Security News

Half of cybercrime losses in 2019 were the result of BEC scams
2020-02-12 13:32

Business email compromise and email account compromise scams are still the most lucrative schemes for cybercriminals: the FBI's Internet Crime Complaint Center has calculated that, in 2019, the average monetary loss per BEC/EAC scam complaint reached $75,000. During the past year, the IC3 received a total of 467,361 cybercrime complaints with reported losses exceeding $3.5 billion, and $1.77 billion of those are the result of BEC/EAC. For comparison, BEC/EAC-associated losses were $1.3 billion in 2018, $676 million in 2017 and $360 million in 2016.

Coronavirus-Themed Emails Deliver Malware, Phishing, Scams
2020-02-12 05:04

Several cybersecurity companies have spotted campaigns that use coronavirus-themed emails to deliver malware, phishing attempts and scams. The malicious emails warn potential victims about the impact of the coronavirus on the shipping industry.

Active PayPal Phishing Scam Targets SSNs, Passport Photos
2020-02-10 20:56

A recently uncovered phishing campaign, targeting PayPal users, pulls out all the stops and asks victims for the complete spectrum of personal data - even going so far as to ask for social security numbers and uploaded photos of their passports. Some parts of the phishing email make strange use of exclamation points - For instance, the top of the email says "PayPal Notifications Center !" and the phishing link button reads, "Secure and update my account now !".

13 tips to avoid Valentine's Day online romance scams
2020-02-10 18:41

Valentine's Day will give rise to romance scams, often directed toward people who use dating sites and apps. Victims of such scams sometimes avoid reporting them out of shame, embarrassment, or humiliation, according to the FBI. As such, the criminals can make a clean getaway.

Coronavirus “safety measures” email is a phishing scam
2020-02-05 17:51

Sadly, cybercrooks love a crisis, because it gives them a believable reason to contact you with a phishing scam. Of course, if you put in your email address or your password and click through, you'll be submitting the filled-in web form to the crooks.

PayPal SMS scams – don’t fall for them!
2020-02-05 17:39

Crooks almost certainly can't get hold of a server name that ends with, say, paypal DOT com, but can create any number of subdomains that start with paypal DOT and end with some unrelated domain. The suspicious-looking right-hand end of a full domain name often ends up invisible on a mobile phone because it won't fit in the address bar.

Community Housing Nonprofit Hit with $1.2M Loss in BEC Scam
2020-02-04 22:50

A non-profit community housing collective has been swindled out of more than $1.2 million in a business email compromise campaign. Red Kite Community Housing, a coop housing association in High Wycombe, U.K. announced in a recent website notice that £932,000 of the money paid into its coffers by tenant-owners was transferred to cybercrooks thanks to a convincing domain-spoofing effort.

Ashley Madison Breach Extortion Scam Targets Hundreds
2020-02-03 15:56

Nearly five years after the high-profile Ashley Madison data breach, hundreds of impacted website users are being targeted by a new extortion attack this past week. Victims are receiving emails threatening to expose their Ashley Madison accounts - along with other embarrassing data - to family and friends on social media and via email, unless they pay a Bitcoin ransom.

FBI issues warning about lucrative fake job scams
2020-01-23 10:30

What's the difference between a real job and the horde of fake ones found on the internet? It's even more basic than the fact that one is fake - fake jobs are suspiciously easy to get interviews for.

The Six Million Dollar Scam: London cops probe Travelex cyber-ransacking amid reports of £m ransomware demand, wide-open VPN server holes
2020-01-08 06:03

More than a week after its website and online services were taken offline by malware, foreign currency super-exchange Travelex continues to battle through what has become an increasingly damaging outage that may have unpatched VPN servers at its heart. While the capital's cops declined to name a specific victim, a spokesperson told us: "On Thursday, 2 January the Met's Cyber Crime Team were contacted with regards to a reported ransomware attack involving a foreign currency exchange. Enquiries into the circumstances are ongoing."