Procédure
Regularly, fake emails impersonating LWS circulate.
Their goal is to make you click on a fraudulent link or to get you to share sensitive information.
In this article, you will learn how to:
This documentation concerns all LWS customers using one of the following services:
Before following this procedure, you must:
Fraudsters regularly send emails that use the name, logo, or tone of LWS to sow doubt.
Their method is simple:
These fraudulent messages do not pass through LWS infrastructure.
It is important to note that no data breach has been detected at LWS.
Fraudsters mainly exploit:
When these campaigns are reported, blocking requests are made to the relevant providers, even if they do not always succeed.
The fake emails observed can take several forms.
For example, you may receive a message announcing:








Even if the subject changes, the goal remains the same:
to make you click on a fraudulent link or enter personal information.
Several elements should alert you.
All emails sent by LWS contain your customer ID in the format:
LWS-XXX depending on the case.
If you receive a message that:
but does not contain your customer ID, you must consider it fraudulent.
LWS communicates only:
If the message comes from another address, it must be considered suspicious.
Example of a suspicious email:

Fraudsters often use phrases such as:
This alarming tone is used to push you to act without checking.
An email that asks you to:
via a link contained in the message must be handled with caution.
If in doubt, never click the link and contact LWS support from your customer area.
A fraudulent email may also include:
Follow this procedure in order.
Step 1: Do not click any links
Do not click:
Even if the message seems credible, do not take any action from the email.
Step 2: Do not reply to the message
Do not reply to the sender.
The fact that a familiar name appears does not guarantee that the email is legitimate.
Step 3: Check the visible elements in the email
First of all, check:
Step 4: Log in directly to your LWS customer area
Open your browser yourself and access your LWS customer area without using the link contained in the email.
This makes it possible to check the situation from the official source.
Step 5: Check whether a real action is required
Once logged in to your customer area, check:
If nothing matches the content of the email, it is very likely a fraudulent message.
Step 6: Contact support if in doubt
If you are not sure where the message came from, contact LWS support via the Assistance section of your customer area.
Do not request verification by replying to the received message.
Always use the official channel.
You can consider a message reliable only if several elements match.
Check the following points
The message must:
If the email asks you to take action but no equivalent request appears in your customer area, consider the message suspicious.
Case 1 — You received the email but did not click anything
In this case:
Case 2 — You clicked the link but entered nothing
In this case:
Case 3 — You entered your password
If you entered the password for your customer account or an email address on a fraudulent site:
Case 4 — You entered your bank details
In this case:
Case 5 — You made a payment
If you paid from a fraudulent link:
“The message looks professional, so it’s probably true”
That is not a sufficient criterion.
Fraudsters know how to reproduce the appearance of an official email.
Good reflex: always check the customer ID, the sending address, and your customer area.
“The message talks about an urgent problem, I need to click quickly”
That is exactly what fraudsters are looking for.
Good reflex: never click under pressure from urgency.
“I saw LWS in the sender name”
The displayed name can be misleading.
Good reflex: check the real sending email address.
“I clicked, so my account has definitely been hacked”
Not necessarily.
The risk mainly depends on what you did afterwards.
Good reflex: if you entered nothing, close the page and check your account.
If you entered a password or paid, act immediately.
“I received an email talking about a full mailbox, so it’s probably real”
Not necessarily.
Good reflex: check from your customer area or your official tools, never from the link contained in the message.
“The message does not contain my customer ID but seems serious”
That is a major warning sign.
Good reflex: consider any message requesting action without a customer ID as fraudulent.
At the end of your check, you must be able to clearly determine one of these two situations.
You can be reassured if:
You must act quickly if:
In this type of situation, certain actions must be carried out immediately.
Do not wait several hours or several days if:
The faster you react, the more you limit the risks.
To reduce the risks, keep these reflexes:
Fake emails pretending to be LWS try to trigger a quick reaction by using fear, urgency, or doubt.
To protect yourself:
If you shared a password or banking information, act immediately.
Bonjour,
Je vous remercie pour votre message.
Les coordonnées de nos clients sont masquées sur le Whois, sauf lorsque ceux-ci ont enregistré le nom de domaine en tant que société (pour les noms de domaines en .FR) par exemple.
Dans votre cas, je ne retrouve pas votre fiche client, je ne peux donc pas me prononcer.
Cependant, sachez que les SPAMS et autres mails indésirables, sont reçus, car les spammeurs envoient des emails à des adresses mails très génériques, du type contact@votredomaine.fr ...
Ces derniers ont également des outils qui récupèrent les adresses mails potentielles en clair sur les sites web, et ce quelque soit l'hébergeur, l'outil whois est donc très rarement la porte d'entrée pour les spams.
Je vous remercie de votre attention et reste à votre disposition pour toute autre question ou complément d'information.
Vous pouvez nous contacter depuis votre espace client ou sur cette page : https://www.lws.fr/contact.
Cordialement, L'équipe LWS
Ask the LWS team and the community. Answers are published after moderation.