Can you help?

  • Profile Image
    Jiqing Ye 
    Asked on January 01, 2019 at 11:23 AM

    Hi,

    I was recently got scammed with $600 loss and am trying to learn a bit.  The response after filling out the form on the fraudulent website (puppypug.com) is an nonreply email from jotform.com.  I am wondering if you have the email address that person(s) who set up the form.  Would you guys do anything to stop them using your forms?  Thanks, Jiqing


    Received: from CY1NAM02HT178.eop-nam02.prod.protection.outlook.com (2603:10b6:a02:bc::45) by BYAPR04MB4119.namprd04.prod.outlook.com with HTTPS via BYAPR07CA0032.NAMPRD07.PROD.OUTLOOK.COM; Thu, 27 Dec 2018 18:50:06 +0000 Received: from CY1NAM02FT052.eop-nam02.prod.protection.outlook.com (10.152.74.58) by CY1NAM02HT178.eop-nam02.prod.protection.outlook.com (10.152.75.6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id 15.20.1471.13; Thu, 27 Dec 2018 18:50:05 +0000 Authentication-Results: spf=pass (sender IP is 152.160.252.94) smtp.mailfrom=jotform.com; hotmail.com; dkim=pass (signature was verified) header.d=jotform.com;hotmail.com; dmarc=pass action=none header.from=jotform.com; Received-SPF: Pass (protection.outlook.com: domain of jotform.com designates 152.160.252.94 as permitted sender) receiver=protection.outlook.com; client-ip=152.160.252.94; helo=pool62.formresponse.com; Received: from pool62.formresponse.com (152.160.252.94) by CY1NAM02FT052.mail.protection.outlook.com (10.152.74.123) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id 15.20.1471.13 via Frontend Transport; Thu, 27 Dec 2018 18:50:05 +0000 X-IncomingTopHeaderMarker: 

  • Profile Image
    ktyaguirre
    Answered on January 01, 2019 at 12:26 PM

    Upon review of your request we have taken action to take down the account and block the forms that are scamming people. Do not hesitate to report these type of forms.

    Thank you

  • Profile Image
    Jiqing Ye 
    Answered on January 18, 2019 at 07:43 PM
    The scammer migrated their website to animalscuddle.com. They still use you form as I tested it. They have changed their domain from puppyhope.com, puppycomfy.com, and puppycomes.com. Is there a way to prevent them from using your form for good.
    Thanks
    ...
  • Profile Image
    ktyaguirre
    Answered on January 18, 2019 at 10:40 PM

    We are taking down the account that contains the form and also banned the IP.

    We can only deter the user from using the services, by blocking reported attempts.

    Thank you for reporting. Please feel free to forward more findings if any.

    Thank you


  • Profile Image
    Jiqing Ye 
    Answered on January 19, 2019 at 05:43 PM
    Thank you for your response. The scammers rebuild their form with 123 form builder. For my learning purpose, what do you mean that you banned the IP? Do you know the scammer's device IP?
    ________________________________
    ...
  • Profile Image
    BitiaP
    Answered on January 19, 2019 at 07:28 PM

    We ban the the public IP attached to the forms we suspended, because it is form's information.

    Thank you.