Better Business Bureau Tangled in E-Mail Scam

Discussion Policy
Comments that include profanity or personal attacks or other inappropriate comments or material will be removed from the site. Additionally, entries that are unsigned or contain "signatures" by someone other than the actual author will be removed. Finally, we will take steps to block users who violate any of our posting standards, terms of use or privacy policies or any other policies governing this site. Please review the full rules governing commentaries and discussions. You are fully responsible for the content that you post.
By Annys Shin
Washington Post Staff Writer
Wednesday, February 14, 2007

The Better Business Bureau network was the target of a "spoofing" scam yesterday in which thousands of businesses in the United States and Canada received e-mails encouraging them to download what is thought to be a computer virus.

The e-mails, using the name of the 95-year-old network of nonprofit groups that looks into consumer complaints, told businesses that they were the subject of a complaint and included a link to view related documents. Clicking on the link, however, accessed the address book of an infected computer and distributed the counterfeit e-mail to more recipients, said Steve Cox, spokesman for the Council of Better Business Bureaus.

The council is the umbrella group for the system's 129 local branches, which are funded by member businesses.

BBB members and nonmembers received the e-mail.

Confused business owners began calling the council's offices in Arlington at 6 a.m. yesterday, Cox said. By mid-morning, the organization had confirmed the attack was systemwide.

"It is the first time in recent memory where we've had an attack on this scale," Cox said.

The counterfeit e-mails were traced to an advertising firm in Kennesaw, Ga., that had had its computer system hacked into Monday night, Cox said. The agency had no prior affiliation with the BBB.

The Council of Better Business Bureaus warned recipients not to open any e-mail that contains a return address of "operations@bbb.org" or a link citing a complaint case number, such as "Documents for Case #263621205."



More in Technology

Brian Krebs

Security Fix

Brian Krebs on how to protect yourself from the latest online security threats.

Cecilia Kang

Post Tech Blog

The Post's Cecilia Kang on the FCC, net neutrality and more tech policy.

Rob Pegoraro

Faster Forward

Tech columnist Rob Pegoraro blogs about gadgets, software, tech glitches and more.

© 2007 The Washington Post Company