Fake emails impersonating LWS: how to recognize them and what to do

Procédure

Objective of this article

Regularly, fake emails impersonating LWS circulate.
Their aim is to get you to click on a fraudulent link or to prompt you to share sensitive information.

In this article, you will learn how to:

  • recognize a fake email pretending to be LWS;
  • check whether the message received is legitimate;
  • know what to do according to your situation;
  • react quickly if you clicked, entered your password, or made a payment.

Services concerned

This documentation concerns all LWS customers using one of the following services:

  • domain name
  • web hosting
  • mail service
  • LWS customer account
  • services requiring renewal or action from the [ADDRESS] area>

Prerequisites

Before following this procedure, you must:

  • have access to the email received;
  • be able to log in to your LWS customer area;
  • not have deleted the message if you want the support team to verify it.

Context: why are you receiving this type of email?

Fraudsters regularly send emails that use the name, logo, or tone of LWS to sow doubt.

Their method is simple:

  • create an alarming message;
  • make you believe a service will expire, be suspended, or be deleted;
  • push you to click quickly on a link;
  • then recover your credentials or banking information.

These fraudulent messages do not pass through LWS infrastructure.

It is important to note that no data breach has been detected at LWS.
Fraudsters mainly exploit:

  • public information;
  • email addresses found on the Internet;
  • made-up scenarios to create a sense of urgency.

When these campaigns are reported, blocking requests are made to the providers concerned, even if they do not always succeed.

What types of fake emails have been identified?

The fake emails observed can take several forms.

For example, you may receive a message announcing:

  • a fake service renewal notice;
    Fake emails impersonating LWS: how to recognize them and what to do
  • a fake contract termination notice;
  • an alleged deletion of your customer account;
    Fake emails impersonating LWS: how to recognize them and what to do
  • a malfunction of your mail service;
    Fake emails impersonating LWS: how to recognize them and what to do
  • an expired password for an email address;
    Fake emails impersonating LWS: how to recognize them and what to do
  • an expired password for your customer account;
    Fake emails impersonating LWS: how to recognize them and what to do
  • a suspended email address;
    Fake emails impersonating LWS: how to recognize them and what to do
  • a deleted email address;
  • a mailbox that is almost full, for example 95% or 98%;
    Fake emails impersonating LWS: how to recognize them and what to do
  • a request to verify identity;
  • a confirmation of email address after alleged maintenance;
  • an urgent payment request to avoid a service interruption.
    Fake emails impersonating LWS: how to recognize them and what to do

Even if the subject changes, the goal remains the same:
to get you to click on a fraudulent link or enter personal information.

How to recognize a fake LWS email?

Several elements should alert you.

The message does not contain your customer ID.

All emails sent by LWS contain your customer ID in the format:

LWS-XXX depending on the case.

If you receive a message that:

  • asks you to click on a link;
  • asks you to pay;
  • asks you to verify your account;
  • asks you to confirm your information;

but does not contain your customer ID, you must consider it fraudulent.

The sending address is not correct.

LWS communicates only:

  • with the email address registered in your customer area;
  • and sends its messages from [EMAIL].

If the message comes from another address, it should be considered suspicious.

Example of a suspicious email:

Fake emails impersonating LWS: how to recognize them and what to do

The message tries to make you act urgently.

Fraudsters often use phrases such as:

  • “Your service will be suspended today.”
  • “Your account will be deleted.”
  • “Your mailbox is almost full.”
  • “Your password has expired.”
  • “Final reminder before termination”

This alarming tone is used to push you to act without checking.

The message contains a payment link or button.

An email that asks you to:

  • pay an invoice;
  • renew a service immediately;
  • confirm your identity;
  • reactivate an email address;
  • update your password;

via a link contained in the message should be treated with caution.

If in doubt, never click the link and contact LWS support from your customer area.

The content is vague, unusual, or inconsistent

A fraudulent email may also contain:

  • unusual wording;
  • mistakes;
  • requests that are too vague;
  • exaggerated threats;
  • an inconsistency between the announced problem and your actual services.
  • an incorrect price

What to do immediately if you receive a potentially suspicious email

Follow this procedure in order.

Step 1: Do not click any link

Do not click:

  • on [PERSON_NAME];
  • on any link;
  • on any attachment.

Even if the message seems credible, do not take any action from the email.

Step 2: Do not reply to the message

Do not reply to the sender.
The fact that a known name appears does not guarantee that the email is legitimate.

[PERSON_NAME] 3: Check the elements [PERSON_NAME] the email

First of all, [PERSON_NAME]:

  • the presence of your customer ID;
  • the sender's actual address;
  • the type of request made;
  • the urgent or threatening nature of the message.

Step 4: Log directly into your LWS customer area

Open your browser yourself and access your LWS customer area without using the link contained in the email.

This allows you to verify the situation from the official source.

Step 5: Check whether a real action is required

Once logged into your customer area, [PERSON_NAME]:

  • your active services;
  • your due dates;
  • your pending requests;
  • your notifications;
  • the actions actually required on your account.

If [PERSON_NAME] matches the content of the email, it is most likely a fraudulent message.

Step 6: [PERSON_NAME] support if in doubt

If you are not sure about the origin of the message, contact LWS support via the Support section of your customer area.

Do not ask for verification by replying to the received message.
Always use the official channel.

How to check that an email is legitimate?

You can consider a message reliable only if several elements match.

Check the following points

The message must:

  • contain your customer ID;
  • come from [EMAIL];
  • concern a service that actually exists in your account;
  • correspond to an action visible in your customer area;
  • not rely solely on a link contained in the email.

  

If the email asks you to take action but no equivalent request appears in your customer area, consider the message suspicious.

What to do depending on your situation?

[PERSON_NAME] — You received the email but did not click anything

In this case:

  1. do nothing from the email;
  2. check your account from the customer area;
  3. delete the message if the fraud is confirmed;
  4. contact support via the customer area if you want an additional check.

Case 2 — You clicked the link but did not enter anything

In this case:

  1. close the opened page immediately;
  2. do not enter any information;
  3. log in to your LWS customer area to check that no real action is required;
  4. monitor your account as a precaution.

Case 3 — You entered your password

If you entered the password for your customer account or an email address on a fraudulent site:

  1. change the relevant password immediately;
  2. choose a strong password different from the old one;
  3. check that your account contact information has not been changed;
  4. verify that no unusual action has been performed on your services.

Case 4 — You entered your bank details

In this case:

  1. contact your bank immediately;
  2. request a block if necessary;
  3. monitor your banking transactions;
  4. keep any useful evidence: [PERSON_NAME], screenshot, payment time, amount.

Case 5 — You made a payment

If you paid from a fraudulent link:

  1. contact your bank without delay;
  2. report the payment as suspicious;
  3. ask what steps to follow depending on your card or payment method;
  4. then check your LWS customer area to confirm that no official payment was actually expected.

Common mistakes and solutions

“The message looks professional, so it must be true”

That is not a sufficient criterion.
Fraudsters know how to reproduce the appearance of an official email.

Good reflex: always check the customer ID, the sending address, and your customer area.

“The message talks about an urgent problem, I need to click quickly”

That is exactly what fraudsters are looking for.

Good reflex: never click under pressure of urgency.

“I saw LWS in the sender name”

The displayed name can be misleading.

Good reflex: check the real sending email address.

“I clicked, so my account has definitely been hacked”

Not necessarily.
The risk mainly depends on what you did afterward.

Good reflex: if you did not enter anything, close the page and check your account.
[PERSON_NAME] a password or paid, act immediately.

“I received an email talking about a full mailbox, so it must be real”

Not necessarily.

Good reflex: check from your customer area or your official tools, never from the link contained in the message.

“The message does not contain my customer ID but it seems serious”

That is a major warning sign.

Good reflex: consider any message requesting action without a customer ID as fraudulent.

Expected result after verification

At the end of your check, you should be able to clearly determine one of these two situations.

Normal situation

You are reassured if:

  • no unusual action is requested in your customer area;
  • the message does not correspond to any real need;
  • you [ADDRESS] communicated any sensitive information;
  • no abnormal banking transaction appears.

Situation to handle immediately

You must act quickly if:

  • you entered a password;
  • you entered banking details;
  • you made a payment;
  • you notice an abnormal change on your account;
  • you can no longer access your customer area or services.

Deadlines and urgency level

In this type of situation, some actions must be carried out immediately.

To do immediately

  • no longer click on the message;
  • change the password if you shared it;
  • contact the bank if you entered banking details or paid;
  • check the actual status of your services in the [PERSON_NAME] area>

What not to wait for

Do not wait several hours or several days if:

  • you have shared a password;
  • you have communicated banking data;
  • you see unusual activity.

The faster you react, the more you [PERSON_NAME] risks.

Best practices to avoid phishing

To reduce the risks, keep these reflexes:

  • never click on an email link if in doubt;
  • always check [PERSON_NAME] customer ID;
  • always check the sending address;
  • log directly into your customer area;
  • never enter your banking information from a suspicious email;
  • contact support only via the Support section of your customer area [PERSON_NAME] doubt.

Conclusion

Fake emails pretending to be LWS try to provoke a quick reaction by using fear, urgency, or doubt.

To protect yourself:

  • never click on a suspicious link;
  • always check [PERSON_NAME] customer ID;
  • consider suspicious any message that does not come from [EMAIL];
  • always check the situation from your LWS customer area;
  • contact support via the Assistance section of your customer area if in doubt.

If you have shared a password or banking information, act immediately.

 

Rate this article :

4.6/5 | 18 opinion

This article was useful to you ?

Article utileYes

Article non utileNo

MerciMerci ! N'hésitez pas à poser des questions sur nos documentations si vous souhaitez plus d'informations et nous aider à les améliorer.


Vous avez noté 0 étoile(s)

Similar articles

1mn reading

Anti-DDoS filter - management policy in the event of a DDoS attack


Questions sur l'article (2)

Ask a question
SAMUEL
28 sept. 2022
bonjour Monsieur, Madame est il possible d'avoir un deuxième nom de domaine pour la formule starters? je suis sur la formule STARTERS. CORDIALEMENT
fabrice-LWS Reponse officielle
1 oct. 2022
Bonjour, je vous invite à souscrire à un second nom de domaine en vous rendant sur votre espace client LWS, cliquez sur "Votre identifiant" puis sur "Acheter un service". Une fois le nom de domaine actif sur votre espace client, il vous sera possible de le lier à votre formule LWS Starter en suivant la procédure suivante: https://aide.lws.fr/a/1415
Cette reponse vous a aide ?
Loloito78
il y a 10 mois
Pourquoi ne pas coder les adresses mail que vous faîtes figurer sur les registar à linstar d'ovh par exemple, les mails clients sont des mails [domaine masqué] Cela éviterait de diffuser systématiquement nos domaines mails aux premiers robots venus
Maxence-LWS Reponse officielle
il y a 10 mois

Bonjour,

Je vous remercie pour votre message.

Les coordonnées de nos clients sont masquées sur le Whois, sauf lorsque ceux-ci ont enregistré le nom de domaine en tant que société (pour les noms de domaines en .FR) par exemple.

Dans votre cas, je ne retrouve pas votre fiche client, je ne peux donc pas me prononcer.

Cependant, sachez que les SPAMS et autres mails indésirables, sont reçus, car les spammeurs envoient des emails à des adresses mails très génériques, du type contact@votredomaine.fr ...

Ces derniers ont également des outils qui récupèrent les adresses mails potentielles en clair sur les sites web, et ce quelque soit l'hébergeur, l'outil whois est donc très rarement la porte d'entrée pour les spams.

Je vous remercie de votre attention et reste à votre disposition pour toute autre question ou complément d'information.

Vous pouvez nous contacter depuis votre espace client ou sur cette page : https://www.lws.fr/contact.

Cordialement, L'équipe LWS 

 

Cette reponse vous a aide ?

Ask the LWS team and its community a question

RGPD : Responsable LWS-Ligne Web Services. Finalité : modération et publication publique de votre question, notification éventuelle d'une réponse. Base légale : consentement (art. 6.1.a RGPD). Conservation des emails : 90 jours après notification, 12 mois maximum sans réponse. Vous pouvez exercer vos droits via notre nos CGV - section RGPD.