durablenapkin / scamblocklist

A blocklist to protect users against untrustworthy sites.
MIT License
78 stars 6 forks source link

Scammer pretending to be Mexico's Power company stealing account info and credit card data. #82

Closed mondomx closed 4 months ago

mondomx commented 4 months ago

I fell victim of a scam today. The scammer created a sponsored ad on google so when you search for "CFE" or "Comision Federal de Electricidad" you get served this ad.

This add looks just like that of the Mexican government electric company (it even shows the correct URL under the ad name), but upon clicking on the link it actually sends you to the domain: account-cfe.mx

Which has an exact replica of the power company's website, and it asks you to fill your user data to log in (which turns out to be a dead page because you can introduce garbage and will still let you in. But upon login (and before you can see your power bill) it asks you that for security you need to introduce credit card information which they steal.

The DNS domain is registered under a guy in Nevada, and not the mexican government and if I as an IT professional fell for this I'm pretty most regular people will too.

I urge you to add this page to your scammers list.

Screenshot 2024-04-06 at 16-08-01 cfe - Buscar con Google

image

durablenapkin commented 4 months ago

Very sorry to hear, thank you for reporting this - it will be included in the next update.