I am a brand new Nachi member - just signed up a few days ago. Last night I got an email that is clearly a phishing scam. It claims to be from the “InterNACHI Security Team” and says that I need to “follow the instructions and fill verification form to re-activate your InterNACHI membership” The link redirects to InterNACHI Member Verification – My Blog which contains a request for Name, Email address, NACHI username and credit card information. (Screenshot Attached)
Obvious phishing, obviously targeted at NACHI members. Since I received this within 48 hours after signing up, I suspect it is targeted at new NACHI members.
We’re working with the company that this site is hosted with to have it shut down. An Indonesian hacker has been targeting home inspectors with emails like this over the last few months. So far we’ve been able to get each site he sets up shut down, but he keeps on popping up. Always check to make sure you’re on NACHI.ORG if you click a link in an email that appears to be from InterNACHI.
Also, due to the nature of the underlying email protocols, it’s possible to fake the “From” address on messages, so it’s possible that these messages will look like they’re coming from an @nachi.org or @internachi.org email address. Always be careful when you receive an email that’s suspicious, even it parts of it look legitimate.