📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Have you used annualcreditreport.co.uk?

For want of a better board to put this on, I chose this one since those stoozing are more likely to get their CRA reports. I may post links to this thread in the general CC board and Current accounts boards if I get few replies.

Backstory: I use a unique (unguessable) email address[1] with every company that asks for one, so that if I start getting spam, I know who initially received that email address.

Around October (I think) last year, I signed up to Annual Credit Report to get their free service which, once a year, for the price of receiving a monthly email from them, will acquire your online your CRA reports from the 3 main companies and show you the results online.

Their privacy policy states that they won't sell your email address.

Today, I get two spam emails (no, I don't want part of my body enlarged, nor do I want cheap software) on that address. Has anyone else signed up with them with a unique email address and has received spam email to that address?

I'm mainly interested in people who, like me, use unique email addresses and can trace them back to the company they were given to.

I've sent them a mail enquiring about this, but since it's Saturday I'm not expecting a reply until Monday. I realise it might just be a lucky guess on the part of some spammer (highly unlikely however), but I've caught one other company selling addresses in the same way, and I've had no spam from all the other companies I've used this system with.


[1] http://www.sneakemail.com
Conjugating the verb 'to be":
-o I am humble -o You are attention seeking -o She is Nadine Dorries

Comments

  • Dagobert
    Dagobert Posts: 1,625 Forumite
    I use exactly the same system (handy for spotting phishing emails, too).

    But as I only just signed up to annualcreditreport last week, I have no problems to report as yet.
    Dagobert
  • Paul_Herring
    Paul_Herring Posts: 7,484 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    Well all credit to them - they did reply.

    And denied everything. :/

    (After suggesting that I write back to the spammers to ask where they got my name under the UK's Data Protection Act. Har Har.)
    Conjugating the verb 'to be":
    -o I am humble -o You are attention seeking -o She is Nadine Dorries
  • MrsMillar
    MrsMillar Posts: 100 Forumite
    I've signed up to annual credit report and, yes, I get loads of spam. Unfortunately I don't meet your criterion of being able to trace where it comes from. I didn't notice a link with annual credit reports, but that does not mean the link is not there.

    However, I don't think these spamming/phishing email originators try to "guess" email addresses. I think they generate them by computer and probably get loads of bounce-backs as well as their "hits", so I really don't think it makes any difference if your email is a random jumble of letters, or if it is actually your name.

    Just my theory, anyway.
  • Spammers use web crawlers that trawl the internet and look for text that match an email address's format.
    This is then added to a mailing list that they use.
    Search engines use the same techniques. That is why when you perform a google search, you see a small link under the main one that says 'cached'. The crawlers that google use take a copy of the page and place it in google's servers. The next time the crawler scans the website, their cached copy is updated.

    An approach many people have started to adopt is displaying their email address as someone@NOSPAMdomain.com - obviously the user is meant to delete the NOSPAM from the address, but the spammer's crawler would try and send the spam to a non-existant address (that contains the NOSPAM part).
  • Paul_Herring
    Paul_Herring Posts: 7,484 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    MrsMillar wrote: »
    I've signed up to annual credit report and, yes, I get loads of spam. Unfortunately I don't meet your criterion of being able to trace where it comes from. I didn't notice a link with annual credit reports, but that does not mean the link is not there.
    Not quite what I was after - the only people who should be emailing me on *that* address is them; this applies to the hundreds of companies I've used this with (yes, I do have hundreds of unique email addresses which all direct to my usual gmail account which obviously gets spam in its own right.) Only one other email address used with a company has received spam in the years I've been using this - and it was 'personal' spam - not the generic spam most people get.
    However, I don't think these spamming/phishing email originators try to "guess" email addresses. I think they generate them by computer and probably get loads of bounce-backs as well as their "hits", so I really don't think it makes any difference if your email is a random jumble of letters, or if it is actually your name.
    They do guess, but usually with what's called a 'dictionary attack' - they 'guess' the bit before the @ sign with common usernames, sometimes adding numbers (see AOL) - this is unlikely with SneakEmail since the user bit of the email address are essentially random - one I've generated just to post here (lets see how long it takes to get spammed ;) ) is [EMAIL="b83ahfv02@sneakemail.com"]b83ahfv02@sneakemail.com[/EMAIL]
    Conjugating the verb 'to be":
    -o I am humble -o You are attention seeking -o She is Nadine Dorries
  • jamesd
    jamesd Posts: 26,103 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    Paul_Herring, I supplied a unique email address to annualcreditreport back in 2006. The only email I've had to that address is from them. I use spamgourmet for mine and that appears to be better protected than sneakemail.com, which does appear potentially vulnerable to dictionary attacks just using random sequences of alphanumerics of appropriate length. I think you just got unlucky with a spammer.

    At the moment my stats are 419 addresses with 6322 emails sent on to me and 126,173 eaten without me seeing them. Most of the eaten ones are from a few published addresses. The record spammer has caused 69,655 emails to me from a commission paying medical site I used to potentially get income from. Next worst after that was an address used in a bug reporting system that didn't protect addresses, at 15,936 emails from the harvesting.
  • Paul_Herring
    Paul_Herring Posts: 7,484 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    one I've generated just to post here (lets see how long it takes to get spammed ;) ) is [EMAIL="b83ahfv02@sneakemail.com"]b83ahfv02@sneakemail.com[/EMAIL]

    Just a brief follow up 3+ years on - strangely I've had less spam (or indeed any mail whatsoever) on this email address than I've had from the first one I supplied to annualcreditreport.
    Conjugating the verb 'to be":
    -o I am humble -o You are attention seeking -o She is Nadine Dorries
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.3K Banking & Borrowing
  • 253.2K Reduce Debt & Boost Income
  • 453.7K Spending & Discounts
  • 244.2K Work, Benefits & Business
  • 599.4K Mortgages, Homes & Bills
  • 177.1K Life & Family
  • 257.7K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.