MySpace Identity Theft Scams On the Rise?

MySpace has become a target for identity thieves. Not that this is surprising, there is an added twist that takes it beyond what I’ve seen done on sites like PayPal or Ebay.

For example, who hasn’t received an email claiming to be from PayPal or Ebay telling you that your account has been exploited, that you need to update your account information, or that you have won an auction that you hadn’t bid on? They VERY common, and all done with the same purpose: to get you to click on a link to a fake PayPal or Ebay site where you’ll enter your login information. This can then be used to drain your accounts, run fraudulent auctions, and other malicious activity.

Similar behavior is happening using MySpace, which makes sense since there are millions of registered members who could be tricked into turning over their login information – Information that’s surely usable on other sites like PayPal or Ebay.

But here’s the twist: this is being done from within MySpace.

Here’s an example email I received in my MySpace inbox from a MySpace friend of mine. It wasn’t a typical MySpace webcam girl spam request. This looked like a legitimate email from an actual friend of mine:

MySpace Spam

I’m sure a LOT of people would open an email like that when it’s sent to them from a friend. Here’s what the link took me to:

Fake MySpace Site

Whoops. Looks like I got logged out when I tried to visit the page my friend suggested I check out. That’s certainly not uncommon on MySpace.

But wait, what’s up with that URL:

Fake MySpace Site URL

As ugly as most MySpace URLs are, they’re not THAT ugly. A .cn domain? Why am I suddenly in China visiting a sub-sub-sub-sub-sub-sub-domain of 378d38.cn?

That’s an impressively good spoof site. Reading the domain from left to right would be enough to reassure many MySpace members.

Does anyone actually fall for this?

Take a look at the spike in traffic to the identity theft site over the past month:

378d38.cn Page Views

That’s a LOT of traffic. Evan a minuscule conversion rate would generate a ton of MySpace member’s login information.

How many MySpace members have to click on links to 378d38.cn before MySpace gets around to blocking emails mentioning that domain?

MySpace the Best Choice for Bands

This may seem pretty obvious, but it really hit home with me tonight: most bands should use MySpace as their primary online communications platform.

Why? Because it’s simply too hard to create what MySpace already has in place.

That, and the fact that most musicians don’t seem to have experts on building web communities as friends. They’re more likely to have designers as friends who can build beautiful web sites that the band has no idea how to update. That’s kind of a big deal when your fans are looking for information on upcoming concerts, new CD releases, etc.

MySpace really is the ultimate band site, with easy to blogs, bulletins, community building, an RSS feed, photos, videos, and song samples. Recreating that from scratch would take a lot of work, and it wouldn’t provide easy access to the fans who are already on MySpace.

Of course, there is one big advantage to building something independent of MySpace: Access to Facebook and other audiences beyond MySpace’s walls. And MySpace tends to be very stingy with the content you contribute to their site, so don’t expect to be able to easily retrieve your own content should you choose to more to Facebook or your own site in the future.

Ah, crap. I may have just talked myself out of using MySpace as a band platform.

I think what bands need is a resource for helping them find band-specific web developers who can build the right type of site for them so they won’t get trapped into something like MySpace or an underpowered site built by a friend.

Any thoughts?