{"id":425478,"date":"2026-10-08T18:34:06","date_gmt":"2026-10-08T18:34:06","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=425478"},"modified":"2026-10-08T18:34:06","modified_gmt":"2026-10-08T18:34:06","slug":"subway-subcard-email-scam-excel-documents","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/subway-subcard-email-scam-excel-documents\/","title":{"rendered":"Subway Subcard Email Scam: Fake Orders and Password-Protected Excel Files"},"content":{"rendered":"<p>The email looks like an order update from a loyalty service you recognize. Your documents are supposedly ready, and the sender wants one more confirmation.<\/p><div id=\"mwtad169870199\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The Subway Subcard email scam starts with that familiar-looking transaction. Before reviewing a document, ask why this particular order requires the steps the message proposes.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-425479\" width=\"1254\" height=\"1254\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/subway-subcard-email-scam-excel-documents-image-1.png\" alt=\"Illustrative fictional historical Subcard order email directing the reader to a sample document-review page\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/subway-subcard-email-scam-excel-documents-image-1.png 1254w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/subway-subcard-email-scam-excel-documents-image-1-300x300.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/subway-subcard-email-scam-excel-documents-image-1-1024x1024.png 1024w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/subway-subcard-email-scam-excel-documents-image-1-290x290.png 290w\" sizes=\"auto, (max-width: 1254px) 100vw, 1254px\" \/><\/figure>\n<div id=\"mwtad1344687977\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>A fake order became a route to a malicious spreadsheet<\/h3>\n<p>The December 2020 campaign used Subcard order-confirmation messages to draw recipients toward document links. The reported route led to a malicious Excel download, not an ordinary restaurant receipt.<\/p><div id=\"mwtad540708915\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Contemporaneous investigators identified TrickBot delivery through the analyzed campaign. Some spreadsheet variants were password-protected and urged recipients to enable active content to view a document.<\/p>\n<p>That evidence concerns a historical campaign. We have not downloaded a specimen, tested a current link, or established that every later email with similar wording carries the same malware.<\/p>\n<p>Subway, Subcard, and the document-service names borrowed along the route were not the scam products. Their identities supplied familiarity for a malicious delivery process.<\/p><div id=\"mwtad3509747534\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<h3>The email system&#8217;s compromise was not a finding about every customer account<\/h3>\n<p>In its <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/subway-marketing-system-hacked-to-send-trickbot-malware-emails\/\" target=\"_blank\" rel=\"noopener\">reported statement at the time<\/a>, Subway said the email-campaign system had been compromised and that the affected system did not hold bank or card details.<\/p>\n<p>The company also said it had no evidence that guest accounts were hacked. Those were historical statements, not a current independent audit or a guarantee about every system.<\/p>\n<p>The distinction matters: an abused mailing relationship can make an email convincing without proving that the recipient&#8217;s restaurant payment account was already taken over.<\/p><div id=\"mwtad1196080770\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>It also explains why a familiar sender alone was not enough. The content and proposed file workflow needed scrutiny even when the message appeared connected to earlier marketing.<\/p>\n<h3>Do not bypass document protection to complete an unexpected order<\/h3>\n<ul>\n<li>Check the real order through the service you used to place it.<\/li>\n<li>Do not download a spreadsheet just to investigate an unsolicited receipt.<\/li>\n<li>Keep macro and active-content restrictions in place.<\/li>\n<li>Distinguish receipt, download, opening, and content activation when seeking help.<\/li>\n<li>Involve workplace IT promptly if a managed device was exposed.<\/li>\n<\/ul>\n<p>Our images are fictional historical interface examples, not actual emails or a usable workbook. The second contains no macros, executable file, or genuine document content.<\/p>\n<div id=\"mwtad4097653008\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why an Order Email Can Survive a Quick Glance<\/h2>\n<h3>A known relationship supplies the reader&#8217;s explanation<\/h3>\n<div id=\"mwtad3470582820\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>Someone who has used a loyalty program may expect promotional emails or receipts. An order subject can fit that expectation before the recipient checks the actual transaction.<\/p>\n<p>A personal name can make the message feel targeted and legitimate. It does not establish that its document link serves the purpose the email describes.<\/p>\n<p>If no order was placed, that discrepancy is useful. You can check the real account without opening a file to discover what the supposed purchase was.<\/p>\n<p>Even if you did order something, verify the requested workflow. A matching everyday event does not automatically authenticate an additional document or content-enabling instruction.<\/p>\n<h3>The email turns curiosity into document handling<\/h3>\n<p>A reader may click to see the receipt, cancel an unfamiliar order, or identify a mistaken transaction. Each reason feels like a check rather than a risky installation.<\/p>\n<p>The message can then introduce another page, download, password, or preview step. The process moves further from the original order while still using it as justification.<\/p>\n<p>You can stop at any point. Completing the next step is not necessary to prove that you are a responsible account holder.<\/p>\n<p>Ask the genuine service about a real transaction instead. A suspicious email does not earn permission to change your document-security settings.<\/p>\n<div id=\"mwtad4257172353\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Subway Subcard Email Scam Works<\/h2>\n<h3>Step 1: An order-confirmation message borrows the Subcard identity<\/h3>\n<p>The historical messages used order-processing language and told recipients that documents were ready. This gave the link an apparently routine reason to be opened.<\/p>\n<p>The campaign&#8217;s use of customer names and a familiar mailing identity strengthened that impression. Those details were not evidence that the requested document was safe.<\/p>\n<p>Do not label a displayed address&#8217;s present owner a criminal. An address can be impersonated or a legitimate sending arrangement can be abused.<\/p>\n<p>The practical check is the real transaction and requested action. You should not need to run document content to understand a sandwich order or loyalty notice.<\/p>\n<h3>Step 2: The link introduces a document-service page<\/h3>\n<p>The <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/massive-subway-uk-phishing-attack-is-pushing-trickbot-malware\/\" target=\"_blank\" rel=\"noopener\">original campaign investigation<\/a> described a FreshBooks-style imitation page before the Excel download. A trusted-looking document brand became another layer of borrowed authority.<\/p>\n<p>A page heading can be copied just as easily as an email subject. It does not establish that the real document service controls the download.<\/p>\n<p>Keep that distinction separate from whether those services are legitimate. The attack used their appearance; it did not make every document from a genuine service fraudulent.<\/p>\n<p>If a receipt unexpectedly changes into a workbook download, pause. Verify the business purpose through the organization you already know, not the page&#8217;s own reassurance.<\/p>\n<h3>Step 3: A spreadsheet and possible password add a sense of privacy<\/h3>\n<p>Some analyzed variants were password-protected. That can make a file seem intentionally secured, but password protection is not evidence of a trustworthy sender.<\/p>\n<p>Encryption can also limit inspection of contents without the password. It does not prove the file defeats every security product or that every protected document is malicious.<\/p>\n<p>Legitimate organizations use protected files for privacy. Their appropriateness still depends on a verified relationship, expected content, and a safe workflow.<\/p>\n<p>Do not search for a password or unblock the file merely to investigate this email. A provider or IT team can review the claim without you activating its content.<\/p>\n<h3>Step 4: A preview problem is used to request active content<\/h3>\n<p>The malicious document claimed it could not be previewed and directed the user toward editing or content controls. A technical obstacle became the reason to loosen protection.<\/p>\n<p>That is the critical persuasion step. The file asking for permission is not an independent authority on whether it deserves that permission.<\/p>\n<p>Editing and active-content permissions are not identical. Do not treat every Office banner as the same action or assume a receipt requires macros to be understood.<\/p>\n<p>The fictional worksheet below shows a historical-style persuasion message. It is an illustration of instructions to reject, not a guide for opening an actual suspicious file.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-425480\" width=\"1254\" height=\"1254\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/subway-subcard-email-scam-excel-documents-image-2.png\" alt=\"Illustrative fictional historical spreadsheet using a preview-error message to encourage enabling disabled macro content\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/subway-subcard-email-scam-excel-documents-image-2.png 1254w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/subway-subcard-email-scam-excel-documents-image-2-300x300.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/subway-subcard-email-scam-excel-documents-image-2-1024x1024.png 1024w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/subway-subcard-email-scam-excel-documents-image-2-290x290.png 290w\" sizes=\"auto, (max-width: 1254px) 100vw, 1254px\" \/><\/figure>\n<h3>Step 5: Executed content can create a device or network incident<\/h3>\n<p>The analyzed campaign used malicious macros to deliver TrickBot. That historical finding is different from merely receiving an email or saving an unopened file.<\/p>\n<p>Actual execution may put account information or a network at risk. The consequences depend on the file, environment, controls, and actions taken.<\/p>\n<p>Do not identify an infection solely from a normal Windows process name. Legitimate programs can be present on healthy systems, and malware identification needs stronger evidence.<\/p>\n<p>If you enabled content or suspect execution, seek trusted technical review. Avoid additional experiments that could expand exposure or interfere with incident evidence.<\/p>\n<div id=\"mwtad2094082811\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What Changed in Office Since the Historical Attack<\/h2>\n<h3>Current macro blocking is not the old yellow-banner workflow everywhere<\/h3>\n<p>Microsoft&#8217;s <a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-365-apps\/security\/internet-macros-blocked\" target=\"_blank\" rel=\"noopener\">current Internet-macro guidance<\/a> describes default blocking in affected Office applications. The outcome depends on version, file origin, and organizational policy.<\/p>\n<p>Some users may see a stronger block rather than a simple Enable Content option. Others have different software or managed settings.<\/p>\n<p>The old screenshot is not a promise of today&#8217;s interface. Preserve the protection you actually encounter instead of trying to reproduce the attack&#8217;s historical sequence.<\/p>\n<h3>A block is not something to remove because the document requests it<\/h3>\n<p>A page or file can describe protection as an inconvenience that must be fixed. That explanation comes from the content seeking permission to run.<\/p>\n<p>Do not follow instructions to change trusted locations or security policy for an unexpected order document. Ask the genuine organization or your IT team about the need.<\/p>\n<p>A legitimate business process should be verified independently. The fact that a software setting can be changed does not make changing it appropriate.<\/p>\n<h3>Active content has uses beyond this scam<\/h3>\n<p>Macros, add-ins, and data connections can support legitimate work. Microsoft&#8217;s <a href=\"https:\/\/support.microsoft.com\/en-us\/office\/collab-files\/active-content-types-in-your-files\" target=\"_blank\" rel=\"noopener\">active-content explanation<\/a> helps distinguish those features from the file&#8217;s trustworthiness.<\/p>\n<p>Do not condemn every spreadsheet that includes automation. The issue here is an unexpected malicious delivery and a deceptive reason to authorize execution.<\/p>\n<p>Equally, do not assume an unopened or blocked file is harmless in every possible environment. Tell support what happened rather than relying on one button as a universal rule.<\/p>\n<h2>Match Your Response to the Actual Interaction<\/h2>\n<h3>Receiving and downloading are not the same as running content<\/h3>\n<p>If the email arrived but nothing was opened, report and remove the message through the normal safe process. Its arrival alone does not establish malware execution.<\/p>\n<p>If a file was saved, record that fact without opening it for a closer look. A work-device download belongs with the team&#8217;s established incident process.<\/p>\n<p>If you opened the workbook, note any warnings and whether you changed permissions. Accurate observations are more useful than guessing which stage must have installed something.<\/p>\n<h3>Account protection may remain necessary after cleanup<\/h3>\n<p>If malicious content executed, security review can involve both the device and the accounts used on it. A scan alone cannot explain every possible exposure.<\/p>\n<p>Use a trustworthy device for urgent password or financial-support actions when the original computer is still under investigation. Coordinate workplace recovery with IT.<\/p>\n<p>Do not treat the historical campaign&#8217;s behavior as a diagnosis of your current file. The actual specimen and evidence need their own assessment.<\/p>\n<h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li>\n<p><strong>Stop the order-document workflow.<\/strong> Do not open another link, enter a supplied file password, or activate content because a preview message tells you to.<\/p>\n<p>Keep the email and visible document names for reporting. Avoid forwarding a suspicious workbook casually to friends or colleagues.<\/p>\n<\/li>\n<li>\n<p><strong>Record which stage you reached.<\/strong> Distinguish receipt, link opening, download, workbook opening, security changes, and any observed program activity.<\/p>\n<p>If you are uncertain, say so. Do not replay the steps on the same computer to determine whether malware would run.<\/p>\n<\/li>\n<li>\n<p><strong>Seek technical help when execution or compromise is possible.<\/strong> If suspicious content ran or device behavior changed, stop sensitive activity on that computer.<\/p>\n<p>A workplace device should be reported to IT promptly. Follow its instructions for network isolation and evidence rather than improvising removal of files or management tools.<\/p>\n<p>For a personal device, use trusted support to assess the incident and establish a safe recovery route.<\/p>\n<\/li>\n<li>\n<p><strong>Use genuine security tools, not the document&#8217;s repair offer.<\/strong> Malwarebytes can assist with checking malicious software; built-in and organizational protections should remain enabled.<\/p>\n<p>AdGuard can help reduce harmful advertising and risky destination exposure. It does not make a malicious workbook safe or undo active-content execution.<\/p>\n<p>A clean result is useful evidence, not a guarantee that no information was accessed. Continue with any account review the incident warrants.<\/p>\n<\/li>\n<li>\n<p><strong>Protect accounts from a trusted environment.<\/strong> If credentials or sessions may have been affected, replace exposed passwords and review recovery settings and unfamiliar activity.<\/p>\n<p>Do not enter new sensitive details on an unresolved computer. Let the IT team coordinate work-account recovery where it manages the environment.<\/p>\n<\/li>\n<li>\n<p><strong>Contact financial providers if their accounts were involved.<\/strong> Report actual unfamiliar activity, a payment disclosure, or banking use during the suspected incident.<\/p>\n<p>Explain the document interaction accurately and ask about appropriate safeguards. The historical email-system statement does not determine what your own device exposure may have affected.<\/p>\n<\/li>\n<li>\n<p><strong>Verify a genuine Subway transaction independently.<\/strong> Use the account or ordering service where you actually placed it, rather than the document-review link.<\/p>\n<p>Report the misleading message through the relevant service and local fraud route. Preserve the original correspondence without accusing an address&#8217;s current owner based on old campaign material.<\/p>\n<\/li>\n<li>\n<p><strong>Reject paid cleanup or recovery demands from the sender.<\/strong> An unsolicited contact may claim it can repair the document or retrieve money after another payment.<\/p>\n<p>The <a href=\"https:\/\/www.ncsc.gov.uk\/section\/respond-recover\/phishing\" target=\"_blank\" rel=\"noopener\">NCSC&#8217;s exposure-specific guidance<\/a> offers a practical reference. Your trusted support team and actual providers should direct recovery, not the order email.<\/p>\n<\/li>\n<\/ol>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Is the legitimate Subway loyalty service the scam?<\/h3>\n<p>No. The historical campaign abused familiar identities and order language to deliver malicious documents. That is different from ordinary loyalty membership or a genuine restaurant order.<\/p>\n<h3>Did Subway say every guest account and bank card was hacked?<\/h3>\n<p>No. Its reported historical statement concerned the email-campaign system and said it did not hold bank or card details. This is not a fresh security audit.<\/p>\n<h3>Does a document password prove it is safe?<\/h3>\n<p>No. Password protection can support privacy or complicate inspection. Verify the sender and expected purpose instead of treating encryption as a safety verdict.<\/p>\n<h3>Does Enable Editing mean the same thing as enabling macros?<\/h3>\n<p>No. Editing and active-content permissions differ, and interfaces vary. Do not follow an unexpected document&#8217;s instructions to weaken protections in order to view it.<\/p>\n<h3>Will every current Office installation show the pictured warning?<\/h3>\n<p>No. The image illustrates a historical-style prompt. Current blocking depends on the application, version, file origin, and organization policy.<\/p>\n<h3>Should I identify TrickBot from a Windows process name?<\/h3>\n<p>No. A legitimate process can exist on a healthy device. Use actual security evidence and trusted analysis rather than killing programs based only on a familiar name.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The Subway Subcard email scam used a familiar order message to lead readers into a malicious document workflow. An unexpected receipt did not justify activating spreadsheet content.<\/p>\n<p>Verify the transaction independently and leave document protections in place. If content ran, seek trusted technical review and protect affected accounts without testing the file again.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The email looks like an order update from a loyalty service you recognize. Your documents are supposedly ready, and the sender wants one more confirmation. The Subway Subcard email scam starts with that familiar-looking transaction. &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Subway Subcard Email Scam: Fake Orders and Password-Protected Excel Files\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/subway-subcard-email-scam-excel-documents\/#more-425478\" aria-label=\"Read more about Subway Subcard Email Scam: Fake Orders and Password-Protected Excel Files\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":425479,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-425478","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/425478","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=425478"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/425478\/revisions"}],"predecessor-version":[{"id":425481,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/425478\/revisions\/425481"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/425479"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=425478"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=425478"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=425478"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}