Security News

The Amazon Prime phishing attack that wasn’t…
2020-02-21 17:51

If the email is true, you can simply go to the Amazon site yourself, or use the Amazon app - the online location of Amazon isn't a secret. We don't know whether the crook who sent us the phishing email made a mistake, and used the wrong URL, or whether a second crook had arrived in the interim and then taken over the hacked server from the original hackers.

SMS Phishing Campaign Used to Spread Emotet: Report
2020-02-21 15:48

The phishing campaign apparently started earlier this year and has since slowed down, according to IBM. SMS Phishing. In their report, IBM researchers attribute the increasing spread of Emotet to a group that they refer to as the "Mealybug gang." After a lull of several months, Emotet resurfaced in September 2019, and it has been spreading rapidly since.

Phishing Campaigns Tied to Coronavirus Persist
2020-02-19 19:48

The warning from WHO confirms earlier reports from security firms such as Sophos that scammers were attempting to use images, graphics, and realistic-looking domains as part of various phishing and others malicious campaigns. On Tuesday, security firm Check Point published a report about a spike in the number of domains being registered related to coronavirus.

Mobile Banking Users Targeted in SMS Phishing Campaign
2020-02-18 20:33

Cybercriminals targeted mobile banking users by sending malicious SMS messages to their smartphones as part of a phishing campaign to steal account holders' information, including usernames and passwords, according to the cybersecurity firm Lookout. More than 3,900 mobile banking app users of several Canadian and American banks fell victim to the SMS phishing attacks, which started in June 2019 and apparently recently ended, researchers at Lookout say in their new report.

How to report a phishing or spam email to Microsoft
2020-02-17 17:26

Another option is to report the email to Microsoft for analysis via the Outlook add-in called Report Message or a specific Microsoft address. You can use the process to report a "False negative," meaning a spam message that should have been identified as spam but was not.

SMS Phishing Campaign Targets Mobile Bank App Users in North America
2020-02-14 17:45

A mobile phishing campaign that targeted customers of more than a dozen North American banks, including Chase, Royal Bank of Canada and TD Bank, managed to hook nearly 4,000 victims. The attacks used an automated SMS tool to blast bogus security text messages to mobile phone users between June and last month.

How banks can protect their customers from coronavirus-themed phishing emails
2020-02-14 15:42

Knowing the topic is critical for many, spammers are sending phishing emails with malicious attachments masquerading as instructions around the coronavirus. These coronavirus-themed phishing emails could affect businesses due to China's role in the world economy, according to OneSpan.

Official: Puerto Rico Govt Loses $2.6M in Phishing Scam
2020-02-14 12:04

Puerto Rico's government has lost more than $2.6 million after falling for an email phishing scam, according to a senior official. The finance director of the island's Industrial Development Company, Rubén Rivera, said in a complaint filed to police Wednesday that the agency sent the money to a fraudulent account.

Puerto Rico Gov Hit By $2.6M Phishing Scam
2020-02-13 14:49

A phishing scam has swindled a Puerto Rico government agency out of more than $2.6 million, according to reports. According to reports, the email-based phishing scam hit Puerto Rico's Industrial Development Company, which is a government-owned corporation aimed at driving economic development to the island along with local and foreign investors.

Phishing Attacks: Best Practices for Not Taking the Bait
2020-02-12 11:35

Deceptive Phishing - The most common type of phishing attacks, whereby threat actors impersonate a legitimate company to steal users' personal data and access credentials. Spear Phishing - These types of attacks are more sophisticated, whereby the threat actor customizes the attack email with the target's name, job title, company, and other personal information to make the recipient believe they have a connection to the sender.