Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Spam Reports

December 5th, 2011, 19:27 GMT · By Eduard Kovacs

Amazon Expiration Emails Lead to Phishing

SHARE:

Adjust text size:


Beware of Amazon account expiration warnings
Enlarge picture
Emails that alert recipients their Amazon online accounts are about to be deactivated turn out to be part of a cleverly designed phishing campaign that targets users with the purpose of stealing their credentials.

The message provided by Graham Cluley reads:

Dear customer,
Your online account is about to expire and will be deactivated.
Please confirm wether you want to continue using Amazon or not.
If the answer is yes, download and complete the attached form.
If the answer is no, please ignore this e-mail.
Best wishes,
Amazon Team
Note - Do not reply to this e-mail.

The message comes with an HTML attachment that represents a form which requires the user to provide loads of sensitive information that will allow a hacker to steal his account.

Sophos detected the attached file as Troj/Phish-AZ which means that a good antivirus solution can keep you safe in case you might believe the warning to be true.

I will take this opportunity to remind you how to avoid phishing campaigns and how to identify malicious emails.

First of all, legitimate emails rarely come with attachments, especially if they consist of .zip or HTML files. Unfortunately, cybercrooks devised ways of hiding their malicious files even in PDF or Windows Help files, so treat everything with suspicion.

Even if the sender’s email address can be easily spoofed to resemble a legitimate address, website URLs are much harder to fake. If the message contains a link that should point to Amazon, PayPal or any other similar site, be careful to check the precise name. Amazon.com is not the same as Amason.com

Finally, check for spelling errors. In the above example you’ll notice that the cybercriminals misspelled the word “whether”, a typo that would most certainly not appear in a legitimate email coming from a company.

TELL US WHAT YOU THINK:

1,285 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


iPad 2 and Millions of Dollars Advertised by Chinese Phishing Sites

Google, AOL, Yahoo and Microsoft Partner with Agari to Reduce Phishing

Nepali Hacker Showcases Results of Massive Facebook Phishing (Updated)

How to Protect Yourself from 'Pharming' Websites

Thanksgiving Brings Bank Phishing Scams

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM