{"id":416386,"date":"2026-09-19T05:15:57","date_gmt":"2026-09-19T05:15:57","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=416386"},"modified":"2026-09-19T05:15:57","modified_gmt":"2026-09-19T05:15:57","slug":"public-surplus-phishing-email-scam","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/public-surplus-phishing-email-scam\/","title":{"rendered":"Public Surplus Phishing Email Scam Targets Auction Accounts"},"content":{"rendered":"<p>An email says your public auction account needs attention. It may mention a document, a bid, an invoice, or a change that cannot wait. The name in the message is familiar enough to lower your guard.<\/p><div id=\"mwtad3636159144\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The Public Surplus phishing email scam is not a theory built from one unhappy customer. A county government published a direct warning after fraudulent messages began impersonating a trusted auction partner.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" width=\"1536\" height=\"1024\" class=\"skip-lazy\" data-no-lazy=\"1\" data-skip-lazy=\"1\" loading=\"eager\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/public-surplus-phishing-email.png\" alt=\"Illustrative Public Surplus phishing email with a fictional auction account notice\" title=\"\"><\/p>\n<div id=\"mwtad1612825610\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>Officials confirmed the emails are fraudulent<\/h3>\n<p>On September 17, 2026, Jefferson County, Washington posted a <a href=\"https:\/\/www.co.jefferson.wa.us\/m\/newsflash\/home\/detail\/1790\" target=\"_blank\" rel=\"noopener\">scam alert about fraudulent emails impersonating Public Surplus<\/a>. The notice says the Washington State Association of Counties had been told of a phishing campaign using the name of its Solutions Center partner.<\/p><div id=\"mwtad927729657\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>That detail matters because Public Surplus is a real service used by public agencies. The scam does not need to invent an unknown organization. It borrows trust already created by legitimate auctions and government relationships.<\/p>\n<p>The alert tells recipients to verify that a claimed Public Surplus message comes from an official <strong>@thepublicgroup.com<\/strong> address. It also says not to click links, download attachments, or provide information when the communication has not been confirmed.<\/p>\n<h3>The target may be a worker, bidder, vendor, or agency contact<\/h3>\n<p>Auction platforms touch several groups. Government employees may manage listings. Buyers may follow bids or payments. Vendors and finance teams may exchange documents. A vague account notice can feel relevant to many people without proving the sender knows anything private.<\/p><div id=\"mwtad942081522\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The lure can change. One message may claim an account document is ready. Another may mention an invoice, a bidder question, a payment issue, or a security review. The shared feature is an unverified route that the sender wants you to use.<\/p>\n<p>Do not decide that an email is safe merely because the topic fits your work. A phishing campaign succeeds when routine business context replaces sender verification.<\/p>\n<h3>A familiar display name does not identify the real sender<\/h3>\n<p>Email apps emphasize a display name, while the actual address may appear only after a click or tap. A scammer can type \u201cPublic Surplus\u201d into the display-name field without controlling the company&#8217;s domain.<\/p><div id=\"mwtad3406473289\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Even an address that looks close deserves a careful reading. Extra words, swapped letters, unusual endings, and unrelated domains can disappear in a narrow preview. A reply-to address may also differ from the visible sender.<\/p>\n<ul>\n<li>The message arrives unexpectedly or outside a normal auction task.<\/li>\n<li>The sender is not on the official @thepublicgroup.com domain.<\/li>\n<li>A link asks you to sign in again before viewing a document.<\/li>\n<li>An attachment is presented as urgent account or payment paperwork.<\/li>\n<li>The email discourages you from contacting a known representative.<\/li>\n<\/ul>\n<div id=\"mwtad794395284\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why This Auction Email Looks Believable<\/h2>\n<p>Public-sector auctions create natural urgency. Inventory closes, bids expire, and payment windows can be short. A criminal can imitate that rhythm without knowing whether you placed a bid.<\/p>\n<div id=\"mwtad1953924028\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>The email may include a county name, job title, or item category found on a public page. Those details make the story specific, but they do not prove the sender has access to an official system.<\/p>\n<p>Business email is also full of links and attachments. A request to view a bid sheet or invoice may not feel as suspicious as a promise of free money. That ordinary appearance is the point.<\/p>\n<p>The safest habit is to separate the claim from the route. The claim may be true or false. The route inside an unsolicited message is still untrusted until you verify it independently.<\/p>\n<div id=\"mwtad1360448123\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>Open the auction service from a saved bookmark or known official page. If a real task exists, it should be visible there without the email choosing your destination.<\/p>\n<div id=\"mwtad3027959012\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What the Phishing Page May Be Trying to Capture<\/h2>\n<p>A fake sign-in page can ask for a work email and password while copying the colors of an auction or document portal. The page does not need to reproduce the entire service. It only needs to look convincing for the few seconds before someone submits credentials.<\/p>\n<p>Stolen work credentials can expose email, shared files, invoices, and contact lists. They may also give criminals a believable account from which to send the next round of messages.<\/p>\n<div id=\"mwtad1196908928\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>An attachment can pursue a different goal. It might contain a fake document link, an archive, or a file that tries to install unwanted software. The county alert does not identify one universal payload, so treat unexpected attachments as unsafe rather than assuming every version behaves the same way.<\/p>\n<p>The reconstruction below uses a fictional domain. It illustrates the kind of unnecessary sign-in that should stop you, not a captured page from the reported campaign.<\/p>\n<p><img decoding=\"async\" width=\"1536\" height=\"1024\" class=\"skip-lazy\" data-no-lazy=\"1\" data-skip-lazy=\"1\" loading=\"eager\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/public-surplus-login-page.png\" alt=\"Illustrative fake Public Surplus account login page at a fictional domain\" title=\"\"><\/p>\n<div id=\"mwtad2453349013\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Public Surplus Phishing Email Scam Works<\/h2>\n<h3>Step 1: Criminals borrow a trusted auction relationship<\/h3>\n<p>The email uses the name of Public Surplus because agencies and buyers may already recognize it. Recognition saves the scammer from explaining why an unfamiliar company has account information.<\/p>\n<p>The sender may reference a partner program or government entity to make the message feel connected to official work. That borrowed context is not authentication.<\/p>\n<p>Look for the actual sender address before doing anything else. A convincing name and subject line can be created without access to the real company.<\/p>\n<h3>Step 2: The message invents a task that feels routine<\/h3>\n<p>The recipient is told to review a document, confirm an account, resolve a bid issue, or open an invoice. The request is deliberately ordinary enough to avoid sounding like a classic prize scam.<\/p>\n<p>A deadline may be added so the recipient acts before consulting a coworker. The email may also imply that bidding privileges or account access will be interrupted.<\/p>\n<p>Pause when an email creates both the problem and the only route to solve it. A real account issue can be checked through a separately opened official portal.<\/p>\n<h3>Step 3: A link or attachment moves the victim away from email<\/h3>\n<p>The button may lead through one or more redirects before reaching a sign-in page. The first address can look harmless while a later destination hosts the credential form.<\/p>\n<p>An attachment may display a document preview with another link. This extra step makes the request feel like office workflow while still sending the user to a site controlled by the attacker.<\/p>\n<p>Do not open the destination to investigate on behalf of the sender. Forward the suspicious message to the appropriate security contact or verify it using known details.<\/p>\n<h3>Step 4: The page collects credentials or business information<\/h3>\n<p>A fake portal may accept any password and then display an error or ordinary document. That behavior can make the user think the first attempt failed rather than that the credentials were captured.<\/p>\n<p>Some pages ask for a Microsoft or Google business login instead of an auction password. The requested brand may change according to the email address entered.<\/p>\n<p>If you submitted credentials, assume they were exposed even if the page later looked broken. Do not wait for an unauthorized login alert before changing the password.<\/p>\n<h3>Step 5: The compromised account supports a second fraud<\/h3>\n<p>Access to a real mailbox allows criminals to study current conversations and reply inside existing threads. A fake invoice sent from a familiar account is harder for the next recipient to question.<\/p>\n<p>The attacker may create forwarding rules, change recovery details, or search for payment discussions. A password reset alone can miss persistent access if sessions and rules are not reviewed.<\/p>\n<p>That is why a work-account response should involve the organization&#8217;s IT or security team. The incident may reach beyond one employee&#8217;s inbox.<\/p>\n<div id=\"mwtad823566006\" class=\"gas_fallback-ad_381388-ad_309685-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Company and Sender Checks for a Public Surplus Email<\/h2>\n<h3>The real company and the phishing sender are separate<\/h3>\n<p>Public Surplus and The Public Group are legitimate business names. The official alert concerns criminals impersonating that relationship, not a finding that the real auction service is fraudulent.<\/p>\n<p>Use precise language when reporting the message. Include the full sender and reply-to addresses so investigators can distinguish the impersonator from the company being copied.<\/p>\n<h3>The official domain check is unusually clear<\/h3>\n<p>Jefferson County&#8217;s notice specifically tells recipients to verify an official <strong>@thepublicgroup.com<\/strong> sender. An address ending in another domain should not be treated as official merely because it contains the words public, group, surplus, or auction.<\/p>\n<p>Read from the final @ symbol to the end. The important domain is on the right, not the official-looking words placed before it.<\/p>\n<h3>Known contacts beat contact details in the email<\/h3>\n<p>The official notice provides WSAC addresses for questions and points readers toward its Solutions Center information. A workplace may also have a known Public Surplus representative or documented support route.<\/p>\n<p>Do not call a number printed in the suspicious message. Independent contact is valuable only when the scammer did not supply the channel.<\/p>\n<h3>The real account should show the real task<\/h3>\n<p>Open the service in a clean tab using a bookmark or known official page. Check recent bids, messages, payments, and profile notices from inside the account.<\/p>\n<p>If the supposed task is absent, that is a strong warning. If it appears, complete it only inside the genuine account you reached independently.<\/p>\n<div id=\"mwtad2457104959\" class=\"gas_fallback-ad_381392-ad_309685-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How to Handle the Email Safely at Work<\/h2>\n<p>Do not forward a suspicious attachment to coworkers as a normal file. Use your organization&#8217;s phishing-report button or security process so the message is handled as evidence.<\/p>\n<p>If a colleague seems to have sent it, contact that person through an existing chat, directory number, or face-to-face conversation. Their mailbox may have been compromised even when the message truly came from it.<\/p>\n<p>Security teams should preserve headers, URLs, timestamps, and attachment hashes. Those details can help block related messages without asking employees to revisit the page.<\/p>\n<p>Organizations that regularly use auction platforms should document the approved domain and login route. A simple internal reference gives staff something concrete to compare when an urgent message arrives.<\/p>\n<div id=\"mwtad287348137\" class=\"gas_fallback-ad_381392-ad_309685-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li>\n<p><strong>Stop interacting and preserve the original email.<\/strong> Do not click again, reply, or open another attachment. Save the message with its headers when your mail system allows it.<\/p>\n<p>Take screenshots of the sender, subject, and visible destination. Do not revisit a dangerous page merely to collect a cleaner image.<\/p>\n<\/li>\n<li>\n<p><strong>Tell your security or IT team immediately.<\/strong> A work account can affect shared systems and other employees. Explain whether you clicked, downloaded a file, entered a password, or approved a sign-in prompt.<\/p>\n<p>Fast reporting gives the organization a chance to block the sender, revoke sessions, inspect rules, and warn other recipients.<\/p>\n<\/li>\n<li>\n<p><strong>Change exposed credentials from a trusted device.<\/strong> Open the real provider directly and replace the password. Change it anywhere else it was reused.<\/p>\n<p>Review active sessions, recovery methods, connected apps, and mailbox forwarding rules. Sign out unfamiliar sessions rather than assuming a new password removes every token.<\/p>\n<\/li>\n<li>\n<p><strong>Protect any payment or identity data you submitted.<\/strong> Contact the relevant bank or card issuer through an official number. Ask what access should be blocked and how to monitor or dispute unauthorized activity.<\/p>\n<p>If government or employee identity information was exposed, follow your organization&#8217;s breach process and the appropriate identity-theft guidance.<\/p>\n<\/li>\n<li>\n<p><strong>Report the impersonation through verified channels.<\/strong> Send the message to the workplace contact responsible for auction services and use the contact information in the county alert when appropriate.<\/p>\n<p>Include the fraudulent domain and sender, but do not publicly post passwords, personal records, or live authentication links.<\/p>\n<\/li>\n<li>\n<p><strong>Scan only when the incident involved a download or execution.<\/strong> A submitted password requires account response first. A downloaded or opened file also warrants device investigation.<\/p>\n<p>Malwarebytes can help scan a supported personal device for malicious software. AdGuard may block some known phishing domains and deceptive ads, but neither product changes a stolen password or replaces an organizational incident review.<\/p>\n<\/li>\n<\/ol>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Is Public Surplus itself a scam?<\/h3>\n<p>No. The confirmed warning concerns fraudulent emails impersonating a real auction partner. Keep the legitimate company separate from the criminals borrowing its name.<\/p>\n<h3>Which sender domain did officials identify as legitimate?<\/h3>\n<p>The Jefferson County alert tells recipients to verify an official @thepublicgroup.com address. A display name alone is not enough.<\/p>\n<h3>What if the email mentions a real auction item?<\/h3>\n<p>Public listing details can be copied. Open your genuine account independently and check whether the same task or message appears there.<\/p>\n<h3>Is an attachment safe if antivirus does not flag it?<\/h3>\n<p>No single scan proves an unexpected file is safe. The attachment may contain a link, delayed behavior, or content that is not yet detected. Verify the sender first.<\/p>\n<h3>Should I reply and ask the sender to confirm?<\/h3>\n<p>No. A reply keeps you inside the channel controlled by the impersonator. Contact a known representative or official support route separately.<\/p>\n<h3>Are the screenshots in this article from the live campaign?<\/h3>\n<p>No. They are non-functional reconstructions using fictional .example domains. The official warning confirms the phishing emails but does not publish every message or destination page.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The Public Surplus phishing email scam works because the name, business context, and urgency can all feel normal. Jefferson County&#8217;s warning gives recipients a concrete check: verify the official sender domain and do not trust unsolicited links or attachments.<\/p>\n<p>Open the real auction service yourself, confirm the task through a known contact, and treat submitted work credentials as an incident that may affect more than one inbox.<\/p>\n<div id=\"mwtad2822984405\" class=\"gas_fallback-ad_176819-ad_309685-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>An email says your public auction account needs attention. It may mention a document, a bid, an invoice, or a change that cannot wait. The name in the message is familiar enough to lower your &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Public Surplus Phishing Email Scam Targets Auction Accounts\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/public-surplus-phishing-email-scam\/#more-416386\" aria-label=\"Read more about Public Surplus Phishing Email Scam Targets Auction Accounts\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":416384,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-416386","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/416386","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=416386"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/416386\/revisions"}],"predecessor-version":[{"id":416404,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/416386\/revisions\/416404"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/416384"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=416386"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=416386"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=416386"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}