The issues:
- Contact from a contact form and email wording
- Email domain was not from the companies main domains
- Quickly changing domain information and website
- Files not what they should have been
We were contacted by ashley at kitchenaid-us dot com via the contact form on our website, with the content:
Hi,
KitchenAid, a leading brand in premium kitchenware and appliances, is seeking a creative and strategic advertising agency to develop and execute a high-impact advertising campaign in United Kingdom.
With our commitment to innovation and quality, we aim for a campaign that effectively conveys our brand story while strongly resonating with our target audience. We believe that with your expertise, you will be a strong partner in creating an engaging and compelling campaign.
We would be delighted to explore this opportunity with you. Please feel free to contact me via this email to discuss the collaboration further.
Sincerely,
This was a great contact from an amazing brand, but this was a contact from the website contact form, we do get a few spam emails each week, so we can’t take these at face value. Also, some of the wording of the email didn’t sound quite right (I won’t go into it here, but if you read the emails below you will understand), so we can say this is the first issue.
Domain
The domain the email address was using, didn't feel quite right with that -us at the end. I decided to investigate this a little further.
who.is didn’t have any real information on that particular domain, but the company KitchenAid has the domains kitchenaid.com and kitchenaid.co.uk with all the information set to public, so these differences was the second issue.
I sent a second email asking about performance and domain redirects and telling Ashley we could create a Web Report to help with this sort of thing.
When I checked on the domain a second time, just a day later some things had changed.
- All the information had been set to private in who.is, not the name of the company
- The website had gone from a direct copy of the US version of KitchenAid’s website to a redirect.
Changing information just after I’d checked it and made some comments could have been a coincidence or extremely quick development, but I was sceptical. This was the third issue.
Files
I downloaded the 'pack' Ashley asked me to look at and unzipped the file. It contained a bunch of marketing information, videos, images and looked pretty authentic (I didn't open any files). However, there was a file with a Word document icon that was not a Word document:
17_KitchenAid-MARKETING STRATEGY AND STATISTICS(2-19).docx.scr
I always enable show file name extensions to see the real file endings, but if I didn’t I would have seen:
17_KitchenAid-MARKETING STRATEGY AND STATISTICS(2-19).docx
Notice there is no scr
on the second version? This is a scr
file, hidden as a Word document and this was the fourth issue.
If I was not paying attention and had simply clicked on the file it would have ran and it would not have opened a word document as most people would expect but would have ran an a screen saver file which has access to all sorts of low level parts of the system.
At this point I was sure this was a scam and ran a Microsoft Defender scan on the file, which found nothing.
What could have been
There are 3 main issues that could have occurred if we click on and run the scr
file:
- Virus / Worm – The computer is infected with a virus that attacks other files on the computer and makes the computer unusable. A virus checker can fix this and most files can usually be brought back from a drive. Cloud files and backups can be affected.
- Malware – A program is installed and runs in the background, passing all data including passwords to a 3rd party. We may not even know this is running. Cloud files / backups are not usually affected.
- Ransomware – Special type of Malware that will zip up data with a password, then ask for a ransom to get access to the files, usually in the form of crypto coin. There is a good chance there is no password and data is gone forever. Cloud files / backups are usually not affected.
If there is no backup of the data, any of these can be disastrous for any size of business from data breaches to loss of all contact with clients.
Protect yourself
- Make sure any computer has protection and that protection is not switched off.
- If it sounds too good to be true, then it usually is too good to be true
- Backup your data, preferably offsite to another location e.g. the cloud
- Don’t just click links, think about what the worst-case scenario could be
- Enable file types so you can see what you are clicking
Summary
We didn’t fall for this one, but people fall for these scams every day and it can happen to anyone. If I’ve missed anything or you have any stories about scams or security let us know in the comments or contact page.
Emails
I'm adding these here so you can see the wording used and see if you can pick up on the wording issues
Email 1
Hi ????,
My name is Ashley from KitchenAid, owned by Whirlpool. As a representative responsible for the company's business expansion, I am looking for support about effective marketing services to grow the retail sales of kitchen products.
We are a globally recognized leader in premium kitchen appliances. With over 100 years of history, KitchenAid has established itself as a trusted brand in households around the world, offering a wide range of high-quality products from stand mixers to modern kitchen appliances such as: coffee makers, dishwashers, . . .
http://kitchenaid.com
https://www.facebook.com/KitchenAid
We aim to scale growth and implement professional, multi-channel and multi-platform marketing strategies to achieve further success in sales and customer growth.
Our planned scale and marketing budget range from $1.8 to $2.5 million annually for marketing activities.
Our goals for 2025 include enhancing brand visibility, attracting new customers in emerging markets, and driving sales through exploring new marketing platforms and optimizing existing ones, such as Google Ads, YouTube advertising, KOL advertising, social media advertising and TikTok.
These are the services that we are particularly interested in and would like to receive your support to develop them (depending on the services your company provides).
We are looking for a long-term collaboration to ensure effective, stable allocation for personnel and related costs across departments.
Our proposed service fee is between 14-18% of the total monthly marketing budget (+ any applicable taxes). You are welcome to propose budgets and bids that match your company’s capabilities and resources.
In addition to public data, we have gathered our business information, detailed documents outlining our marketing objectives, year-over-year metrics, actual market data, product pricing, advertising metrics, CRM information, ROAS, ad conversion rates, cost per acquisition, our strengths, and other relevant details:
Document: Campaign Materials, Service Fees, Job Requirements:
Password: ????
I believe this information will provide you with the most accurate and clear introduction to our company.
I look forward to receiving a preliminary proposed communication plan from you and your team on Thursday or Friday, about the project and the service fee schedule for the work items your company proposes for this project so that we can move quickly to the next step.
After receiving your feedback along with the necessary materials, please allow us 1–3 days to review internally, arrange personnel, and schedule an online meeting.
This meeting is intended to clarify initial working issues to finalize the agreement and begin the partnership.
If you require additional information, please let me know! We are ready to meet and discuss further.
Best regards,
Ashley
Email 2
Hi ????,
As detailed in the documents, the annual budget for paid marketing is $2 million, and the budget for supporting marketing activities or other marketing forms is $500,000 per year. (If the secondary budget proves effective, we can propose to the company to double it.)
Your service sounds interesting, I don't really have a clear concept about optimizing that part. Previously, we trusted and assigned the marketing service company to do and report on measuring everything. I think we should apply this service to proactively check and measure the effectiveness, helping business activities develop well and on schedule as planned.
The secondary budget category is meant to support marketing efforts, helping to accelerate growth, enhance credibility, and ensure greater success. Therefore, I believe we are well-suited to collaborate in this area, as it aligns with the services your company provides.
Could you please review and provide me with a quote based on the secondary budget category, with a total budget of $500,000 per year? (I would expect the budget to not exceed $500,000 per year, as the company has allocated a fixed budget for us. If the trial is successful, we will be able to propose and increase the budget to a higher amount, but this will only be possible at least 3 months after the successful trial.)
Best regards,
Email 3
Hi ????,
As detailed in the documents, the annual budget for paid marketing is $2 million, and the budget for supporting marketing activities or other marketing forms is $500,000 per year. (If the secondary budget proves effective, we can propose to the company to double it.)
Your service sounds interesting, I don't really have a clear concept about optimizing that part. Previously, we trusted and assigned the marketing service company to do and report on measuring everything. I think we should apply this service to proactively check and measure the effectiveness, helping business activities develop well and on schedule as planned.
The secondary budget category is meant to support marketing efforts, helping to accelerate growth, enhance credibility, and ensure greater success. Therefore, I believe we are well-suited to collaborate in this area, as it aligns with the services your company provides.
Could you please review and provide me with a quote based on the secondary budget category, with a total budget of $500,000 per year? (I would expect the budget to not exceed $500,000 per year, as the company has allocated a fixed budget for us. If the trial is successful, we will be able to propose and increase the budget to a higher amount, but this will only be possible at least 3 months after the successful trial.)
Best regards,