Recently, “cloud” suddenly appeared in many people’s mailboxes.bill“Notification of Winning Prize”, the content of the letter looks quite formal, and it even uses the names of well-known companies such as EasyCard, HiNet or Taiwan Petroleum Corporation to inform the invoice of winning and attach a query link. Many people have seen “Winning “1,000 yuan” will inevitably make you curious, but in fact there may be a carefully designed fraud trap hidden behind it.
This type of letter usually requires you to log in to inquire or fill in information. It seems like it is just a process of receiving invoice bonuses, but in fact, it may induce people to hand over personal information or even credit card information step by step. What kind ofScamHow does the letter work? What details can help us quickly identify it? The following will take you through the common routines of this type of cloud invoice phishing scam.

Won 1,000 yuan in CNPC invoice? Be careful, this type of letter is a scam! Completely crack the common tricks of fraudulent web pages
Recently, many netizens have shared that they have received emails that appear to be scams, with titles that look quite official, such as “Check your EasyCard cloud invoice exclusive award results now” or “TWM e-Invoice cloud invoice inquiry portal update notification.” The content of the letter usually indicates that the user’s cloud invoice has won a prize, and attaches a query link to remind the public to log in to the member center to confirm the bonus collection process.
On the surface it looks like a normal winning notification, but if you look closely you will find a lot of things that are wrong.
These letters often require you to click on a link to enter the so-called “Official Cloud Invoice Platform” or “Member Center”, and you must log in to your account to receive the bonus. For many people, seeing the lottery winning information may make them excited for a moment, but in fact, most of these links point to fake phishing websites.
The EasyCard company also specifically reminded that such emails are not officially sent, and emphasized that the company will not ask users to provide account or personal information through emails, calling on the public to be vigilant.
In addition to EasyCard, people have recently discovered that fraudulent letters are also sent in the name of other companies, including brands such as Chunghwa Telecom HiNet or Taiwan’s CPC. Scammers use the names of large, familiar companies to make their letters appear more credible.

If you look closely at the sender, you will actually find something “weird”.

After actually clicking on these suspicious links, the author found that the design of the fraudulent website was quite realistic. The appearance of the page is almost very similar to that of the Ministry of Finance’s electronic invoice integration service platform. If you don’t check the URL carefully, it is easy to mistake it for the real official website.
However, careful comparison can still reveal some differences. For example, the official platform will provide login methods such as natural person certificates or mobile natural person certificates, but fraudulent websites usually only provide simplified version login options. In addition, on the mobile phone barcode login page, the real official platform will have a graphic verification code, while fake websites often omit this step and only require entering the mobile phone number and password. If the user does enter the information, the fraud group can obtain the mobile phone number and account information.

Even after successfully logging into the fake website, the fraud process is not over yet. The next page will display the “Vehicle Binding Verification Area” and require you to fill in the cardholder’s name, credit card number, expiration date, and the 3-digit security code (CVV) on the back of the card.
This step is the most critical part of the entire fraud. If people really fill it out and send it in, they are giving their complete credit card information directly to the fraud group, and there may be a risk of subsequent theft.
What’s even more exaggerated is that even if you enter a random phone number or password, the website can “log in successfully.” This is actually a typical feature of a phishing website, and its purpose is only to induce users to enter the next step to fill in information.

This suspicious webpage can be found through the Internet Fraud Reporting and Inquiry Network of the Ministry of Digital Information and Communications Technology. The Internet Fraud Reporting and Inquiry Network is an anti-fraud platform created by the Ministry of Digital Development to provide the public with real-time inquiry and reporting of suspected fraud information, and jointly protect digital security.

In actual unified invoice winning letters, people will not be asked to enter additional personal information.

fact-checking website MyGoPen It was also pointed out that fraud groups often take advantage of people’s familiarity with cloud invoices and send notification letters pretending to be e-commerce platforms or service providers. The letter will claim that the user’s invoice is a winner and provide a query link. As long as you click to enter and enter the information, your personal information may be grasped by the fraud group. This type of fraud is actually not new, but because cloud invoices often notify winnings via email, it is easier for people to lower their vigilance.
Conclusion
In the face of this type of cloud invoice winning notification email, the safest way is actually very simple, that is, do not click on any links in the email. If you really want to confirm whether you have won the prize, you can directly go to the Ministry of Finance’s electronic invoice integration service platform or official app to check, instead of logging in through the URL provided by email.
Another important principle to remember is that any website that requires you to enter complete credit card information must be extremely careful, especially the 3-digit security code on the back of the card. Once this information is leaked, it may cause money loss.
As the fraud techniques become more and more realistic, the design of phishing websites is getting closer and closer to the official platform. Staying alert and developing the habit of not clicking on unfamiliar links is the most effective way to avoid falling into scam traps.
Further reading:
Source: KOCPC Chinese