AARP, SureClick, Offerweb and Spam

On Tuesday Laura wrote about receiving spam sent on behalf of the AARP. The point she was discussing was mostly just how incompetent the spammer was, and how badly they’d mangled the spam such that it was hardly legible.
One of AARPs interactive advertising managers posted in response denying that it was anything to do with the AARP.

This isn’t from AARP…this is a SPAM that’s been going around for years now. Did you bother looking into the source code to see where it sends you? My guess is it aint AARP…Do you know what your talking about?

Yes, Scott, we do know what we’re talking about, and we did look into the source code.
Yesterday Laura discussed in general principles how mainstream companies typically send spam by hiring a company who hires a company who hires a company to send spam.
We’re fairly familiar with how this works – one of the things Word to the Wise does is to provide forensics and expert witness services in email-related cases – so we dug into this email so as to work out what the story behind it was.
The story, as far as we can tell at a quick look, is that the AARP hired a company called SureClick to generate “Qualified Leads”.

SureClick homepage
You can see that they’re fairly proud to have the AARP as a flagship client.
What do SureClick do for their flagship client? They pay affiliates to drive traffic to their AARP membership signup page. I’m not sure exactly how much they’re paying for each signup, but it must be more than $12 as that’s how much SureClick’s affiliates are, in turn, offering to pay their affilliates.
In the case of the spam sent to Laura the affiliate SureClick hired was OfferWeb. What do OfferWeb do? They pay affiliates to drive traffic to their landing page. Seeing a pattern yet?
OfferWeb then hired a hard core spammer to actually send the spam on AARPs behalf. This guy, apparently based in Utah but spamming from a machine hosted in Pennsylvania, is doing everything he can to avoid his spam being recognised and blocked, using dozens of domains and IP addresses and sending messages stuffed full of hashbusters that have hardly any text, just images, to try and hide from spam filters.
One irony is that the Pennsylvania ISP who is hosting the spammer is also the same ISP who host the email account the spam was sent to. Sometimes the best place to start cleaning up is close to home.
So the spammer sends out millions of pieces of email to addresses he’s harvested or bought, most of which is blocked or ends up in the junk folder. When someone responds he passes them on to OfferWeb, who pass them on to SureClick who sign them up for the AARP. Then the AARP pays SureClick, who keep some of the money and pay OfferWeb, who keep some of the money and give the rest to the spammer.
It’s the advertising budget at AARP, and hundreds of companies like them, that makes this sort of spamming worthwhile.
If you’re interested in where all this data came from, check back tomorrow.

Related Posts

Did anyone actually look at this email before sending?

I received spam advertising AARP recently. Yes, AARP. Oh, of course they didn’t send me spam, they hired someone who probably hired someone who contracted with an affiliate marketer to send mail.
The affiliates, while capable of bypassing spam filters, are incapable of actually sending readable mail.

Read More

TWSD: keep spamming even when they say they'll stop

About a month ago I posted about receiving spam from a psychic attempting to sell me candles and stuff. The spammer was sending mail from a company called “Garden of Sound” using an ESP called OnLetterhead. A brief investigation led me to believe that unsubscribing from the mail was not going to do anything.
The post prompted an email from Scott B. the VP of Marketing of the company that is responsible for OnLetterhead. I replied to his email, pointing out a number of things he was doing that made his business look like an ESP front for spammers.
After he received my mail he called me to talk to me about the content of my post and the email and to assure me they were immediately implementing one of my suggestion (that they not put a generic “here’s how to unsubscribe” link on their 1000+ link domains, instead have those actually point to their AUP and corporate pages). He also assured me they took my complaint seriously and I would no longer be receiving email.
Guess what?
Garden of Sound is still spamming me from OnLetterhead. They’ve not even managed to implement the changes they pledged would be rolled out the same week as my blog post. Sure, the domain I’m getting spam from is different, the physical postal address is different, the product is different, the friendly from is different. But the preheader still says “this mail sent by Garden of Sound.” It’s all the same list, it’s all the same company, it’s all the same group of spammers.
Despite Scott’s attempt to convince me he wasn’t a spammer, it seems my initial impression was right. OnLetterhead is simply are a company attempting to look like they’re legitimate without actually taking any responsibility for the email going out from their network. They can’t even manage the bare minimum.
It’s companies like this that give the rest of ESPs a bad name.

Read More

Spammers aren't who you think they are

Shady direct marketers exploit CAN SPAM to continue spamming but protect themselves from the law. This is something I’ve been talking about for a while (TWSD), and it’s nice to see the mainstream press noticing the same thing.
HT: Box of Meat

Read More