The link is clearly unrelated to MetaBrainz and asks for money to “regain access”. I already received two emails, so the scammer is probably sending this email en masse. It is well done enough that some people can fall for it. This account should be terminated ASAP, but they will probably just create more accounts.
I have disabled all their editing rights, set as ‘spammer’ in the system, etc, but I’m not sure if any of that stops them from sending emails - I’m hesitant to delete the account because I’d like that particular account name to be blocked from re-use (without having to make a placeholder myself each time, after deletion).
There are three things I’m thinking that could help with this situation:
One is preventing new users picking usernames including words like system, notification, official, mod, moderator, admin, administrator, MusicBrainz, BookBrainz, MetaBrainz, etc.
Another would be not allowing URLs that lead outside MetaBrainz domains (MB, BB, forum, wiki, etc.) The point of messages here is to communication about edits; this should cover most links you would that would be useful in an MB message. Of course you will still be able to mask a link with space characters or something similar if you need to, but it would look very suspicious in an email pretending to be a system message.
One other would be to add a clear disclaimer above the message saying it was sent by a user and is not an official message when the user sendinng it isn’t an admin.
Whoever sent those emails is unlikely to stop after one account, and they are quite good. It really confused me for a bit, and I’m a long-time editor, a new user could easily be fooled.
How about blocking beginner editors from sending messages to other editors (except staff maybe?). That would make new accounts useless for phishing attempts and should be trivial to implement.
I haven’t seen much use for the messages system, but recently a new editor did message me with questions because he noticed I was working on releases of the same language. In this case it was quite useful.
I think I’ve occasionally sent messages with links to an image on Discogs or to an artist’s website or something else related to an edit that someone made. Adding spaces would be fine though if it helps combat spam like this.
Speaking as a user (not staff), I don’t think we should comsider hamstringing the messaging service quite yet. I think the burden to editors will outweigh the benefit and spammers will just add spaces or find other workarounds. Ultimately the only way to make it 100% safe is to remove all user-user messaging/interaction functions.
It’s just a suggestion, I really don’t know what the best solution would be. But I also don’t thing that would be “hamstringging” the message service. Any user would be able to send a message to any user with any textual content.
Maybe “hamstringing” is a strong word. Nonetheless the suggestion is to limit the functionality of the messaging service for legitimate users, by removing the ability to send links.
I’m not saying that it’s a bad suggestion, I just don’t think it’s worth it.
p.s. my post wasn’t about your suggestion in particular, but it does apply