Showing posts with label Phish & 419's. Show all posts
Showing posts with label Phish & 419's. Show all posts

Thursday, May 11, 2017

Unhappy 39th birthday, spam, and many unhappy returns

From Sophos Naked Security:

Unhappy 39th birthday, spam, and many unhappy returns

"In October 2011, email turned 40. Last week it was the turn of its troublesome twin, spam, to make it to within a year of the same hoary milestone.

Inevitably in an industry ageing fast, personal computing’s calendar is filling up with significant anniversaries. So, does spam’s – or email’s – really matter that much?"

Monday, May 8, 2017

Defining Your Overarching Goal for Email Phishing Testing

Great article by Kevin Beaver on Toolbox.com:

Defining Your Overarching Goal for Email Phishing Testing

"Are you among the relatively small number of organizations that performs email phishing tests against your users? If so, why do you do it? The easy answer is to, of course, to minimize your information security risks. So, you go about testing your users’ gullibility, train them on why they should not respond to such emails, and you’re done, right? In a nutshell, yes. However, if you are going to get the most out of your email phishing testing you need to have specific end goals in mind. There is likely more testing that needs to be done."

How to protect your boss from phishing attacks

From Sophos Naked Security:

How to protect your boss from phishing attacks

"We already know that more than 75% of us lie on social media.

Too bad it’s impracticable to lie more about our workplaces on professional networking sites like LinkedIn: it might spare our employers a lot of grief."

Friday, May 5, 2017

FBI: Business- and Email Account Compromise Attack Losses Hit $5 Billion

From Dark Reading:

FBI: Business- and Email Account Compromise Attack Losses Hit $5 Billion

"The FBI's IC3 division reports a 2,370% spike in exposed losses resulting from BEC and EAC between January 2015 and December 2016.

The FBI's Internet Crime Complaint Center (IC3) reports business email compromise (BEC) and email account compromise (EAC) attacks caused $5.3 billion in exposed loss for global and domestic companies between October 2013 and December 2016. Victims, which come from 50 states and 131 countries, reported a total of 40,203 incidents in the same time period."

Attackers Unleash OAuth Worm via 'Google Docs' App

From DataBreach Today:

Attackers Unleash OAuth Worm via 'Google Docs' App

"A malicious app named "Google Docs" by attackers has been making the rounds, attempting to trick Google users into logging in and giving the app access permissions to their account.

The phishing campaign began with an email to victims from an address they likely would have recognized, according to multiple analyses of the attack that have now been posted online by security researchers. But the campaign quickly turned into a worm, as users authorized the bogus app in droves, allowing it to spread to their own contacts."

Europe Pumps Out 50% More Cybercrime Attacks Than US

From Dark Reading:

Europe Pumps Out 50% More Cybercrime Attacks Than US

"Cyberattacks originating from Europe were substantially higher than nefarious activity launched from the US during the first quarter.

Cybercrime attacks launched from Europe reached more than 50 million in the first quarter, double the volume coming out of the US, according to the ThreatMetrix Q1 Cybercrime Report released today."

Google Docs Phishing Scam a Game Changer

From Dark Reading:

Google Docs Phishing Scam a Game Changer

"Experts expect copycats that take advantage of passive authentication from third-party applications using standards such as OAuth.

The Google Doc phishing scam that conned over a million users this week illustrates how attackers cleverly respond to wider spread end-user awareness about how phishing attacks work."

Thursday, May 4, 2017

Google Docs Phishing Attack Abuses Legitimate Third-Party Sharing

From Dark Reading:

Google Docs Phishing Attack Abuses Legitimate Third-Party Sharing

"Phishing messages appear nearly identical to legitimate requests to share Google documents, because in many ways, they are.

Google users today were hit with an extremely convincing phishing spree launched by attackers who manipulated Google Docs' legitimate third-party sharing mechanism."

Update: Google Doc phishing story takes some bizarre turns

From Sophos Naked Security:

Update: Google Doc phishing story takes some bizarre turns

"Since news began circulating last night of a phishing campaign parading around as Google Doc access links, the tale has taken strange twists and turns.

A self-described graduate student claims he was behind the blast of emails, and that they were part of a test for a school project, not a phishing attack. But according to the university he claims to be enrolled at, he’s not a student there."

FYI - to help reduce the attack surface block:

hhhhhhhhhhhhhhhh @ mailinator . com

on your email system(s).

Wednesday, May 3, 2017

OAUTH phishing against Google Docs ? beware!

From SANS ISC:

OAUTH phishing against Google Docs ? beware!

We got several reports (thanks to Seren Thompson, Tahir Khan and Harry Vann) about OAUTH phishing attacks against Google users. The phishing attack arrives, of course, as an e-mail where it appears that a user (potentially even one on your contact list, so it looks very legitimate) has shared a document.

An image of such an e-mail is shown below:


Phishing email

Tuesday, May 2, 2017

How Cybercrooks Put the Beatdown on My Beats

From Krebs On Security:

How Cybercrooks Put the Beatdown on My Beats

"Last month Yours Truly got snookered by a too-good-to-be-true online scam in which some dirtball hijacked an Amazon merchant’s account and used it to pimp steeply discounted electronics that he never intended to sell. Amazon refunded my money, and the legitimate seller never did figure out how his account was hacked. But such attacks are becoming more prevalent of late as crooks increasingly turn to online crimeware services that make it a cakewalk to cash out stolen passwords."

Blind Trust in Email Could Cost You Your Home

From Krebs On Security:

Blind Trust in Email Could Cost You Your Home

"The process of buying or selling a home can be extremely stressful and complex, but imagine the stress that would boil up if — at settlement — your money was wired to scammers in another country instead of to the settlement firm or escrow company. Here’s the story about a phishing email that cost a couple their home and left them scrambling for months to recover hundreds of thousands in cash that went missing."

Infographic: 7 Ways Hackers Look To Exploit Your State & Local Governments

PDF format infographic from CoreSecurity:

7 Ways Hackers Look To Exploit Your State & Local Governments


Monday, May 1, 2017

POLICE PHONE SCAM ALERT

Yesterday I received a call from someone pretending to be Det. Garry McFadden from the Charlotte-Mecklenberg PD.  The caller left a message stating there was a criminal charge filed against me & I would be arrested if I didn't call back within 24-48 hours.

I returned the call several times.  Each time the phone rang three (3) times before giving me a message stating "The person you are calling has a voicemail box that has not been set up."  This morning I spoke with a person with the CMPD.  They confirmed that Det. Garry McFadden was a detective in their department but has retired because he has a show on Investigation Discovery.  The person indicated this is a scam and forwarded me to their Fraud Dept.

Earlier today I spoke with the person claiming to be Det. McFadden.  He went into a high pressure spiel about charges being filed if I did not take care of this matter immediately.  I confirmed his name & asked if he was still with the CMPD.  The male stated he was.  I then asked if he was the same Det. McFadden who now has a show on ID.  He said that was him & he is now a private investigator.  At this point I asked if he was a private investigator & no longer associated with the CMPD why was he misrepresenting himself as an officer of the law?  The male did not answer this question, instead he stated that he had "talked to some people up in my area."  I asked what PD & with whom he had spoken to.  The male hung up the phone immediately.

I have made repeated calls to the number for this scammer after he hung up.  All have gone directly to the voicemail & message noted above.  I've also provided the number to several of my colleagues who have been calling it with the same results.

In the event you have been contacted by this person please report it to the CMPD at 704-336-7600.  The number this "person" was calling from is 704-292-4414.

704-292-4414 / 704-292-4414 / 704-292-4414 / 704-292-4414 / 704-292-4414 / 704-292-4414 / 704-292-4414 / 704-292-4414 / 704-292-4414 / 704-292-4414 / 704-292-4414 / 704-292-4414 / 704-292-4414 / 704-292-4414

Leaked document reveals Facebook conducted research to target emotionally vulnerable and insecure youth

From news.com.au:

Leaked document reveals Facebook conducted research to target emotionally vulnerable and insecure youth

"FACEBOOK has come under fire over revelations it is targeting potentially vulnerable youths who “need a confidence boost” to facilitate predatory advertising practices.

The allegation was revealed this morning by The Australian which obtained internal documents from the social media giant which reportedly show how Facebook can exploit the moods and insecurities of teenagers using the platform for the potential benefit of advertisers."

FTC Offers ID Theft Victims Online Crime Reporting Tool

From Dark Reading:

FTC Offers ID Theft Victims Online Crime Reporting Tool

"ID theft victims can report their cybercrime attack to the Federal Trade Commission, without having to file a police report in most cases.

ID theft victims now have an alternative to filing a police report, a self-service online reporting tool from the Federal Trade Commission (FTC)."

Discovery of 8,800 servers sends warning to Asian cybercriminals

From Sophos Naked Security:

Discovery of 8,800 servers sends warning to Asian cybercriminals

"In one of the more curious cybercrime announcements of recent times, Interpol’s Asian centre says it has “identified” 8,800 servers used as command & control (C2) for all sorts of bad things including DDoS attacks and distributing ransomware and spam.

You read that correctly. Interpol hasn’t disrupted these servers, merely passed information on their whereabouts and malevolent purpose to police forces in eight countries, including Malaysia, Myanmar, Philippines, Singapore, Thailand and Vietnam."

Friday, April 28, 2017

Wednesday, July 22, 2015

Report: Spammers Hacked JPMorgan Chase

From Data Breach Today:

Report: Spammers Hacked JPMorgan Chase

The Manhattan U.S. Attorney's office has charged three men with running a pump-and-dump stock scheme that blasted out millions of spam emails per day to artificially "pump" up the price of penny stocks they owned, before the defendants allegedly "dumped" their stocks, making at least $2.8 million in profits. The scheme was reportedly also tied to hack attacks against financial services heavyweights JPMorgan Chase, Fidelity Investments and E*Trade Financial.

Separately, authorities also announced that two men have been arrested in Florida on charges that they ran an unlicensed online Bitcoin exchange that was used in part by cybercriminals based in the United States, Russia and beyond.