FTC 'Fraud Department' E-Mail Hoax

E-mail users should be on the lookout for spoof e-mails claiming to be from the Federal Trade Commission, the FTC and the Department of Homeland Security warned on Wednesday.

The e-mails reference a "complaint" filed with the FTC against the individual address that received the message.

The bogus message contains a phony sender address claiming to be from the FTC "Fraud Department," which appears in the message as "frauddep@ftc.gov." The message also "spoofs the return-path and reply-to fields to hide the e-mail's true origin," according to the FTC.

The FTC became aware of the issue after being "flooded" with calls and e-mails, agency spokeswoman Jackie Dizdul told ABC News. Dizdul didn't know the exact number of complaints received, but said the number was "in the thousands."

Though opening the message doesn't cause any apparent harm, those who have received the e-mail and opened the attachment or clicked any links in the message might have downloaded a virus, and are advised to run anti-virus software on their computers.

The virus in the message "appears to install a 'key logger' that could potentially grab passwords and account numbers," the FTC warning states.

The spoofers appeared to be careless in the writing of the message itself, as it "has grammatical errors, misspellings, and incorrect syntax," the warning notes. Even with the errors, Dizdul said, "at the same time, these things can look very official."

The spammers used the common tactic of mimicking the appearance of a legitimate e-mail to entice users to open the message and its attachment, going as far as using the commission's seal in the message.

As with similar e-mail scams claiming to be from banks, credit card companies or other legitimate businesses or organizations, "obviously, it makes you think twice," Dizdul said.

DHS's U.S.-Computer Emergency Readiness Team, which is a public-private sector partnership created in 2003 with the goal of protecting the U.S. Internet infrastructure, also issued a notice on the e-mail spoof on behalf of the FTC.

Both U.S.-CERT and the FTC advise the message recipients to forward the e-mail to spam@uce.gov, and then delete it. E-mails sent to that address are kept in the FTC's spam database to assist with investigations.

Dizdul said that the FTC hasn't yet identified the source of the "Fraud Department" e-mails, but that the incidents are still under investigation.

The government directs consumers to its Web site www.OnGuardOnline.gov for more tips on keeping computers safe, as well as information on spoof e-mails and viruses.

The site is a joint effort between the FTC, DHS and several other government entities and the technology industry.

ABC News' Jason Ryan contributed to this report.