only/HOWTO-Spot-phishing-emails/m-p/263190#M12353</link>
      <description>&lt;P&gt;Thank you for sharing &lt;a href="https://community.squareup.com/t5/user/viewprofilepage/user-id/145"&gt;@ryanwanner&lt;/a&gt;! &lt;span class="lia-unicode-emoji" title=":sparkles:"&gt;✨&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Apr 2021 16:14:45 GMT</pubDate>
      <guid>https://community.squareup.com/t5/Archived-Discussions-Read-Only/HOWTO-Spot-phishing-emails/m-p/263190#M12353</guid>
      <dc:creator>isabelle</dc:creator>
      <dc:date>2021-04-12T16:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: HOWTO: Spot phishing emails</title>
      <link>https://community.squareup.com/t5/Archived-Discussions-Read-Only/HOWTO-Spot-phishing-emails/m-p/667447#M12354</link>
      <description>&lt;P&gt;Thank you for the thorough details, &lt;a href="https://community.squareup.com/t5/user/viewprofilepage/user-id/145"&gt;@ryanwanner&lt;/a&gt;. I found one of these messages in my spam folder today (see image).&amp;nbsp; It has a couple of the elements you said would be in a valid Square email (the "Reply to..." instruction and the "Respond" button).&amp;nbsp; Because Square does have a team in San Francisco, that address they provided could be legit.&amp;nbsp; But the one thing they didn’t (couldn't?) fix was the sender's email address; it's from a personal address, not the Square Messaging one you mentioned.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20230623-090522_Yahoo Mail.jpg" style="width: 720px;"&gt;&lt;img src="https://community.squareup.com/t5/image/serverpage/image-id/38168iD11FA0FF989F6A32/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_20230623-090522_Yahoo Mail.jpg" alt="Screenshot_20230623-090522_Yahoo Mail.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 13:56:07 GMT</pubDate>
      <guid>https://community.squareup.com/t5/Archived-Discussions-Read-Only/HOWTO-Spot-phishing-emails/m-p/667447#M12354</guid>
      <dc:creator>dabblrscre8ions</dc:creator>
      <dc:date>2023-06-23T13:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: HOWTO: Spot phishing emails</title>
      <link>https://community.squareup.com/t5/Archived-Discussions-Read-Only/HOWTO-Spot-phishing-emails/m-p/667483#M12355</link>
      <description>&lt;P&gt;&lt;a href="https://community.squareup.com/t5/user/viewprofilepage/user-id/277035"&gt;@dabblrscre8ions&lt;/a&gt;&amp;nbsp;&amp;nbsp; No. Never reply to any email that looks right that doesn’t come from messaging.squareup.com&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the last four days I received two emails to my spam folder that looked just like a Square email but came from a private address. This is how they get you.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;In your example, it was for a negative feedback. Whenever I get emails like this I always log into my dashboard from my bookmarked link and check the feedback section. My emails were about disputes this time: I did the same login check and discovered there were no disputes.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;NEVER click on a link from an email, even if it does come from a verified square address. Log into your dashboard and check there. It’s the safest way.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 15:38:49 GMT</pubDate>
      <guid>https://community.squareup.com/t5/Archived-Discussions-Read-Only/HOWTO-Spot-phishing-emails/m-p/667483#M12355</guid>
      <dc:creator>ryanwanner</dc:creator>
      <dc:date>2023-06-23T15:38:49Z</dc:date>
    </item>
  </channel>
</rss>

