New American Express Credit Card Identity Theft Phishing Scam

A new American Express credit card identity theft phishing scam is being sent out in spam email. The subject line is “A recent charge attempt requires your attention” with a random number, so that the subject of our sample reads “A recent charge attempt requires your attention 688836786” The spam goes on to ask “did you recently use your card?”

Here’s our sample, with full headers below in case you’re into that sort of thing. Note that the actual “From” says ‘America Express’, and also the address is fake, this was not sent out through a San Diego edu account, it was sent out through MailJet.

From: America Exp𝖗ess Subject: A recent charge attempt requires your attention 688836786


Verify Your identity

Your Account Number Ending: *****

Dear Cardmember:

Did you recently use your card ?

To help protect your identity your access to your credit has been paused, We wanted to be sure that you had made this transaction.

See Have your card handy, Sign ln and follow the simple step, Then our intelligent security system will connect you back instantly.

Thank you for your Card Membership.

Of course, the “” link (note the ‘l’ instead of an ‘i’) is actually linked to a link (, which in turn goes to a subdomain at, in turn, was just registered a few days ago, and at the home page has only a “welcome to WordPress” splash page. Obviously the unique subdomain has a page mimicking the actual American Express home page, so that you try to log in and voila! The phisher has captured your username and password.

Hopefully if you received this, you did some research first and weren’t taken in!

Here are the full headers of that email, with the actual recipient redacted:

America Exp𝖗ess A recent charge attempt requires your attention 688836786
One thought on “New American Express Credit Card Identity Theft Phishing Scam

  1. I’ve been getting my fair share of those kinds of emails (and not just for American Express), but I’m a lot more concerned about my phone SPAM. Lately, I’m being bombarded with SCAM phone calls from fake Amazon asking me to verify a $1300 iPhone purchase. What’s worse, they call from spoofed phone numbers (there’s an unlimited supply of those!) and they continue calling every few minutes all day long. They’ll keep it up for a few days and then stop. They wait about a week (or sometimes two) until they think I’ve probably forgotten about it and then they start all over again.

    I never answer my phone unless the caller is on my contacts list. If it’s a legitimate caller, they’ll leave a message. If it’s not a legitimate caller, they might still leave a message, but at least you know not to return the call. Ditto all callers that don’t leave any message.

