null /help/200103570 h &ts=74969 177-8405305-4664140

Cart

Saved for later

Help > Your Security and Privacy > Safety and Security Tips > Phishing and Spoofed E-mails

Phishing and Spoofed E-mails

Identifying Phishing or Spoofed E-mails

From time to time, you might receive e-mails that look like they come from Endless.com, but they are, in fact, falsified. Often these e-mails direct you to a Web site that looks similar to the Endless.com Web site, where you might be asked to provide account information such as your e-mail address and password combination. Unfortunately, these false Web sites can steal your sensitive information; later, this information may be used to commit fraud. Some phishing messages contain potential viruses or malware that can detect passwords or sensitive data. We recommend that you install an anti-virus program and keep it updated at all times.

Below are some key points to look for in order to identify these e-mails:

1. Know what Endless.com won't ask for

Endless.com will never ask you for the following information in an e-mail communication:

  • Your social security number or tax identification number
  • Your credit card number, PIN number, or credit card security code (including "updates" to any of the above)
  • Your mother's maiden name
  • Your Endless.com password

2. Requests to verify or confirm your account information

Endless.com will not ask you to verify or confirm your Endless.com account information by clicking on a link from an e-mail.

3. Attachments on suspicious e-mails

We recommend that you do not open any e-mail attachments from suspicious or unknown sources. E-mail attachments can contain viruses that may infect your computer when the attachment is opened or accessed. If you receive a suspicious e-mail purportedly sent from Endless.com that contains an attachment, we recommend that you delete it and do not open the attachment.

4. Grammatical or typographical errors

Be on the lookout for poor grammar or typographical errors. Some phishing e-mails are translated from other languages or are sent without being proofread, and as a result, contain bad grammar or typographical errors.

5. Check the return address

Is the e-mail from Endless.com? While phishers often send forged e-mail to make it look like it came from Endless.com, you can sometimes determine whether or not it's authentic by checking the return address. If the "from" line of the e-mail looks like "endless-security@hotmail.com" or "endless-fraud@msn.com," or contains the name of another Internet service provider, you can be sure it is a fraudulent e-mail.

6. Check the Web site address

Genuine Endless.com web sites are always hosted on the "endless.com" domain--"http://www.endless.com/. . . " (or "https://www.endless.com/. . ."). Sometimes the link included in spoofed e-mails looks like a genuine Endless.com address. You can check where it actually points to by hovering your mouse over the link--the actual Web site where it points to will be shown in the status bar at the bottom of your browser window or as a pop-up.

We never use a web address such as "http://security-endless.com/. . ." or an IP address (string of numbers) followed by directories such as "http://123.456.789.123/endless.com/. . . ."

Alternately, sometimes the spoofed e-mail is set up such that if you click anywhere on the text you are taken to the fraudulent Web site. Endless.com will never send an e-mail that does this. If you accidentally click on such an e-mail and go to a spoofed Web site, do not enter any information and just close that browser window.

7. If an e-mail looks suspicious, go directly to the Endless.com Web site

When in doubt, do not click the link included in an e-mail. Just go directly to www.endless.com and click "My Account" in the top right menu to view recent purchases, or review your account information. If you cannot access your account, or if you see anything suspicious, let us know right away.

8. Do not "unsubscribe"

Never follow any instructions contained in a forged e-mail that claim to provide a method for "unsubscribing." Many spammers use these "unsubscribe" processes to create a list of valid, working e-mail addresses.

9. Protect your account information

If you did click through from a spoofed or suspicious e-mail and you entered your Endless.com account information, you should immediately update your Endless.com password. You can do this through My Account by choosing the option to "Change your name, e-mail address, or password" found under My Account Settings.

Please be assured that if someone has been able to look at your account, they are not able to see your full credit card information. However, orders can be sent from your account using your credit card so please contact us immediately if you notice any orders that you do not recognize.

However, if you did submit your credit card number to the site linked to from the forged e-mail message, we advise that you take steps to protect your information. You may wish to contact your credit card company, for example, to notify them of this matter. Finally, you should delete that credit card from your Endless.com account to prevent anyone from improperly regaining access to your account. To do so, click "Edit or delete a credit card" under Payment Settings in My Account.

Home | My Account | Order Status | Shipping | Returns | 100% Price Guarantee | Contact Us | Help | About Us
Affiliates Program | Conditions of Use | Secure Shopping | Privacy Notice | Jobs
© 2006 - 2008 Endless.com or its affiliates. All rights reserved. Endless and the Endless logo are trademarks of Endless.com or its affiliates.