Showing posts with label phishing scam. Show all posts
Showing posts with label phishing scam. Show all posts

Saturday, February 20, 2010

And Even More Phishing...

Do Not Reply To An Email That Looks Like This!!!
A legitimate email will never, ever, ever ask for this kind of  info for any reason at all...EVER! (I'm not kidding)

From: YAHOO ACCOUNT SERVICE maescott053025@sbcglobal.net

Date: February 20, 2010 8:46:07 AM PST
To: undisclosed recipients: ;
Subject: Dear Yahoo account users please respond urgent this account is about to close
Reply-To: yahaccountservice92@rocketmail.com



















Yahoo account users,


All yahoo free account owners,We are having congestions due to the anonymous registration of yahoo accounts so we are shutting down some yahoo accounts and your account was among those to be deleted.We are sending you this email so that you can verify and let us know if you still want to use this account.If you are still interested please confirm your account by filling the space below.

User name;...................................

password;.....................................

date of bith;..................................

country;.........................................

all this information would be needed to verify your account.

Due to the congestion in all Yahoo users and removal of all unused Yahoo Accounts, Yahoo would be shutting down all unused Accounts, You will have to confirm your E-mail by filling out your Login Information below after clicking the reply button, or your account will be suspended within 48 hours for security reasons.


* Username: .......................... ....

* Password: ....................................

* Date of Birth: .............................

* Country Or Territory:...............


After following the instructions in the sheet, your account will not be interrupted and will continue as normal. Thanks for your attention to this request. We apologize for any inconveniences. Warning!!! Account owner that refuses to update his/her account after two days of receiving this warning stands the risk of lossing his or her account permanently.


The Yahoo Management

Yet Another Phishing Trip...

If you get one of these and you know for a fact you did not order anything of the sort from Amazon or anyone else DO NOT open the attachment that comes with it!


Subject: Your order has been paid! Parcel NR.9510.

Friday, February 19, 2010 7:20 PM
From: "Your Manager Bernardo Pitts" mailto:shop.order@amazon.com%20To 
To: somepoorsucker@xyz.com


Hi!

Thank you for shopping at Amazon.com
We have successfully received your payment.

Your order has been shipped to your billing address.

You have ordered " Nokia E51 "

You can find your tracking number in attached to the e-mail document.

Print the postal label to get your package.

We hope you enjoy your order!

Amazon.com

Thursday, November 5, 2009

Why should I worry about my privacy on the Internet?


Viruses, spam, worms, Trojan horses, spyware, adware, keyloggers, zombies, phishing schemes. Sometimes it seems that danger is always lurking on the Internet, in your email inbox, and maybe even on your computer. But are you and your personal information really at risk? And are the consequences really that bad?

From time-worn email cons allegedly originating from Nigeria to keylogger programs that capture everything you type, scams, fraud, and cons do abound on the Web. And the perpetrator may not be a suspicious-looking email or software hidden on your hard disk. It could be that new friend you met in a chat room or on a social networking site who befriends you and over time gathers your personal and financial information.

What can happen if you're the victim of a scam? You could be locked out of your online account and be unable to access your email. But there can be even greater consequences. You could be the victim of identity theft. Alibaba

Friday, October 23, 2009

Phishers Dangle Some Brand-New Bait


Just when you thought it was safe to shop or bank online, criminals have invented new ways to steal your personal information.

In September 2009, some unlucky visitors at the New York Times Web site clicked on an ad that attempted to install malware. The advertisement displayed a popup window informing readers that their computer might be infected with a virus; only by purchasing a new antivirus product could they be sure of having a clean system.

The Times later acknowledged the scam in a posting on its Web site: "Some NYTimes.com readers have seen a pop-up box warning them about a virus and directing them to a site that claims to offer antivirus software....If you see such a warning, we suggest that you not click on it. Instead, quit and restart your Web browser." Phishers and scammers use this and other new tactics to deceive unsuspecting victims.

Phishing 2.0

Phishing refers to an attempt to collect usernames, passwords, and credit card data by posing as a legitimate, trusted party. Often the deception in­­volves using e-mail sent from a trusted address. Originally, phishing applied to the banking and payment industry only, but now it also covers theft of log-in credentials to games, and personal passwords to social networks such as Facebook and Twitter.

Most people wouldn't reveal their social security number or mother's maiden name at a strange site. Modern browsers and security software flag such content and ask you whether you're sure you want to send it; some block it with a red-and-black warning label. So phishers have adopted new tactics.

Fake Antivirus Software an Emerging Problem

Rogue antivirus products are among the latest phishing in­­struments to appear, and many are quite convincing. Bearing names like Antivirus 2009, AntiVirmin 2009, and AntiSpyware 2009, they have interfaces similar to those of real antivirus apps. Some rogue antivirus products have their own keywords on search engines and cite fake reviews recommending them (including one that I supposedly wrote).

The rogue antivirus product that showed up on the New York Times site installed malware that, if executed, would have lowered the security settings in Internet Explorer, run executable files, and altered the system Registry. Such ac­­tions by phishing malware are fairly common. The real security apps knew it, too: Legitimate antivirus vendors AVG, Comodo, Kaspersky, McAfee, Microsoft, Nod32, and Sophos, (among others) detected this particular piece of malware within the first few hours.

PC World

Tuesday, October 6, 2009

Hackers hook Web email users with "phishing" scams


SAN FRANCISCO — Google and Yahoo! on Tuesday joined a growing roster of Web-based email service providers with users duped by hackers into betraying passwords to accounts.

A day after Microsoft blocked access to thousands of Hotmail accounts in response to hackers plundering password information and posting it online, the list of victims was growing to include users of an array of email services.

"We recently became aware of a phishing scheme through which hackers gained user credentials for Web-based mail accounts including a small number of Gmail accounts," Google said in response to an AFP inquiry.

"As soon as we learned of the attack, we forced password resets on the affected accounts. We will continue to force password resets on additional accounts if we become aware of them."

Cyber-crooks evidently used "phishing" tactics to trick users of free Web-based email service into revealing account and access information.

"We are aware that a limited number of Yahoo! IDs may have been made public," Yahoo! said in a statement to AFP. "Online scams and phishing attacks are an ongoing and industry-wide issue."

Time Warner subsidiary AOL, in response to an AFP inquiry, said it is "closely monitoring the situation."

"Our guidance to users is to keep your wits about you: do not click on live links, or insert any details into input fields in emails, pop-ups or Web pages if you are not sure where they come from."

Microsoft said Monday that it learned of the latest problem during the weekend after Hotmail account information of "several thousand" users, many of them reportedly in Europe, was posted at a website.

The unconfirmed list of Hotmail accounts compromised by "phishing" has grown into the tens of thousands.

"We are aware that some Windows Live Hotmail customers' credentials were acquired illegally by a phishing scheme and exposed on a website," Microsoft said. "We have taken measures to block access to all of the accounts that were exposed and have resources in place to help those users reclaim their accounts."

Phishing is an Internet bane and involves using what hackers refer to as "social engineering" to trick people into revealing information online or downloading malicious software onto computers.

Phishing tactics include sending people tainted email attachments that promise enticing content such as sexy photos of celebrities and luring people to bogus log-in pages that are convincing replicas of legitimate websites.

Microsoft, Google, and Yahoo! stressed that hackers did not breach their databases, but rather email users were conned into revealing information.

"Phishing is an industry-wide problem... exercise extreme caution when opening unsolicited attachments and links from both known and unknown sources, and install and regularly update anti-virus software," Microsoft said.

Google advises Gmail users not to "click through" on warnings browsers may raise about certificates nor sign in at Web addresses that don't start with google.com/accounts.

Web-based email users who suspect their accounts have been compromised should change passwords and check to make certain any secondary email or texting options in accounts have not been changed.

"We encourage users to be very careful when asked to share their personal information," Google said.

The email service providers urged people to visit pages at their websites with advice and tools for protecting accounts.

AFP

Wednesday, August 26, 2009

`Phishing' drops; are scammers switching tactics?

AP SAN FRANCISCO — Internet criminals might be rethinking a favorite scam for stealing people's personal information.
A report being released Wednesday by IBM Corp. shows a big drop in the volume of "phishing" e-mails, in which fraud artists send what looks like a legitimate message from a bank or some other company. If the recipients click on a link in a phishing e-mail, they land on a rogue Web site that captures their passwords, account numbers or any other information they might enter.

IBM's midyear security report found that phishing accounted for just 0.1 percent of all spam in the first six months of this year. In the same period in 2008, phishing made up 0.2 percent to 0.8 percent of all spam.

It's not clear what, if anything, the decline means. (It also doesn't appear to be a statistical illusion caused by an increase in other kinds of spam. IBM said overall spam volume hasn't expanded, like it did in years past.)

"That is a huge, precipitous decline in the amount of phishing," said Kris Lamb, director of the X-Force research team in IBM's Internet Security Systems division, which did the report. But "I wouldn't tell anybody that phishing has died as a threat."

Lamb believes phishing might have fallen off because computer users are getting smarter about identifying phony Web sites. Security software is also getting better at filtering out phishing sites before Web surfers ever seen them.

It could also be that criminals are moving on from phishing to another kind of attack, involving malicious software. IBM said it is seeing more instances of "Trojan horse" programs, which are used to spy on victims.

Dean Turner, director of Symantec Corp.'s global intelligence network, who was not involved in IBM's research, said Symantec has also noticed less phishing, but warned that it could increase again later in the year. Phishing scams spike around the holidays, he said.

IBM found that criminals are changing the types of businesses they attack with phishing. Sixty-six percent of phishing targets were banks, down from 90 percent last year. Meanwhile, companies that handle online payments, like PayPal, are being mimicked in phishing messages more frequently.

To protect yourself against phishing, access sensitive sites on your own, rather than by following links in e-mails, which might lead to phishing sites.
AP