A perfect replica of the legitimate O2 website is used in the scheme

Sep 18, 2012 14:22 GMT  ·  By

Emails apparently coming from [email protected] warn recipients that their O2 email accounts are unsecured.

Entitled “YOUR O2 EMAIL ACCOUNT IS UNSECURED,” the notifications attempt to convince users to visit a replica of the O2 email login page and enter their credentials.

“To ensure your O2 online account is secured. Click here and follow steps to protect your O2 Online account now with new O2 EV SSL certification. We appreciate your prompt attention to ensure O2 online account safety. This security ALERT intended to help protect you and your account,” the shady emails read.

The malicious website that hides behind the link contained in the email is very well designed. It almost perfectly replicates the genuine site, and to make it even more realistic, all the buttons and links – except for the Sign In button - are designed to point to the legitimate domain.

We advise users to be on the lookout for such emails. If you’re a victim, be sure to change your O2 password as soon as possible.