Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

February 24th, 2011, 06:14 GMT · By

Aggressive PayPal Phishing Scam Hitting People's Inboxes

SHARE:

Adjust text size:


PayPal users targeted in new phishing campaign
Enlarge picture
Security researchers from Sophos warn that a new wave of PayPal phishing emails are hitting people's inboxes in an attempt to trick them into exposing their login credentials.

The emails bear a subject of "Please confirm your identity" and have forged headers to appear as originating from PayPal.

However, it appears the attackers forgot to also change the sending email address from tax@ato.gov.au, which suggests they previously ran a phishing campaign against Australian taxpayers.

The fake PayPal emails do not contain a link to a phishing site like most such attacks do. Instead they have an HTML document attached, which, when opened inside the browser, mimics the PayPal website and contains a form for inputting credit card data.

The email message does not stand out and uses a traditional lure. It informs recipients that unusual activity was detected on their accounts, which led to them being restricted.

They are asked to verify their identity using credit card details, so that account restrictions can be lifted. In order to make sure the form works, phishers included instructions on how to bypass the browser security mechanisms.

"When you will complete the document we have sent, remember to ALLOW javascript and ActiveX to run from the bar that will pop-up, otherwise we cannot verify the informations you have provided," they write.

"If you're ever uncertain whether a message really comes from PayPal or not, visit the real PayPal website and log in as usual. If they really have a security message for you, you'll be able to read it via the PayPal messaging system itself," advises Graham Cluley, senior technology consultant at Sophos.

In addition, the PayPal website is protected with SSL. Users are always advised to check for visual cues that indicate the connection is secure before logging into their accounts or providing any kind of information.

TELL US WHAT YOU THINK:

1,283 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


PayPal and Facebook Were the Most Phished Sites of 2010

New PayPal Phishing Campaign in Circulation

Well Crafted PayPal Phishing Emails in Circulation

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM