Jerry on Mastodon<p>Woke this morning with an email from <a href="https://hear-me.social/tags/Scotia" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Scotia</span></a> bank about my account. I don't have a Scotia account. </p><p>Usually, I ignore these as phishing, but I have a <a href="https://hear-me.social/tags/Thunderbird" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Thunderbird</span></a> add-on that tells me when SPF and DKIM pass. And the "from" domain was truly scotia bank. So, yes, it did come from them.</p><p>Spent 30 minutes on the phone bouncing around, queuing and waiting while they checked. Their conclusion is that their customer carelessly entered my email address instead of their own, and they will contact the customer.</p><p>Two things. </p><p>Email addresses should always be validated with an OTP. When will banks learn this?</p><p>Second: Some people are a pain in the ass.</p><p><a href="https://hear-me.social/tags/banking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>banking</span></a> <a href="https://hear-me.social/tags/phishing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>phishing</span></a> <a href="https://hear-me.social/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a></p>