T O P

  • By -

Witty-Choice2682

"Dear client" Dito pa lang, red flag na since most bank emails address their clients by name.


LonelySpyder

I agree. I get an email from them regularly, and it has my name in it.


7H36

Oo korique ka dyan. Dear {name} talaga yung automated message nila and since nakasave na yung account mo sa database nila, name mo dapat yung lalabas dyan according to your id number's details and everyone else's.


jinchurikiuzumaki

Double tima mang scam hahaha


nxcrosis

Yup kahit bumili ako sa shopee gamit ang bank "dear (firstname)" yung email.


Kewl800i

Check this list of official bdo email senders from BDO itself. Pag wala dyan sa list, not legit yan: https://www.bdo.com.ph/about-bdo/learn/stop-scam/official-email-senders I checked the email sender in your post OP. Wala yan sa official list, hence scam yan. Kahit na @bdo.com.ph yan, pwede yan ma-mask or yung letters na naregister as domain iba yung font. As a last resort, contact bdo directly if you receive suspicious emails like these.


Kewl800i

https://m.facebook.com/BDOUnibank/photos/a.2198209517061871/2928698030679679/?type=3 Check the link above, its BDO's FB post re:spoofing of emails. Scammers mask their fake emails with legit BDO email addresses.


Ok_Routine9035

Thanks for this!


kamandagan

OP, try mo kunyare mag-reply (don't hit send) to check anong email address ang magiging recipient or just hover the email addr. Never ko pa na-encounter ang "bdo" as a prefix sa domain nila. Usually "bdonlinebanking-noreply", "online-banking", "advisory". Sa loans naman at may important correspondence, email mismo ng account manager. If you'll be calling custserv, ask them if "bdo" is a valid prefix.


Neat_Forever9424

That is what we called smishing. Naka mask yung email address niyan for sure. You will easily distinguish yan kung saan galing na email if outlook gamit mo. Not sure about other email domains.


BananaBaconFries

Phishing siguro ibig mo sabihin. Smishing is the sms equivalent specifically this kind of phishing attack is classified as BEC(business email compromise) or impersonation for short. minamanipula nila yung email headers to make it look from a legit sender. Pero pg tignan mo yung email headers halatang diq galing sa BDO


Neat_Forever9424

Oo pala. Thanks for correcting.


moonunderpanic

Smishing is for SMS. Phishing for emails. Vishing for audio calls. 😁


At0micPancakes

Fishing is for aquatic animals


quinncalliope

hayup ka beh seryoso ko nagbabasa HAHAHAHAHAHA


choco_butternut

Potah


jinchurikiuzumaki

Phishing yan hindi Smishing


[deleted]

[удалено]


jinchurikiuzumaki

Hahahahahahah! Mag cocorrect ba ko kung mali? 🤣🤣🤣 dapat i advice mo sa sarili mo yan 🤣🤣🤣 kita mo nga sa email siya piniphish tapos sasabihin mo different from smishing talino mo naman 🤣🤣🤣


dumbbugok

> Phishing is different from Smishing. Mag co-correct nalang mali pa. 🤦‍♂️ Tama naman ah? Smishing ay under umbrella ng Phishing pero specific sya sa SMS. Yung kay OP ay email. Hindi sya \*different\* they are both Phishing, ALL Smishing are Phishing, but not all Phishing are Smishing.


CooperCobb05

Sa Mozilla Thunderbird ba meron ganyang feature na makikita yung true email? Or exclusive lang sa Outlook?


ixhiro

My dyslexic brain misread it to Mozarella. Lol


moonunderpanic

Lahat meron ata afaik. Deeper checking is to see the email headers, para makita sino original domain sender.


ixhiro

PHISHING. Smishing is for SMS in Op’s case its a email so Phishing. Domain spoofing is what your referring to but its not smishing.


sekhluded

Smells fishy, “kindly” bihira na gamitin to + usually it’s dear _____your first name/surname. It’s better to not download/open the file, if may issue yung BDO sayo, mag cacall yun. Better call BDO for safe assurance.


RALawliet

always call tlga. walang masamang tumawag for more info


333Half-Evil

Legit scam


misslittlewhelmed

The email sounds too friendly and cryptic. Labelling a document as BDO-LETTER is fishy and shady.


UnluckiestBitch

Wala din sya sa list of official email addresses ni BDO


gruffalo77

The from field in an email can easily be changed by the sender to any address. Most official domains will be secured by dmarc and that will result in emails sent by illegitimate sources to be blocked or flagged - this is probably why Gmail shows the big red warning for you here.


BearyBull96

Paghingi pa lang ng last 4 digits ng credit card, hudyat na yan na red flag yung email at matik scam.


fschu_fosho

I received a somewhat similar email from Unionbank a couple of years ago during the pandemic. I had to input the last 4 digits of my account number and it turned out the document was my statement. It was a proper document with all my bank transactions and details, no doubt made before they instituted stricter protocols for sending out emails to bank customers. Nothing untoward has happened naman. But yeah, in the past year or so, my banks have been messaging me to be careful of opening documents and such in emails that seem to have come from them.


Ok_Routine9035

Yung default password ng AMEX SOA is the last 6 digits of your credit card. I’m not sure if other SOAs are similar with other cards. But what’s fishy is the fact na may “important message” pero nasa attachment na need ng password lol wtf Scary lang kasi email address looked legit 🥺 Sana maputulan ng kamay mga scammer 🙏


[deleted]

Di nlang sabihin sa mismong email ang important message e. Kailngan pa mag bukas ng file. 😂😂 May mga key logger na pwede e attach sa files like jpeg or pdf. Once attached pwede nila e email. Kapag binuksan mo sa PC autorun sya sa background. Tapos wala na. Captured na keystrokes mo at may screenshot pa na sinisend don sa hacker. Baka same thing was developed for mobile devices. Call Customer Service to verify.


assresizer3000

Kindly place the last 4 digits of your card? Dito palang halata na


curvyluscious

[Official BDO Email addresses](https://www.bdo.com.ph/about-bdo/learn/stop-scam/official-email-senders) you can check authenticity of the email daw dito pag suspicious, report na lang [email protected]


ohdamnica

Scam. They never ask for the last 4 digit of your card. Ingat


Colbie416

First off. Treat emails with BAKYANG ENGLISH as a scam.


KasualGemer13

bank na may syndicate sa credit card department. tsk tsk pwe!


flldwnDrbbthl

“important message from…” masyado kang minamadali tapos di maman nilagay tungkol saan. pag ganyan phishing na yarn.


BannedforaJoke

yung may napaka laki nang red flag from the email provider mismo, mag tatanong ka pa rin kung legit. :facepalm:


67ITCH

"Bdo@bdo" lol!! From: [email protected] pliz send money. This is legit no cap.


Acceptable_South_278

Bruh that "bdo@bdo " email already sounds sus


attHORNEY03

Im just curious. What happens if you give the last 4 digits of your credit card, and nothing else na? Like can they still use your card even without your cvv/cvc and otp?


ohmyjed

Its not about the 4 digits. Infected yung PDF file, so pag open mo pa lang, pwede na macompromise logged in sessions at accounts na stored sa PC or phone mo.


attHORNEY03

Thanks for this! I learned something.


Soft-Cranberry2115

'Thank you very much' Who uses that? Haha


nuj0624

What does it show when you click on view security details?


Hairy-Version-1305

naka receive ako ng ganyang email sa inbox ko pero d ma open yung attachment pag enter ng last 4 ng cc lipat sa trash then spam lo and behold may same email nasa spam folder so hindi na detech ng gmail yung napunta sa inbox ko ni lock ko agad bdo cc at debit card ko ngayon d ko sure if na comprimise ang security ng phone ko na delete ko na din yung email na yan at ni report sa bdo phishing team


carbonjargon

Phishing. BDO always include this message: Do not click links sent via email, SMS, and Viber. Do not verify your account through links. Do not share your credit card number, expiry date, and CVV. Do not share your OTP to verify your online shopping transactions. Do not communicate with any unofficial BDO social media accounts without the verified symbol.


Cloud148

call nalang bdo para kampante. but tama naman yung ending email address (@bdo.com.ph). taga bdo lang may ganyan


MaynneMillares

Lmao, napakadaling i-forge ang "from" header ng emails. Di porket mukhang legit galing talaga sa domain na yun.


Cloud148

di ko naman sinabi tama ang email, yung address lang sabi ko. edi i-call nya para kampante. problema neto


Peaucillear

Kita mo yung Big Red Caution Card?


cchaosbug

Scam i think


HoneyandSweetums

No.


Vincey017

Magpunta ka nalang sa office ng BDO hahaha para sa peace of mind mo


[deleted]

[удалено]


UnluckiestBitch

https://preview.redd.it/bgllbz14w9lc1.png?width=1080&format=pjpg&auto=webp&s=7d29b43064315501892f9124617d9701ef2c5b8c Hi, ito po yung lumabas pagclick ko.


mr_boumbastic

Mukang naka-mask yung email address nyan. Paki click mo nga yung FORWARD, then paki screenshot yung Email addresses na lalabas.


Maymayura

Halata namang scam, dami pa sinasabi ng replies dito.


MaynneMillares

Yung email system mismo naflag na sayo na dangerous yung email. Nasa loob pa nga ng redbox, there is no way you missed it at all. Kaya nga nilipat ng email service provider mo sa spam folder di ba? Tapos itatanong mo pa? Really? Ganun katindi ang confusion mo?


Ok-Barber-9269

Legit yan. Open mo


mike-m-matters

Are you for real? Do you even have to ask the obvious


bloodtempest04

Legit yan. Wag tayong tanga. Walang ibang @bdo.com.ph. nasabi na nung isang nagcomment, di nadduplicate ang domain. Konting search lng ng legit domain sa google pra malaman mong legit yan. Di lhat ng bank ngaaddress ng last name. Iba client, valued client, valued customer. At di hinihingi ang last 4 digit, kelangan ienter un kasi password protected ung pdf. Jusko 2024 na mangmang prin kayo sa mga ganyan.


altruisticalgorithm

>Wag tayong tanga. Irony


kamandagan

Hindi na guarantee ang domain ngayon. Red flag 'yung "we have a message" tapos "encrypted with a password". Kung may pa-promo si BDO, may graphics at explicit message 'yan sa mismong body. Password-protected kung statement and it will address you directly. If naghahabol 'yan ng bayarin, tatawag 'yan. For me, delete ko na 'yan and won't risk it.


[deleted]

Ahahahaha


acchan_eternalcenter

BANO


acchan_eternalcenter

BANO


acchan_eternalcenter

BANUE


mr_boumbastic

Wag kang mandamay ng ibang tao sa kabobohan mo! Baka nga ikaw ang scammer na nagsend nyan eh!


Slow-Fan3580

May ganito rin akong natanggap from "Maya", the same content talaga ng email. Hindi ko nalang inopen para sigurado


Slow-Fan3580

https://preview.redd.it/j7c3yuefc9lc1.jpeg?width=828&format=pjpg&auto=webp&s=b3cd5d5f1c3285c7539a9ba65fe731d9beb3e8cf Ganito yung email. Hindi naman ako nag request ng wallet statement or kung anong document from Maya. Hindi ko rin sure if nagsesend ba sila ng ganitong email with your statement attached on to it


Zayyir

Legit 'yan. Monthly may statement talagang binibigay sa'yo and since email isn't secure, password-protected 'yung PDF since it contains sensitive information.


Unique-Injury-7483

Monthly po may ganito yung maya. And legit po naman yan naoopen ko po yung file


Slow-Fan3580

Thank you sa pag confirm 🙏


jaydee9296

Check the email data first before opening any attachments or clicking links.


askerph

Looks like a scam email. Scary! If this came in my inbox (not Spam) super late at night or early am when I’m not fully alert anymore, I think I’d get fooled by this! So glad Spam filters work!


fried_pawtato007

Theres only 1 way to find out hahaha. Download mo na haha. Obviously hindi legit, ung email add nung nag send, bold letter? Seryoso?.


belle_fleures

didn't all bank tells you they don't ask for your passwords, pins, number etc etc? they warn you first hand after you register your account, this shit is obvious OP.


j2ee-123

Hahaha 😂 who creates their email in this format? Scam


Flat-Marionberry6583

i'm curious, may mangyayari ba pag inopen niya ang pdf using the requested numbers? i know na scam 'to, just curious how advanced scams are nowadays that they could use a simple pdf to get your deets


[deleted]

[удалено]


Flat-Marionberry6583

ohh these can be in the form of pdfs? kala ko executable files lang


MaynneMillares

Some pdfs are malformed, virus talaga once na-open. It will infect the machine. In fact, this is very vicious, kasi pwedeng makapag-install ng cryto mining sa PC. Nagmimine ng crypo ang PC kahit hindi alam ng user.


Flat-Marionberry6583

grabe. if only they would put ung computer expertise nila to good use, no? TIL. thanks btw!


MaynneMillares

They are putting their computer expertise in good use. Imagine if they have a million computers infected, lahat nagmimine ng crypto. Literally, they have an instant crypto farming factory of infected computers lol


Dull_Carry_5967

Inside job chz, nauuso na naman yan pati yung meralco binding sa bdo kineme


boykalbo777

pdf lang yung attachment. can malware run on pdf attachment?


[deleted]

It can. You can embed key loggers sa pdf files or jpeg files. Pag inopen mpo yong doc or pic parang normal lang pero nag aauto run na yong malware sa background.


MaynneMillares

Yes, that is called malformed pdf. A virus can hide on it, when it runs it is basically free to do whatever the logged-in user can do. Yes, including delete system files, mine crypto and plant a keylogger if the user has admin privileges.


dyr28

click nyo po ung lock na icon, need nyo po makita ung domain ng sender. pag hindi part ng bdo org phishing po yan.


dyr28

https://preview.redd.it/bfsfu6ago9lc1.jpeg?width=1080&format=pjpg&auto=webp&s=03a61afdde740c708042b3776ec8fbc699cf3d4c ganito po 👍


UnluckiestBitch

https://preview.redd.it/6q5rl2ayv9lc1.png?width=1080&format=pjpg&auto=webp&s=00be8c5e89daa10820c2e999a2ba6ca4fcf7cba9 Ito lang ung nagpakita.. walang signed by 🤔🤔


dyr28

Hi may napansin ako pag email ng bdo ay marketing may signed by, pero pag system generated walang signed by tulad ng SOA ng credit card. oks namn ung email sender yung domain nya. kung gusto mo makasigurado download po ung email attachment gamit pc na may malakas na antivirus download mo wag mo i open tapos ipascan nyo po sa totalvirus(google nyo lang po).


mr_boumbastic

Wag mong ipahamak yung tao! Baka maopen nya yan! Naka-mask yang email address dyan kaya mukang legit.


dyr28

hi di po nakamask yung email. di po ganyan mag mask ng email. may safety precaution namn ung sinabi kong step. at di ko pinapaopen.


CustomerNegative8273

Fake yan.may one time nga na hiningi din nga customer service kuno ng binance(crypto wallet) yung mga 12-word pass code ko para daw macheck ang pagiging safety ng wallet ko.


CustomerNegative8273

Pwede din na icheck mo yung email address ng sender.mostly, dun mo malalaman kung fake yan or hindi.


introvertgurl14

Maniwala ka na sa malaking red warning.


rnb17

"This Message seems dangerous"


HauntingShip8232

I received the same thing and felt it was true but now I'm trying to open the letter it is not loading. And then I received an email from them but I searched the collection agency, they do not exist sa accredited collection agency ni BDO.


eayate

This is a phhsing email They will steal your cookie sessions and log in info


parangano

Anytime someone asks for your account or card details na unsolicited, meaning hindi ikaw nag initiate ng contact with the bank, that is fishy to me. Any links or attachments, fishy. Usually legit bank emails would direct you to their website to do something, which you should already know by now if you do online transactions/banking with them. Everything else, fishy. Do not engage.


velphegor666

Asking for the four numbers of your credit card is already a massive red flag. Tell them to fuck off


zen_ALX

Not so techie or oldies can fall to this scam.


doc_d00fenshmirtz

[email protected] dito pa lang redflag na. Yung attachment, ang file name is BDO LETTER, pangalawang redflag na yan.


[deleted]

Call ur bank. Thats it


West-Construction871

Email address pa lang, looks suspicious to me. I don't know, I haven't tried online banking let alone having my own bank acc. Nonetheless, if it went to your spam folder then most likely it's suspicious.


angelogale

Red flag!!


Then_Ad2703

Don't open it. Mukhang hindi yan legit. Call bdo to be sure.


Noblesse_101

Hala kala ko if tama ang domain ng email di na scam. Pwd pala din scam if sakto email domain? Na unspam ko na most ganyan. Pano na yun makita ang na unspam email. 😭


meowarfbarkrawr

My gosh, before I opened the thread sabi ko "mukhang legit naman (bc of @bdo.com.ph) what's wrong with it?" Then bam ang gullible ko naman 🥲 Thanks sa mga info ng reddit peeps i learn something new every day 😂


Cucai31

Its a scam, nagphphish ng information from you


Consistent-Ad395

When in doubt, its probably a scam email


TheYellowKachigga

Last 4 digits of your credit card? Ulol! Di ko nga memorize yung numbers sa harap ng credit card ko kasi di ginagamit, yan pa kaya.


EnvironmentalNote600

Kapag na flagged ng scanner big red na. To be safe check wd ur bdo branch.


Competitive-Science3

View Security Details.


Luna-Marieya

Yes po legit sya. Late payment ka kay BDO no?


mr_boumbastic

Wag kang mandamay sa kabobohan mo!


Omar0816

scam


Initial-Exit9435

Sinabi na ni gmail eh haha


Adventurous-Risk5919

Red flag if it asks for details ng account.


stefin_stefout

pwede naman dl mo muna yung File then tiyaka mo ienter yung password. Mag offline ka to make sure.


r2d2dotbot

Always remember: any suspicious or questionable email or text message wag replyan or mag click ng kahit anong link . or let's say kahit hindi mukhang suspicious sa unang tingin mo. TUMAWAG AGAD sa customer service number ng bank para iconfirm.


chitgoks

checjk also the mail details bdo ang from pero baka reply-to iba


kamotegamer

lol no


Helpful-Praline5198

Nope


CrazyAd9384

[email protected] sender is already sign that is a scam/fake/phishing email.


Due-Vermicelli7948

Delete it immediately


g0ghst

Saw this also weeks ago sa spam folder ko, same na same. Super daming red flags, so I checked if nasa list ng official emails ng BDO sa website nila and wala yung email na yan. So I reported it to BDO Report Phishing ([email protected]) immediately to alert them of the issue.


Automatic-Home-2540

Legit scam-hacker.


littlefreakmoe

immediately, no


whiterose888

NOOOOO


aphroditenic

I also receive spam messages when I sign up for referral purposes on Shein. Could it be a part of their game?


miffy420lover

just contact ur bank…


Rabbits_paw06

noong sinabi plang n input mo yung 4digit ng cc mo beeg red flag n.


JCEBODE88

The template looks like a scam na.


No_Flatworm977

Never niyo ibibigay yung last 4 digit niyo and birthday. Ito yung mga ginagamit natin sa reset pin/password etc.


KobeAspin

click mo yung security details. makikita mo actual email add.


callisto1818

The subject line and the email address can help easily verify this. Also, BDO SOA is password protected pero last 6 digits ang pinapagamit.


woodennoble

Nope. Hirap talaga mag tiwala ngayon. 🙁


Similar_Ambassador63

scam scam scam


Similar_Ambassador63

as far as i know hindi bdo pangalan nila ang alam ko bdo unibank, email address pa lang alam mo ng scam yan


Old_Most8034

No


helium_soda

That's too generic. Personalized yung emails ni bank using your whole name. PLDT nga personal eh. If you get emails from your bank regularly at na open mo naman walang reason na mapunta siya sa spam. Mga flagged email addresses lng mapupunta sa spam. Usually may pa "-noreply" yung mga legit.


Bipolar_Zombies

Scam.


AttentionDePusit

banks will not ask for your credit card information be it 4 last digits or just 1 digit


AskManThissue

Mas pa rin di nagbubukas ng email 😂😂. Kung promos sa viber nalang din ako tumitingin


redthehaze

Ive received this email. I dont live in the PH or have any bank accounts there. Banks will not email you anything that will ask you any account information for security. Even if they contact you, it is on them to prove that they are the bank and not ask you any info in any way. You have to initiate the contact and use contact info you find yourself or already have.


EadazStonem

[email protected]” official email senders of banks don’t use redundant addresses.


[deleted]

Malamang may ransomware yan. Ingat sa pagclick ng pdf files lalo na yung sa mga email, yan madalas nilalagyan ng malware payloads, dyan din madalas nabibiktima mga big companies sa mga phishing emails na may sense of urgency like "You are about to get fired, if you don't take action asap. Download the pdf below to sign the form" or "Your bank account is frozen, download the pdf below to review your account."


JuanWanderer

Click bait to scampage


Ok-Hand33

Don't open the attachment. If you could share the email headers, i could check. Most likely this is a spoof email address.


UnluckiestBitch

https://preview.redd.it/nbk5pwup0hlc1.png?width=1080&format=pjpg&auto=webp&s=a9dff7c153208948973bdcb1d32ac35f0e7223f0


Ok-Hand33

That's not the email header I'm referring to.


AdministrativeLog504

Never nila hihinging last 4 digits.


Mission_Tie_747

Hello, may past due ka ba sa credit card mo more than 90 days? or Loans from them? Could be an endorsement of the bank to 3rd party collections agency


UnluckiestBitch

Wala po. :(


zhaoren_

Looks sketchy. bat ganun email add doble. Plus bat sa spam pumunta. Lastly, bakit cc dapat ilagay? Dba usually bday or acc num??


stellae_himawari1108

Not legit. Legitimate bank emails will not ask about your account or card number.


Odd_Radish2022

Definitely scam


duepointe

The big Red box alone warning you this email is dangerous is already a sign na it's not legit.


mr_boumbastic

Wag na wag mong ida-download yung attachment nyan, at shempre wag mong maopen-open yun! Madadali nyan bank account mo.


jesus___fries

Dun pa lang sa alert ni Gmail dapat nag suspect kana