Security News > 2020 > July > Phishing attack spoofs Twitter to steal account credentials

A new phishing campaign spotted by Abnormal Security attempts to trick people with a phony Twitter security notification.
A new phishing campaign analyzed by the security provider Abnormal Security shows how the attackers are taking advantage of Twitter users to steal account credentials.
Using the Twitter brand name and logo, the initial email itself impersonated a Twitter security alert by claiming that the recipient's account was used to log into a different device in a different location, specifically a Windows 7 computer in Canada.
Of course, if the recipient takes the bait, their Twitter credentials fall into the hands of the attackers who will use them to compromise the person's account.
First, the security notification tries to convince the recipient that there's been malicious activity on their Twitter account.
News URL
Related news
- Phishing platform 'Lucid' behind wave of iOS, Android SMS attacks (source)
- Australian pension funds hit by wave of credential stuffing attacks (source)
- Phishing kits now vet victims in real-time before stealing credentials (source)
- iOS devices face twice the phishing attacks of Android (source)
- Phishing Campaigns Use Real-Time Checks to Validate Victim Emails Before Credential Theft (source)
- Windows NTLM hash leak flaw exploited in phishing attacks on governments (source)
- CVE-2025-24054 Under Active Attack—Steals NTLM Credentials on File Download (source)
- Three Reasons Why the Browser is Best for Stopping Phishing Attacks (source)
- Phishing detection is broken: Why most attacks feel like a zero day (source)
- DPRK Hackers Steal $137M from TRON Users in Single-Day Phishing Attack (source)