
Nordstrom customers have received deceptive emails seemingly from the company, promoting cryptocurrency scams disguised as a St. Patrick’s Day special.
These fraudulent emails promise to double any cryptocurrency the receiver deposits into a given wallet within a two-hour timeframe.
The scam email says, “Send cryptocurrency to your provided wallet and get 200% back.”
Numerous customers shared on social media [1, 2] that they were sent these emails. Some stated the email was delivered to addresses that were never shared publicly.
The scammers give potential victims only two hours to decide, creating a sense of urgency to pressure people into the “deal” before realizing it’s a scam, possibly missing errors like the misspelled company name “Normstorm” in the email’s header.
The ruse is further validated because the emails originated from [email protected], an official Nordstrom email used for marketing communications, a sign of a security compromise.
BleepingComputer did not hear back from Nordstrom, but customers reported that the company emailed a warning, asking recipients to ignore the previous “unauthorized” email.
The firm stated in its warning that it “will never ask customers to transact or transfer funds using cryptocurrency” and is “taking immediate action to investigate and address the issue.”
Nordstrom is a major American fashion retailer selling clothes, shoes, beauty products, and accessories online and in physical stores.
The company, founded in 1901, has millions of customers, employs approximately 55,000 people, and generates over $15 billion in annual revenue.
It is not known if all Nordstrom customers received the message, but some victims have already sent cryptocurrency to the provided wallet address.
The cryptocurrency wallets used for the scheme have received over $5,600 since the emails were sent.
A source familiar with the situation told BleepingComputer that the incident stemmed from a breach stemming from an Okta SSO > Salesforce compromise, and the emails were sent to customers, using Salesforce Experience Cloud.
While BleepingComputer could not independently confirm it, this incident is similar to recent crypto scams targeting Betterment and GrubHub.
Nordstrom shoppers should disregard the promotional email and avoid sharing funds or sensitive information.
Exercise caution with suspicious content, especially from a recognizable sender, and verify promotions on the company’s website, communication channels, and social media pages.
#crypto #email #for #hacked #news #nordstrom’s #scams #shoppers. #targeting #used — News
© Bulletproof Servers. All rights reserved.